Privacy explained with facts
Privacy policy
What data TideFold processes, why it is needed, who supports the service and the control you retain.
01
Controller and scope
The controller is [[LEGAL NAME]], tax ID [[TAX ID]], at [[REGISTERED OR TAX ADDRESS]]. TideFold is developed by Actually Better. This policy covers visitors, account and workspace members, transfer recipients, file-request contributors and people who contact us.
Privacy and data rightsprivacy@actually-better.com
02
Data we process
Stripe processes full payment-instrument details. TideFold does not use file content for advertising, data sales or commercial profiling.
- Account data: name, email, avatar, time zone, language, identifiers and linked sign-in methods.
- Workspace and delivery data: plan, roles, invitations, titles, messages, recipients, files, paths, sizes, hashes, versions, expiry and access rules.
- Activity and security data: sessions, publications, downloads, confirmations, revocations, technical errors and abuse-prevention signals.
- Billing and communications: subscription and transaction identifiers, invoice data and support, legal, security or privacy enquiries.
03
Purposes and legal bases
We process data to provide accounts, storage, deliveries, version history, recipients and requests under the contract; to authenticate, authorise, prevent abuse and investigate incidents under the contract and our legitimate security interests; and to manage billing and legal duties.
Operational communications rely on the contract, legitimate interests or legal obligations. Any future non-essential cookie purpose will rely on separate, withdrawable consent.
04
Processors, recipients and international transfers
Supabase supports authentication and the database; Cloudflare provides R2 storage, downloads and network services; Vercel hosts the web application; Resend sends transactional email; Stripe handles payments; and Google or Microsoft provide sign-in when selected.
Where data is processed outside the EEA, an adequacy decision, standard contractual clauses or another recognised safeguard is used, with supplementary measures when needed. Data may also be disclosed to authorities, courts or advisers where legally justified.
05
Retention and security
Account data is retained while the account is active and as needed to close operations or meet liabilities. Transfers remain until expiry, revocation or deletion plus configured technical protection periods. Billing and security records are limited to applicable legal and reasonable operational periods.
TideFold uses transport encryption, provider encryption at rest, account separation, server-side authorisation, unpredictable tokens, expiry, revocation, file validation and operational audit trails. No system is infallible.
Security incidentssecurity@actually-better.com
06
Your rights
Where applicable, you may request access, correction, erasure, objection, restriction and portability, and withdraw consent without affecting earlier processing. You may complain to the Spanish Data Protection Agency or the competent authority in your country.
We may request additional information to verify identity and will respond within the legal time limits.
Exercise your rightsprivacy@actually-better.com
07
Automation, changes and contact
TideFold does not make solely automated decisions producing legal effects and does not use file content for behavioural advertising. Automated security controls may temporarily limit an operation and can be reviewed through support.
We will update this policy when purposes, providers or applicable rules materially change and will request a new choice when required.
Privacy enquiriesprivacy@actually-better.com
