Last updated: [DATE — set when published]
Data controller: [OPERATOR LEGAL NAME], [ADDRESS] — contact: [CONTACT EMAIL]. This policy covers the Polytail website and app.
No advertising trackers. The only cookies are the session cookie (sign-in state, CSRF protection) — strictly necessary, no consent banner required for them.
We share data only with the processors needed to run the service: Stripe (payments), [HOSTING PROVIDER — e.g. Hetzner Online GmbH, Germany] (hosting), [EMAIL PROVIDER — e.g. Resend/Postmark] (transactional email), [BACKUP PROVIDER — e.g. Backblaze B2, if used for encrypted backups]. [TO REVIEW: list actual providers + transfer safeguards (SCCs) for any non-EU processor.]
Account data: while your account exists, then deleted within [30] days of account deletion. Invoicing records: [10 years] (legal requirement). Server logs: [90] days.
You can request access, rectification, erasure, portability, restriction or object to processing by writing to [CONTACT EMAIL]. You can lodge a complaint with the CNIL (cnil.fr) or your local supervisory authority. To delete your account and data, contact us at the same address [TO IMPROVE: self-service account deletion].
Passwords are hashed with argon2; transport is encrypted (HTTPS); payment data never touches our servers; access to production data is restricted to the operator. No system is perfectly secure — in case of a breach affecting your data we will notify you and the authority as required by law.