Privacy Policy
This Privacy Policy explains what personal data EdgeNFC processes, why, on what legal basis, who we share it with, how long we keep it, and how you can exercise your rights. It covers the EU/EEA and UK (GDPR / UK GDPR), California (CCPA / CPRA), and Brazil (LGPD).
1. What we collect and why
The table below is our data map — the categories of personal data we process:
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Email, password hash | Account / authentication | Contract | Life of account + 30 days |
| Stripe customer / subscription IDs | Billing | Contract / legal obligation | Per tax law ⚠︎ placeholder |
| Tag UIDs, counters | Product function (verify) | Contract / legitimate interest | Life of system |
| Verify events (UID, counter, verdict, time, coarse country) | Anti-replay, scan analytics | Legitimate interest | Rolling window ⚠︎ placeholder |
| IP / rate-limit state | Security, abuse prevention | Legitimate interest | Short TTL |
| Consent records | Prove consent | Legal obligation | 5 years after withdrawal ⚠︎ placeholder |
| Orders — shipping name, address, phone Not currently collected. | Would fulfil hardware orders — we no longer sell hardware, so no shipping data is collected, stored, or shared. Row retained because it would apply again if the EdgeNFC store re-opens; if it does, this policy is updated first. | Contract (n/a today) | n/a — nothing collected |
People who tap your tags (end users). The public tap/verify path processes a tag UID and counter to perform the verification the tag exists for. That processing is strictly necessary to deliver the service and is not gated on a cookie banner. We record a coarse (country-level) geo hint for analytics and never store a raw IP address for this path; UID-hiding (encrypted PICC) is available as a privacy control.
2. Processors and sub-processors
We use the following sub-processors to operate the Service. Each processes personal data only on our instructions and under a data-processing agreement:
| Sub-processor | Purpose | Data |
|---|---|---|
| Stripe | Payments & billing | Billing identifiers, payment status (card data is handled by Stripe, never by us) |
| Cloudflare | Hosting, edge compute, storage (D1/KV) | All Service data processed at the edge; request metadata |
We no longer use a fulfillment sub-processor. EdgeNFC previously sold physical tags and shared shipping details with GoToTags to fulfil those orders. We have stopped selling hardware, so GoToTags is no longer a sub-processor and we send them no personal data. We still recommend them as a place to buy tags at /hardware, but any purchase you make there is directly with them under their own privacy policy — we are not involved in it and never see your order.
We keep this sub-processor list up to date. Transfers to these sub-processors rely on Standard Contractual Clauses and/or the applicable Data Privacy Framework ⚠︎ placeholder — confirm transfer mechanism per sub-processor.
3. International transfers
Personal data may be processed in countries other than your own. Where data leaves the EEA/UK, we rely on an approved transfer mechanism (Standard Contractual Clauses or an adequacy / Data Privacy Framework decision) ⚠︎ placeholder — confirm with counsel. Our EU/UK representative and, where required, our DPO are ⚠︎ placeholder.
4. Your rights and how to exercise them
Depending on where you live, you have rights to access, correct, export (portability), delete, restrict, and object to the processing of your personal data, and to withdraw consent. To exercise them:
- Self-serve in Settings. You can export your data (a JSON copy of your account, systems, tags, subscription, and consent history — never any secret key bytes) and delete your account directly from Settings.
- API. The same actions are available via
POST /api/dsarwith{type:"export"}or{type:"delete"}(deletion requires explicit confirmation and re-authentication). - Deletion timeline. We complete verified deletion requests within 30 days. Deletion revokes your systems, so tags in the field for those systems will stop verifying — we surface this consequence before you confirm.
- Retained data. Some billing and consent records may be retained to meet legal or tax obligations even after account deletion, as noted in the data map above.
California (CCPA/CPRA). We do not sell your personal information. You may still exercise "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information", and we honor Global Privacy Control (GPC) browser signals as a valid opt-out. ⚠︎ placeholder — confirm posture.
We verify your identity before acting on an access or deletion request to protect your account. Requests we cannot fulfil self-serve, and any complaint, can be sent to our privacy contact: ⚠︎ placeholder — privacy contact / DPO email. You also have the right to lodge a complaint with your local supervisory authority.
5. Cookies and local storage
For details on cookies, local storage, and how to change your consent, see our Cookie Policy.
EdgeNFC