PRIVACY / 15
Privacy policy
What we collect, why we collect it, who else processes it and how long it is kept. Nothing here describes a practice the product does not actually follow.
Last updated 5 September 2026
Who is responsible
- Legal business name
- Amortoae Petru Persoană Fizică Autorizată
- Registered address
- B-dul Bucureștii Noi 136, Parter, ap. 5, Sector 1, Bucharest, Romania
- Company registration
- CUI 52361814, Trade Register F2025030447007
- VAT number
- RO54733868 (intra-community VAT code; not registered as a VAT payer)
- Legal contact
- info@tasktoprod.com
- Privacy contact
- info@tasktoprod.com
- Governing law
- Romanian law
What we collect
When you send a task
Your work email, name, company, what you are trying to build, your current stack, links you share, your desired outcome, any attachments, and your explicit consent to be contacted about the enquiry.
When you become a member
Your account identity from Supabase Auth, your organization membership and role, the projects and requests you create, comments and files you upload, and the delivery history of your work.
Billing
Stripe processes your payment. We store the identifiers needed to reconcile your membership — customer, subscription, invoice and settlement references — and never receive or store card details.
Operational records
Append-only audit and request events record who changed what and when. These records deliberately exclude credentials, tokens and secrets.
Why we can use it
We process this data to perform the contract you entered into, to meet legal obligations such as accounting, and for the legitimate interest of keeping the service secure and abuse-free.
Who else processes it
| Processor | Purpose | Data |
|---|---|---|
| Supabase | Application database, authentication and private file storage | Account identity, organization membership, project and request content, uploaded files |
| Stripe | Subscription billing, hosted Checkout and the Customer Portal | Billing contact details and payment records held by Stripe; no card data reaches TaskToProd |
| Hostinger | Application hosting and content delivery | Request metadata and standard server logs |
| Brevo | Transactional email delivery | Recipient address and message content for notifications you have asked for |
How long we keep it
- Retention period
- 12 months after the membership ends
Project and delivery history remains available in your portal while your membership is active and for the configured retention period afterwards. You can ask us to delete your data sooner.
Your rights
You can request access to your data, correction, deletion, a portable export, or restriction of processing. Write to the privacy contact above and we will respond within the period required by applicable law.
When you ask us to delete your data we remove your projects, requests, comments, delivered work, uploaded files and your sign-in — everything we hold about the work we did together. Two things stay behind, and we would rather say so than imply otherwise. We keep the billing record, because accounting and tax law requires it; it holds amounts and dates, not your name or address. And copies persist for a while in our providers' own systems: the payment provider keeps its records under its own retention, our email provider keeps delivery logs, and platform backups age out on their own schedule. Ask us and we will tell you exactly where things stand for your account.
Security
Tenant isolation is enforced in the database with row-level security, not only in the interface. Files live in private, path-constrained storage and are served through short-lived signed URLs after membership is verified. Administrative capability comes from a server-controlled allowlist. The security page describes the implemented controls in detail.