Privacy Policy
Last updated: April 29, 2026
At SelfEcoFarm ("we," "our," or "us"), user privacy is a foundational principle. We build and maintain our web applications under a strict Privacy by Design model. We do not use tracking or analytics cookies, we do not perform session tracking, and we do not collect any personal data except what is strictly necessary to run your member library.
1. Identity of the Data Controller
The entity responsible for processing your personal data (the Data Controller) is:
SelfEcoFarm
Contact Email: [email protected]
2. Data We Collect
Because we do not track visitors, the only data we process is what you explicitly provide to use the services:
- Library Account Credentials: Your name, email address, profile avatar, and Google/Apple identifiers when you log in to your guides library.
- Transaction Details: Purchase item description, purchase time, price paid, and transaction tokens (payment operations are handled directly on secure Stripe/PayPal screens; we do not store billing card numbers).
- Garden Library Database: The garden lists, plants, reminders, settings, and journal notes you explicitly save in your account.
- Security Metadata: Temporary client IP logs mapped to request rate-limits to protect our servers from DDoS attacks and server abuse.
3. Legal Bases for Processing (GDPR Art. 6)
We process your data strictly under the following legal bases:
| Purpose of Processing | Data Categories Involved | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Account registration, login, and library database access | Name, Email, Profile Avatar, Google/Apple ID | Contractual Necessity: Required to fulfill our contract with you. |
| Processing payments and delivering digital horticultural guides | Name, Email, Purchase details, Transaction tokens | Contractual Necessity: Essential for processing purchases. |
| Saving user garden layouts, reminders, and notes | Garden data, Plants, Reminders, Journal records | Contractual Necessity: Essential to run the sync features. |
| Rate-limiting, server firewalls, and spam prevention | IP address, client request paths | Legitimate Interest: Essential for maintaining system security. |
4. Data Recipients & Third-Party Processors
We do not sell, rent, or share your data for marketing. We only share personal data with external service providers acting as our processors to perform operations, or as independent controllers when legally required:
- PayPal & Stripe: Process transaction funds securely. They act as independent controllers.
- Google Sign-In API: Handles secure authentication. When you log in, Google's scripts verify your credentials and send us your basic profile fields.
- Hosting & Server Infrastructure: Host the web application and SQLite database.
5. International Data Transfers
Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA), including the United States, where our cloud infrastructure is located. We secure these transfers using European Commission-approved Standard Contractual Clauses (SCCs) to guarantee an equivalent level of protection.
6. Data Retention
We store your data only for as long as necessary to fulfill the purposes for which it was collected, or as legally required:
- User Account & Garden Data: Retained for as long as your account remains active. You can request deletion of your account at any time.
- Purchase Logs: Maintained for up to 7 years to meet tax, audit, and legal accounting obligations.
- Rate Limit Registers: Automatically cleared within 24 hours of creation.
7. Your Privacy Rights
Depending on your jurisdiction (such as the EU, UK, or California), you have rights regarding your personal data:
- Right to Access: You can request a summary and a copy of all personal data we hold about you.
- Right to Rectification: You can request that we update or correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You can request that we delete your personal data from our systems.
- Right to Restrict or Object: You can object to our processing of your data, or request restriction under specific circumstances.
- Right to Data Portability: You can request that we transfer your personal data to another service provider in a machine-readable format.
- Right to Non-Discrimination: We will never discriminate against you for exercising your rights (CCPA/CPRA).
To exercise any of these rights, please email us at [email protected]. We will respond to your request within 30 days. You also have the right to file a complaint with your local Data Protection Authority.
8. Cookies & Local Storage Disclosures
In accordance with ePrivacy regulations, your browser local storage is only used to store variables that are strictly necessary for the functionality you explicitly request (logging in to your library):
| Key Name | Provider | Purpose & Category | Duration |
|---|---|---|---|
| sf_web_token | First-Party | Stores secure Google Authentication JSON Web Token (JWT) [Necessary] | Persistent |
| sf_web_user | First-Party | Caches client-side user metadata (name, email, avatar) for greets [Necessary] | Persistent |
| g_state | Google Inc. | Manages sign-in prompts and state for the Google Sign-in API [Necessary] | Persistent |
Privacy Questions?
If you have any questions about your data or wish to exercise your rights, please contact us:
Go to Contact Page