Privacy Policy — Craftale (DRAFT)
Draft for legal review — not legal advice. Last updated: 2026-07-15. Controller: Iuliia Nikonorova, operating Craftale as a private individual based in the Czech Republic (business registration — IČO — pending; a full registered business address will be added here once issued). Contact: info@craftale.eu.
Craftale ("we") helps you generate product listings — titles, descriptions, SEO and staged product photos — for the shops you sell on. This policy explains what personal data we process and your rights under the EU General Data Protection Regulation (GDPR).
1. What we collect
- Account data: your email address, display name, and a securely hashed password (we never store your password in plain text). If you sign in with Google or Facebook (when enabled), we receive your basic profile from them.
- Brand & listing content you create: brand name, description, logo, voice settings; selling platforms; items (name, details, price, materials); and the photos you upload.
- Generated content: the AI-generated titles, descriptions, SEO and images produced from your inputs, including their version history.
- Donations: during the pilot, subscriptions are off and the Support page links out to Stripe Payment Links and Ko-fi. We do not process or receive any data from these donations — clicking a donation link takes you directly to that service, which acts as its own independent controller for the transaction under its own privacy policy. See the disclosure for details. When paid subscriptions launch, billing will be handled by our payment processor (Stripe), integrated directly into the Service — at that point Stripe becomes our sub-processor for that data. We never store your card details ourselves either way.
- Technical data: a session cookie to keep you signed in, a theme preference cookie, and minimal server logs (including IP address for security and abuse prevention).
2. Why we process it (lawful bases)
- To provide the service you asked for (performance of a contract): running your account, storing your content, and generating listings.
- To keep the service secure (legitimate interests): rate limiting, abuse/fraud prevention, and security logging.
- To process payments (contract) where you subscribe.
- With your consent where required (e.g. optional communications).
3. AI processing of your content
When AI generation is enabled, the content you submit (brand and item details, and — for photos — your uploaded images) is sent to third-party AI providers to produce the generated output. These providers act as our sub-processors. See the AI & sub-processor disclosure for who they are, what they receive, and data-residency arrangements. We do not sell your data or use your content to train third-party models beyond producing your results, subject to each provider's terms which we review before enabling them.
4. How long we keep it
- Account and content: for as long as your account exists. When you delete your account, we erase your profile, brands, items, generated content and uploaded files (see §6).
- Security/event logs: retained for 6 months by default (admin-configurable
via
LOG_RETENTION_MONTHS) and then purged. - Billing records: retained as required by law/accounting rules by our payment processor.
5. Who we share it with
We share data only with the sub-processors needed to run the service — hosting, the AI providers (when enabled), and the payment processor — each under a data-processing agreement. See the disclosure document. We may disclose data if required by law.
6. Your rights
Under the GDPR you can, at any time:
- Access / export your data — download everything we hold about you as a JSON file from Account & privacy → Export your data.
- Erasure — permanently delete your account and all associated data from Account & privacy → Delete your account. This is immediate and irreversible.
- Rectification — correct your data by editing it in the app.
- Object / restrict / withdraw consent, and lodge a complaint with your local supervisory authority.
To exercise any right you cannot self-serve, contact info@craftale.eu. If unsatisfied with our response, you may lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ, uoou.gov.cz), or your own country's authority if you live elsewhere in the EEA.
7. International transfers
Where a sub-processor processes data outside the EEA, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses) and prefer EU-region endpoints. See the disclosure for the current arrangements.
8. Children
The service is not directed at children under 16; we do not knowingly collect their data. (16 is the GDPR baseline age of consent; some EU member states set it lower, but we apply 16 uniformly across all markets for simplicity.)
9. Data Protection Officer
We have not appointed a Data Protection Officer. Under GDPR Article 37, a DPO is required only where core activities involve large-scale systematic monitoring of individuals, or large-scale processing of special-category data. Craftale's current processing (account, brand/listing content, and generated output for a small pilot user base) does not meet that threshold. We will revisit this if the scale or nature of processing changes materially.
10. Changes
We will post changes here and, for material changes, notify you in-app or by email.
Content-complete. Still have counsel review for CZ, DE, FR, IT, PL, DK — and specifically the implications of operating without a registered business entity yet — before treating this as binding. See the README.