Privacy Policy
At Snap Notes, we are committed to protecting the privacy of our users and customers. Below, we explain how we collect, use, and protect your personal data when you access our application, create notes, store data, or subscribe to our services.
1. Data Controller and Responsibility
The data controller is Snap Notes, located at Madrid, Spain. For any inquiries related to data protection and privacy, you can contact us at:
2. Data We Collect
- Identification data: Full name, email address, phone number, password hash, profile information.
- Account data: Subscription tier, billing information, payment method, usage statistics, storage quota.
- Note content: All notes, documents, and files you create, upload, or store within Snap Notes (encrypted and stored securely).
- Usage data: Devices used, application access times, features accessed, synchronization information, crash reports.
- Technical data: IP address, device type, operating system, browser information, cookies, unique device identifiers.
- Communication data: Messages sent through support forms, feedback, feature requests, and customer support tickets.
3. Purpose of Data Processing
- Service Delivery: Create and manage your account, store and sync your notes across devices, provide cloud storage and backup functionality.
- Account Management: Process billing, manage subscriptions, handle renewals and cancellations, send receipts and invoices.
- Communication: Send account notifications, security alerts, password resets, service updates, and respond to support inquiries.
- Service Improvement: Analyze usage patterns, improve features, optimize performance, and personalize user experience.
- Security: Detect fraud, prevent abuse, ensure platform security, and protect user accounts.
- Legal Compliance: Comply with laws, regulations, tax requirements, and respond to legal requests.
- Marketing (with consent): Send newsletters, product announcements, promotional offers, and feature updates.
4. Legal Basis for Processing
We process your data based on the following legal grounds:
- Consent: For marketing communications, optional analytics, and feature subscriptions.
- Contract Performance: To provide the Snap Notes service you have subscribed to.
- Legitimate Interest: To improve services, prevent fraud, ensure security, and provide customer support.
- Legal Obligation: To comply with tax, legal, and regulatory requirements.
5. Data Retention Periods
We retain your data for different periods depending on the type and purpose:
- Active Account Data: While your account is active and for 30 days after deletion (grace period for recovery).
- Deleted Notes: Retained in secure backups for up to 90 days before permanent deletion.
- Billing Records: Retained for 7 years to comply with tax and accounting regulations.
- Support Communications: Retained for 2 years or as long as necessary to resolve issues.
- Marketing Preferences: Until you withdraw consent or for 3 years of inactivity.
- Technical Logs: Retained for up to 90 days for security and troubleshooting purposes.
6. Data Recipients and Sharing
We may share your data with third parties in the following circumstances:
- Payment Processors: Stripe, PayPal, and other payment providers (only payment information necessary for billing).
- Cloud Infrastructure Providers: AWS, Google Cloud, and data center operators (under strict data processing agreements).
- Analytics Services: Google Analytics, Sentry, and monitoring tools for performance and error tracking.
- Customer Support Platforms: Helpdesk and ticketing systems for managing support requests.
- Email Services: SendGrid, Mailgun for sending transactional emails and notifications.
- Compliance Authorities: Law enforcement and government agencies when legally required.
- Business Partners: In case of merger, acquisition, or business transfer (with appropriate safeguards).
All third parties are contractually bound to maintain confidentiality and use data only for specified purposes.
7. International Data Transfers
Your data may be transferred to and stored in countries outside your location, including the European Economic Area (EEA):
- Cloud Storage: Data may be stored on servers in multiple countries for redundancy and availability.
- Service Providers: Some processors may have servers in countries with different privacy laws.
- Legal Compliance: We comply with Standard Contractual Clauses (SCCs) and adequacy decisions for all international transfers.
We ensure appropriate safeguards are in place, including Data Processing Agreements and compliance with GDPR and international data protection regulations.
8. Your Rights
- Right of Access: Request a copy of your personal data we hold.
- Right to Rectification: Correct inaccurate or incomplete information.
- Right to Erasure: Request deletion of your data (subject to legal obligations).
- Right to Restrict Processing: Limit how we use your data.
- Right to Data Portability: Download your data in a structured, machine-readable format.
- Right to Object: Opt-out of marketing communications and certain processing activities.
- Right to Withdraw Consent: Withdraw consent for any processing at any time.
To exercise these rights, please contact us:
9. Data Security
We implement industry-leading technical and organizational measures to protect your personal data:
- Encryption in Transit: All data transmitted uses TLS/SSL encryption (256-bit or higher).
- Encryption at Rest: Sensitive data is encrypted using AES-256 or equivalent.
- Access Control: Only authorized personnel can access user data, with role-based access controls.
- Regular Backups: Automated backups stored geographically for disaster recovery.
- Security Audits: Regular penetration testing and security assessments.
- Incident Response: We maintain protocols to respond to and report security breaches if they occur.
- Employee Training: All staff receive data protection and security training.
10. Policy Updates
We reserve the right to modify this privacy policy to adapt to legislative changes, new features, or security improvements. Any significant changes will be communicated via email or prominent notice on our website. Your continued use of Snap Notes constitutes acceptance of updated terms.
11. Cookies and Tracking Technology
Snap Notes uses cookies and similar tracking technologies to improve your experience, remember preferences, analyze usage, and provide personalized features.
What are Cookies?
Cookies are small text files stored on your device when you access our application. They help us remember your preferences, authentication status, and usage patterns to enhance your experience.
Types of Cookies We Use
- Essential Cookies: Required for basic functionality (authentication, security, session management).
- Performance Cookies: Analyze how you use Snap Notes to improve features and performance (Google Analytics, Sentry).
- Preference Cookies: Remember your settings, notification preferences, and personalization choices.
- Marketing Cookies: Track your interest in features to show relevant content and offers (with your consent).
- Third-Party Cookies: Set by external services for analytics, payments, and integrations.
Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to:
- Accept or reject all cookies
- Accept only certain types of cookies
- Delete existing cookies
- Receive notifications when new cookies are set
Important: Disabling essential cookies may affect functionality of the Snap Notes application and your ability to log in or access your notes.
Third-Party Services Using Cookies
- Google Analytics: Tracking website and app usage patterns
- Stripe/PayPal: Processing payments securely
- Sentry: Monitoring errors and application performance
- Microsoft/Google Auth: Authentication services
Please review their privacy policies for information about their cookie usage and data practices.
12. Contact and Support
If you have questions about this privacy policy, concerns about your data, or wish to exercise your rights, please contact us:
- Email: contact@snap-notes.vercel.app
- Contact Form: Submit a request
- Response Time: We respond to privacy inquiries within 30 days as required by law
Last updated: October 23, 2025. We recommend reviewing this policy periodically for updates. Your continued use of Snap Notes constitutes acceptance of this Privacy Policy.