Privacy Policy
This Privacy Policy explains how Daniele Zotta ("we", "us", "our") collects, uses, and protects personal data when you use the Shotpilot website, desktop application, and related services (the "Service").
1. Controller
The data controller is Daniele Zotta, Via Cesare Battisti 36, 38053 Castello Tesino (TN), Italy. For privacy requests, email [email protected].
2. Data we collect
- Account data — your email address and authentication details when you register or sign in, including social-login identifiers and profile information provided by Google or GitHub if you choose social login.
- Subscription data — plan, status, and renewal dates. Payment details such as full card numbers are collected and stored by our payment provider, not by us.
- Content data — the screenshots, thumbnails, and project files you choose to save or sync to your account.
- Device and project metadata — project names, device names/models, operating-system versions, screenshot dimensions, timestamps, checksums, tags, and storage usage.
- Usage and technical data — basic logs needed to operate and secure the Service, such as IP address, user agent, request timestamps, authentication/session events, API calls, error logs, and security events.
- Support data — messages and files you send when you contact us for support.
3. Screenshots and project files
When you save or sync a project, your screenshots, thumbnails, and related project files are uploaded to and stored in our cloud object storage, provided by Cloudflare R2, so they are available across your devices and to your team. We store this content solely to provide the Service; we do not use it for any other purpose and we do not sell it. Your files are served back to you through time-limited signed links. You can delete individual projects and screenshots at any time, and deleting your account removes your stored content.
4. Cookies, sessions, and bot protection
We use cookies and similar browser storage that are necessary for login sessions, CSRF protection, security, and remembering interface preferences such as theme choice. These are used to provide a service you requested and do not require separate marketing consent.
On protected forms such as login, registration, and password reset, we may use Cloudflare Turnstile to prevent abuse. Cloudflare receives technical data such as your IP address, browser information, and the challenge token needed to verify that the form submission is legitimate.
5. How and why we use data
- To provide the Service, including accounts, authentication, screenshot sync, team access, downloads, subscriptions, and support. Legal basis: performance of a contract or steps requested before entering into a contract.
- To secure and maintain the Service, including abuse prevention, debugging, fraud prevention, rate limiting, and protecting accounts and infrastructure. Legal basis: legitimate interests in operating a secure service.
- To process billing and subscriptions through Lemon Squeezy. Legal basis: performance of a contract and compliance with legal obligations.
- To comply with legal, tax, accounting, and consumer-law obligations. Legal basis: legal obligation.
- To send service messages, such as email verification, password reset, subscription, security, or support emails. Legal basis: performance of a contract, legal obligation, or legitimate interests depending on the message.
6. Payment processing
Payments are handled by our merchant of record, Lemon Squeezy, which acts as an independent data controller for payment information and processes it under its own privacy policy. We receive only the subscription status, customer/subscription identifiers, plan information, and related billing metadata needed to grant access, provide support, and reconcile subscriptions.
7. Sharing
We do not sell your personal data. We share data only with service providers who help us operate the Service — including our payment provider (Lemon Squeezy), authentication providers (Google, GitHub), cloud storage and security provider (Cloudflare), email providers, hosting and database providers, and support tools — and where required by law. These providers may process data in countries outside your own.
8. International transfers
Your data may be processed in the European Economic Area and in other countries where we or our providers operate. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or equivalent contractual and technical protections.
9. Retention
We retain account and subscription data for as long as your account is active and as needed for legal, tax, accounting, dispute-resolution, and security purposes. Stored screenshots and project files are retained until you delete them or delete your account. Security logs are kept only as long as reasonably needed to protect the Service and investigate abuse or errors. Some backup copies may persist for a limited time before automatic deletion.
10. Your rights
Depending on your location, and in particular if you are in the European Economic Area, you may have the right to request access, correction, deletion, restriction, objection, and data portability. Where processing is based on consent, you may withdraw consent at any time without affecting processing that happened before withdrawal.
You also have the right to lodge a complaint with a supervisory authority. In Italy, the supervisory authority is the Garante per la protezione dei dati personali. You may also contact the supervisory authority in your country of residence or work, or where an alleged infringement occurred.
11. Required data and automated decisions
Some data is required to create an account, provide subscriptions, sync projects, secure the Service, or comply with legal obligations. If you do not provide required data, we may not be able to provide the relevant feature or account. We do not use your personal data for solely automated decisions that produce legal or similarly significant effects.
12. Security
We apply reasonable technical and organizational measures to protect personal data, including authenticated access, time-limited signed links for stored files, access controls, and transport security. However, no method of transmission or storage is completely secure.
13. Changes
We may update this Policy; material changes will be posted here with a revised date.
14. Contact
Data controller: Daniele Zotta, Via Cesare Battisti 36, 38053 Castello Tesino (TN), Italy. Privacy requests: [email protected].