Privacy Policy — SunsetVue
Last updated: 2026.07.14
This policy explains what personal data SunsetVue collects, why, on what legal basis, and what rights you have. It is written to satisfy the Swiss Federal Act on Data Protection (FADP/nFADP) and the EU General Data Protection Regulation (GDPR).
1. Controller
Maciej Karpinski, Arnistrasse 5, 8908 Hedingen, Switzerland.
We are the controller of the personal data described below.
2. What we collect
2.1 Data you give us
| Data | Purpose |
|---|---|
| Email address | Account creation, login (magic link), service and notification emails |
| Name / profile image (if you use social login) | Displaying your account |
| Saved locations (name, latitude, longitude) | Delivering forecasts for the places you care about |
| Notification and alert preferences | Sending the alerts you asked for |
| Support messages | Answering you |
2.2 Data collected automatically
| Data | Purpose |
|---|---|
| Approximate location (from device GPS with your permission, or coarse IP-based lookup) | Producing a forecast for where you are |
| Forecast check history (timestamp, coordinates, resulting score) | Showing you your history; enforcing plan limits; improving the model |
| Technical log data (IP address, browser type, timestamps, error traces) | Security, abuse prevention, debugging |
| Usage and consent state (cookies / local storage) | Keeping you logged in, remembering your consent choices |
2.3 Payment data
If you subscribe, Stripe collects and processes your payment details directly. We never see or store your full card number. We receive only a customer identifier, subscription status, and billing metadata (e.g. country, last four digits, invoice history).
2.4 What we do not collect
We do not knowingly collect special-category data (health, biometrics, political opinions, etc.), and we do not collect data from children under 16.
3. Legal bases (GDPR Art. 6)
| Processing | Legal basis |
|---|---|
| Creating and running your account; delivering forecasts; processing payments | Contract (Art. 6(1)(b)) |
| Security, fraud and abuse prevention, debugging, enforcing usage limits | Legitimate interests (Art. 6(1)(f)) — keeping the Service working and affordable |
| Aggregated/anonymised model improvement | Legitimate interests (Art. 6(1)(f)) |
| Precise device location | Consent (Art. 6(1)(a)) — granted via your browser permission prompt, revocable at any time |
| Advertising, analytics, and any non-essential cookies | Consent (Art. 6(1)(a)) — granted via the cookie banner, revocable at any time |
| Marketing emails (if any) | Consent, revocable via the unsubscribe link |
| Retaining invoices | Legal obligation (Art. 6(1)(c)) — Swiss accounting law |
Under Swiss law, the corresponding justifications under Art. 31 FADP apply.
4. Who we share data with (processors and recipients)
We do not sell your personal data. We share it only with the service providers we need to run SunsetVue:
| Provider | Role | Data | Location |
|---|---|---|---|
| Vercel | Hosting, edge network | Request logs, IP address | US / global edge |
| Supabase | Database | Account data, saved locations, forecast history | eu-west-1 (Ireland) |
| Clerk | Authentication | Email, name, session data | US |
| Stripe | Payments | Billing and card data (collected directly by Stripe) | US / IE |
| Resend | Transactional and notification email | Email address, message content | US |
| Open-Meteo | Weather data (primary) | Coordinates only — no account identifiers | EU |
| Tomorrow.io | Weather calibration | Coordinates only — no account identifiers | US |
| IPGeolocation | Sun position / azimuth | Coordinates only — no account identifiers | US |
| Google AdSense | Advertising (free plan) | Cookie identifiers, IP address, ad interaction data — only if you consent | US / global |
We may also disclose data where legally required (court order, regulatory request), or in connection with a merger or sale of assets, in which case you will be notified.
5. International transfers
Some of our providers are located in the United States or process data globally. Where we transfer personal data outside Switzerland or the EEA, we rely on:
- the European Commission's Standard Contractual Clauses (SCCs), recognised by the Swiss FDPIC with the Swiss addendum; and/or
- an adequacy decision, including the EU–US Data Privacy Framework and the Swiss–US Data Privacy Framework where the provider is certified.
You can request a copy of the relevant safeguards by emailing us.
6. Retention
| Data | Retention |
|---|---|
| Account data | For as long as your account exists |
| Saved locations and preferences | For as long as your account exists |
| Forecast check history | 24 months, then deleted or anonymised |
| Server and security logs | 90 days |
| Invoices and payment records | 10 years (Swiss accounting law, Art. 958f CO) |
| Consent records | 12 months or until withdrawn |
When you delete your account, we delete or anonymise your personal data within 30 days, except where we must retain it by law (e.g. invoices) or for the establishment or defence of legal claims.
7. Your rights
You have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict or object to processing based on legitimate interests;
- data portability — receive your data in a machine-readable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- not be subject to a decision based solely on automated processing with legal or similarly significant effects (we do not carry out such processing — the forecast score has no legal effect on you).
To exercise these rights, email sunsetvueapp@gmail.com. We will respond within 30 days. Many actions (editing locations, deleting your account, exporting your history) are also available directly in the app under Settings.
Complaints. If you are unhappy with how we handle your data, you may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, if you are in the EU/EEA, to the supervisory authority in your country of residence.
8. Security
We use TLS in transit, encryption at rest via our database provider, scoped API keys held in environment variables, and role-based access to production systems. No system is perfectly secure; if a breach occurs that is likely to result in a high risk to your rights, we will notify you and the competent authority without undue delay.
9. Cookies
See our separate Cookie Policy.
10. Changes
We may update this policy. Material changes will be announced by email or in-app before they take effect. The "Last updated" date above always reflects the current version.