Privacy policy
This policy explains what personal data we process when providing the WebFixPlan website audit service, on what basis, and what rights you have.
Last updated:
Data controller
The data controller is the service provider identified below. You can contact us at the email address shown for any data protection matter.
What data we process
- Account data: your email address and sign-in information. Passwords are handled by Supabase Auth; we never see or store them.
- Audit request data: the website address plus any information you choose to provide — company name, industry, audit goal, city, country, services, target audience, competitor address and report language.
- Crawl results: extracted and sanitised data from public pages, check results and scores.
- Payment data: purchase status, Stripe session identifier, amount and currency.
- Technical data: security and rate-limiting hashes, and AI request telemetry — model, tokens used, duration, cost and a safe error code.
What we do not process
When crawling we do not store raw HTML, send cookies or submit forms — we collect only publicly available information.
We never see or store payment card details. These are handled by Stripe.
An anonymous audit access token is stored only as a SHA-256 hash, so it cannot be reconstructed from the database.
Legal bases for processing
- Performance of a contract — running the audit, delivering the report and administering your account.
- Legitimate interest — service security, abuse and fraud prevention, and rate limiting.
- Legal obligation — accounting and tax requirements relating to payments made.
- Consent — where you give it separately, such as agreeing that the report be prepared immediately.
Processors
We use the following processors, which process data only on our instructions:
- Supabase — database and user authentication.
- Vercel — website hosting and technical logs.
- Stripe — payment acceptance and processing.
- OpenAI — generating the AI report text from audit findings.
Transfers outside the EU
Some processors may process data outside the European Economic Area. Where this happens, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.
Retention
- Audit and report data is kept while your account exists or until you ask us to delete it.
- Accounting data relating to payments is kept for as long as the law requires.
- Security and rate-limiting records are kept briefly and used only to prevent abuse.
Your rights
You have the right to access your data, request correction or erasure, restrict processing, object to processing, and receive your data in a portable format. Contact us at the email address below.
If you believe your data is being handled improperly, you have the right to lodge a complaint with the supervisory authority.
Cookies and session
We use only essential cookies needed to maintain your sign-in session and keep the service secure. We do not use marketing or tracking cookies.
Service provider
- Edvinas Kaluškevičius
- Individual activity certificate no.
- 1398901
- Address:
- J. Matuso g. 25, Kaunas, Lithuania
- Email:
- info@webfixplan.com
- Phone:
- +37069175025
The seller is not registered for VAT — no VAT is added.
Supervisory authority: State Data Protection Inspectorate
Other legal documents
This page is general information, not individual legal advice.