Privacy Policy
Last updated: March 25, 2026
This Privacy Policy describes how B2C Boilerplate("we", "our") collects, uses, and protects your personal data.
I. Data Collected
We collect the following data when you create and use your account:
- Full name (first and last name)
- Email address
- Password (stored exclusively as a hash — never in plain text)
- Email verification date
- Account creation and update date
We do not collect payment, location, device, or browsing behavior data.
II. Purpose of Processing
We use your data to:
- Create and maintain your user account.
- Authenticate your access to the Service.
- Send transactional emails (email verification, password reset).
- Ensure account security (login attempt control).
III. Legal Basis
- Contract performance: data is necessary to provide the contracted Service.
- Legitimate interest: account security and fraud prevention.
- Consent: for optional communications, where applicable.
IV. Data Retention
Your data is retained while your account is active. Upon account deletion, all personal data is permanently removed from our systems. Temporary tokens (email verification, password reset) expire automatically after 1 to 24 hours.
V. Data Sharing
We do not sell, rent, or share your personal data with third parties, except:
- Essential service providers: transactional email service (Resend) and cloud database (Neon), bound by confidentiality agreements.
- Legal obligation: when required by law or court order.
VI. Your Rights
You have the right to:
- Access: view the data we hold about you.
- Correction: update your name or email directly in your profile.
- Deletion: delete your account and all associated data.
- Portability: request a copy of your data in a structured format.
- Withdrawal of consent: withdraw consent at any time.
- Objection: object to processing in case of non-compliance.
To exercise these rights, contact us at the email address in the section below. We will respond within 15 days.
VII. Security
We adopt technical measures to protect your data: bcrypt password hashing, encrypted communication via HTTPS, single-use tokens with expiration, and login attempt control.
VIII. Cookies
We use two types of cookies:
- Essential: required for authentication and Service operation (e.g., NextAuth session cookie). Do not require consent.
- Optional: analytics or tracking, when configured. Require explicit consent.
You can manage your cookie preferences at any time in the consent banner.
IX. Data Controller and DPO
Data controller: [COMPANY NAME], registered at [FULL ADDRESS].
Data Protection Officer (DPO): [DPO NAME] — privacy@example.com
X. Changes to this Policy
We may update this Policy periodically. We will notify you by email or in-Service notice for relevant changes. Continued use after changes indicates acceptance of the new version.