Privacy Policy
1. Introduction
PilaFlow ("we", "us", "our", or "Company") respects the privacy of our users ("you" or "your"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (the "Service").
This privacy policy is compliant with the General Data Protection Regulation (GDPR) applicable to the European Union and other privacy laws. Please read this privacy policy carefully. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Email address, name, password, profile picture (if linked via Google OAuth)
- Studio Information: Studio name, description, address, contact information
- Instructor Data: Names, specialties, color preferences, availability schedules
- Client Data: Names, email addresses, phone numbers, notes, attendance records
- Booking Information: Class dates, times, instructors assigned, client bookings, capacity
- Communication Data: Emails, inquiries, support messages
2.2 Information Collected Automatically
- Device Information: IP address, browser type, operating system, device type
- Usage Data: Pages visited, time spent, features used, interactions
- Location Data: General location derived from IP address (not precise geolocation)
- Session Data: Session tokens stored in sessionStorage and localStorage
- Cookies: Non-essential cookies only after explicit consent
2.3 Information from Third Parties
- Google OAuth: When you authenticate via Google, we receive your email, name, and profile picture
- Stripe (historical only): PilaFlow no longer takes payments and has no checkout. While in-app payments were briefly available, Stripe processed them and returned payment references (such as a payment identifier, amount and status) which we still hold as accounting records. We never received or stored card details.
PilaFlow is free to use. If you choose to donate through Buy Me a Coffee, that transaction happens on their platform under their privacy policy; we do not receive your payment details and the donation is not linked to your PilaFlow account.
3. Legal Basis for Processing (GDPR Art. 6)
We process your data based on the following legal grounds:
- Article 6(1)(b): Contract Performance - Processing necessary to provide the Service you requested
- Article 6(1)(a): Consent - For non-essential cookies, marketing communications, and optional features
- Article 6(1)(f): Legitimate Interests - For security, fraud prevention, analytics, and service improvement
- Article 6(1)(c): Legal Obligation - When required by law
4. How We Use Your Information
- To create and maintain your account
- To provide, operate, and improve the Service
- To send you service-related notifications and updates
- To respond to your inquiries and provide customer support
- To monitor and analyze trends, usage, and activities (for service improvement)
- To detect, prevent, and address technical issues and security incidents
- To comply with legal obligations
5. How We Share Your Data
5.1 Third-Party Service Providers
We may share your information with trusted third parties that assist us in providing and improving the Service:
- Supabase (Database & Auth): Hosted in EU and US; provides authentication and data storage
- Stripe (former payment processor): We no longer send any data to Stripe. It processed the payments taken while in-app checkout existed, and we retain those payment records for accounting purposes
- Google (OAuth): Provides authentication service
- Font Awesome & Google Fonts: Provide design resources (non-personal data)
- Sentry (Error Tracking): Monitors application errors for stability improvement
5.2 Data Processors
All third parties listed above have Data Processing Agreements (DPAs) in place ensuring GDPR compliance.
5.3 Legal Requirements
We may disclose your information if required by law, court order, or government request.
5.4 No Sale of Data
We do not sell, trade, or rent your personal information to third parties.
6. International Data Transfers
Your information may be transferred to countries other than where you reside, including to the United States (Supabase and Sentry, and historically Stripe). These countries may have data protection laws different from your home country.
When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where available
- Binding corporate rules
7. Data Retention
We retain your information for as long as necessary to provide the Service:
- Account Data: Retained while your account is active; deleted after you request account deletion (right to erasure) — see “How to Exercise Your Rights” below
- Booking & Client Records: Retained for historical reference unless deleted
- Payment Records: Records of payments taken while in-app checkout existed are retained for 7 years for accounting and legal compliance. No new payment records are created
- Logs & Error Data: Automatically deleted after 30 days (Sentry)
- Session Data: Expires when you log out
8. Your Rights (GDPR Articles 15-22)
Under GDPR, you have the following rights:
8.1 Right of Access (Art. 15)
You can request a copy of all personal data we hold about you. Contact support to request a data export (see contact details below). We will provide the data within 30 days.
8.2 Right to Rectification (Art. 16)
You can request correction of inaccurate or incomplete information about yourself by contacting us at the email below.
8.3 Right to Erasure (Art. 17 - "Right to be Forgotten")
Contact support to request account deletion and erasure of all associated data. We will process your request within 30 days, except where legally required to retain certain data (e.g. payment records).
8.4 Right to Restrict Processing (Art. 18)
You can request that we limit how we use your data while we handle a dispute or request.
8.5 Right to Data Portability (Art. 20)
Contact support to request a copy of your data in a machine-readable format (e.g. JSON/CSV) to transfer to another service. We will provide it within 30 days.
8.6 Right to Object (Art. 21)
You can object to processing based on legitimate interests. We will honor this request.
8.7 Withdrawal of Consent
You can withdraw consent to non-essential cookies and marketing communications at any time.
How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@pilaflow.cloud. For account deletion and data export, send an email from the address linked to your account; we will process your request within 30 days.
9. Security Measures
We implement industry-standard security measures to protect your information:
- HTTPS encryption for all data in transit
- Row-Level Security (RLS) policies in our database
- Secure password storage and authentication via Supabase Auth
- Regular security updates and vulnerability scanning
- No storage of credit card information; we never receive card details
- Access controls and audit logging
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
10. Cookies and Local Storage
We use the following storage mechanisms (consent required for non-essential items):
10.1 Essential Cookies/Storage (No Consent Required)
sessionStorage: pilaflow_session— Authentication token (expires on logout)sessionStorage: auth_token— Temporary auth data
10.2 Functional Storage (Requires Consent)
localStorage: pilaflow_session— Persists login sessionlocalStorage: pilaflow_last_studio— Remembers selected studiolocalStorage: pilaflow_cookie_consent— Stores your consent preferences
10.3 How to Manage Cookies
You can manage your cookie preferences through our Cookie Consent Banner or your browser settings. Note that disabling functional cookies may limit service functionality.
11. Children's Privacy
The Service is not intended for children under 16 years old. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal data, we will delete such information promptly.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices:
- Operator: PilaFlow di Mario Rossi
- Email: privacy@pilaflow.cloud
- Address: Via Roma 12, 20121 Milano (MI), Italia
- VAT / Tax ID: IT01234567890
- Data Protection Officer: Not appointed. Privacy requests go to the email above.
13. Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.
For Italy: Garante per la Protezione dei Dati Personali (Authority for the Protection of Personal Data)
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by updating the "Last updated" date and, if required, obtaining your consent.