Privacy Policy — SunsetVue
Last updated: 2026.09.03
This policy explains what personal data SunsetVue collects, why it is used, and what rights you have. It is intended to address the Swiss Federal Act on Data Protection (FADP/nFADP) and the EU General Data Protection Regulation (GDPR).
1. Controller
Maciej Karpinski, Arnistrasse 5, 8908 Hedingen, Switzerland.
We are the controller of the personal data described below.
2. What we collect
2.1 Data you give us
| Data | Purpose |
|---|---|
| Email address | Account creation, login, service messages, and requested notifications |
| Name and profile image, if supplied through social login | Displaying your account |
| Saved places, including name, coordinates, altitude, timezone, and any camera URL you add | Delivering forecasts for the places you choose |
| Notification and alert preferences, where the feature remains available to your account | Sending the alerts you request |
| Forecast ratings and optional comments | Showing your feedback and measuring forecast performance |
| Support messages | Responding to you |
2.2 Data collected when you use the Service
| Data | Purpose |
|---|---|
| Coordinates you search, select on a map, enter manually, or provide through device location with your permission | Finding a place, resolving its timezone and elevation, and producing its forecast |
| Forecast-check record, including place, event, time, result, model version, and data sources | Showing history, enforcing plan limits, debugging, and measuring forecast performance |
| Detailed forecast inputs and outputs, including weather layers, terrain, derived light calculations, and special-condition results | Producing and explaining a forecast; investigating errors; validating the forecasting model |
| Account and product-use events, such as first forecast, paywall view, or opening the installed web app | Operating entitlements and understanding whether product flows work |
| Technical request and log data, such as IP address, browser type, timestamps, route, and error traces | Hosting, security, abuse prevention, and debugging |
| Consent state stored in your browser and the limited browser preferences listed in the Cookie Policy | Applying your choices and remembering optional display preferences |
| Analytics events and session replays, only after analytics consent | Understanding product flows and diagnosing usability problems |
SunsetVue does not perform a coarse IP-based location lookup. Device location is requested through your browser only when you choose that feature.
2.3 Payment data
Stripe collects and processes payment details on its hosted pages. We do not receive or store your full card number. We store the Stripe identifiers and subscription facts needed to provide and describe your plan, such as subscription status, price, currency, billing period, cancellation state, and trial dates.
2.4 What we do not collect
We do not knowingly collect special-category data such as health data, biometrics, or political opinions, and accounts are not offered to children under 16.
SunsetVue no longer accepts or stores customer-provided Tomorrow.io API keys.
3. Legal bases under the GDPR
| Processing | Legal basis |
|---|---|
| Creating and running an account; delivering forecasts; managing a subscription | Contract (Art. 6(1)(b)) |
| Security, fraud and abuse prevention, debugging, enforcing usage limits, and improving reliability | Legitimate interests (Art. 6(1)(f)) |
| Measuring forecast performance from ratings and limited validation samples | Legitimate interests (Art. 6(1)(f)) |
| Precise device location | Consent (Art. 6(1)(a)), granted through the browser permission prompt and revocable in browser or device settings |
| Analytics and optional browser storage where consent is required | Consent (Art. 6(1)(a)), managed through the cookie banner |
| Marketing emails, if introduced | Consent, revocable through the unsubscribe method provided |
| Retaining invoices and required transaction records | Legal obligation (Art. 6(1)(c)) |
Under Swiss law, the corresponding justifications under Art. 31 FADP apply.
4. Who receives data
We do not sell personal data. We use the following services to operate SunsetVue:
| Provider | Role | Data disclosed |
|---|---|---|
| Vercel | Hosting and edge delivery | Request and technical log data, including IP address |
| Supabase | Hosted database | Account data, saved places, preferences, forecast history, and feedback |
| Clerk | Authentication | Email, name, profile image, and session data |
| Stripe | Checkout, subscriptions, and billing portal | Payment and billing data collected by Stripe; account and subscription identifiers exchanged with SunsetVue |
| Resend | Transactional and requested notification email | Email address, message content, and delivery events |
| Open-Meteo | Weather, air quality, place search, timezone, and elevation data | Search terms and coordinates; no SunsetVue account identifier |
| Photon by komoot | Nearby-place lookup after a map selection | Selected coordinates; no SunsetVue account identifier |
| Amazon Web Services public terrain tiles | Terrain profile data | Requested terrain tile identifiers and server request data; no SunsetVue account identifier |
| OpenStreetMap | Interactive map tiles and embedded maps | IP address, browser request data, and the map area viewed |
| UNPKG | Delivery of the Leaflet map stylesheet | IP address and browser request data when an interactive map loads |
| Google Analytics, only after analytics consent | IP address, browser and request data, analytics identifiers, and usage events after consent | |
| Amplitude | Product analytics and session replay, only after analytics consent | IP address, browser and request data, analytics identifiers, usage events, and recorded page interactions after consent |
SunsetVue does not use IPGeolocation or Tomorrow.io. A separate meteoblue control is used only for internal, administrator-run model validation and does not receive SunsetVue account identifiers.
The Service also contains outbound links, including links to Google Maps and public camera sites. Those providers receive data only when you choose to open their pages and process it under their own policies.
We may disclose data where legally required, or in connection with a merger or sale of the Service, subject to applicable notice requirements.
5. International transfers
Some providers are outside Switzerland or the EEA, or process data through globally distributed infrastructure. Where required, transfers rely on an applicable adequacy decision, including the Swiss–US or EU–US Data Privacy Framework for certified recipients, and/or contractual safeguards such as the European Commission's Standard Contractual Clauses with the Swiss addendum.
You can request more information about the safeguards used by emailing us.
6. Retention
| Data | Retention |
|---|---|
| Account data | While your account exists, subject to the exceptions below |
| Saved places and account notification preferences | While your account exists |
| Forecast check record (place, time, score, and version) | While your account exists, unless you request deletion or a longer period is needed for a legal claim |
| Detailed forecast data behind an unrated, unsampled check | 5 days, then removed; the smaller check record remains in history |
| Detailed data for a forecast you rated or that was sampled for model validation | While it is used to measure forecast performance and investigate the model |
| Product-use events stored on your account | While your account exists |
| Server and security logs | For the period configured by the relevant hosting or security provider and only as long as needed for security and debugging |
| Invoices and required payment records | 10 years where required by Swiss accounting law |
| SunsetVue browser preferences | As described in the Cookie Policy; removed when preference consent is withdrawn |
| Third-party consent and analytics data | According to your choices and the relevant provider's retention settings |
The detailed weather and calculation data is much larger than the history record and usually stops being useful after the event. Rated and sampled forecasts are retained longer because a score without the inputs behind it cannot show where the model succeeded or failed.
When you delete your account, we delete or anonymise personal data held in the application within 30 days, except where retention is required by law or needed for the establishment, exercise, or defence of legal claims. This includes detailed forecast data, whether or not the forecast was rated.
7. Your rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion of your data;
- restrict or object to processing based on legitimate interests;
- receive eligible data in a portable, machine-readable form;
- withdraw consent at any time, without affecting earlier lawful processing; and
- avoid decisions based solely on automated processing that produce legal or similarly significant effects. SunsetVue's forecast score does not produce such an effect.
To exercise these rights, including requesting a machine-readable copy of your data or forecast history, email sunsetvueapp@gmail.com. Editing places and deleting your account are available in Settings; history export is handled by request rather than by a self-service Settings control. We will respond within the period required by applicable law.
You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if applicable, the supervisory authority in your EU/EEA country of residence.
8. Security
We use TLS in transit, encryption at rest provided by our hosting and database services, managed secret storage for SunsetVue's provider credentials, and access controls for production systems. No system can be guaranteed completely secure.
9. Cookies and browser storage
See our separate Cookie Policy.
10. Changes
We may update this policy. Material changes will be announced by email or in the Service before they take effect where required. The "Last updated" date reflects the current version.