Privacy Policy
Effective date: 25 August 2026
Primalog (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable national law.
1. Who we are
Primalog Mateusz Mrożek, Leśna 78, 32-050 Skawina, NIP: 7393388400, REGON: 389730263, is the controller responsible for personal data processed through the CubeOn Studio application and website. Contact: info@primalog.pl.
The applicable Paddle contracting entity identified in Paddle's current Buyer Terms (“Paddle”) acts as an independent data controller, not our processor, for financial, payment-card, and tax-invoicing data it collects when it processes your subscription as Merchant of Record — see Terms of Service & EULA, Section 3. Paddle's privacy policy governs that processing; this Policy covers the data Primalog itself controls.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, account identifier, profile name when provided, password hash for password sign-in, subscription status | You or your chosen sign-in provider |
| Project data | Parametric designs, grid configs, box dimensions | You (Studio editor) |
| Usage data | Pages visited, features used, browser type, IP address | Automatically |
| Payment data | Billing identity, tax details, invoices — collected and controlled by Paddle as Merchant of Record, not by Primalog | You (Paddle checkout) |
| Subscription and billing-event data | Paddle customer, subscription, transaction and adjustment identifiers; plan, status and billing-period data; purchase-country code; and signed billing-event payloads that may contain limited payment-method metadata such as method type, card brand, last four digits, expiry and cardholder name, or a PayPal email and reference. We do not receive or store a full card number or CVV. | Paddle |
| Consent records | Document version and hash accepted, timestamp, hashed IP, browser, locale — one record per Terms/EULA, Privacy Policy, Acceptable Use, or withdrawal-waiver acceptance | Automatically on acceptance |
| Export records | Timestamp, licence tier at export time, and a hash of the exported file — kept to evidence the commercial rights described in the EULA | Automatically on file export |
3. Legal basis for processing
- Contract performance — processing necessary to provide the Service (account management, project storage, subscription billing).
- Legitimate interests — security monitoring, service reliability, abuse prevention, and fraud prevention.
- Legal obligation — tax and accounting records.
- Consent — optional Studio product analytics, privacy-masked session replay diagnostics, and marketing emails (you may withdraw consent at any time).
4. How we use your data
- Creating and managing your account.
- Storing and synchronising your Studio projects.
- Synchronising subscription status received from Paddle. Paddle processes payments and issues buyer receipts or invoices as Merchant of Record.
- Sending transactional emails (order confirmations, password resets).
- Improving the Service through product analytics (aggregate CubeOn Studio usage).
- Complying with legal obligations.
5. Data sharing, processors, and Paddle
We do not sell your personal data. We use these processors under written agreements:
- Supabase — database and authentication (EU region).
- Resend — transactional email (account, export, and consent confirmations).
- Sentry — error and performance monitoring. Sampled, privacy-masked session replay is used only if you enable diagnostics cookies.
- PostHog — product analytics for Studio (usage patterns and conversion funnels). When enabled, it may use cookies or browser storage; events are scoped to the Studio experience and are not used for third-party advertising.
- Vercel — application hosting and content delivery.
- Cloudflare Turnstile — bot and abuse protection during authentication.
- Upstash — distributed rate-limit counters for protected endpoints.
Paddle is not on this list. As explained in Section 1, Paddle processes your payment as an independent controller under its own privacy policy, not as a processor acting on our instructions. To operate, secure and reconcile your subscription, we receive and durably store Paddle's signed billing-event payloads. These contain the identifiers and subscription data listed in Section 2 and may include limited payment-method metadata (for example method type, card brand, last four digits, expiry and cardholder name, or a PayPal email and reference), together with Paddle address, business or billing-detail identifiers. We do not receive or store the full card number or CVV. For regional consent routing, we fetch and store only the two-letter country code from the completed transaction address; we do not copy the transaction's street address into the Studio jurisdiction record.
Google and Apple are not on this processor list. If you choose Google or Apple sign-in, that provider acts as an independent controller for the authentication data it collects. We receive the email address and account identifier needed to create or link your CubeOn Studio account, and the profile name supplied by that provider when it is available.
6. Data retention
- Account and project data: retained while your account is active and then deleted or anonymised after a valid deletion request, except where a limited record is needed for security, accounting, dispute, or legal-obligation purposes.
- Runtime and security logs: retained according to the provider's configured retention window and only as long as needed to investigate reliability, abuse, or security events.
- Signed Paddle billing-event payloads: processed or ignored events are retained for up to 180 days for reconciliation, fraud investigation and support, then removed automatically. Failed or unresolved events may be kept longer until the billing state is safely reconciled.
- Consent and export records: retained for the establishment and defence of legal claims, including after account deletion. On deletion we remove the direct account link and keep only a pseudonymised record (a one-way hash of your account email), as permitted by GDPR Article 17(3)(e).
- Payment and tax records: retained by Paddle under its own retention schedule.
7. Your rights under GDPR
You have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure (“right to be forgotten”) — ask us to delete your data where there is no overriding legal basis for retention.
- Portability — receive your data in a structured, machine-readable format (JSON).
- Restriction — ask us to restrict processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — use Manage cookies for optional analytics and diagnostics; for marketing emails, use the unsubscribe link or contact us.
To exercise any of these rights, email info@primalog.pl. We will respond within one month, subject to any extension permitted by applicable law. If you believe we have not addressed your concern, you have the right to lodge a complaint with your national data-protection authority — in Poland, the Urząd Ochrony Danych Osobowych (UODO).
8. Cookies
We use strictly necessary cookies to maintain your session and authentication state. We do not use advertising or cross-site tracking cookies. Optional analytics and session replay stay off until you enable them; see our Cookie Policy.
9. International transfers
We process data primarily within the EU/EEA. Where a processor is located outside the EEA — including cloud hosting infrastructure in the United States — the transfer is safeguarded by European Commission Standard Contractual Clauses (SCCs), an adequacy decision, or another transfer mechanism permitted by Chapter V GDPR.
Paddle transfers your payment data internationally under its own safeguards as an independent controller; see Section 1 and Paddle's privacy policy.
10. Notice for California residents (CCPA/CPRA)
Under the California Consumer Privacy Act, California residents have the right to know what personal information we collect, request its deletion, and opt out of the sale or sharing of personal information. Primalog does not sell or share personal information for cross-context behavioural advertising. To exercise these rights, contact info@primalog.pl.
11. Security
We apply industry-standard security measures including TLS encryption in transit, encrypted storage at rest, and role-based access controls. No system is completely secure; we encourage you to use a strong, unique password.
12. Changes to this Policy
We may update this Privacy Policy. Material changes will be notified by email or an in-app notice at least 30 days before they take effect.
13. Contact
For privacy enquiries, contact our privacy contact at info@primalog.pl.