Legal

Privacy Policy

Last updated: April 11, 2025

1. Who We Are

Heee.ro is operated by Axiontic SRL, a company incorporated in Romania (VAT: RO46009350). We are the data controller for personal data collected through the Service.

Contact: heee.ro@axiontic.com

2. Data We Collect

Account data

When you register, we collect your name, email address, and a hashed password (if you sign up with email). If you sign in via Google OAuth, we receive your name, email, and profile picture from Google.

Site content

We store the content of your Sites — text, images, links, and configuration — in order to display and serve them to your visitors.

Payment data

Payments are processed by Stripe. We do not store your full card details. We store your Stripe Customer ID and subscription status to manage your plan.

Analytics data

If you enable analytics on your Site (Pro/Business feature), we collect page views and CTA click events, along with an anonymised IP hash, referrer URL, and user-agent string. We do not track visitors across sites.

Usage data

We use Vercel Analytics to collect aggregated, anonymous usage data (page views, performance metrics). No personally identifiable information is stored by this service.

Form submissions

If you add a contact form block to your Site, visitor submissions are emailed directly to you via Resend. We do not permanently store form submission data.

3. How We Use Your Data

  • To create and manage your account.
  • To host and serve your published Sites.
  • To process payments and manage your subscription.
  • To send transactional emails (form submissions, account notifications).
  • To improve the reliability and performance of the Service.
  • To comply with legal obligations.

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

4. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Contract performance — to provide the Service you signed up for.
  • Legitimate interests — to improve and secure the Service.
  • Legal obligation — where required by Romanian or EU law.
  • Consent — for any optional data processing you explicitly opt in to.

5. Third-Party Services

We use the following sub-processors:

ServicePurposeLocation
VercelHosting and infrastructureUSA / EU
SupabaseDatabase (PostgreSQL)EU
StripePayment processingUSA / EU
ResendTransactional emailUSA
Google OAuthSocial loginUSA
Vercel AnalyticsAnonymous usage analyticsUSA

Transfers to the USA are covered by Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms as required by GDPR.

6. Data Retention

We retain your account data for as long as your account is active. When you delete your account, we delete your personal data within 30 days, except where we are required to retain it by law (e.g. billing records for tax purposes, which are retained for 5 years as required by Romanian law).

7. Cookies

We use a single session cookie to keep you logged in. We do not use third-party tracking cookies or advertising cookies. Vercel Analytics uses no cookies — it is fully cookieless.

8. Your Rights (GDPR)

If you are located in the EU/EEA, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — request deletion of your personal data.
  • Portability — receive your data in a machine-readable format.
  • Restriction — ask us to restrict processing in certain circumstances.
  • Objection — object to processing based on legitimate interests.
  • Complaint — lodge a complaint with your national data protection authority.

To exercise any of these rights, email us at heee.ro@axiontic.com. We will respond within 30 days.

9. Security

We implement industry-standard security measures including TLS encryption in transit, hashed passwords (bcrypt), and Row-Level Security on our database. No method of transmission over the internet is 100% secure and we cannot guarantee absolute security.

10. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

Axiontic SRL

VAT: RO46009350

Romania

Email: heee.ro@axiontic.com

Website: axiontic.com

Privacy Policy — Heee.ro