Skip to main content

Privacy Policy

Privacy Policy

NOTICE: this document contains [PENDIENTE: …] placeholders that the owner must complete before trading. Guidance document pending review by a licensed attorney.

This policy describes how Stelvia processes the personal data it collects through the stelvia.space site — including data associated with user accounts and public signatures on stars — in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

Controller: Rubén Jarne Cabañero (Stelvia). Tax ID: 77217706J. Registered address: Calle del Canal 9, 50007 Zaragoza (España). Contact and rights requests: hello@stelvia.space. Data Protection Officer (DPO): not appointed. Stelvia is not a public body, does not carry out large-scale processing of special categories of data, and its core activity does not consist of operations requiring regular and systematic large-scale monitoring (art. 37 GDPR), so the grounds for mandatory appointment do not apply. This assessment must be reviewed periodically.

2. Data we collect

We collect the following data: (a) account data: email address, verification status, language and notification preferences (including the signature-substitution notice); (b) user-provided content: the chosen name and message of each signature — public while the signature is active and potentially containing third parties' personal data — and the account's private history of previous signatures; (c) lock order data: order reference and billing data where necessary; payment data is handled directly by Stripe and Stelvia does not store full card details; (d) moderation report data: selected reason, optional comment and IP address in pseudonymised form (hash), to limit abuse of the mechanism; (e) technical data: IP address, session identifiers, browser and device type, collected through strictly necessary cookies; (f) aggregated usage data through Google Analytics 4 (Google Ireland Ltd.), pseudonymised and with anonymised IP, captured only if you have accepted the “Analytics” category in the cookie banner; (g) technical error-diagnosis data through Google Cloud Error Reporting (browser type, route, message and trace), with no cookies of its own and a “no PII” configuration.

3. Purposes of processing

We process data to: (a) create and manage your account, including verifying your email address; (b) provide the signature service: publish your signature on the service's surfaces, enforce the one-free-signature-per-account rule, keep your private history and manage substitutions; (c) perform the lock contract: process the payment, secure your signature and generate and deliver your certificate and video; (d) send you service status notifications, such as the notice that your signature has been replaced or your payment confirmation (you can turn off substitution notices in your account); (e) moderate reported content and prevent abuse of the service and of the reporting mechanism itself; (f) comply with the accounting and tax obligations imposed by the Commercial Code and tax legislation; (g) handle enquiries, complaints and the exercise of rights; (h) with prior consent, measure aggregated site usage (Google Analytics 4) and, where applicable, send commercial communications; (i) ensure the security and operational continuity of the site, including technical incident diagnosis through Google Cloud Error Reporting.

4. Legal bases

(a) Performance of a contract (art. 6.1.b GDPR): the account and its verification, signatures and their publication, the private history, the lock with its certificate and video, and service status notifications — including the signature-substitution notice, which is a service communication and not a commercial communication, and which can be turned off in the account; (b) compliance with a legal obligation (art. 6.1.c GDPR): accounting and tax retention; (c) legitimate interest (art. 6.1.f GDPR): moderation of reported content and abuse prevention (including the pseudonymised IP of reports), site security, fraud prevention and technical error diagnosis through Google Cloud Error Reporting, following the corresponding balancing test; (d) consent (art. 6.1.a GDPR): analytics cookies (Google Analytics 4) and commercial communications when activated. [PENDIENTE: validación por abogado colegiado del encuadre del aviso de sustitución de firma como comunicación de servicio a efectos del art. 21 LSSI-CE]

5. Public signatures and account deletion

Your signature (chosen name and message) is public by default while it is active: it is displayed on the sky map, in augmented reality, on the star's page and in the search. We never display your email address or any other account data next to the signature, and there are no public user profiles. If another user signs the same star, your message stops being public at that moment and moves to your private history. When you delete your account (self-service, from within the account): your signatures and their messages are removed from public surfaces; the certificates and videos associated with your locks are deleted; the corresponding stars become free; and your private history is erased. Order data is kept in anonymised form due to tax obligations (section 7). If you are mentioned in someone else's signature, you can request its removal through the report button (reason “personal data”) or by writing to hello@stelvia.space; we will handle it in accordance with arts. 17 and 21 GDPR.

6. Moderation and reports

Any visitor may report a signature without needing an account. When processing a report we process the selected reason, the optional comment and the reporter's IP address in pseudonymised form (hash), for the sole purpose of limiting abuse of the mechanism (rate limits) and auditing moderation decisions. The reported signature is precautionarily hidden from public surfaces until it is reviewed. Legal basis: legitimate interest (art. 6.1.f GDPR). Retention: report data is kept while the review lasts and as a record of the decision taken. [PENDIENTE: fijar plazo máximo de conservación de los reportes — validación por abogado colegiado]

7. Retention periods

Account data, signatures and the private history are kept for as long as the account exists; upon deletion, the effects described in section 5 apply. The retention policy applicable to long-inactive accounts is under review [PENDIENTE: definir la regla de retención de cuentas inactivas y reflejarla aquí]. Lock order data is kept for the duration of the contractual relationship and, afterwards, for the applicable legal periods: 6 years for accounting and commercial documentation (art. 30 Commercial Code) and 4 years for tax obligations (art. 66 General Tax Law); after 5 years, orders are anonymised automatically.

8. Recipients and processors

To provide the service we rely on the following processors, all located in the European Union or bound by adequate safeguards: Stripe Payments Europe Ltd. (Ireland, EU) to process payments; Supabase Inc. with infrastructure in Frankfurt (Germany, EU) for storage, database and account authentication; Resend Inc. with servers located in the European region (Ireland) for transactional email; Vercel Inc. with compute deployed in European regions for frontend hosting; Inngest Inc. for asynchronous task execution; Google Ireland Ltd. for aggregated site usage measurement with Google Analytics 4 when you have accepted the “Analytics” category, and Google Cloud EMEA Ltd. for hosting, database, storage, transactional email and technical error diagnosis (Cloud Error Reporting), with data hosted in the europe-west1 region (Belgium, EU) [PENDIENTE: validación por abogado colegiado de la redacción de las transferencias de Google Analytics 4 a EE. UU. al amparo del EU-U.S. Data Privacy Framework y de las CCT del art. 46.2.c RGPD]. Processors access data solely to provide their service under our documented instructions and under a contract compliant with art. 28 GDPR. If we enable social media advertising, Meta Platforms Ireland Ltd. (Ireland, EU) and TikTok Technology Limited (Ireland, EU) also take part in measuring our campaigns, solely in respect of users who have accepted the “Advertising” category in the cookie banner and only while the corresponding pixel is deployed; the cookie policy states which ones are deployed at any given time.

9. International transfers

We have selected providers with European infrastructure to avoid unnecessary international transfers. However, some of them are US entities (Resend Inc., Vercel Inc., Inngest Inc., Stripe Inc. within its group). Where a transfer to the United States is unavoidable for technical support or operational continuity of the parent company, that transfer is covered by the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) under article 46.2.c GDPR, or by the provider's adherence to the EU-US Data Privacy Framework where available, additionally assessing supplementary measures in line with the Schrems II judgment. Advertising pixels deserve a separate mention: although the contracting entity is the Irish subsidiary, data is shared with their US parents (Meta Platforms, Inc. and TikTok Inc./ByteDance Ltd.) and, in TikTok's case, the provider has acknowledged remote access by group staff from China. That is why no advertising pixel loads without express, specific consent to the “Advertising” category [PENDIENTE: antes de activar el píxel de TikTok, completar la evaluación de impacto de la transferencia (TIA) y validarla con abogado colegiado].

10. Data subject rights

You have the right to access your data, rectify it, erase it, object to processing, restrict it and request portability. You can exercise these rights by sending an email to hello@stelvia.space stating the right you are exercising and attaching a copy of a document proving your identity, or directly from your account (deletion). We will reply within one month, extendable to two where the complexity or volume of requests justifies it. You also have the right to lodge a complaint with the Spanish Data Protection Agency (https://www.aepd.es) if you consider that the processing does not comply with the law.

Visibility notices (ephemerides)

If you have secured your signature with the lock, you can voluntarily subscribe to the ephemerides: a single email notice per year, on the night the star you signed reaches its best visibility. Purpose: to send you that annual notice. Data processed: your email address and an approximate latitude we calculate from the country and, if you provide it, the city you select manually in the form; we do not use GPS or browser geolocation, nor do we set cookies for this feature. Legal basis: your consent (art. 6.1.a GDPR), given when you subscribe through double confirmation. Retention: for as long as your consent remains valid; if you unsubscribe, we delete this data. Rights: you can access, rectify, object to or erase your data as described elsewhere in this policy, and unsubscribe in a single click from the link included in every notice.

11. Minors

Registering an account and publishing signatures require being at least 14 years old (art. 8 GDPR and art. 7 LOPDGDD). By registering you declare that you meet this requirement; we do not carry out documentary age verification. Purchasing the lock additionally requires the capacity to use the corresponding payment method. If we detect an account belonging to a child under 14, we will delete it together with their signatures; holders of parental authority or guardianship may request this by writing to hello@stelvia.space.

12. Security

We apply reasonable technical and organisational measures to protect data: encryption in transit (HTTPS/TLS), encryption at rest in the database, role-based access control, activity logs and periodic review of providers. In the event of a security breach posing a risk to your rights, we will notify the Spanish Data Protection Agency within 72 hours and, where necessary, inform you directly.

13. Changes to this policy

We may modify this policy to adapt it to regulatory or service changes. The date of the last update appears at the end of the document. Substantial modifications will be communicated by email where we have your address.

Last updated: 24 August 2026

Guidance document. Before commercial operation it must be reviewed by a licensed attorney specialised in consumer and data protection law.