CHRONO GATE0 online
Privacy Policy
Last updated: April 4, 2026
Key Points
  • We collect only essential data: name, email, shipping address, and device telemetry
  • Payments are processed by Stripe and Revolut — we never store card data
  • We share data only with processors listed in Section 3
  • You have full GDPR rights: access, correction, deletion, portability
  • Contact us: privacy@chronogate.io
1. Data Controller

Chrono Gate — an independent research project, registered in Belgium.
Email: privacy@chronogate.io

2. Data We Collect
2.1 Account Data

Name, email, date of birth (optional). Legal basis: performance of contract (GDPR Art. 6(1)(b)). Date of birth — legitimate interest (Art. 6(1)(f)) for birthday messages.

2.2 Order Data

Shipping address, city, postal code, country, chosen platform color, order history. Legal basis: performance of contract.

2.3 Payment Data

We do not store any credit card data. All payments are processed by Stripe and Revolut. We only receive payment confirmation and a transaction reference number.

2.4 Device Data (IoT)

Platform ID, GPS coordinates (set by the owner), heartbeat (online status), battery level, firmware version. Legal basis: performance of contract. Coordinates are displayed on the public map.

2.5 Technical Data

IP address, session cookies. Legal basis: legitimate interest (security, rate limiting).

3. Data Processors

Data Processors

ServicePurposeData Shared
StripePayment processingEmail, order amount
RevolutPayment processingOrder amount
Google reCAPTCHASpam protectionIP address, browser behavior
Gmail (SMTP)Email deliveryEmail, name
HetznerHosting, databaseAll data (encrypted)
4. Cookies

We only use session cookies (HttpOnly, Secure, SameSite) for authentication. We do not use advertising or analytics cookies. Google reCAPTCHA may set its own cookies on the contact page.

5. Data Transfers Outside the EU

Some processors (Google, Stripe) are based in the United States and operate under the EU-U.S. Data Privacy Framework. Hetzner — hosting in Finland (EU).

6. Retention Periods
  • Account data — until account deletion
  • Order data — 10 years (Belgian tax law)
  • Platform registration log — indefinitely (immutable registry)
  • Device data — until platform deactivation
  • IP addresses (rate limiting) — 5 minutes
7. Your Rights (GDPR Art. 15–22)

You have the right to:

  • Access — obtain a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data
  • Portability — receive your data in a machine-readable format
  • Restriction — restrict the processing of your data
  • Objection — object to processing based on legitimate interest

To exercise your rights, contact us: privacy@chronogate.io. We will respond within 30 days.

8. Security

We apply appropriate technical measures to protect your data: connection encryption (HTTPS/TLS), password hashing, CSRF/XSS attack prevention, rate limiting.

9. IoT Devices

Chrono Gate platforms periodically send a heartbeat signal to the server (online status, battery level). GPS coordinates are set manually by the owner and displayed on the public map. You can deactivate your platform by contacting us.

10. Complaints

If you believe your rights have been violated, you can file a complaint with the Belgian Data Protection Authority (APD/GBA):
www.autoriteprotectiondonnees.be

11. Changes to This Policy

If we make material changes, we will notify registered users by email. The current version is always available on this page.