Airco Tracker
ENNLFR中文

GDPR information

Privacy notice

This notice explains what personal data Airco Tracker processes, why, for how long and with whom it is shared.

Effective version: 2026-07-22

Operator information is incomplete. Live checkout is disabled until the required legal information has been verified.

1. Controller and contact

Controller: operator not configured — live checkout disabled, address not configured — live checkout disabled. Privacy requests: privacy contact not configured — live checkout disabled. Registration: not configured — live checkout disabled.

2. Data we process

Account data: UUID, email, nickname, language, delivery country and alert preference. Security data: one-time-code hashes/salts/attempts, session identifiers, timestamps, IP/network security signals and audit logs. Purchase data: Stripe customer, Checkout, PaymentIntent, refund/dispute identifiers, pass, amount, card brand/last four digits, legal versions and acceptance timestamps; we never receive full card numbers. Alert data: recipient projections, entitlement/token version, outbox/delivery state, ACS operation status and bounce/complaint fingerprints. Usage requests and retailer links may generate necessary server logs.

3. Purposes and legal bases

We process account, authentication, delivery preferences and requested alerts to perform the contract or take requested pre-contract steps (GDPR 6(1)(b)); payment, contract evidence, accounting and consumer requests to perform the contract and meet legal obligations (6(1)(b)/(c)); service security, abuse prevention, reliability, aggregate measurement and legal claims for legitimate interests (6(1)(f)); and optional marketing only with consent where required (6(1)(a)). You may object to legitimate-interest processing.

4. Recipients and international transfers

Microsoft Azure hosts the service and Azure Communication Services sends email; Stripe processes payments and acts under its own and processor responsibilities. Retailers/affiliate networks receive data only when you follow their links, under their notices. Professional advisers and authorities may receive data where legally necessary. Azure resource data locations may be European, but associated Azure Event Grid system-topic event data can be processed in Microsoft data centres globally. Stripe and other providers may process data in the US or other countries using adequacy decisions, the EU Standard Contractual Clauses and supplementary measures under their DPAs.

5. Retention

Verification codes expire after about 10 minutes and sessions normally after 30 days. Account/preferences remain until deletion. Published alert-outbox rows are kept for 30 days and terminal delivery metadata for 90 days. Unavailable-product diagnostic state is compacted after 90 days and its minimal tombstone removed after 365 days. Exceptional ACS Event Grid dead-letter bodies are deleted after 7 days. The web service creates no separate persistent request/security-log database; limited platform logs follow the retention configured for the Azure workspace. On account deletion, direct login/profile data is erased. A separate pseudonymous minimum ledger keeps necessary contract, payment, refund, withdrawal and legal-acceptance evidence for retention basis not confirmed — live checkout disabled from the latest legally relevant timestamp in the retained evidence, not from deletion; it is then purged or irreversibly anonymised. It contains no plaintext email, nickname, delivery preference, withdrawal name or card brand/last four. Stripe separately retains payment records under its policy and legal duties.

6. Your rights

Depending on law, you may request access, correction, deletion, restriction, portability, object to processing, and withdraw consent without affecting earlier processing. You may complain to the Dutch Autoriteit Persoonsgegevens, CNIL in France, or another competent EEA authority. We may need proportionate identity verification. Email privacy contact not configured — live checkout disabled.

7. Cookies and automated decisions

We use a strictly necessary session cookie and local language/preferences needed to provide the service. We do not currently use advertising analytics cookies on Airco Tracker. Retailer sites may set their own cookies after you leave. We do not make decisions producing legal or similarly significant effects solely by automated processing.

8. Security and updates

We use access controls, managed identities, encryption in transit, hashed one-time codes, signed links and audit controls. No service is risk-free. The version displayed here applies from its effective date; material changes are communicated where required.

Withdraw / request refundBack home

Airco Tracker · airco-tracker.eu