Privacy Policy
Version 1.0 · 18 August 2026
1. Data controller
SMARTEDTECH SL (NIF B66970831, VAT ESB66970831), Carrer Agricultura, 16, 1º, puerta 9, 08320 El Masnou, Barcelona, Spain. Privacy contact: privacy@vitrinoro.com. SMARTEDTECH SL is the controller for personal data of Vitrinoro account holders.
When a published customer site collects end-customer data (for example bookings, once that feature is live), the business owner is the controller of that visitor data and SMARTEDTECH SL is the processor. That relationship is set out in the Data Processing Agreement.
2. Data we collect
Account data: email address; password (handled by Supabase Auth; we do not store the plaintext); display name from Google if you use Google sign-in.
Studio content: business name, category, tagline, description, about, hours, location, services, social links, design choices, owner contact and billing identity fields you enter, and photographs you upload (EXIF including GPS is stripped before variants are stored).
Billing data: Stripe customer id, subscription status, plan and period end. We do not store card numbers.
Consent records: which cookie categories you chose, and which legal document version you accepted, with locale and time.
Technical data: IP address and security logs as needed to run the service. Product analytics (PostHog) and error reporting (Sentry) are not live. If they are enabled later, they will require the matching consent category and an update to this Policy.
3. Legal basis
Contract performance (GDPR Art. 6(1)(b)): creating and hosting your site, authenticating you, and processing subscription payments.
Legitimate interest (Art. 6(1)(f)): securing the service and preventing fraud.
Consent (Art. 6(1)(a)): non-essential storage (device drafts, PWA invite, service worker) and any future analytics cookies. You may refuse as easily as you accept.
Legal obligation (Art. 6(1)(c)): tax and accounting records.
4. How we use data
We use this data to provide Vitrinoro, process payments through Stripe, communicate about the account, keep the service secure, and meet legal duties. We do not sell personal data. We do not use your studio content to train AI models.
6. Retention
Account and studio data are kept while the account exists. After a deletion request we aim to remove reachable personal data within 30 days, then retry leftovers. Consent evidence and tax-relevant billing identifiers may be kept as required by law. Unpublished sites keep their data; unpublishing is not deletion.
7. Your rights
Under the GDPR you may access, rectify, erase, restrict, port and object to processing of your personal data, and withdraw consent. Write to privacy@vitrinoro.com. You may also complain to the Agencia Española de Protección de Datos (AEPD).
8. KVKK (Turkish residents)
If you are in Türkiye, Law 6698 (KVKK) also applies. You may exercise access, correction, deletion, restriction and objection rights by writing to privacy@vitrinoro.com. We will respond within the statutory period.
9. Sub-processors
Current subprocessors: Supabase (database, auth and private file storage, eu-west-3, Paris); Vercel (application hosting, cdg1, Paris); Stripe (payments; card data stays with Stripe). Resend is configured for transactional email and is not a live sender until the sending domain is authenticated.
International transfers, if any, use EU Standard Contractual Clauses where required.
10. Contact
SMARTEDTECH SL (NIF B66970831, VAT ESB66970831), Carrer Agricultura, 16, 1º, puerta 9, 08320 El Masnou, Barcelona, Spain. Privacy contact: privacy@vitrinoro.com.