Privacy Policy
This page explains what data we collect, why, on what legal basis, and how to exercise your rights under the GDPR.
Who we are
The data controller is the SaveMate team (operator of gosavemate.com). Contact for privacy matters: gosavemate@gmail.com.
What we collect
- Email address — only when you opt in to receive a personalised plan via the calculator email-capture form.
- Account email address — when you request a one-time login code or create an account.
- One-time login code metadata — hashed code, creation time, expiry time, usage time, and failed-attempt count.
- Saved calculator results — if you sign in and choose to save a result, we store the calculator, language, inputs, outputs, title, and creation time.
- Calculation inputs you submit — stored alongside the email so we can send you a tailored plan.
- Hashed IP address (SHA-256 + salt) — for abuse prevention; raw IP is never stored.
- Cookies — see the Cookie Policy for the full list. Strictly-necessary cookies are set without consent; analytics and marketing cookies only after opt-in.
- Server logs — request paths, status codes, timestamps. Not linked to identified users; retained 14 days.
Legal basis
We rely on:
- Consent (Art. 6(1)(a) GDPR) — for analytics, marketing cookies, and email opt-ins.
- Consent (Art. 6(1)(a) GDPR) — for processing your email address to send one-time login codes and manage your account.
- Contract / requested service (Art. 6(1)(b) GDPR) — for saved calculator results you ask us to store in your account.
- Legitimate interest (Art. 6(1)(f)) — for hashed-IP abuse prevention and aggregated server logs.
Third parties
With your consent, we load Google Analytics 4 (Google Ireland Ltd). When loaded it sees pages you visit and standard event data. Without consent, no GA scripts are executed.
Your rights
- Access your data
- Correct inaccurate data
- Erasure (right to be forgotten)
- Data portability
- Withdraw consent at any time without affecting prior processing
- Lodge a complaint with your supervisory authority
Email gosavemate@gmail.com to exercise any of these.
Retention
Email leads: 24 months. One-time login codes: kept only for short-term login and abuse-prevention records. Account email and saved calculator results: kept until you ask us to delete the account or the saved result. Hashed IPs: 6 months. Server logs: 14 days.
Updates
Material changes to this policy will be announced on the homepage at least 14 days in advance.
Last reviewed: in development. This page contains placeholder wording marked with “LEGAL: review” comments and must be finalised by qualified counsel before launch.