Legal
Privacy Policy
Last updated: 18 August 2026
The short version: we store your email, your profile and what you prep, all in the EU. Your card details live with Stripe, never with us. No trackers, no ads, no selling data. You can see, correct or delete your data whenever you like.
1. Who is responsible for your data
The data controller is Mark Makin, an independent professional (autonomo) registered in Spain, contactable at info@markmakin.com. This policy explains what we collect, why, where it lives and the rights you have under the EU and UK GDPR.
2. What we collect, and why
- Account data: your email address, and the name and role you choose to add to your profile. Legal basis: performance of our contract with you.
- Usage data: which match documents you prep, your credits, your notes, and your support messages. Legal basis: performance of the contract, and our legitimate interest in running and improving the service.
- Billing data: your subscription plan and payment history. Your card number and billing address are collected and stored by Stripe, not by us; we never see your card details. Legal basis: performance of the contract and legal obligations (tax and accounting).
- Technical data: standard server logs (IP address, browser type, timestamps) kept for security. Legal basis: legitimate interest in keeping the service secure.
We do not use advertising trackers, we do not profile you, and we do not sell or share your data for marketing. We practise data minimisation: we hold the least we need to run the service.
3. Where your data lives
Your account and usage data are stored with Supabase on infrastructure in the European Union (AWS, Paris region). The application is served by Vercel. Payments are processed by Stripe as merchant of record. Transactional email is delivered by our email provider.
These providers act as our processors under data processing agreements. Where a processor transfers data outside the EU or UK (for example some Vercel or Stripe infrastructure), the transfer is protected by the European Commission's Standard Contractual Clauses or an equivalent lawful mechanism.
4. How long we keep it
- Account and usage data: for as long as your account exists, then deleted or anonymised within 90 days of account closure.
- Billing records: kept as long as tax law requires (in Spain, generally at least 4 years).
- Security logs: up to 12 months.
- Support conversations: up to 2 years, so we can follow up properly.
5. Your rights
You can ask us at any time to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, or hand it over in a portable format. Where processing is based on consent, you can withdraw consent at any time.
Email info@markmakin.com and we will respond within one month. You also have the right to complain to a supervisory authority: in Spain the AEPD (aepd.es), in the UK the ICO (ico.org.uk), or the authority where you live.
6. Security
All traffic is encrypted in transit (HTTPS with HSTS). Data is encrypted at rest by our hosting providers. Access to accounts is by secure one-time email links rather than stored passwords. Row-level security in our database means each account can only ever read its own data, enforced at the database itself. Payment credentials never touch our systems.
No system is perfectly secure, but if a breach ever affects your data we will notify you and the relevant authority as the law requires.
7. Cookies
We use only essential cookies: the session cookies that keep you signed in. We set no analytics, advertising or third-party tracking cookies. See the Cookie Policy for the full list.
8. Changes to this policy
If we change this policy in a meaningful way we will tell you by email or in the app before the change takes effect. The date at the top always shows the current version.