# ShipStreak Privacy Policy

Canonical HTML: https://www.shipstreak.space/privacy  
Last updated: see the HTML page (authoritative if this file drifts).

## 1. Who we are

ShipStreak is a publishing-streak tool operated from the European Union. This policy explains what personal data we collect, why, how we use it, and which third parties process it. It applies to `shipstreak.space`, all subdomains (e.g. `username.shipstreak.space`), and any custom domain bound to a public profile.

We are the data controller. Sub-processors act under our instructions.

## 2. What we collect

**Account:** email, Firebase uid, display name (optional), public username, timezone, preferred output tone, custom domain (Pro).

**Product:** streak metadata, daily entry bullets, generated post text, completion timestamps for the public calendar.

**Billing:** Stripe customer id and subscription state mirror. We do not see or store card number, CVC, or full card details.

**Operational:** essential cookies (`session`, `csrf_token`, `csrf_token_client`); DataFast cookies (`datafast_visitor_id`, `datafast_session_id`); security audit logs.

## 3. How we use it

- Run the daily publishing loop and enforce streak rules
- Render public profiles (completion calendar + streak state). Bullets and generated post text are never published on the public profile
- Process subscriptions / entitlements
- Attribute marketing traffic to revenue (DataFast + Stripe Checkout metadata)
- Support, abuse prevention

We do not sell your data and do not run advertising or retargeting networks on the site.

## 4. Third-party processors

- **Firebase (Google):** auth, Firestore, session tokens
- **Stripe:** payments and subscriptions; optional DataFast visitor/session IDs in Checkout metadata
- **DataFast:** analytics and revenue attribution ([DataFast privacy](https://datafa.st/privacy))
- **OpenAI:** only when a Pro user triggers a polished tone; bullets sent per-request; not used to train OpenAI models
- **Vercel:** hosting; standard request metadata for delivery and abuse prevention

## 5. Cookies

Essential auth/CSRF cookies. DataFast visitor/session cookies for analytics. No advertising cookies. See https://www.shipstreak.space/cookies

## 6. Retention

Kept while the account exists. Delete anytime from `/dashboard/account`. Audit logs up to 12 months. Stripe retains billing records per its own rules.

## 7. Your rights (GDPR)

Access, correct, delete, export (`GET /api/user/export` from the account page), withdraw consent/object, lodge a DPA complaint. Contact the support email listed on the site. We respond within 30 days.

## 8. Children

Not intended for users under 16.

## 9. Changes

We may update this policy; the HTML page date is authoritative.
