Privacy Policy
Last updated: April 25, 2026
1. Who is the controller
The data controller is {EMPRESA}, tax ID {NIF}, registered at {DOMICILIO}. For any privacy-related question, write to {EMAIL_CONTACTO}.
2. What we collect
- Account data: username, email, bcrypt-hashed password.
- Usage data: the furniture projects you save, board and hardware selections, exports performed.
- Billing data (only if you subscribe): tax name, address, VAT/tax ID. Card details are handled by Stripe directly — we never store them.
- Technical data: IP address, browser, access timestamps, kept in logs for up to 90 days for abuse prevention.
3. What we use it for
- Letting you sign in and keep your designs across sessions.
- Processing your subscription, issuing invoices, providing support.
- Notifying you of important changes (end of trial, payment problems).
- Detecting and preventing abuse (mass account creation, scraping, attacks).
4. Legal basis
- Performance of contract — for everything related to your account and subscription.
- Legal obligation — for invoicing and tax compliance.
- Legitimate interest — for security logs and service integrity.
5. Who else sees your data
We work with the following data processors. All comply with GDPR and only process your data for the services we engage them for:
- Stripe Payments Europe Ltd. — payment gateway (Ireland; data may transfer to the US under Standard Contractual Clauses).
- {HOSTING} — web servers hosting the application and database.
- {EMAIL_PROVIDER} — transactional emails (verification, password reset, invoices).
6. How long we keep your data
- Account data and projects: as long as your account is active. If you ask to delete it, we remove it within 30 days.
- Invoices and accounting: 6 years, as required by Spanish tax law.
- Technical logs: 90 days.
7. Your rights
As an EU resident, you can:
- Access the data we hold about you.
- Rectify it if it's wrong.
- Erase it ("right to be forgotten").
- Restrict or object to processing.
- Port your data in standard JSON format.
- Lodge a complaint with the Spanish Data Protection Agency (aepd.es) if you feel we breach your rights.
To exercise any of them, send an email to {EMAIL_CONTACTO}. We answer within 30 days.
8. Cookies and local storage
We don't use tracking or advertising cookies. Only:
- One session cookie (PHP) to keep you logged in while you browse.
- localStorage in your browser to save preferences and unsaved drafts.
Both are technically necessary for the service to work, so they don't require prior consent.
9. Changes to this policy
If we change anything important (new processors, additional purposes), we email you at least 15 days before the change takes effect.