Privacy Policy
Last updated: March 1, 2026
We collect information you provide directly: name, email address, payment details (processed by Stripe — we never store card numbers), and any profile information you choose to add. We also collect usage data such as pages visited, features used, and device/browser information.
We use your data to: provide and improve our services (legal basis: performance of contract); process transactions (legal basis: performance of contract); send transactional emails such as account confirmation and purchase receipts (legal basis: performance of contract); analyze usage to improve the platform (legal basis: legitimate interest). We do not sell your personal data to third parties.
Data is stored on secure servers (Neon PostgreSQL, hosted in the EU). We use industry-standard encryption (TLS in transit, AES at rest). Access to production data is restricted to authorised personnel only.
We use the following third-party services that may process your data: Stripe (payments), Vercel (hosting & analytics), Nodemailer/Gmail (transactional email), Upstash (rate limiting — stores IP hashes only, no PII).
You have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your account and associated data; withdraw consent for optional processing (e.g. analytics cookies); lodge a complaint with your national data protection authority (in France: the CNIL at www.cnil.fr; in Belgium: the APD at www.autoriteprotectiondonnees.be; in the UK: the ICO at www.ico.org.uk). Contact us at the address below to exercise these rights.
We use strictly necessary cookies for authentication and session management. With your consent, we also use analytics cookies (Vercel Analytics) to understand how users interact with our platform. You can manage your cookie preferences at any time via the cookie settings button.
We retain your personal data for as long as your account is active. If you delete your account, your personal data is permanently deleted within 30 days, except where we are required to retain it for legal or tax obligations (e.g. transaction records, retained for 5 years under French accounting law). Anonymised analytics data may be retained indefinitely.
For privacy-related requests or questions, contact us at: esseck44@gmail.com
