Privacy Policy
Last updated: 10 September 2026
1. Data controller
The controller responsible for processing personal data is Masterweb Solutions, contactable at [email protected].
2. Data we collect
We collect only the data strictly necessary to provide the service:
- Account data: name, email address, company and phone number (optional).
- Google sign-in data: when you sign in with Google we receive your email address, name and Google unique identifier. We do not access your Gmail, contacts, calendar or Drive.
- Usage data: access logs (IP address, date, browser) for security and diagnostics.
- Commercial data: estimates, proposals and requests you create on the platform.
- Interaction with our emails: when you click a link in one of our announcements we record which link, when and from which browser. We never read your mailbox.
3. Purposes
We use your data to:
- Create and administer your account.
- Authenticate you by password or Google OAuth.
- Process the estimates and proposals you request.
- Send communications related to your account and the service.
- Meet legal, accounting and tax obligations.
- Learn which announcements interest you so we can follow up commercially. You can stop receiving them with the link at the bottom of every email.
4. Use of data obtained from Google
This application's use of information received from Google APIs is governed by the
Google API Services User Data Policy, including its Limited Use requirements. We request only the minimum scopes:
openid,
email,
profile.
5. Sharing data with third parties
We do not sell your data. We share it only with service providers needed to run the platform (hosting, transactional email, payment gateway), under confidentiality agreements and only to the extent strictly necessary.
6. Retention
We keep your data for as long as your account is active. If you request deletion, the data is erased or anonymised within 30 days, except where the law requires us to keep it longer (invoicing, auditing).
7. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability at any time by writing to [email protected]. We will respond within the legally required timeframes.
8. Security
We apply reasonable technical and organisational measures to protect your data: encryption in transit (HTTPS), password storage with bcrypt, role-based access control, audit logs and automatic lockout on suspicious attempts.
9. Changes
We may update this policy. When we do, we will change the "Last updated" date and, where the changes are substantial, notify you by email.