PrimeApp Studio

Privacy Policy

Last updated: 2026-08-10

This policy explains what personal data PrimeApp Studio collects, why, and what you can do about it. It is written to meet Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Who is responsible

No data protection officer has been appointed, as the criteria in art. 37 GDPR do not apply. Write to the address above for any privacy matter.

2. Two very different roles

This distinction decides which parts of this policy apply to you.

  • Your own account data — the email, name and billing details of the person who signs up. Here we are the controller, and this policy governs it.
  • The records you enter — members, donors, contributions. Here you are the controller and we merely process on your behalf, under the terms of Annex A of the Terms. We do not decide what goes in, and we do not use it for anything other than running the service for you.

3. What we collect and why

DataPurposeLegal basis
Email, name, workspace name, password hashCreate and run your accountPerformance of the contract (art. 6.1.b)
Billing details held by Stripe; subscription statusTake payment, meet accounting dutiesContract (6.1.b) and legal obligation (6.1.c)
IP address, sign-in attempts, timestampsRate limiting and abuse prevention; keeping accounts secureLegitimate interest in service security (6.1.f)
Service emails (sign-up, password reset, billing notices)Operate the accountContract (6.1.b)
Website analytics (see section 6)Understand how the site is used and improve itYour consent (6.1.a)
The records you enter about other peopleProvide the module you subscribed toProcessed on your instructions — you set the basis

We do not run advertising, we do not sell personal data, we do not share it with third parties for their own marketing, and we do not use it to train machine-learning models.

4. Who else sees the data

We use the service providers below, each bound by a data processing agreement and permitted to act only on our instructions.

ProviderPurposeLocation
NeonDatabase hosting — stores all workspace recordsEuropean Union
VercelApplication hosting — serves the app and processes requestsEuropean Union / United States (SCCs)
Stripe Payments Europe, Ltd.Subscription billing and card processingIreland / United States (SCCs)
ResendTransactional email (sign-up, password reset)United States (SCCs)

We also disclose data where a law, a court or a competent authority requires it.

5. International transfers

Customer records are hosted in the European Union. Where a provider processes data outside the EEA, the transfer relies on an adequacy decision, on the EU-U.S. Data Privacy Framework, or on the European Commission’s Standard Contractual Clauses with any supplementary measures needed. You can ask us for a copy of the safeguards in place.

6. Cookies and analytics

Essential cookies are set because the service cannot work without them. Everything else runs only after you agree: the analytics scripts are not loaded at all until you accept, so refusing means no request is ever made to those providers.

You can change your mind whenever you like through the Cookie preferences link in the footer of any page. Withdrawing consent also deletes the analytics cookies already stored on your device.

CookieProviderPurposeDurationCategory
bs_sessionPrimeApp StudioKeeps you signed in30 daysEssential
bs_consentPrimeApp StudioRemembers your cookie choice6 monthsEssential
_ga, _ga_*Google AnalyticsDistinguishes visitors for usage statistics2 yearsAnalytics
_clckMicrosoft ClarityPersists a visitor identifier1 yearAnalytics
_clskMicrosoft ClarityGroups page views into one session1 dayAnalytics

Analytics providers, if you consent:

ProviderPurposeLocation
Google Analytics 4 (Google Ireland Ltd.)Aggregate website usage statisticsIreland / United States (SCCs, DPF)
Microsoft Clarity (Microsoft Ireland Operations Ltd.)Aggregate interaction and heatmap analysis of the websiteIreland / United States (SCCs, DPF)

Analytics only ever cover visitors to the website. They are not present on the data inside a workspace and never receive the records you enter.

7. How long we keep it

  • Account data: while the account exists, then deleted within 30 days of a deletion request.
  • Workspace records: while the workspace exists; they survive cancellation so you can still export them, and are deleted on request.
  • Backups: aged out within a further 30 days after deletion.
  • Sign-in and rate-limiting logs: short-lived, cleared as counters reset.
  • Invoicing records: kept for the periods Spanish tax and commercial law require (generally 4 to 6 years).

8. Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to data portability, and to withdraw a consent you have given (which does not affect processing already carried out).

Exercise them by writing to admin@primeappstudio.com. We reply within one month. If your request concerns records held inside a customer’s workspace, we will refer you to that customer, who is the controller for them.

If you are not satisfied, you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos, or to the authority where you live.

9. Security

Traffic is served over HTTPS, data is encrypted at rest, passwords are stored only as bcrypt hashes, each workspace is isolated and checked on every request, sessions can be revoked centrally, and sign-in is rate limited by both account and network address. The full list is in Annex A.5 of the Terms.

10. Children

The service is not directed at children and accounts may only be created by adults. Records about minors may be entered by a customer acting as controller; the legal basis for doing so is that customer’s responsibility.

11. Changes to this policy

We may update this policy. The date at the top changes with it, and we will notify account owners by email of material changes.