- We collect only essential data: name, email, shipping address, and device telemetry
- Payments are processed by Stripe and Revolut — we never store card data
- We share data only with processors listed in Section 3
- You have full GDPR rights: access, correction, deletion, portability
- Contact us: privacy@chronogate.io
Chrono Gate — an independent research project, registered in Belgium.
Email: privacy@chronogate.io
Name, email, date of birth (optional). Legal basis: performance of contract (GDPR Art. 6(1)(b)). Date of birth — legitimate interest (Art. 6(1)(f)) for birthday messages.
Shipping address, city, postal code, country, chosen platform color, order history. Legal basis: performance of contract.
We do not store any credit card data. All payments are processed by Stripe and Revolut. We only receive payment confirmation and a transaction reference number.
Platform ID, GPS coordinates (set by the owner), heartbeat (online status), battery level, firmware version. Legal basis: performance of contract. Coordinates are displayed on the public map.
IP address, session cookies. Legal basis: legitimate interest (security, rate limiting).
Data Processors
We only use session cookies (HttpOnly, Secure, SameSite) for authentication. We do not use advertising or analytics cookies. Google reCAPTCHA may set its own cookies on the contact page.
Some processors (Google, Stripe) are based in the United States and operate under the EU-U.S. Data Privacy Framework. Hetzner — hosting in Finland (EU).
- Account data — until account deletion
- Order data — 10 years (Belgian tax law)
- Platform registration log — indefinitely (immutable registry)
- Device data — until platform deactivation
- IP addresses (rate limiting) — 5 minutes
You have the right to:
- Access — obtain a copy of your data
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and data
- Portability — receive your data in a machine-readable format
- Restriction — restrict the processing of your data
- Objection — object to processing based on legitimate interest
To exercise your rights, contact us: privacy@chronogate.io. We will respond within 30 days.
We apply appropriate technical measures to protect your data: connection encryption (HTTPS/TLS), password hashing, CSRF/XSS attack prevention, rate limiting.
Chrono Gate platforms periodically send a heartbeat signal to the server (online status, battery level). GPS coordinates are set manually by the owner and displayed on the public map. You can deactivate your platform by contacting us.
If you believe your rights have been violated, you can file a complaint with the Belgian Data Protection Authority (APD/GBA):
www.autoriteprotectiondonnees.be
If we make material changes, we will notify registered users by email. The current version is always available on this page.