Privacy Policy
1. Who we are
Stubsmith (operating as Stubsmith, pending formal incorporation as Stubsmith B.V. in the Netherlands) operates the Stubsmith service at stubsmith.dev. For GDPR purposes, Stubsmith is the data controller for account and usage data. For API sample data, Stubsmith acts as a data processor on your behalf.
Contact: privacy@stubsmith.dev
2. Data we collect
2.1 Account data (controller)
- Email address and name (required for authentication)
- Organization name and member list
- Subscription and billing status (amounts, plan, not full card data)
- Authentication logs (login timestamps, passkey credentials)
2.2 API sample data (processor)
API samples captured by the SDK are encrypted before they leave your infrastructure. Stubsmith stores only ciphertext and structural fingerprints. We cannot read the contents of your sample payloads. You are the data controller for any personal data contained in your samples; our Data Processing Agreement governs this processing.
2.3 Usage and technical data
- Request counts, fingerprint counts, storage usage (for plan enforcement)
- Server access logs (IP address, request path, timestamp) — retained 30 days
- Error logs and traces (no sample payload content)
3. How we use your data
- To provide, operate, and improve the Service
- To enforce plan limits and process billing
- To respond to support requests
- To send transactional emails (account, billing, security notifications)
- To comply with legal obligations
We do not sell your data. We do not use your data for advertising.
4. Legal basis (GDPR)
- Contract: processing necessary to provide the Service you signed up for (account data, usage data).
- Legitimate interest: security monitoring, fraud prevention, service improvement.
- Legal obligation: tax records, regulatory compliance.
5. Data sharing
We share data only with:
- Scaleway (France) — infrastructure hosting, managed PostgreSQL, object storage, key management
- Mollie (Netherlands) — payment processing
- Bunny.net (Slovenia) — CDN and DNS
All sub-processors are EU-based or cover data transfer under standard contractual clauses where applicable.
6. Data retention
- Account data: retained while your account is active, plus 90 days after deletion for legal/audit purposes.
- API samples: per plan retention schedule (24h / 7d / 30d / 90d).
- Fingerprints and stubs: retained until you delete them or close your account.
- Billing records: retained 7 years per Dutch tax law.
7. Your rights (GDPR)
EU/EEA residents have the right to: access, rectification, erasure, restriction, portability, and to object to processing. To exercise these rights, contact privacy@stubsmith.dev. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Security
Account data is protected in transit (TLS 1.2+) and at rest. API samples are end-to-end encrypted — see the Security page for architecture details. We conduct regular security reviews and will notify affected users of any breach within 72 hours as required by GDPR.
9. Cookies
The marketing site (stubsmith.dev) sets no tracking or analytics cookies. The application (app.stubsmith.dev) sets a session cookie (ss_session, httpOnly, Secure) and an optional login-hint cookie (ss_logged_in, non-httpOnly, Domain=.stubsmith.dev) used only to show or hide the "Dashboard" button on the marketing site.
10. Changes
We will notify you of material changes to this policy by email and via the dashboard at least 14 days before they take effect.
11. Contact
Privacy questions: privacy@stubsmith.dev