Legal

Privacy Policy

Effective date: March 25, 2026. This policy explains how NicheSpotted collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Italian law.

1. Data Controller

The data controller is Salvatore Castellitti, based in Italy.

For any privacy-related request or inquiry, contact: s.castellitti.dev@gmail.com

2. Data We Collect

We collect the following categories of personal data:

DataPurposeLegal Basis
Email addressAccount creation, authentication, transactional emailsContract
Usage data (pages visited, features used, search queries)Improving the service, analyticsLegitimate interest
Payment metadata (subscription status, plan)Billing and access controlContract
IP addressSecurity, fraud prevention, analyticsLegitimate interest
Device & browser typeAnalytics, compatibilityLegitimate interest

We do not collect payment card details. All payment processing is handled by Polar (polar.sh), which has its own privacy and security practices.

We do not collect or process sensitive personal data (health, religion, ethnicity, etc.).

3. How We Use Your Data

  • Provide, operate, and maintain the NicheSpotted service
  • Authenticate your account and manage your subscription
  • Send transactional emails (login codes, billing receipts, policy updates)
  • Analyze usage patterns to improve features and fix bugs
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Analytics and Tracking

We use the following analytics tools that may process your personal data:

  • Vercel Analytics — collects anonymized page view data. No cookies are used. Privacy policy: vercel.com/legal/privacy-policy

Vercel Analytics does not use cookies and does not track individuals across sessions. No opt-out is required.

5. Cookies

We use a minimal number of cookies:

  • Session cookie — strictly necessary for authentication. Expires at session end.

We do not use advertising, tracking, or profiling cookies. You can manage cookies through your browser settings. Disabling strictly necessary cookies will prevent you from logging in.

6. Data Sharing and Third Parties

We share your data only with:

  • Polar (polar.sh) — payment processing. Your billing data is governed by their privacy policy.
  • Vercel — hosting and infrastructure. Servers are in the EU/US.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

We do not currently transfer personal data outside the EU/EEA for analytics purposes. If this changes, we will update this policy and rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Data Retention

We retain your personal data for as long as your account is active. After you delete your account, your personal data is permanently deleted within 7 weeks.

Billing records and transaction logs are retained for 10 years as required by Italian accounting and tax law (D.P.R. 600/1973).

Anonymized, aggregated analytics data that cannot identify you may be retained indefinitely.

8. Your Rights Under GDPR

As an EU/EEA resident, you have the following rights regarding your personal data:

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request deletion of your data
  • Right to restrict processing — limit how we use your data
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right not to be subject to automated decision-making

To exercise any of these rights, email s.castellitti.dev@gmail.com. We will respond within 30 days. We may ask you to verify your identity before processing the request.

9. Right to Lodge a Complaint

If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the Italian data protection authority:

Garante per la protezione dei dati personali
Website: garanteprivacy.it
Email: garante@gpdp.it

You may also contact the supervisory authority in your EU member state of residence.

10. Children's Privacy

NicheSpotted is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with their data, please contact us at s.castellitti.dev@gmail.com and we will delete it promptly.

11. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, or destruction. These include encrypted connections (HTTPS), secure session management, and access controls.

No system is 100% secure. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority as required by GDPR (within 72 hours of becoming aware).

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email at least 14 days before any material changes take effect. The updated policy will always be available at this URL with a revised effective date.

Privacy questions? Email s.castellitti.dev@gmail.com and we will respond within 30 days.