Privacy Policy
Learn how SmartCookie collects, uses, and protects personal data.
Martina Monreal Carnicero is the data controller and is responsible for processing the personal data of users in this section. For the purposes of compliance with Regulation (EU) 2016/679 of the European Parliament of April 27, 2016 (GDPR), and Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), the following information is provided.
Data Controller
Business Name: Martina Monreal Carnicero
NIF: 53637848P
Address: Calle de les Gal-lies, 1 - Creixell (43839) - Spain
Email: martinamonreal@gmail.com
Purpose
The information provided by interested parties via any of the forms available on the website will be processed to manage the delivery of the requested information. A commercial profile may be created, based on the provided information, if necessary. Automated decisions will not be made based on this profile. Personal data will be retained as long as the commercial relationship is maintained and until the data subject requests its deletion.
Legal Basis
The consent of the interested party is requested for processing their data and the prospective offering of products and services.
Recipients
To run the service we rely on providers that act as data processors or sub-processors (for example, Meta for advertising measurement, Stripe for payments, and PostHog and Microsoft Clarity for analytics and session recording). These disclosures happen on the basis of your consent (marketing, analytics, and session recording) or the performance of the contract (payments). See the "Third-Party Tracking & Advertising Tools" section and the "Sub-processors" list for the full detail.
Rights
Interested parties have the right to access their personal data, as well as to request the rectification of inaccurate data or, if applicable, request the deletion of data when they are no longer necessary for the purposes for which they were collected. Interested parties, in certain circumstances, may also limit or oppose the processing of their data, as well as request the portability of their data. You also have the right to withdraw your consent and to file a complaint with the Supervisory Authority. To exercise your rights, please contact the Data Controller at the address provided above, along with a copy of the data subject's identity document.
1. Who is responsible for processing your personal data?
Martina Monreal Carnicero, NIF: 53637848P, Address: Calle de les Gal-lies, 1 - Creixell (43839) - Spain, and Email: martinamonreal@gmail.com is the DATA CONTROLLER of your personal data and informs you that this data will be processed in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
2. What is the purpose of processing the data and what legal basis legitimizes it?
The information provided by interested parties is processed to manage the delivery of requested information and, if necessary, to create a commercial profile based on the provided data. This includes processing orders, requests, responding to inquiries, or any other type of request made by the USER through any available contact form on the website.
3. How long will the data be retained?
Personal data provided will be retained as long as the commercial relationship is maintained and until the data subject requests its deletion. When no longer necessary, the data will be deleted securely.
4. What rights do you have and how can you exercise them?
Interested parties have the right to access their personal data, request the rectification of inaccurate data, or request its deletion when no longer necessary. They may also oppose or limit the processing of their data in certain circumstances. Additionally, they have the right to withdraw their consent at any time and file a complaint with the Data Protection Authority.
To exercise your rights, please contact the Data Controller at the address provided above.
5. Who do we share your personal data with?
We share personal data with service providers that act as data processors or sub-processors, solely for the purposes described below and in line with your consent settings:
- Meta (Facebook): hashed email, an internal user id, Meta click identifiers, IP address, and user-agent, for advertising measurement and attribution. Legal basis: consent (marketing).
- Stripe: payment and billing data to process purchases and subscriptions. Legal basis: performance of the contract.
- PostHog: product usage data for analytics. Legal basis: consent (analytics).
- Microsoft (Clarity): interaction data for session recording and heatmaps. Legal basis: consent (session recording).
Per-provider detail is set out in the "Third-Party Tracking & Advertising Tools" section, and the complete list is in the "Sub-processors" list.
Third-Party Tracking & Advertising Tools
When you give consent, we use the following third-party tools. Each one processes only the data listed and only while you keep the matching consent category active.
Meta (Facebook)
Advertising measurement and conversion tracking via the browser pixel and the server-side Conversions API. Data sent: hashed email, an internal user id, Meta click identifiers, IP address, and user-agent. Consent category: marketing. Privacy policy: facebook.com/privacy/policy.
Stripe
Processes payments and subscriptions. Legal basis: performance of the contract. In addition, when you give marketing consent, Stripe acts as a pass-through for Meta ad-attribution signals: at checkout we store the Meta click identifiers, IP address, and user-agent in the Stripe payment object metadata, then read them back to enrich the conversion events sent to Meta. Stripe sets no new cookie in your browser for this. Privacy policy: stripe.com/privacy.
PostHog
Product analytics to understand how the app is used. Consent category: analytics. Privacy policy: posthog.com/privacy.
Clarity (Microsoft)
Session recording and heatmaps to spot and fix usability issues. Consent category: session recording. Privacy policy: privacy.microsoft.com/privacystatement.
Sub-processors
The following providers may process personal data on our behalf, together with their role and what they process:
- Meta Platforms, Inc. - advertising measurement and conversion attribution; processes hashed email, user id, Meta click identifiers, IP, and user-agent.
- Stripe, Inc. - payment and subscription processing; processes payment and billing data (and passes Meta attribution signals through via metadata).
- PostHog, Inc. - product analytics; processes app usage data.
- Microsoft Corporation (Clarity) - session recording and heatmaps; processes interaction data.
- Google LLC - Google Calendar integration (calendar import and sync); see the "Google Calendar Integration" section for detail.
6. Do we make automated decisions?
No automated decisions will be made based on the commercial profile.
7. Do we transfer data internationally?
Some of our providers (for example, Meta, Microsoft Clarity, and PostHog) may process data outside the European Economic Area, including in the United States. Where this happens, we rely on the appropriate safeguards provided for under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, to protect your data. You can request more information about these safeguards by contacting the Data Controller.
8. Why do we process your personal data?
We ask for the consent of the interested party to process their data and offer prospective products and services. The personal data collected through the website forms will be processed based solely on the consent provided by the user by accepting the checkbox for this purpose. This consent may be withdrawn at any time. The legitimate interest of the data controller also applies for statistical purposes regarding website usage.
9. Google Calendar Integration (Google API Services User Data)
SmartCookie connects to Google Calendar via Google's OAuth 2.0 flow to power two optional features for teachers: Calendar Import (reading existing lessons into SmartCookie) and Calendar Sync (mirroring SmartCookie sessions out to a dedicated Google calendar). This section discloses how we use Google user data, as required by Google's API Services User Data Policy, including the Limited Use requirements.
Scopes requested
https://www.googleapis.com/auth/calendar.readonly: read-only access to the user's Google Calendars and events, used only for the Calendar Import feature.https://www.googleapis.com/auth/calendar.app.created: access limited to a dedicated secondary calendar that SmartCookie itself creates. This scope grants no access to the user's other Google calendars or their events. It is used only for the Calendar Sync feature.
How we use Google user data (Calendar Import)
We use the read-only scope solely to read the user's existing calendar events when the user explicitly initiates the Calendar Import flow. Events are processed in-memory, grouped into proposed lesson series by our algorithm, and shown to the user for review. Only the lesson data the user explicitly confirms (lesson date, time, title, and attendee email or name) is persisted to SmartCookie's database. We do not poll Google Calendar in the background, set up webhooks, or sync continuously. We never read from, write to, modify, or delete events in the user's other Google calendars with this scope.
How we use Google user data (Calendar Sync)
When a teacher connects Calendar Sync, SmartCookie creates a dedicated "SmartCookie" secondary calendar in their Google account and one-way mirrors their SmartCookie sessions to it (creating, updating, and cancelling events as the teacher manages sessions in SmartCookie). At the teacher's option, SmartCookie may add a Google Meet link to those events. Enrolled students who have an email address are added as guests on the event; their name and email are shared with Google as event attendees so Google can deliver the invitation. We store only the integration status, the id of the calendar we created, event-mapping ids, and conference (Meet) link metadata. We do not read events from the user's calendars with this scope, and the sync is one-way: SmartCookie is always the source of truth.
Limited Use compliance
SmartCookie's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not transfer Google user data to third parties except as necessary to provide or improve the Calendar Import and Calendar Sync features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data for serving advertisements, including retargeting or personalized advertising.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models.
- We do not allow humans to read Google user data, except: (a) with the user's affirmative consent for specific events, (b) where necessary for security purposes (e.g. investigating abuse), (c) to comply with applicable law, or (d) where data has been aggregated and anonymized.
Data retention
Raw Google Calendar event data is processed in-memory during the user-initiated import request and is not retained. Lessons that the user confirms during import are stored in SmartCookie's database as the user's lesson records and are retained for the duration of the user's account. The user may delete imported lessons at any time from within SmartCookie. For Calendar Sync, we retain only the integration status, the id of the dedicated calendar we created, event-mapping ids, and conference link metadata for the duration of the integration; this metadata is removed when the user disconnects the integration or deletes their account.
Data security
We apply security measures to protect the confidentiality of Google user data and all of your personal data. All data is transmitted over encrypted connections (HTTPS/TLS) and stored on hosting infrastructure that encrypts data at rest. Access to your data is restricted by authentication and authorization controls, so that only you, as the account owner, can access your imported calendar data. Google access tokens are stored securely, used solely for the Calendar Import and Calendar Sync features, and deleted when you revoke access. We follow the principle of least privilege, periodically review our security practices, and limit staff access to data as described in the Limited Use section above.
Revoking access
The user may revoke SmartCookie's access to their Google account at any time at myaccount.google.com/permissions. Revocation immediately disables the Calendar Import and Calendar Sync features but does not affect data already persisted from prior imports. Disconnecting Calendar Sync stops future syncing; events already created in the user's Google Calendar remain there until the user removes them in Google.
Legal Notice
All texts, photographs, logos, coupons, products, services, and images viewed, as well as voice messages, are collected by Martina Monreal Carnicero under the sole and exclusive responsibility of the advertiser, who is responsible for the veracity of the information contained on the website. Complaint forms are available for consumers at the address of Martina Monreal Carnicero: Calle de les Gal-lies, 1 - Creixell (43839) - Spain, and can be contacted at any time via email at martinamonreal@gmail.com. In accordance with national and EU consumer protection legislation, an online dispute resolution mechanism is available via the platform provided by the Commission at the following link: https://ec.europa.eu/consumers/odr/main/index.cfm?event=main.home2.show&lng=EN