1. Controller and scope
Hustle Got Real S.L., NIF B16589004, VAT number ESB16589004, with registered address at C/ Joan Ripoll Trobat 34, 2º A, 07013 Palma, Illes Balears, Spain and registered in the Registro Mercantil de Palma de Mallorca, volume 2776, folio 156, section 8, sheet PM-84769, entry 5, is the controller of personal data described in this policy. You can contact us about privacy at [email protected].
This policy covers Product Information API’s public website, customer app, API, billing administration, and support. It does not govern third-party source websites, Stripe, or other services that publish their own privacy terms.
2. Personal data we collect
- Account data: name, business or organisation, email address, account identifiers, verification status, preferences, and authentication and security records.
- Billing data: selected plan, credits, subscription and invoice status, billing contact details, transaction references, and Stripe customer and payment identifiers. Stripe receives payment-card details directly; we do not store complete card numbers.
- API and usage data: API credential identifiers, submitted product-page URLs, request and response metadata, results where operationally necessary, timestamps, credit usage, errors, source coverage, and account-level limits.
- Device and security data: IP address, user agent, request headers, authentication events, rate-limit events, and diagnostic or security logs.
- Communications: support requests, billing questions, feedback, and other messages you send to us.
Please do not submit sensitive personal data or private, authenticated, or access-controlled pages to the API. The Service is designed for public product-page URLs.
The account, authentication, plan, and billing details marked as required in our forms are necessary to create and secure an account, enter into the service contract, and administer payments. If you do not provide them, we cannot create the account or provide the applicable Service. Support messages and any optional marketing preferences are voluntary.
3. Where data comes from
We receive data directly from you and your systems, automatically when you use the Service, from Stripe in connection with billing, and from public product pages that you ask the API to process. If your organisation provides your details, it must have authority to do so.
4. Why we use personal data
| Purpose | Typical legal basis |
|---|---|
| Create accounts, authenticate users, deliver API results, manage credits, provide support, and administer subscriptions. | Performance of our contract and steps taken at your request before entering it. |
| Secure the Service, prevent abuse and fraud, diagnose errors, enforce limits, and improve reliability. | Our legitimate interests in operating a safe, reliable business service. |
| Process payments, keep accounting records, respond to lawful requests, and establish or defend legal claims. | Legal obligations and our legitimate interests in protecting our rights. |
| Send requested support, transactional, verification, security, billing, and service-change messages. | Performance of our contract, legal obligations, and legitimate interests. |
| Send optional marketing communications where offered. | Your consent, where consent is required. You may withdraw it at any time. |
Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where their rights and interests override ours.
5. Payments and Stripe
Checkout and recurring payments are handled by Stripe. We send Stripe the information needed to create and reconcile a customer, Checkout session, subscription, invoice, refund, or dispute, and Stripe sends us the related status and identifiers. Stripe handles payment details under its own Privacy Policy and may act as our service provider or as an independent controller, depending on the activity.
6. Sharing and service providers
We may share personal data only as needed with:
- payment, cloud hosting, infrastructure, email, monitoring, security, and support providers;
- professional advisers, auditors, insurers, and financial institutions;
- public authorities or other parties where required by law or necessary to protect rights and safety; and
- a buyer, investor, or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality protections.
We do not sell personal data.
7. International transfers
Some providers may process data outside Spain or the European Economic Area. Where required, we use an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with appropriate safeguards. You may contact us for more information about the mechanism relevant to your data.
8. Retention
We keep personal data only for as long as needed for the purposes described above. Account and subscription records are generally retained for the customer relationship and then deleted or anonymised, subject to legal, accounting, tax, security, fraud-prevention, and claim limitation requirements. API and security logs are kept for the shortest period reasonably needed to operate, secure, troubleshoot, and demonstrate correct billing of the Service. Aggregated or anonymised statistics may be retained longer.
When deciding a retention period, we consider the data’s amount, nature, sensitivity, risk, purpose, technical architecture, and applicable legal requirements.
9. Cookies and similar technologies
The public marketing site does not currently set analytics or advertising cookies. The customer app and Checkout may use cookies or similar storage that is strictly necessary for authentication, security, session continuity, fraud prevention, and payments. Stripe’s use of these technologies is governed by its own policy. If we introduce non-essential analytics or advertising technologies, we will update this notice and request consent where required.
10. Security
We use technical and organisational measures designed to protect personal data, including access controls, encrypted transport, credential protection, logging, and service monitoring. No internet service is completely secure, so we cannot guarantee absolute security. Contact [email protected] promptly if you believe an account or API credential has been compromised.
11. Your data protection rights
Subject to applicable law, you may ask us to provide access to, rectify, erase, restrict, or port your personal data, and you may object to processing based on legitimate interests. If processing is based on consent, you may withdraw consent at any time without affecting prior processing.
To exercise a right, email [email protected]. We may need to verify your identity and authority. You may also complain to the Spanish Data Protection Agency (AEPD) or the supervisory authority where you live or work.
12. Automated decisions and children
We do not use personal data to make decisions that produce legal or similarly significant effects solely by automated means. The Service is intended for business and professional users and is not directed to children under 18.
13. Changes to this policy
We may update this policy when the Service, our providers, or legal requirements change. We will post the new version with a revised effective date and provide additional notice where a change is material or the law requires it.
14. Contact
Hustle Got Real S.L.NIF: B16589004; VAT: ESB16589004
Registro Mercantil de Palma de Mallorca, volume 2776, folio 156, section 8, sheet PM-84769, entry 5
C/ Joan Ripoll Trobat 34, 2º A, 07013 Palma, Illes Balears, Spain
Privacy and legal: [email protected]
Product support: [email protected]