Privacy Policy
Last updated: June 4, 2026
Introduction
This Privacy Policy explains how Stackedge ("we", "us", or "our") processes personal data when you visit our website, create an account, or use AuditFlow, our AI-powered website audit platform for agencies.
We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR), the Spanish Organic Law on Data Protection and Digital Rights (LOPDGDD), and the Spanish Law on Information Society Services (LSSI-CE).
By using AuditFlow, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use our services.
Data Controller
The data controller responsible for your personal data is:
- Stackedge (sole proprietorship)
- Barcelona, Spain
- Tax ID (CIF): ESY5818456E
- Email: hello@stackedge.ai
Data We Collect
We collect different categories of data depending on how you interact with AuditFlow:
- Account data: name, email address, profile information, and authentication credentials managed through Clerk.
- Billing data: subscription plan, payment status, and transaction records processed by Stripe: We do not store full credit card numbers.
- Usage data: audit configurations, monitored website URLs, audit results, report history, and feature usage within the platform.
- Technical data: IP address, browser type, device information, log files, and cookies when you access our website or application.
- Communication data: messages you send us via contact forms, support requests, or email correspondence.
- Website audit data: publicly accessible content, performance metrics, and technical information from URLs you submit for auditing, including data retrieved via Google PageSpeed Insights.
How We Use Your Data
We use your personal data for the following purposes:
- Providing and operating the AuditFlow service, including running website audits, generating reports, and delivering monitoring alerts.
- Creating and managing your user account and authenticating access to the platform.
- Processing subscription payments, managing billing cycles, and handling refund requests.
- Sending transactional emails such as account confirmations, audit notifications, and billing receipts via Resend.
- Generating AI-powered audit insights and recommendations using OpenAI based on website data you submit.
- Improving our service, fixing bugs, analyzing usage patterns, and developing new features.
- Responding to your inquiries, support requests, and GDPR-related data subject requests.
- Complying with legal obligations, enforcing our Terms of Service, and protecting our rights and the security of our users.
Legal Basis (GDPR Art. 6)
Under the GDPR, we process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b)): processing necessary to provide AuditFlow services you have subscribed to, including account management, audits, and billing.
- Legitimate interests (Art. 6(1)(f)): service improvement, fraud prevention, security monitoring, and analytics, balanced against your rights and freedoms.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing communications where applicable, and any optional data processing where we explicitly request your consent.
- Legal obligation (Art. 6(1)(c)): processing required to comply with tax, accounting, and other applicable legal requirements in Spain and the European Union.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
Account and profile data is retained for the duration of your active subscription and for up to 30 days after account deletion, unless legal obligations require longer retention.
Audit results and generated reports are retained according to your subscription plan settings. You may delete audit data at any time through the platform.
Billing and transaction records are retained for seven (7) years in compliance with Spanish tax and accounting regulations.
Server logs and security records are typically retained for up to 90 days unless needed for ongoing investigations or legal proceedings.
Your Rights (GDPR Art. 15–22)
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights regarding your personal data. To exercise any of these rights, contact us at hello@stackedge.ai. We will respond within one month, as required by the GDPR. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) at www.aepd.es.
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your data, subject to legal retention requirements.
- Right to restriction (Art. 18): request that we limit processing of your data in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing.
- Right not to be subject to automated decision-making (Art. 22): where applicable, request human review of decisions with significant effects.
International Transfers
Some of our third-party service providers are located outside the European Economic Area (EEA), including in the United States. When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place.
These safeguards include Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions where applicable, and supplementary measures such as encryption in transit and at rest.
You may request further information about the specific safeguards applied to international transfers by contacting us at hello@stackedge.ai.
Cookies & Tracking
We use cookies and similar tracking technologies to operate AuditFlow, remember your preferences, and analyze website traffic. Some cookies are essential for the platform to function; others require your consent.
For detailed information about the cookies we use, how to manage your preferences, and your rights regarding cookies, please see our Cookie Policy.
You can manage cookie preferences at any time through our cookie consent banner or your browser settings. Disabling certain cookies may affect the functionality of the service.
Contact & GDPR Requests
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or need to report a data protection concern, please contact us using the details below. We aim to respond to all privacy-related inquiries within 30 days. For urgent security matters, please include "URGENT" in your subject line.
- Email: hello@stackedge.ai
- Subject line: "GDPR Request" or "Privacy Inquiry"
- Data controller: Stackedge, Barcelona, Spain (CIF: ESY5818456E)
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or service features. When we make material changes, we will notify you by email or through a prominent notice on the AuditFlow platform.
The "Last updated" date at the top of this page indicates when the policy was most recently revised. We encourage you to review this policy periodically.
Your continued use of AuditFlow after changes take effect constitutes acceptance of the updated Privacy Policy, unless applicable law requires your explicit consent.