Legal
Privacy Policy
Effective 1 July 2026 · Michal Svoboda
1. Who we are and how to reach us
The data controller for the Quante platform is:
Michal Svoboda · Founder & Developer of Quante
Švermova 441/12, 273 43 Buštěhrad, Czech Republic
For questions about this policy or to exercise your rights, contact us at the address above. We will respond within 30 days.
2. Data we collect and why
Account data. When you sign up, we collect your email address and (optionally) your name. Legal basis: performance of a contract.
Payment data. Payment card information is processed exclusively by Stripe. We receive only a token and last-four-digits confirmation; we never store raw card details. Legal basis: performance of a contract.
Store content. Text, product descriptions, images, and other content you enter into the Studio are stored to provide the Service. Legal basis: performance of a contract.
AI generation inputs. Your prompts and the AI-generated manifests are stored per project to support version history and iteration. These inputs are transmitted to Anthropic's API for processing. Legal basis: performance of a contract.
Usage data. We log which features you use, credit transactions, and error events, primarily for debugging and product improvement. Legal basis: legitimate interests.
Domain registration data. If you purchase a domain through Quante, your name and address are shared with Namecheap as required for ICANN-compliant domain registration. Legal basis: performance of a contract.
Session & authentication data. We use Clerk to manage authentication. Clerk stores your session token in a secure HTTP-only cookie. Legal basis: performance of a contract / legitimate interests.
3. Sub-processors
We use the following third-party processors who may access your data:
Stripe, Inc.
Payment processing, Stripe Connect for merchant payouts
United States (EU SCCs / Privacy Shield successor in place)
Vercel, Inc.
Cloud hosting and serverless infrastructure for the platform
United States (EU SCCs)
Anthropic, PBC
AI model inference (Claude API) for store generation
United States (EU SCCs)
Namecheap, Inc.
Domain registration and DNS management
United States (EU SCCs)
Clerk, Inc.
Authentication and session management
United States (EU SCCs)
Supabase, Inc.
PostgreSQL database hosting
EU region
4. Data retention
We retain your personal data for as long as your account is active. If you delete your account:
- Account data is deleted within 30 days.
- Store content and manifests are deleted within 30 days.
- Payment records are retained for 7 years as required by Czech accounting law.
- Anonymised usage logs may be retained for up to 2 years for product analytics.
5. Your rights under GDPR
If you are in the European Economic Area, you have the following rights:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Ask us to correct inaccurate or incomplete data.
- Erasure. Request deletion of your data where there is no overriding legitimate interest or legal obligation.
- Restriction. Ask us to restrict processing in certain circumstances.
- Portability. Receive your data in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interests.
- Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, contact us using the contact details in Section 1. We will respond within 30 days.
6. Right to complain
You have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů — ÚOOÚ):
Website: www.uoou.cz
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
We would, however, appreciate the chance to address your concerns before you contact the supervisory authority.
7. Security
We use industry-standard security measures including encryption in transit (TLS), encryption at rest (for sensitive database fields), short-lived access tokens, and row-level security policies on our database. No system is completely secure; in the event of a data breach that materially affects your rights, we will notify you and the relevant supervisory authority as required by GDPR.
8. Cookies and local storage
We use browser cookies and local storage for authentication sessions and user preferences (such as dismissing announcements). See our Cookie Policy for details.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or a prominent in-app notice at least 14 days before they take effect. The "Effective" date at the top of this page reflects the latest revision.