Privacy Policy
Effective date: 2026-05-14. This policy explains what personal data we collect, why we collect it, how long we keep it and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Data controller
The data controller is the operator of FootClaw. You can contact us at privacy@footclaw.example for any privacy-related question.
2. What we collect
Account data: email, optional username and avatar. Provided directly by you.
Billing data: cryptocurrency wallet address or external payment ID. No card numbers are stored on our servers.
Usage data: pages visited, features used, language preference, theme preference. Collected for product analytics.
Technical data: IP address (masked after 24 hours), browser type, device type. Collected for security and uptime monitoring.
3. Legal basis
Account and billing data — contractual necessity (Art. 6(1)(b) GDPR).
Usage and technical data — legitimate interest (Art. 6(1)(f)) for service operation and abuse prevention.
Optional analytics and marketing emails — explicit consent (Art. 6(1)(a)) given via the cookie banner or settings.
4. Sharing
We share data only with sub-processors necessary for service operation: hosting provider, email delivery service (Resend), payment processor (NowPayments / Stripe), product analytics (PostHog), error tracking (Sentry). All sub-processors are contractually bound by GDPR-equivalent terms.
We never sell your data and we never share it for third-party advertising.
5. Data retention
Account data: kept while your account exists, deleted within 30 days of account deletion.
Billing records: kept for 7 years as required by tax law.
Analytics data: kept for 24 months in aggregated form.
6. Your rights
You can request access, correction, deletion or export of your personal data at any time via Settings or by emailing privacy@footclaw.example.
You can also lodge a complaint with your local data protection authority.
7. International transfers
Some sub-processors operate outside the EEA. In those cases we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data is protected to GDPR standards.
8. Security
We use TLS encryption in transit, hashed passwords (Argon2id), least-privilege access controls and quarterly security reviews. Despite this, no system is 100% secure; we will notify you within 72 hours of any breach affecting your data.
Contact: legal@footclaw.example · Last updated: 2026-05-14