Privacy policy
The operator of this service has not entered their company details yet (environment variables LEGAL_COMPANY, LEGAL_ADDRESS, …).
Controller
—, —, info@alinio.app
What we process and why
Customer accounts
When you create an account we store your name, e-mail address and a one-way hash of your password, as well as the websites, settings and translations you manage. We need this data to provide the service (Art. 6 (1) (b) GDPR). You can delete your account at any time in the dashboard; all associated data is deleted with it.
While you are logged in, a strictly necessary session cookie keeps you signed in. We use no analytics or advertising cookies.
Payments
Paid plans are paid through Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland). Stripe receives your name, e-mail address and the payment and billing details you enter on Stripe's payment page; we never see your full card details. We store the Stripe customer and subscription identifiers and the subscription status to provide your plan (Art. 6 (1) (b) GDPR) and keep invoices as required by tax law (Art. 6 (1) (c) GDPR). Stripe also processes data under its own responsibility, e.g. for fraud prevention: stripe.com/privacy.
Visitors of our customers' websites
The alinio widget sends the text of the page a visitor is reading, the page path and the chosen language to our servers in order to return translations. It does not set cookies and does not create visitor profiles. The chosen language and already received translations are stored in the visitor's browser (local storage) so that later page views are translated instantly. The website operator is responsible for informing their visitors and acts as controller; we process the texts on their behalf.
Server logs
Our servers log technical request data (IP address, time, requested URL, user agent) to operate the service securely and to prevent abuse (Art. 6 (1) (f) GDPR). Logs are deleted after a short period.
Website statistics
When you open a page of this website (not the dashboard) without being logged in and arrive from a link on another site, we record the address of that site as your browser passes it on (usually only the domain), the page you arrived on and the time. For search engines and other bots we record their user agent instead. We store no IP address and set no cookie for this, so the entries cannot be traced back to you. They show us which sites bring visitors to us (Art. 6 (1) (f) GDPR) and are deleted after one year.
Backups
We back up the database every day and keep each backup for up to 31 days. Deleted data disappears from the backups once the last backup holding it has been replaced.
Machine translation
Texts that have not been translated before are sent to an AI model provider for translation. Only page text is transmitted — no visitor identifiers. Translations are stored so that each text is translated only once.
Recipients
We use hosting and AI translation providers as processors bound by data processing agreements, and Stripe for payments. Where they are located outside the European Economic Area, transfers rely on adequacy decisions or standard contractual clauses.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing, as well as the right to lodge a complaint with a supervisory authority. Contact us at the address above to exercise them.