Privacy policy
Written from how PuntaDB actually works. This policy describes the product as built on the date above. There is deliberately nothing here about tracking buyers, because PuntaDB does not do it.
1. Who is responsible
PuntaDB is operated by Nikola Nesic, an individual trader based in Belgrade, Serbia, who is the controller for everything described in this policy. For anything in this policy, write to [email protected].
2. Two roles, and the difference matters
For agents who use PuntaDB, we are the controller. We decide what we collect about your account and how you use the product, and we are answerable to you for it.
For the people an agent records in PuntaDB, the agent is the controller and we are the processor. When an agent types a client's name, budget or a note, that is the agent's record. We store it for them and do nothing else with it. We do not contact those people, we do not analyse them, and we do not observe them.
3. What PuntaDB does not do
No tracking of an agent's clients. A collection page an agent shows or sends to a client records nothing: no opens, no time spent, no photographs viewed, no searches, no favourites, no cookies, no read receipts. There is no analytics code on those pages and nothing for a client to consent to. The page says so on its face.
No profiling. We do not score, rank or predict any person. The intelligence in the product is computed from developer price sheets, not from people.
No advertising. We do not sell, rent or share data for advertising, and we run no advertising trackers.
4. What we collect about agents
| Data | Where it comes from | Why |
|---|---|---|
| Account: name, email address, profile picture | Google sign-in, or nothing if you use guest access | To know whose workspace is whose |
| Product usage events: which screens and features you use — for example opening a listing, running a search, saving a search | The product, when you use it | To see which features are used and improve them. Tied to your account, kept in our own database, never shared |
| Your own records: clients, collections, shortlists, yield estimates, saved searches | What you type | To give them back to you. Stored on your device today; in your workspace on our database once accounts are live |
| Feedback and support messages | The feedback form or email | To answer you |
| Billing: plan, payment status | Paddle, our merchant of record | To know what you have paid for. We never see your card |
5. Lawful basis
- Contract — providing the product you signed up for: your account, your records, billing.
- Legitimate interest — product usage events, to improve the product. You can ask us to stop recording them for your account and we will.
- Legal obligation — invoices and tax records, which Paddle holds as merchant of record.
6. Local storage, and the one cookie we do not set
PuntaDB keeps your preferences and, today, your own records in your browser's local storage. That data stays on your device, is not sent to us by that mechanism, and is deleted when you clear site data. We set no advertising or analytics cookies. Google sign-in sets what Google sets for the sign-in itself.
7. Who else sees data, and what they see
| Service | What it sees | Why |
|---|---|---|
| Vercel | Your IP address and request logs, as any host does | Hosting |
| Supabase | Your account, your records and your usage events, once accounts are live | Database |
| That you signed in with Google; and your IP address when fonts load from Google Fonts | Sign-in, fonts | |
| Paddle | Your name, email, billing details and payment | Payments — Paddle is the merchant of record and has its own privacy policy |
| Formspree | What you write in the feedback form and your email | Feedback |
| OpenFreeMap | Your IP address when map tiles load | Maps |
| Unsplash | Your IP address when images load | Illustrative imagery |
Each of these processes data under its own terms. None of them receives anything about an agent's clients from us.
8. Where data is held
Our hosting and database providers run in the United States and the European Union. Where data about a person in the EU or UK leaves those regions, the transfer relies on the provider's standard contractual clauses.
9. How long we keep it
- Your account and records: for as long as you have an account, then deleted within 30 days of you closing it.
- Product usage events: 12 months, then deleted.
- Support messages: 12 months.
- Billing records: as long as tax law requires, held by Paddle.
10. Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to stop recording usage events for your account, and take your records with you. Write to [email protected]; we answer within 30 days. You can also complain to a supervisory authority: for the operator that is the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (Poverenik, poverenik.rs), and if you live in the EU or the UK you may complain to the data protection authority in your own country instead.
If you are someone an agent has recorded in PuntaDB and you want that record changed or removed, the agent is the controller of it — ask them. If you cannot reach them, write to us and we will help.
11. Security
Data in transit is encrypted. Database access is limited by row-level rules so that one workspace cannot read another's. We will tell you without undue delay if we learn of a breach affecting your data.
12. Children
PuntaDB is a professional tool for licensed agents and is not intended for anyone under 18.
13. Changes
If we change this policy in a way that matters, we will tell you before it takes effect. The date at the top always shows the current version.
14. Contact
[email protected], or write to Nikola Nesic, PuntaDB, Belgrade, Serbia.