Privacy
Privacy policy
Rules for processing data in the public area of Sprzatly, contact forms, technical statistics and the administrator panel.
Data controller
Sprzatly is the data controller. For privacy and data handling matters, contact us at [email protected].
We process data only to the extent required to handle enquiries, protect the application, provide services and maintain the website.
Categories of data
A client account may contain name, email, phone and saved addresses. A booking stores the selected company, professional, service, time, service address, phone, optional notes, prices and payment status. A company account contains company details, tax ID, services, schedules and employee profiles. Reviews are linked only to completed bookings.
Stripe processes payment details and information required for company payouts as a separate provider; Sprzatly stores only transaction identifiers and statuses. Notifications enter a secured n8n queue; its payload is removed after successful delivery and has bounded retention.
A silent lead does not store the raw IP address or use external IP geolocation. After a successful administrator login, only a hash of the device identifier is stored so later public clicks from that device can be excluded from lead analytics.
The administrator panel records technical activity for security, diagnostics, statistics and access accountability.
The optional-analytics consent receipt contains a random receipt ID, only the SHA-256 hash of a random cookie secret, the version, locale and hash of the exact notice shown, the consent action used in the panel, server-issued time, validity deadline and status or withdrawal time. It contains no email, IP address, user agent or device fingerprint.
An optional page-view record contains only a normalized public path without a query or fragment, time, referring host, pseudonymous hashes of the IP address, user agent and random browser identifier, plus the receipt ID and deletion deadline. The raw IP address and full URL are not stored in that record.
The KMLCode support form stores the selected report type, a message of up to 1,000 characters, an optional reply email, the application identifier and version, and the result of a limited anti-spam assessment. Before storage, an optional image is resized, stripped of metadata and converted to WebP; the original, filename and browser-declared type are not retained.
A valid human submission that the classifier assesses as high risk is stored as flagged for manual review and follows the same retention rules. The generic HTTP 202 response does not reveal the classification. A submission caught by the bot honeypot is not stored.
Purposes of processing
We use data to respond to enquiries, prepare quotes, communicate operationally, protect the application, detect errors and measure website quality.
On the basis of legitimate interests, silent leads help us understand interest in services and bookings without interrupting the public flow and without storing message content, email addresses, phone numbers, passwords, tokens or payment data.
First-party silent-lead recording is an operational mechanism independent of optional analytics. dataLayer or gtag events and public page-view analytics run only after consent is given in privacy preferences and the server verifies an active pseudonymous consent receipt. The server rejects telemetry without that receipt and does not trust a declaration in the event body.
Messages sent through the support area are used to handle bug reports, answer general questions, protect the form from abuse and maintain the application through KMLCode. The technical sending limit uses an irreversible IP-address hash in a short-lived counter and does not store the raw address with the message.
Cookies and similar technologies
Essential local mechanisms support application operation, session security and storage of privacy preferences. localStorage holds a random silent-lead device identifier and sessionStorage holds a random identifier for the current session; the backend stores only salted hashes of these values.
The essential sprzatly_locale cookie contains only the selected locale code, uses Path=/ and SameSite=Lax, is Secure on HTTPS, and expires after at most 365 days. It serves only to remember the interface language, never changes the language of an indexable page without the matching URL, and contains no identifiers, route, query, fragment, form-content or profiling data.
Additional analytics are optional. Checking the status without an existing consent cookie creates neither a cookie nor an analytics identifier. Only after consent does the server set a random sprzatly_analytics_consent cookie with HttpOnly, SameSite=Strict and production Secure flags, Path=/api and a lifetime no longer than 180 days; only its SHA-256 hash is retained in the database.
Your rights
Where provided by law, users may request access, rectification, erasure, restriction of processing, data portability and may object to processing.
Analytics consent can be withdrawn just as easily in the same preferences panel. Analytics is disabled immediately, linked telemetry is deleted, and a failed server withdrawal is retried; the minimal receipt of the earlier consent remains only until its deadline, no later than 180 days after it was granted.
Analytics and consent-proof retention
Every optional page view is linked to an active receipt and has an absolute deletion deadline no later than the consent validity deadline, at most 180 days. Withdrawal deletes all linked views immediately.
Exact TTL indexes for telemetry and the receipt evidenceDeleteAt field are verified at startup and after database reconnection. Consent is not activated and telemetry is not stored without a ready retention guarantee, and readiness reports failure.
Silent-lead retention
Silent-lead records have a separate TTL lifecycle. Retention is at most 180 days and may be shortened by deployment configuration. Recording is suspended if the required retention indexes have not been verified correctly.
The silent-lead endpoint excludes administrative paths and same-application admin referrers, APIs, static assets, likely bot traffic and known administrator devices. An administrator-device marker expires automatically 365 days after the last successful login, and no administrator session is issued if that marker cannot be refreshed.
Support-message retention
Support messages and their compressed attachments are deleted automatically within 180 days. Once archived, the deadline is shortened to no more than 30 days after archiving without extending the original deadline.
Form submissions are suspended if the database or the exact TTL indexes for messages and short-lived abuse counters are not ready. Form content and attachments are excluded from general server request logs.