Privacy Policy
The short version. We collect your email address so you can sign in, and a record of your subscription so we know whether to let you in. We do not sell your data, we do not run advertising trackers, and we never see your card details.
1. Who is responsible
The data controller is [LEGAL ENTITY NAME], registered in Romania, registered office [REGISTERED ADDRESS, ROMANIA], tax identification code [CUI]. For any privacy question, or to exercise the rights in section 7, email max@promisephones.com.
We are established in the EU, so the GDPR governs everything we do with your data, wherever you live. If you are in the United States, you get the same treatment as an EU customer: the same legal bases, the same retention limits, and the same rights in section 7. That is a higher standard than most US law requires, and we apply it to everyone rather than running two systems.
2. What we collect
- Your email address, which you give us at sign-up. It is how you sign in and how we contact you.
- Subscription status: which plan you are on, whether it is active, when the current period ends. This is sent to us by our payment processor.
- A session cookie, set when you sign in, so you stay signed in. It is strictly necessary for the service to work.
- Sign-in tokens, which are single-use and expire after fifteen minutes.
- Basic server logs, which may include IP address and timestamps, kept for security and debugging.
We do not collect or store your card details. Payment information is handled entirely by Dodo Payments and never reaches our servers.
We do not use advertising cookies, analytics trackers, or third-party profiling on this site.
3. Why we use it, and our legal basis
- To give you access to what you paid for. Basis: performance of a contract.
- To take payment and process refunds. Basis: performance of a contract.
- To email you about your account, billing, or material changes to the service. Basis: performance of a contract.
- To keep the service secure and investigate abuse. Basis: legitimate interests.
- To meet tax and accounting obligations. Basis: legal obligation.
We will only send you marketing email if you have separately opted in, and you can withdraw that at any time using the unsubscribe link.
4. Who we share it with
We use a small number of processors, each of which receives only what it needs:
- Dodo Payments, our payment processor and merchant of record, which handles payment and holds your billing details under its own privacy policy.
- Our email provider, [EMAIL PROVIDER], which delivers sign-in links and account email.
- Our hosting provider, [HOSTING PROVIDER], which stores the data at rest.
We may disclose data where legally required. We do not sell your personal data, and we do not share it for advertising.
5. International transfers
We are in Romania and most of our customers are in the United States, so data does cross borders. Your email address and subscription record are stored in the EU. Some processors are US-based, and where personal data is transferred out of the EEA it is done under an approved safeguard: either standard contractual clauses, or the EU-US Data Privacy Framework where the processor is certified under it.
If you are a US customer, your data is held in the EU under GDPR protection. You can ask us for a copy of the safeguards we rely on.
6. How long we keep it
- Account and subscription records: for as long as your account exists, then up to [N] months.
- Sign-in tokens: fifteen minutes.
- Session records: until expiry or sign-out.
- Server logs: [N] days.
- Payment and tax records: as long as tax law requires, typically six to seven years.
7. Your rights
These rights apply to every customer, not only EU ones. You may ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where we rely on it.
If you want to complain, you can contact our supervisory authority in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP), at dataprotection.ro. EU and UK customers may instead complain to their own national authority.
If you are in California, you may additionally request disclosure or deletion under the CCPA and CPRA. We do not sell or share personal information as those statutes define it, and we have never done so.
To exercise any of these, email max@promisephones.com. We will respond within one month. We will not treat you differently for exercising a right.
8. Security
Sign-in links are single-use and short-lived, session cookies are HTTP-only, and access is restricted. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects you, we will notify you and the relevant regulator where the law requires it.
9. Children
This service is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a minor has given us data, contact us and we will delete it.
10. Changes
We may update this policy. Material changes will be notified by email or on this page.
← Back to PromisePhones