Legal

Privacy Policy

We keep this short and honest. This policy explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. We only collect what we need to run the Services and to meet our legal duties. We do not sell your personal data — we never have and never will.

Last updated: 2026-07-27.

1. Who is the data controller

The controller of your personal data is:

  • Nicolas Kurt Francisque Arbogast, individual autónomo trading as SwellShaper
  • NIF/NIE: Y8051829A
  • Address: Camí Ses Rotes, 3 – 07142 Santa Eugènia – Illes Balears, Spain
  • Email: nico@swellshaper.com

We are a small, EU-based studio. We are not required to appoint a Data Protection Officer or an EU representative, and we have not. For any privacy matter, email the address above.

2. What data we collect and where it comes from

We collect data you give us directly, and a little that is created when you use the Services:

  • Account data: name, email, login credentials.
  • Reservation and billing data: the product you reserved or subscribed to, amounts, and payment confirmations. Card payments are handled by Stripe — we do not receive or store your full card number.
  • Support data: the messages you send us and what they contain.
  • Usage and technical data: basic logs such as IP address, device/browser type, and events needed to run and secure the Services.
  • Aggregate usage data: we use PostHog (EU-hosted), configured in its cookieless mode, to measure aggregate, anonymous usage — pages viewed, referring source, device type, and whether visitors click through to a product's checkout. In this mode PostHog sets no cookies, creates no persistent identifiers, and does not collect personal data or track you across sites. Because cookieless mode disables IP-based enrichment, we do not collect your location or country, and we do not record sessions or replay your browsing (see §3 and §9).
  • Marketing preferences: if you opt in to updates.

3. Why we use it, and the legal basis (GDPR Art. 6)

  • To create and run your account, deliver the Services, and take a reservation or subscription — legal basis: performance of a contract (Art. 6(1)(b)). A reservation is a pre-contract/contract step and is covered here too.
  • To process payments via Stripe — contract (Art. 6(1)(b)).
  • To keep tax, accounting and billing recordslegal obligation (Art. 6(1)(c)).
  • To provide supportcontract (Art. 6(1)(b)), or our legitimate interest in helping you.
  • To keep the Services secure and prevent fraud and abuselegitimate interests (Art. 6(1)(f)); our interest is running a safe, reliable, sustainable service, balanced against your rights. This covers essential security logging only, not analytics.
  • To send marketing emails, if you opt in — consent (Art. 6(1)(a)), which you can withdraw at any time.
  • To understand aggregate usage of our siteslegitimate interests (Art. 6(1)(f)); our interest is measuring, in aggregate and without cookies or personal identifiers, how our sites are used so we can improve them. Because our analytics tool (PostHog) sets no cookies and collects no personal data, no cookie consent banner is required; you can still object to this processing at any time. If we ever introduce cookie-based or identifying analytics or advertising, we will first put up a compliant consent banner and rely on your consent (Art. 6(1)(a)) before any such processing begins, and update this policy.

Providing account and billing data is necessary to enter the contract or take a reservation; without it we cannot provide the Services. There is no automated decision-making or profiling that produces legal or similarly significant effects on you.

4. Who we share it with (recipients and processors)

We share data only with service providers who help us run the studio, each under a data-processing agreement (GDPR Art. 28). Our current sub-processor list is published in full — naming each provider, what it does for us, where it processes data, and the transfer safeguard we rely on. You can also request it by emailing nico@swellshaper.com. In summary:

  • Stripe — payment processing. Depending on the activity, Stripe acts as our processor and/or as an independent controller. See Stripe's Data Processing Agreement and privacy policy.
  • Cloudflare — website hosting, CDN and DNS. See the sub-processor list.
  • Proton (Switzerland) — our email provider, for account, transactional and (if you opted in) marketing emails. See the sub-processor list.
  • PostHog (EU Cloud, Frankfurt) — aggregate, cookieless, non-personal usage statistics. See the sub-processor list.

We may also disclose data where the law requires it. We do not sell your data or share it for others' advertising.

5. International transfers

Some providers process data outside the EU/EEA, including in the United States. For each such transfer we rely on an appropriate safeguard under GDPR Chapter V (Art. 45 or 46), chosen per named recipient. Because a provider's certification status can change, we verify it for each provider and record the mechanism we actually rely on in our sub-processor list, so the safeguard is always tied to the specific, named provider rather than asserted in the abstract. In general:

  • Stripe (payments): where Stripe is, at the time of transfer, certified under the EU–US Data Privacy Framework (DPF), we rely on that adequacy decision; for any transfer the DPF does not cover, we rely on Stripe's Standard Contractual Clauses (SCCs) with supplementary measures.
  • Hosting / infrastructure, email, and analytics providers: for each named provider we rely on the DPF where that provider is currently DPF-certified for the relevant data, and otherwise on the European Commission's SCCs with supplementary technical and organisational measures. If a provider we name is not DPF-certified, we do not claim it is — we rely on SCCs instead, and our sub-processor list states which.

You can ask us which mechanism applies to a specific, named provider, and for a copy of the relevant safeguard, by emailing nico@swellshaper.com.

6. How long we keep it

  • Account and service data: for as long as your account or reservation is active, plus the limitation period after it ends so we can handle any claims.
  • Billing, invoicing and tax records: for the periods Spanish tax and commercial law require — generally between 4 and 6 years.
  • Support messages: as long as needed to resolve your query and a reasonable period after.
  • Aggregate usage data: PostHog stores only aggregate, non-personal statistics for the retention period it applies; there is no personal data about you to access or erase.
  • Marketing data: until you withdraw consent or unsubscribe.

When a retention period ends, we delete or anonymise the data.

7. Your rights

Under the GDPR and the Spanish LOPDGDD, you can ask us to:

  • Access the data we hold about you;
  • Rectify data that is wrong or incomplete;
  • Erase your data ("right to be forgotten");
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Port your data to another provider;
  • Withdraw consent at any time (this does not affect processing done before you withdrew).

To exercise any of these, email nico@swellshaper.com. We may need to confirm your identity. We respond within one month.

8. Complaints

If you think we have mishandled your data, please tell us first — we will try to put it right. You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es. If you are in another EU country or the UK, you may complain to your local authority (in the UK, the ICO).

9. Cookies

We use only the strictly-necessary storage we need to run the site and serve pages (such as session, security and Stripe checkout), plus PostHog for analytics — which sets no cookies at all. We set no advertising or cross-site tracking cookies. Because our analytics uses no cookies and no personal identifiers, no cookie consent banner is required and we do not show one. If we later introduce any cookie-based or identifying tracking (for example in-app product analytics or advertising), we will first put up a compliant consent banner — where rejecting is as easy as accepting, and you can change your mind at any time — publish a full cookie list (name, provider, purpose, category and duration), obtain your prior consent, and update this policy before any such cookie is set. This matches §3.

10. Children

The Services are for adults (18+). We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

11. UK users

If you are in the UK, we process your data under the UK GDPR and the Data Protection Act 2018 in the same way described here, and you may complain to the UK Information Commissioner's Office (ICO).

12. US residents

If you live in the United States, you may have rights under your state's privacy law (such as California's CCPA/CPRA) to access or delete your data. To exercise them, email nico@swellshaper.com. We do not sell your personal data and do not share it for cross-context behavioural advertising.

13. Security

We use reasonable technical and organisational measures to protect your data, including limiting who can access it and relying on reputable providers. No system is perfectly secure, but we take this seriously and will notify you and the authorities of a breach where the law requires.

14. Changes and languages

If we change this policy, we will update the date at the top and, for material changes, let you know. This policy is provided in English; your data-protection rights under the GDPR and the Spanish LOPDGDD apply regardless of the language. Questions? Email nico@swellshaper.com.