Carbon Pro
Back
GDPR-aligned

Privacy Policy

How we protect your data and respect your privacy.

Data we collect

  • Account data: name, email, user ID (UUID), account creation date, and last login — for login, subscription management, and support.
  • Authentication data: passwords encrypted with bcrypt, active sessions, JWT tokens, and login attempts — via Lovable Cloud Authentication.
  • Calculator results and reports: complete questionnaire answers (up to 30 questions), computed scores, applied conversion factors, generated Smart Reports, AI notes, and dates of each calculation — linked to your user ID and encrypted at rest.
  • Payment data: handled exclusively by Stripe.com (Merchant of Record). We do not store credit card numbers, CVV codes, or expiration dates. Stripe stores this data in accordance with PCI-DSS Level 1.
  • Usage data: pages visited, buttons clicked, interface errors, and session duration — in anonymized form to improve the product and detect outages.

Authentication & security

  • All passwords are hashed using bcrypt with a minimum cost factor of 10. No password is ever stored in plaintext.
  • Lovable Cloud manages the authentication system, including email/password login and OAuth (Google). We do not have access to user passwords.
  • User sessions expire automatically after a period of inactivity. The user can revoke all sessions from the dashboard.

Subscriptions & payments

  • All payment transactions are handled by Stripe.com, Merchant of Record. Stripe handles billing, tax collection, local compliance, and invoice issuance.
  • We only store the Stripe subscription ID (subscription_id), plan status (free/standard/business), and start/end dates. We do not store any direct financial data.
  • The user can request a copy of their invoices at any time via Stripe (billing portal) or the support team.

Questionnaire & report data

  • Questionnaire answers are used immediately to calculate the carbon footprint and generate reports. They are not shared with third parties and never sold.
  • Smart Reports are stored securely and accessible only to the user. PDF reports are generated on-the-fly and not stored on the server.
  • When sharing a public report via link or QR, a shortened version (Snapshot) is created without personal data or complete questionnaire answers.

Technical security

  • Encryption: all sensitive data is encrypted in transit via TLS 1.3 and at rest via AES-256 at the database level.
  • Access control (ACL): RLS policies are applied to all sensitive tables. No user can access another user's data, even via the API.
  • Backups: daily encrypted database backups are created. Copies are retained for at least 7 days.
  • Monitoring: we use automated monitoring to detect suspicious activity (repeated login attempts, anomalous API requests) and respond within hours.

Retention & deletion

  • We retain account data and reports while the account is active. The user can export their data before deletion.
  • Upon account closure: all personal data is deleted within 30 days. Reports and answers are deleted immediately. Payment records remain with Stripe for the legally required number of years.
  • Anonymized data (not linkable to a person) is retained longer for statistical and improvement purposes.

Cookies & analytics

  • Essential cookies: required for login, language, theme, and security (CSRF). Cannot be disabled.
  • Analytics cookies: used anonymously to understand how to improve the product (e.g., which questions users stop at). Declinable via browser settings.
  • Marketing cookies: we do not use marketing tracking cookies. We do not sell your data to advertising networks.

Your rights (GDPR / CCPA)

  • Access: you can request a complete copy of all your personal data (JSON or CSV) within 30 days.
  • Correction: you can update your account information (name, email, photo) from the dashboard at any time.
  • Deletion (right to be forgotten): you can delete your account and data via the dashboard or by email. No restriction applies to this right.
  • Portability: you can export your result history and reports as JSON on request. We assist you in transferring your data to another platform if requested.
  • Objection: you can object to the use of your data in statistical analyses. In this case, we only cancel the anonymized usage without affecting the core service.

International users

  • The primary server is located in the European Union (Ireland). Data is stored within the EU by default.
  • For users in California (CCPA): you have the right to know what data we collect, request its deletion, and opt out of its sale. We do not sell your data.
  • If you live outside the EU or United States, we adhere to international data protection standards and treat your data with the same level of protection.

Contact us — Privacy

  • Email: alaaameur045@gmail.com (replace with your real email before launch).
  • Response time: we answer privacy inquiries within 48 business hours. Complex requests (e.g., large data exports) may take up to 30 days.
  • If you believe your data has been compromised or misused, please notify us immediately via the same email.

Last updated: May 2026