Privacy Policy
Last updated: 31 August 2026. This template is written to align with GDPR principles but should be reviewed by a qualified lawyer for your specific setup before launch.
1. Data we collect
- Account data: username, email address, hashed password.
- Usage data: session activity, IP address, and audit logs of security-relevant actions (login, password changes, subscription changes).
- Payment data: transaction references and amounts. We do not store full card numbers — payment processing is handled by our payment provider.
2. Legal basis & purpose
We process this data to provide the service you've signed up for (contract), to keep the platform secure (legitimate interest), and, where applicable, to meet legal obligations (e.g. financial record-keeping).
3. Your rights under GDPR
If you are located in the EU/EEA, you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us via the contact page to exercise these rights.
4. Data retention
We retain account and audit-log data for as long as your account is active, plus a reasonable period afterward for security and legal purposes.
5. Cookies & analytics
We use strictly necessary cookies for authentication and session management, and a cookie to remember your cookie consent choice. We also run first-party website analytics: for visitors who accept cookies, we log the page visited, an approximate location derived from your IP address (city/country level — we do not store your raw IP address), device type, browser, and referring site. This is used only to understand how the site is used and is never sold or shared with advertisers. Visitors who decline cookies are not tracked. See our Cookie Policy for details.
6. Third parties
We use a payment provider to process subscription payments and may use an email delivery provider to send transactional emails (verification, password resets). We use a third-party IP geolocation service solely to derive the approximate city/country for the analytics described above. These providers only receive the data necessary to perform their function.
7. Security
Passwords are hashed, sessions are protected against fixation, and all forms are protected against CSRF. No system is 100% secure, and we encourage strong, unique passwords.
8. Contact
For privacy questions or requests, use our contact page.