← Back to home

Privacy Policy

Last updated: March 2026

1. Who We Are

Hata ("we", "us", "our") operates the website hata.house and the web application at app.hata.house. This policy explains how we collect, use, and protect your personal data.

2. Data We Collect

Account data

When you register, we collect your email address and authentication credentials (managed by Supabase, our authentication provider). If you sign in with Google, we receive your name and email from Google.

Usage data

We store your application preferences: scoring weights, filter settings, destination coordinates, and notification preferences. This data is necessary to provide the service.

Payment data

Payments are processed by Stripe. We do not store your credit card number. We store your Stripe customer ID and subscription status to manage your access.

Cookies

We use essential cookies for authentication (session management via Supabase). We do not use tracking or advertising cookies.

3. How We Use Your Data

  • To provide and maintain the service (scoring, filters, notifications)
  • To process your subscription payments via Stripe
  • To send you notifications you have opted into (Telegram)
  • To respond to your support requests

4. Data Sharing

We share your data only with:

  • Supabase — authentication and session management
  • Stripe — payment processing

We do not sell your data to third parties.

5. Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal data (settings, preferences, subscription records) is permanently deleted within 30 days.

6. Your Rights (GDPR)

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Delete your account and all associated data
  • Export your data in a portable format
  • Object to processing of your data

To exercise these rights, use the account deletion feature in the application or contact us at the email below.

7. Security

We use industry-standard security measures: encrypted connections (HTTPS), secure authentication (Supabase JWT), and encrypted payment processing (Stripe). Database access is restricted and credentials are never exposed in client code.

8. Contact

For privacy-related questions, contact us at: privacy@hata.house

We use essential cookies for authentication. No tracking cookies are used. See our Privacy Policy.