Legal
Privacy Policy
Document version: 2026-08-13-v1 · Last updated:
This Privacy Policy explains how Hearthmark (the “Service”) collects, uses, retains, and shares information when you use it. If anything here is unclear, write to us at the address at the bottom.
1. Who we are
Hearthmark is the data controller for the personal information described in this policy. You can reach us at hearthmark-8@polsia.app.
2. What we collect
We collect information in three ways: (a) you give it to us directly, (b) the Service records it as you use it, and (c) a small set of infrastructure providers we rely on generate logs and signals.
Account data (you provide)
- Email address (used as your sign-in identifier and for transactional messages).
- Display name and bakery/workspace labels.
- Billing details handled by our payment processor (we never see your full card number).
Operational data (the Service records)
- Ingredient inventory records, supplier notes, and purchase-order drafts you enter.
- Equipment readings you log (proofer/oven/retarder/oil-bath temperatures, drift history, flagged anomalies).
- Wholesale orders and the morning digest preferences you set.
- Consent records: the Terms/Privacy version you accepted, the timestamp, and the policy kind — so we can show what you agreed to on your profile.
Technical data (our providers generate)
- Standard server access logs for diagnosing outages and abuse.
- Anonymous, aggregated usage analytics (page views, not individual identity) to understand which features are useful.
3. How we use it
We use the data we collect to:
- Provide the Service: track inventory, detect equipment anomalies, run the morning digest, and process payments.
- Authenticate you, keep your session secure, and remember your workspace settings.
- Detect and prevent abuse, fraud, and security incidents.
- Communicate with you about the Service (transactional notices, security alerts, material product changes).
- Comply with legal obligations and respond to lawful requests.
We do not sell personal data. We do not use your operational records to train third-party AI models, and we do not share them with advertising networks.
4. Legal basis (EEA / UK)
If you are in the EEA, the UK, or a similar jurisdiction, our legal bases under GDPR / UK GDPR for processing your personal data are:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, prevent abuse, and improve reliability, balanced against your rights.
- Consent — where required (for example, certain non-essential cookies or optional marketing emails), which you can withdraw at any time.
- Legal obligation — for tax, accounting, and compliance record-keeping.
5. Third-party processors
The Service relies on a small set of vetted subprocessors. Each handles only the data required for its role and is bound by a data-processing agreement:
- Payments — Stripe (card processing, subscription billing, invoices). Stripe receives only the identifiers needed to charge the card you present.
- Transactional email — the Polsia email proxy relays messages (password resets, receipts, consent confirmations, digest summaries) sent from our own address to yours.
- AI assistance — the Polsia AI proxy routes opt-in LLM features (the assistant that drafts supplier notes, summarises a flagged reading). Requests are scoped to the prompt you send; we do not bulk-share your operational database.
- File storage — the Polsia R2 (Cloudflare-backed) proxy stores attachments you upload (e.g. equipment photos, supplier invoices). Objects are access-controlled to your workspace.
- Analytics — anonymous, aggregated page-view counts to understand which parts of the Service are used. No cross-site identifiers are set; no advertising profile is built.
- Hosting — the underlying compute, database, and edge network that runs the Service itself.
6. Cookies & local storage
The Service uses a small number of cookies and local-storage entries, all serving a strictly functional purpose:
- Authentication session cookie (so you stay signed in).
- Theme preference (light/dark) and accessibility settings.
- A signed CSRF token and a per-request security token.
We do not use advertising cookies and we do not set cross-site tracking identifiers.
7. Retention
We keep your operational data for as long as your account is active, plus a reasonable tail period to handle account recovery, billing disputes, and tax obligations. Consent records are kept for the lifetime of the account (they are the audit trail of what you agreed to).
When you delete your account, we delete personal data within 30 days, except records we must keep longer for legal reasons (e.g. settled invoices). Backups are overwritten on their normal rotation cycle (typically within 90 days).
8. Your rights
You can:
- Access — request a copy of the personal data we hold about you.
- Correct — fix inaccurate data from your account settings or by asking us.
- Delete — close your account; we delete associated personal data as described in Retention above.
- Export — receive your operational records in a machine-readable format (CSV / JSON).
- Object / restrict — ask us to limit processing where the legal basis is legitimate interests.
- Withdraw consent — where processing is consent-based, withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint — with your local data-protection authority if you believe we have mishandled your data.
To exercise any of these, write to us at the address below. We respond within 30 days.
9. Security
We protect data with transport encryption (HTTPS), at-rest encryption on the database and object store, role-based access within our infrastructure, audit logging for sensitive operations, and isolation between customer workspaces. No system is perfectly secure, so we commit to notifying affected users of material breaches without undue delay.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will delete it promptly.
11. International transfers
Hearthmark and its subprocessors may process your data in countries other than your own. Where required (e.g. transfers out of the EEA / UK / Switzerland), we rely on Standard Contractual Clauses or equivalent safeguards so your data remains protected to the same standard it has at home.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we update the “Document version” and “Last updated” lines above and, for material changes, notify you by email or in-product notice at least 30 days before the updated policy takes effect. If a change requires your renewed consent under applicable law, we will ask for it on next sign-in.
13. Contact
Questions, requests, or complaints about this policy or our handling of your data: send them to hearthmark-8@polsia.app.