Privacy

Privacy Policy

How PicchuSpot uses personal information to provide visual services, protect customer accounts and files, process eligible payments, and operate support.

Effective:
30 August 2026
Version:
2026-08-30

1. Controller and contact

For the processing described in this Policy, the controller is Mykhailo Lykin, trading as PicchuSpot and established in Spain.

C. Capitán Dema, 303007 AlicanteSpainPrivacy email: hello@picchuspot.com

See the Legal Notice for full operator details. This Policy applies when you browse the public site, create an account, place or review an order, upload files, use support, or submit a property enquiry.

If another organisation gives you access to PicchuSpot or places an order involving your information, that organisation may also be a controller for its own use. Contact it about processing it controls.

2. Information we process

  • Account and contact data: name, email, telephone, company, locale and profile information.
  • Order and commercial data: services, quantities, pricing snapshot, currency, tax/payment status, instructions, revisions, confirmations and transaction references.
  • Project content: property photos, plans, sketches, references, filenames, notes, branding, review attachments and completed deliverables.
  • Communications: contact requests, property enquiries, transactional email, support messages, review comments and recent context shared during a requested human-support handoff.
  • Technical and preference data: authentication session, language, region, currency, cookie choice, browser/device information, security events, rate-limit identifiers and consented analytics events.

Required account, order, payment and project fields are needed to provide the requested service. If they are not supplied, we may be unable to create or complete the order. Portfolio permission and analytics consent are optional.

3. Purposes and legal bases

Accounts, quotes and orders

Information
Account, contact, order, project and communication data
Legal basis
Steps requested before a contract and performance of the service contract

Payments, tax and records

Information
Order totals, billing details, transaction references and status
Legal basis
Contract performance and compliance with accounting, tax and legal obligations

Delivery, review and support

Information
Project files, deliverables, revisions and communications
Legal basis
Contract performance and legitimate interests in responsive customer service

Security and abuse prevention

Information
Session, network/technical events, hashed rate-limit identifier and audit records
Legal basis
Legitimate interests in protecting customers, systems and the service; legal obligations where applicable

Analytics

Information
Consented Google Analytics events and related technology
Legal basis
Consent, which can be withdrawn through Cookie settings

Portfolio publication

Information
Selected project visuals and associated display information
Legal basis
Separate optional permission/consent, withdrawable for future use

Legal claims and compliance

Information
Relevant account, transaction, communication and security records
Legal basis
Legal obligation and legitimate interests in establishing, exercising or defending claims

4. Orders, files and deliverables

Source uploads, visual references and review attachments are used to scope and produce the ordered work. Customer source files and deliverables are kept in private storage and made available through authenticated or time-limited access. Access is limited according to the customer/order relationship and authorised operational roles.

Please avoid including unnecessary personal information in filenames, images or instructions. Real-estate media can reveal an address, occupancy, belongings or other sensitive context even when it does not identify a person by name.

Promotional publication is separate from production. It occurs only when the order's optional portfolio permission is enabled and the work is independently approved for a public location.

5. Payments

Eligible fixed-price orders use Stripe-hosted Checkout. Stripe receives the payment and billing details entered on its page and returns transaction, tax and status information needed to reconcile the order. PicchuSpot's order form does not receive the full card number or CVC.

PicchuSpot retains order totals, currency, payment status, provider identifiers and refund state as needed for service, accounting, disputes and legal obligations. Custom-quote or local services may use a separately confirmed billing route.

6. AI and human support

The support assistant sends the current question and limited recent conversation context to Google's Gemini service to generate a reply. Provider request storage is disabled in the application request, and PicchuSpot does not persist that AI transcript in its application database. Processing by the external provider is still necessary to generate the response.

A limited completed transcript can remain in your browser session to keep the widget usable. For rate limiting, the server converts a trusted network address into an HMAC-hashed identifier before using Upstash; Upstash analytics is disabled.

Crisp loads only after you explicitly request a human handoff in production. Crisp may then receive your submitted email, optional name, locale, current page path, limited recent AI context and the messages you send in its interface. The configured support cookie expires after 30 days. You can instead use the contact page.

Do not place passwords, payment-card data, government identifiers or unrelated confidential information in support messages.

7. Analytics and browser storage

Google Analytics is configured with Consent Mode set to denied before a choice is made. PicchuSpot enables its page-view configuration and analytics events only after you accept analytics. Advertising storage, advertising user data and advertising personalisation remain denied. Admin and client-dashboard routes are excluded from application analytics.

Published property pages also record a small set of first-party, aggregate content events. The application record contains the property/event identifiers and a timestamp, not a visitor identifier, email, telephone number or application-level IP field. Hosting and security infrastructure can still process transient request metadata.

Necessary and functional storage supports authentication, consent choice, language, region, currency, form recovery and support-session continuity. See the Cookie Policy for the complete current browser-storage description and controls.

8. Service providers and recipients

Supabase

Role
Authentication, database and private file storage
Information involved
Account, order, communication, file and access-control data

Vercel

Role
Application hosting, delivery and operational logs
Information involved
Website requests and technical/operational data

Stripe

Role
Hosted Checkout, tax/payment processing and refund events
Information involved
Billing, transaction, tax and payment-status data

Resend

Role
Transactional email delivery
Information involved
Recipient, message and delivery metadata

Google

Role
Gemini support responses and consent-controlled Analytics
Information involved
Support prompt/context or consented analytics/technical data

Crisp

Role
On-demand human support
Information involved
Submitted contact data, page/locale, limited context and messages

Cloudflare

Role
Turnstile anti-abuse checks on relevant forms
Information involved
Security token and technical request data

Upstash

Role
Support rate limiting
Information involved
HMAC-hashed rate-limit identifier and counters

9. Other disclosures

We may disclose relevant information to professional advisers, insurers, authorities, courts or counterparties where reasonably necessary to comply with law, protect rights and security, investigate misuse, complete a corporate transaction, or establish, exercise or defend a legal claim.

Property-enquiry information is delivered to the intended business contact so the enquiry can be answered. We do not describe the providers above as independent advertisers and do not sell personal information as part of the current service.

10. International processing

PicchuSpot operates from Spain, but technology providers may process information in other countries. Where personal information is transferred outside the European Economic Area, PicchuSpot relies on the transfer basis and safeguards applicable to the relevant provider arrangement, such as an adequacy decision or approved contractual safeguards.

You may ask us for further information about safeguards relevant to your information. Provider locations and sub-processors can change, so this Policy does not promise that all processing remains in one country.

11. Retention

We retain information only for as long as reasonably needed for the purpose for which it was collected. Criteria include the life of the account or order, production and revision needs, customer support, file reissue, payment/accounting duties, security, limitation periods, disputes and legal preservation obligations.

Browser session storage normally ends with the session; preference storage remains until it expires, is replaced or is cleared. Provider systems may keep operational backups and logs under their controlled schedules. PicchuSpot does not guarantee permanent storage of source files or deliverables, so customers should keep their own copies.

When information is no longer required, we delete, anonymise or isolate it as appropriate, subject to technical backup cycles and lawful record-keeping needs.

12. Your data-protection rights

Subject to the applicable conditions, you may request access, rectification, erasure, restriction, portability or objection. Where processing relies on consent, you may withdraw it for the future without affecting earlier lawful processing. You may also object to processing based on legitimate interests.

Send the request to hello@picchuspot.com and describe what you need. We may request proportionate information to verify identity and protect the account. Requests are normally free, subject to the exceptions allowed by law.

You can also complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority, especially in the country of your habitual residence, work or the alleged infringement.

13. Security

PicchuSpot uses measures designed to protect information in light of the risk, including authenticated access, server-side ownership checks, private storage, time-limited file access, payment-webhook verification, anti-abuse controls and keeping privileged credentials on the server.

No online service can guarantee absolute security. Customers should protect account credentials, use a secure email account and contact us promptly about suspected unauthorised access.

14. Automated decisions and children

PicchuSpot does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects. The support assistant provides guidance; it does not submit orders, make binding price decisions or authorise payments.

The service is intended for adults and business users, not children. Please do not submit personal information about a child unless it is necessary, lawful and appropriate for a specific property project.

15. Policy updates

We may update this Policy when the service, providers or legal requirements change. The current effective date and version appear at the top. Material changes will be presented through an appropriate website, account or direct notice according to their significance.

For a privacy question or request, email hello@picchuspot.com.

For a privacy question or data-rights request, contact PicchuSpot.

Privacy contact