Privacy Policy
This draft explains how FLAWLINE currently handles personal data while operating a limited free beta for deterministic historical strategy validation. No payments are accepted during this beta. The planned initial operator is an individual established in Spain; the person's identity, NIF, address, final processors, retention periods and launch contact details remain to be supplied and legally reviewed.
Configured operator details
Configuration facts for this draft; final publication remains subject to legal review.
- Operator type: Individual
1. Controller and contact
The legal identity, establishment, public address and privacy contact of the controller have not yet been finalized. They must be inserted and legally reviewed before this service is publicly launched.
2. Data FLAWLINE processes
Depending on how you use the service, FLAWLINE processes:
- your normalized access email and an internal account identifier;
- one-time authentication and email-change challenge records, session records, and hashed security identifiers derived from tokens, IP addresses and user agents;
- validation configurations, status, deterministic results, reports, and data-source and reproducibility metadata;
- credit-account, purchase, provider-reference and webhook-integrity metadata when billing is used;
- directly collected commercial-interest records: your internal user identifier, selected pack identifier and server-recorded credits, price and currency, first/latest interest timestamps and any first post-exhaustion interest timestamp, click count, balance and trial-exhaustion state, completed-validation count, and a separate API-availability request;
- transactional-email delivery status and provider message identifiers;
- limited technical and security logs needed to operate, diagnose and protect the service.
3. Purposes
FLAWLINE uses these data to:
- create and secure passwordless accounts and sessions;
- run, store and reproduce requested historical validations;
- produce and deliver reports;
- maintain credit and purchase records and prevent duplicate economic events;
- measure demand for future paid access and future programmatic validation, understand pack preference, and notify you about the specific availability you requested;
- send service messages requested by you or required for account security;
- prevent abuse, enforce rate limits, investigate failures and protect integrity.
4. Legal bases
The intended bases are performance of the service contract for account, validation and purchase operations; legitimate interests in service security, fraud prevention and reliability; compliance with applicable legal obligations for records that must be retained; and consent only where the law genuinely requires it. The final allocation must be reviewed against the confirmed operating model before launch.
5. Passwordless access and email changes
FLAWLINE uses purpose-specific, expiring, one-use links. Raw tokens are not stored in the database. Security records may retain the destination email, token hash, timestamps, delivery state and hashed request context. A verified email change keeps the same internal account and revokes prior sessions; the former address receives a security notification.
6. Validations and reports
Your selected strategy, market, timeframe and parameters, together with the resulting evidence and reports, are associated with your account. FLAWLINE does not request exchange credentials and does not execute orders. Do not enter personal or confidential information in parameter fields.
7. Purchases and credits
FLAWLINE currently operates as a free beta: the payment process is unavailable and no payment or new paid order is accepted. Eligible new verified users receive two promotional beta validation credits through an immutable account record. Existing purchase/provider evidence may remain in the test environment. If paid access is later opened, FLAWLINE will keep the minimum product, purchase, provider-reference and account information needed to reconcile verified payment events; card details will not be collected by the FLAWLINE application. Lemon Squeezy is retained only as a legacy integration and is not approved for FLAWLINE production. The beta uses no payment provider and sends no beta-user payment data to one.
7A. Paid-pack and API interest
Pack and API interest is first-party product-demand evidence, not a purchase, reservation, entitlement, API contract or generic marketing subscription. A repeat click updates the same owner-scoped record. The selected pack price and credit quantity come from FLAWLINE's server catalogue, not browser input. No IP, device or fingerprint data is added for marketing analytics, and no third-party marketing analytics are used.
Requesting an availability notification authorizes only service communication about that selected pack or API availability. It does not subscribe you to newsletters, unrelated promotions, third-party advertising or general marketing campaigns.
8. Transactional email
The test email system stores messages only in the controlled deployment environment. If an external email provider such as Resend is activated, the recipient address, message content and delivery metadata are sent to that provider. Production activation, contractual role, location and transfer safeguards must be confirmed before launch.
9. Providers and international transfers
The final hosting, email, payment, ingress and support processors are not yet fixed. FLAWLINE will publish the processors actually in use and, where data leave the EEA, the applicable transfer mechanism and safeguards. Future or test-only providers are not presented here as active production processors.
10. Retention
FLAWLINE removes or expires short-lived challenges and sessions according to operational security windows. Final periods for accounts, reports, billing records, delivery metadata, backups and logs have not yet been approved. A retention schedule, deletion procedure and backup-expiry policy are required before launch.
11. Security
Controls include hashed authentication tokens, one-use challenges, session rotation and revocation, CSRF protection, rate limits, least-privilege containers and restricted persistent storage. No internet service can promise absolute security. Please use the future security/support contact to report suspected account misuse.
12. Your data-protection rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability or objection, and may complain to the competent supervisory authority. The verified request channel, identity-check procedure and controller details must be added before launch. Mandatory rights are not limited by this draft.
13. Cookies and browser storage
FLAWLINE currently uses an essential session cookie, an essential CSRF cookie, and a browser-local EN/ES language-preference cookie. It uses no localStorage or sessionStorage, analytics, advertising trackers, tracking pixels or third-party embeds. On that current basis no consent banner is used; this decision must be revisited before adding non-essential technologies.
14. Children
FLAWLINE is not designed for children. The minimum age and any age-verification approach depend on the final customer model and jurisdiction and must be decided before launch.
15. Changes
Material changes will be dated and communicated through an appropriate service channel. This undated working draft is not the launch version.
Drafting checklist informed by the GDPR, Spanish data-protection law, LSSI provider-information duties and mandatory consumer protections. This working text is not a compliance guarantee and requires review against the final operator and providers.