Andrei Sarealba ("we", "us") is the data controller for the personal data we process about you in connection with the SnappSocial service. This notice explains what we collect, why, and what your rights are.
Personal data we collect
- Account data: email address, hashed password, account creation date.
- Subscription data: subscription status, plan, billing period and a Paddle customer/subscription reference.
- Usage and device data: pages visited, features used, IP address, browser/device type, approximate location derived from IP.
- Support correspondence: anything you send us by email or via in-app messages.
- Cookies: essential cookies to keep you signed in, and minimal analytics cookies to understand product use.
We do not store payment card details. Card and billing information is collected and processed by our payment provider, Paddle.
Why we use your data and our legal basis
- To provide the Service — account creation, sign-in, showing you your subscription and Pro features (legal basis: performance of a contract).
- To process payments via Paddle (legal basis: performance of a contract).
- To prevent fraud and keep the Service secure (legal basis: legitimate interests).
- To improve the product through aggregated analytics (legal basis: legitimate interests).
- To communicate with you about service issues, changes and support (legal basis: performance of a contract / legitimate interests).
- To comply with legal obligations such as tax and accounting record-keeping (legal basis: legal obligation).
Who we share data with
- Paddle.com Inc / Paddle.com Market Ltd — Merchant of Record. Paddle handles checkout, payment processing, subscription billing, tax compliance and refunds. See Paddle's privacy notice.
- Hosting and infrastructure providers who run the Service on our behalf, including Lovable Cloud (which is built on Supabase) and Cloudflare.
- Professional advisers (legal, accounting) where necessary.
- Authorities where required by law.
International transfers
Some of our service providers are located outside the UK/EEA. Where this is the case we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.
Data retention
We keep account and subscription data for as long as your account exists, plus a short period afterwards for security, legal and accounting purposes (typically up to 7 years for tax records). You can request deletion at any time (see "Your rights").
Security
We apply appropriate technical and organisational measures to protect your data, including encryption in transit, encrypted storage, access controls, and regular review of our infrastructure.
Your rights
Subject to applicable law (including UK GDPR for UK/EEA residents) you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- object to or restrict certain processing;
- request a copy of your data in a portable format;
- withdraw consent where processing is based on consent;
- complain to your local supervisory authority.
We aim to respond to requests within one month. To exercise your rights, email support@snappsocial.com.
Cookies
We use a small number of essential cookies to keep you signed in. We may also use minimal analytics cookies to understand which features are used. You can manage cookies via your browser settings.
Changes to this notice
We may update this notice from time to time. The "last updated" date at the top of this page indicates when it was last changed.
Contact
For privacy questions, contact support@snappsocial.com.