Privacy policy
Last updated: 14 September 2026
This policy explains what personal data Graflio processes, why, and your rights under the GDPR. Data controller:
Owner: Graflio, operated from Spain.
Contact: info@graflio.com
Tax ID (NIF) and registered address: available on request at the contact address above.
What we collect
- Account: your email address and a hashed password (we never store the password itself).
- Your work: the Amazon listings you import (public listing data), the images you generate or upload, brand kits, and pitch pages you create.
- Billing: payments are handled by Stripe; we receive a payment confirmation and the last digits of your card, never the full card number.
- Technical: server logs (IP address, request, time) kept briefly for security and debugging, and — only if you accept the cookie banner — Google Analytics usage statistics.
Why (legal bases)
- Providing the service you signed up for — contract (art. 6.1.b GDPR).
- Billing and tax records — legal obligation (art. 6.1.c).
- Security, abuse prevention, service improvement — legitimate interest (art. 6.1.f).
- Analytics cookies — your consent (art. 6.1.a), which you can withdraw at any time.
Who processes it for us
- Hetzner Online GmbH (Germany) — hosting. Data stays in the EU.
- Stripe Payments Europe Ltd. (Ireland) — payment processing.
- OpenRouter, Inc. (USA) — AI generation: the listing text and images involved in a generation are sent for processing, under EU Standard Contractual Clauses.
- Google Ireland Ltd. — analytics, only with your consent.
We do not sell personal data and do not use it for automated decisions with legal effect.
Retention
Account data is kept while your account exists and deleted on request; invoices as long as tax law requires; server logs for a few weeks.
Your rights
You can request access, rectification, erasure, portability, restriction or object to processing by writing to info@graflio.com. You can also complain to the Spanish supervisory authority (AEPD, aepd.es).