Privacy Policy

Last updated: [DATE — set when published]

1. Who we are

Data controller: [OPERATOR LEGAL NAME], [ADDRESS] — contact: [CONTACT EMAIL]. This policy covers the Polytail website and app.

2. What we collect

  • Account data: your email address and a salted argon2 hash of your password (we cannot read your password), your subscription status, and your Stripe customer reference.
  • Payment data: handled entirely by Stripe (their privacy policy). We never see or store card numbers.
  • Technical data: standard server logs (IP address, requested pages, timestamps) kept for security and debugging, retained [90] days.
  • Public blockchain data: the wallet statistics shown in the product are computed from public on-chain records and public APIs; they are not data about our users.

No advertising trackers. The only cookies are the session cookie (sign-in state, CSRF protection) — strictly necessary, no consent banner required for them.

3. Why we process it (legal bases, GDPR)

  • Providing the service and your subscription — contract (art. 6(1)(b)).
  • Security, abuse prevention, logs — legitimate interest (art. 6(1)(f)).
  • Invoicing and accounting records — legal obligation (art. 6(1)(c)).
  • Transactional emails (password reset, service notices) — contract. No marketing emails without separate consent.

4. Processors and transfers

We share data only with the processors needed to run the service: Stripe (payments), [HOSTING PROVIDER — e.g. Hetzner Online GmbH, Germany] (hosting), [EMAIL PROVIDER — e.g. Resend/Postmark] (transactional email), [BACKUP PROVIDER — e.g. Backblaze B2, if used for encrypted backups]. [TO REVIEW: list actual providers + transfer safeguards (SCCs) for any non-EU processor.]

5. Retention

Account data: while your account exists, then deleted within [30] days of account deletion. Invoicing records: [10 years] (legal requirement). Server logs: [90] days.

6. Your rights

You can request access, rectification, erasure, portability, restriction or object to processing by writing to [CONTACT EMAIL]. You can lodge a complaint with the CNIL (cnil.fr) or your local supervisory authority. To delete your account and data, contact us at the same address [TO IMPROVE: self-service account deletion].

7. Security

Passwords are hashed with argon2; transport is encrypted (HTTPS); payment data never touches our servers; access to production data is restricted to the operator. No system is perfectly secure — in case of a breach affecting your data we will notify you and the authority as required by law.