Privacy Policy
Last updated: 9/25/2026
1. Data Protection & GDPR Compliance
PoppyNest is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data We Collect
- Account information (email, name)
- Property data (addresses, purchase information)
- Financial data (transactions, receipts)
- Usage data (app interactions, preferences)
- Technical data (IP address, device information)
How We Use Your Data
- Provide and maintain our services
- Process transactions and calculations
- Improve user experience
- Ensure security and prevent fraud
- Comply with legal obligations
2. Security Measures (SOC2 Compliance)
We implement industry-standard security measures to protect your data:
- Encryption: All data is encrypted in transit and at rest
- Access Controls: Role-based access with multi-factor authentication
- Audit Logging: Comprehensive logging of all system activities
- Data Backup: Regular encrypted backups with disaster recovery
- Vulnerability Management: Regular security assessments and updates
- Incident Response: Documented procedures for security incidents
3. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw consent at any time
4. Data Retention
We retain your data only as long as necessary for the purposes outlined in this policy:
- Account Data: Until account deletion or 7 years after last activity
- Transaction Data: 7 years for tax and compliance purposes
- Audit Logs: 7 years for security and compliance
- Marketing Data: Until consent is withdrawn
5. Third-Party Services
We use the following third-party services that may process your data:
- Supabase: Database and authentication services
- Google Maps: Location and mapping services
- Google Drive: File storage and management
- Vercel: Hosting and content delivery
All third-party services are GDPR-compliant and have appropriate data processing agreements.
6. Data Breach Notification
In the event of a data breach that may result in a high risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected users without undue delay
- Provide details of the breach and measures taken
- Offer guidance on protective measures
7. Contact Information
For any privacy-related questions or to exercise your rights, please contact us:
Data Protection Officer:
Email: [email protected]
Address: [Your Business Address]
Phone: [Your Phone Number]
8. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by:
- Posting the new policy on this page
- Sending you an email notification
- Updating the "Last updated" date