Privacy policy
Last updated: FECHA_ACTUALIZACION
This explains what data we process, why, on what legal basis, and what you can do about it. It follows articles 13 and 14 of the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Who the controller is
The controller of your data is:
- Legal name: RAZON_SOCIAL
- Tax number (NIF): NIF
- Address: DIRECCION
- Data protection contact: EMAIL_CONTACTO
- Data Protection Officer: none appointed, as no case under article 37 GDPR applies
What data we process
Depending on how you use Notazo, we process these categories:
- Identity and contact data: name, email, phone if you give it to us
- Delivery data: street address, town, postcode and province
- Billing data: tax number when you need an invoice as a business
- Payment data: handled by Stripe. We never see or store your card number
- Account data: email, language and the venues you attach to the dashboard
- Staff first names: you enter these in the dashboard for the team leaderboard
- Site usage data: only if you accept measurement cookies
Tap logs contain no personal data
When a customer taps their phone on a plate, we store the timestamp, the device identifier, an approximate country and a cryptographic digest of the browser string. We do not store the IP address, we store no device identifiers, and the redirect service sets no cookies at all.
So we cannot tell you who tapped the plate, and neither can you. That is a design decision, not a technical limitation.
Why we process your data, and on what legal basis
Each purpose has its own legal basis under article 6 GDPR:
- Handling your order, shipping it and supporting you: performance of a contract, article 6(1)(b)
- Issuing the invoice and keeping accounting and tax records: legal obligation, article 6(1)(c)
- Creating and maintaining your account and sending your sign-in link: performance of a contract, article 6(1)(b)
- Reading and storing your venue's Google review count and rating: performance of a contract, article 6(1)(b). This is business data, not data about you as an individual
- Emailing you the monthly report, if you turn it on: consent, article 6(1)(a)
- Setting advertising measurement cookies: consent, article 6(1)(a)
- Preventing fraud and keeping the service secure: legitimate interest, article 6(1)(f)
Who else processes your data
We work with providers acting as processors, who only handle your data on our instructions under a contract meeting article 28 GDPR:
- Neon (database): data is stored in the Frankfurt region, Germany, inside the European Union
- Vercel (hosting for the site and the dashboard)
- Cloudflare (domain and redirect service)
- Stripe (payments and tax calculation). Stripe acts as an independent controller for payment data
- Resend (transactional email)
- Meta Platforms (advertising measurement), only if you accept measurement cookies
Google and your business data
To draw your review chart we query the Google Places API with your venue's public place identifier. That request carries no personal data about you or your customers: we ask only for the review count and the rating, both public facts about your listing.
International transfers
The database sits in the European Union. Some of our providers are established outside the European Economic Area or may process data from there. Those transfers rely on the standard contractual clauses approved by the European Commission or on an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified.
You can ask us for a copy of the safeguards in place by writing to EMAIL_CONTACTO.
How long we keep data
We keep each item for the minimum time needed:
- Order and billing data: six years, under article 30 of the Spanish Commercial Code, and four years for tax purposes under the General Tax Act
- Account and venue data: while the account is active and then for the limitation period for legal claims
- Your venues' review history: while the account is active. This is the data that makes the dashboard worth having
- Tap logs: anonymous, so no erasure period applies
- Measurement cookies: the durations listed in the cookie policy
Your rights
You can exercise your GDPR rights at any time:
- Access: find out what data of yours we process
- Rectification: correct anything inaccurate
- Erasure: ask us to delete data that is no longer needed
- Restriction: ask us to stop using it temporarily
- Portability: receive your data in a structured, commonly used format
- Objection: object to processing based on our legitimate interest
- Withdraw consent at any time, without affecting the lawfulness of processing before you did
How to exercise them, and where to complain
Write to EMAIL_CONTACTO saying which right you want to exercise. We will answer within one month.
If you think we have handled your request badly, you can complain to the Spanish Data Protection Agency, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
Security
We apply technical and organisational measures to protect your data: encryption in transit, access limited to the people who need it, and providers with recognised security certifications. No system is perfect, but we handle your data the way we would want ours handled.
For any question about this page, write to us at EMAIL_CONTACTO.