1. Data Controller
The controller of the personal data collected through Lithosbase is:
Filippo Cattaneo · Perth, Western Australia, Australia
Roberto Colonnetti · Perth, Western Australia, Australia
Email: support@lithosbase.app
2. Data We Collect
We collect the following categories of personal data:
- Account data: email address, full name
- Workspace data: inventory items, stock movements, uploaded photographs
- Usage data: access logs, operation timestamps, IP addresses for security purposes
- Communication data: messages sent through the contact form
- Billing data: billing name, address and subscription history. Card details are handled directly by Stripe and never pass through our systems.
3. Purposes and Legal Basis
- Providing the service: authentication, workspace management, platform features. Legal basis: performance of the contract (art. 6.1.b GDPR for EU and EEA users).
- Security and fraud prevention: log analysis, detection of unauthorised access. Legal basis: legitimate interest (art. 6.1.f GDPR for EU and EEA users).
- Transactional messages: team invitations, password resets, system notices. Legal basis: performance of the contract.
- Subscription management: charging, renewing and invoicing the plan. Legal basis: performance of the contract and tax obligations.
- Support: answering user requests. Legal basis: legitimate interest.
4. Retention Periods
- Account data: kept for the duration of the contract and for 30 days after deletion, then permanently erased.
- System logs: kept for 90 days for security purposes.
- Workspace data: erased within 30 days of an account or workspace deletion request.
- Billing records: kept for as long as applicable tax law requires.
5. Storage and Security
Application data is stored on Convex (EU region, Ireland), which also holds uploaded photographs. Login credentials are handled by Clerk and are not stored on our servers. Isolation between workspaces is enforced in the backend code: every read and write checks that the requester is a member of that workspace. All traffic runs over an encrypted connection (TLS).
6. Third Party Providers
We share data with the following providers for the sole purpose of running the service:
- Convex database and file storage (privacy policy)
- Clerk authentication and account management (privacy policy)
- Vercel hosting and CDN (privacy policy)
- Resend transactional email delivery (privacy policy)
- Stripe subscription payments and invoicing (privacy policy)
We do not sell or hand over your personal data to third parties for marketing or profiling purposes.
7. International Data Transfers
The service is operated from Australia. Data may be processed in Australia and in the other countries where the providers listed in section 6 operate. For users in the European Union or the European Economic Area, those transfers rely on the safeguards required by the GDPR (European Commission adequacy decisions or Standard Contractual Clauses).
8. Your Rights
You can exercise the following rights at any time by writing to support@lithosbase.app. We reply within 30 days.
- Access: confirmation that we process your data, and a copy of it
- Rectification: correction of inaccurate or incomplete data
- Erasure: deletion of your data
- Restriction: limiting processing in certain circumstances
- Portability: receiving your data in a structured, machine readable format
- Objection: objecting to processing based on legitimate interest
You can delete your account yourself from the Delete account page.
EU and EEA users: you have the right to lodge a complaint with the supervisory authority in your country (in Italy: Garante per la protezione dei dati personali).
9. Cookies
We only use technical cookies needed to keep you signed in. We use no advertising or profiling cookies. Your theme preference (light or dark) and language are stored on your own device and are never sent to an external server.
10. Changes to This Policy
We may update this policy from time to time. If a change is substantial we will tell you by email or with a notice in the app, at least 14 days in advance. The date of the last update is shown at the top of this page.