Privacy
Information on the processing of personal data under the GDPR. Version 1.0 · as of 10 July 2026.
1. Controller
The controller for data processing is SMART FRET (in formation), Barichgasse 25/10, 1030 Vienna, Austria, represented by Jean-Marc Perc and Ernst Molden. Contact: play@smartfret.app.
2. Scope & structure
This policy applies to the marketing website smartfret.app and to the application at play.smartfret.app ("the app"). Because they process different data, this text is split in two: sections 3–4 concern this website, sections 5–7 concern the app. Sections 8–13 apply to both.
3. This website – hosting & server logs
This website is hosted by Render (Render Services, Inc.) in a data centre in the EU (Frankfurt). When you access it, technically necessary connection data (e.g. IP address, browser, timestamp) is processed. The legal basis is our legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR). Fonts are served self-hosted; no data is transmitted to a font CDN (e.g. Google Fonts).
4. This website – analytics & cookies
Analytics tools load only after your consent via the cookie banner (Art. 6(1)(a) GDPR). You can withdraw consent at any time via the cookie settings.
We use Google Tag Manager to manage and deliver analytics tags. After
your consent it loads Google Analytics 4 (measurement ID
G-4JH8Q2PYP2) to analyse website usage statistically. This may set cookies
and process data (including a truncated IP address, device and browser information, and
interactions), which may be transferred to Google and to the USA. The provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Before your
consent, Google Consent Mode v2 prevents any analytics cookies from being set.
5. The app – categories of data processed
In the app (play.smartfret.app) we process the following categories of data:
- Master / account / profile data: email address, password (encrypted/hashed), account type, role, membership of an institution, and the time and version of the accepted terms/privacy policy; optionally first/last name, primary instrument and profile picture (avatar).
- Application data (teacher/school/university): name, role, website address, expected number of students, message.
- Payment / billing data: the invoice recipient's name/company, address, country and, where applicable, VAT ID, as well as payment/transaction data – to process subscription payments, for invoicing and tax retention. Payment processing is handled by our payment service provider Stripe.
- Content data: exercises, chord progressions, folders, notes, tablature and snapshots you create, and their related settings (app state).
- Usage / statistical data: app and practice times (start/end/duration, instrument) and the time of your last activity – to measure usage and practice intensity (product improvement).
- Session / device data: per login a session identifier, a browser/device identifier (user agent) and timestamps, in order to limit the number of concurrently signed-in devices (abuse / account-sharing prevention).
- Support / error reports (bug reports): title and description, a technical snapshot of the app state, the calling URL, browser/device data (user agent, screen resolution) and, where applicable, a backing-track URL you enter.
- Feedback submissions: rating, free-text message, context and language. A permanent "don't ask again" setting is available.
- Communication / invitation data: email addresses in the context of invitations.
- Log / audit data: security- and evidence-relevant events (e.g. invitation, licence change, member removed); may technically include IP address and user agent.
- Live use: during the live function, the application state (no video or audio recording of the user) is transmitted in real time to invited participants and is not stored permanently. However, invitation and attendance records (which student was invited or attended) are stored.
6. The app – purposes & legal bases
- Provision of the service / performance of contract (account, exercise management, invitations, licence, live invitation/attendance, invoicing) – Art. 6(1)(b) GDPR.
- Legitimate interest (Art. 6(1)(f) GDPR): usage statistics for product improvement, error diagnosis, security (rate limiting), limiting concurrently signed-in devices against account sharing, bug reports and feedback. You may object to statistical analysis at any time (opt-out in your profile, see section 9).
- Legal obligation (Art. 6(1)(c) GDPR): tax retention of billing data, evidence obligations (audit log).
- Consent (Art. 6(1)(a) GDPR): acceptance of the terms/privacy policy at registration.
7. The app – recipients & processors
To provide the service we use carefully selected service providers as processors (Art. 28 GDPR):
- Supabase – database, authentication and file storage (including profile pictures), stored in the EU (Frankfurt). Supabase Inc. is a US company; hosting takes place in the EU.
- Render – application hosting, EU (Frankfurt). Render Inc. is a US company; hosting takes place in the EU.
- Brevo (Sendinblue SAS, France/EU) – sending of transactional emails via an SMTP relay service (including welcome, email confirmation, password reset, invitation, licence/deletion notification). In addition, internal notifications are transmitted to us that may contain user details (feedback message, teacher application, purchase intent including billing address and VAT ID).
- Cloudflare (Cloudflare Inc., USA) – bot/spam protection ("Turnstile", via challenges.cloudflare.com) on the registration page; the IP address, among other data, is transmitted to Cloudflare for verification.
- Sentry (Functional Software Inc.) – error and stability monitoring for front and back end; technical data (e.g. IP address, error context) may be processed. Deliberate personal content is filtered out.
- Stripe (Stripe Payments Europe, Ltd.) – processing of subscription payments. This processes name, email address, billing/address data and payment/transaction data. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
Data processing agreements are in place or are being concluded with the processors. Where data is transferred to third countries (in particular the USA – Cloudflare, and possibly Sentry), this is safeguarded by appropriate guarantees (e.g. EU standard contractual clauses, adequacy decision / Data Privacy Framework).
8. Retention period
- Account and content data: for the duration of the usage relationship.
- On account deletion: access until the end of the licence; then anonymisation, final deletion after a grace period of 30 days (reactivation is possible during this time). On an explicit deletion request without an active licence, final deletion takes place at the latest 30 days after the request.
- Usage / statistical data: retained until the planned automatic pruning is implemented (planned: max. 90 days).
- Billing / tax data: for the duration of the statutory retention period (e.g. 7 years under § 132 BAO); not covered by the 30-day deletion.
- Audit / log data: audit-proof for the required evidence period.
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as to withdraw consent given, with effect for the future.
- Erasure: via the "Delete account" function in your profile or by request to play@smartfret.app.
- Objection to statistical analysis: at any time via the opt-out switch in your profile.
- Data export: on request.
- Complaint: to the Austrian Data Protection Authority (dsb.gv.at).
10. Cookies & local storage
On this website, analytics cookies are only set after consent (see section 4). The app uses technically necessary local storage in the browser (including for login, settings and the transmission of usage events); no service worker / PWA operation takes place. The app uses no marketing or third-party tracking cookies and no web analytics service; fonts are served self-hosted. On the registration page, the bot protection in use (Cloudflare Turnstile) may use client-side storage / challenge mechanisms.
11. Data security
We take appropriate technical and organisational measures, including access restrictions at the database level (Row Level Security, default deny), transport encryption, server-side processing of sensitive logic, rate limiting, security headers and regular rotation of access keys.
12. Minors
The service is not directed at children without the consent of their legal guardians. For users under 14 years of age, the consent of the legal guardians is required under § 4(4) of the Austrian Data Protection Act (DSG). In the case of institutional use, the inviting institution is responsible for obtaining any required consents.
13. Changes to this privacy policy
We adapt this privacy policy where changes in processing make it necessary. The version published in the application at the time applies.