Privacy Policy
Last updated: [EFFECTIVE DATE] — draft, not yet legally finalized.
1. Who we are
Stemarks ("Stemarks", "we", "us") operates the booking and payments platform at stemarks.com and the dashboards used by the businesses ("tenants") who sign up for it.
Data controller: [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS], registration number [COMPANY REGISTRATION NUMBER]. You can reach us about privacy matters at support@stemarks.com.
2. Whose data this policy covers
- Visitors to stemarks.com who submit the "Book a call" or "Contact us" forms.
- Tenant users — the business owners/staff who create an account, sign up their business, and use the dashboard.
- End customers — the people who book and pay through a tenant's public booking page. For these individuals, the tenant is the data controller and Stemarks acts as a data processor on their behalf.
3. What we collect
| Category | Data | Source |
|---|---|---|
| Marketing leads | Name, email, website, industry, preferred call date/time, locale | "Book a call" form |
| Contact requests | Name, email, company (optional), message | "Contact us" form |
| Tenant account | Email, password (hashed by our auth provider), business name, business type, contact email/phone, currency, timezone | Signup / onboarding / settings |
| End customers (of a tenant) | Name, email, phone, booking details | Public booking page, entered by the customer or the tenant |
| Payments | Amount, currency, payment status; card details are handled entirely by Stripe and never touch our servers | Stripe Checkout |
| Technical | IP address, browser/device info, cookies (see Section 8) | Automatically, via normal web request handling |
4. Why we use it (legal basis)
- Providing the service — creating your account, running the booking/payment flow (contract necessity).
- Responding to enquiries — the "Book a call" and "Contact us" forms (consent / legitimate interest in responding).
- Sending transactional emails — booking confirmations, invites, password resets (contract necessity).
- Legal and security obligations — fraud prevention, complying with tax/accounting law (legal obligation).
We do not sell personal data, and we do not use it for third-party advertising.
5. Who we share it with
We use a small number of processors to run the platform. None of them are permitted to use your data for their own purposes.
| Processor | Purpose |
|---|---|
| Supabase | Database, authentication, session management |
| Stripe | Payment processing (Checkout Sessions, webhooks) |
| Resend | Transactional email delivery (lead notifications, contact form, confirmations) |
| Vercel | Application hosting |
We do not otherwise share personal data with third parties, except where required by law.
6. International transfers
Some of our processors (Section 5) may process data outside your country. Where that involves a transfer out of the EU/EEA, we rely on the safeguards those processors provide (e.g. Standard Contractual Clauses). [CONFIRM EACH PROCESSOR'S TRANSFER MECHANISM].
7. How long we keep it
[RETENTION SCHEDULE NOT YET DEFINED] — as a general rule: account and booking/payment records are kept for as long as the account is active plus any legally required retention period afterward (e.g. accounting records); marketing leads and contact messages are kept until you ask us to delete them or they become clearly stale.
8. Cookies
We keep this list current with what the site actually sets — verified directly, not a generic template:
- Strictly necessary — authentication session cookie (name pattern
sb-<project-ref>-auth-token, set by our authentication provider Supabase). Keeps you signed in to your Stemarks dashboard. Set when you log in; not set for anonymous visitors browsing the marketing site or booking pages. - Strictly necessary — cookie choice preference (
stemarks_cookie_consent, stored in your browser's local storage, not a cookie). Remembers whether you accepted or declined this notice, so we don't show it again.
We do not currently use analytics, advertising, or tracking cookies of any kind. Payments are processed on Stripe's own hosted checkout page (a separate domain, not stemarks.com) — any cookies Stripe sets for fraud prevention during checkout are Stripe's, governed by Stripe's own privacy policy, not ours. If our cookie usage changes, this section and the cookie banner will be updated first.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time, where processing is based on consent
To exercise any of these rights, email support@stemarks.com. If you are the end customer of one of our tenants, we may need to direct your request to that tenant, since they are the data controller for that relationship.
10. Children
Stemarks is not directed at children, and we do not knowingly collect data from anyone under 16.
11. Changes to this policy
We'll update the "Last updated" date above whenever this policy changes, and post material changes here before they take effect.
12. Contact
Questions about this policy or your data: support@stemarks.com.