Privacy Policy

    How we collect, use and protect your data. Last updated: July 19, 2025.

    GDPR Compliant
    AES-256 Encryption
    Full Transparency

    1. Data We Collect

    Registration Data:

    • Email address (for authentication and communications)
    • Name and profile photo (if using Google OAuth)
    • Encrypted password (if direct registration)
    • Registration date and time

    Usage Data:

    • Business and location searches performed
    • Analysis parameters (business type, search radius)
    • Analysis request history
    • Anonymized usage statistics

    Technical Data:

    • IP address (for geolocation and security)
    • Browser user agent
    • Session cookies and preferences
    • Access and performance logs

    2. How We Use Your Data

    Service Functionality:

    • Processing analysis requests via AI algorithms
    • Personalizing user experience
    • Saving history for registered users
    • Sending newsletters (only with explicit consent)

    Service Improvement:

    • Anonymized analytics to optimize the platform
    • Training AI models to improve accuracy
    • Debugging and resolving technical issues
    • Developing new features

    Security:

    • Prevention of abuse and fraud
    • Monitoring for suspicious activity
    • Backup for service continuity

    3. Technical Architecture and Security

    Infrastructure:

    • Supabase: PostgreSQL database with Row Level Security (RLS)
    • Authentication: Supabase Auth with JWT tokens
    • Edge Functions: Distributed processing on Deno runtime
    • Storage: End-to-end encryption for sensitive data

    Security Measures:

    • HTTPS connections with SSL/TLS certificates
    • AES-256 encryption for data at rest
    • Rate limiting to prevent abuse
    • Continuous monitoring for anomalies
    • Automatic backups with retention policy

    4. Data Sharing

    We never sell your personal data to third parties.

    Necessary Sharing:

    • Google (OAuth): Only for secure authentication
    • Stripe: Only for payment processing
    • Supabase: Secure data hosting

    5. Data Retention

    • Active accounts: Until account deletion
    • Inactive accounts: 24 months of inactivity, then deletion
    • Analysis data: 12 months to improve AI
    • System logs: 90 days for security

    You can request complete deletion of your data at any time. The process is completed within 30 days.

    6. Your Rights (GDPR)

    In compliance with GDPR, you have the right to:

    • Access: View all data we store
    • Rectification: Correct inaccurate data
    • Erasure: Request complete removal
    • Portability: Export your data in JSON format
    • Restriction: Limit processing
    • Objection: Object to processing for marketing

    How to Exercise Your Rights:

    Contact us through the platform or LinkedIn. We will respond within 72 hours.

    7. Cookies and Tracking

    Essential Cookies:

    • User authentication and session
    • Language and theme preferences
    • Security and CSRF prevention

    We do not use third-party cookies for advertising or behavioral tracking.

    8. International Data Transfer

    Your data is primarily processed in:

    • Europe: Supabase servers in the EU for GDPR compliance
    • USA: Google Cloud for Maps API (with Standard Contractual Clauses)

    All transfers comply with GDPR regulations with adequate legal safeguards.

    9. Minors

    WhereToOpen.ai is intended for professionals and entrepreneurs. We do not knowingly collect data from minors under 16.

    10. Policy Updates

    We will update this policy when necessary. Substantial changes will be communicated via email and platform notification.

    11. Contact

    Data Protection Officer

    WhereToOpen.ai

    Founder: Nicholas Todeschini

    LinkedIn: Nicholas Todeschini