Privacy Policy
Last updated: 19 September 2026
1. Controller and contact details
The controller responsible for the processing described here is Rokas Stulga, a natural person providing the Service in their own name, contact address Pylimo g. 19, Lapainios k., LT-56301 Kaišiadorių r. sav., Lithuania.
For any matter concerning personal data, including the exercise of your rights under Section 10, write to info@veete.app. We have not appointed a Data Protection Officer, as the scale and nature of our processing do not require one under Article 37 GDPR; the address above reaches the person responsible for data protection.
2. Scope of this Policy
This Policy covers the Veete website, web application, account system, subscription billing and support channels. It does not cover third-party websites that we link to, or the independent processing carried out by our payment provider in its own capacity as controller (see Section 6). Where you use Veete on behalf of a company or a client, you are responsible for having a lawful basis to enter any personal data of third parties (for example a client’s address) into the Service; we process such data on your instructions as described in this Policy.
3. Categories of personal data we process
We process only the data needed to operate the Service. We do not buy, enrich or resell personal data.
- Account data
- Email address, display name, a salted one-way hash of your password (we never store or see the password itself), account identifiers, sign-in timestamps and the language of your browser. You provide these when you register.
- Project data
- The gardens and plots you design: object placement, dimensions, materials, plant choices, labels, the prices and labour rates you enter, notes, tasks, meter readings, change history and the project name. Project data may include a site address or a plan drawing you upload, which can identify a location.
- Attachments
- Files you attach to a project on a paid plan (photos, PDFs, spreadsheets and documents), together with their file names, sizes and types. Only file types on our allow-list are accepted.
- Billing data
- Your plan, billing interval, trial and renewal dates, subscription status, the Stripe customer and subscription identifiers, and invoice records. We never receive or store card numbers; you enter them directly with Stripe.
- Support data
- When you use “Report a problem” or email us: your name, email address, the message, the page you were on and, if you leave the box ticked, technical diagnostics (browser, screen size, application version). No project data is included in a report unless you paste it in.
- Technical and security data
- IP address, browser type and version, device type, request timestamps, referring page and error logs, generated automatically by our hosting and database providers when you use the Service, and a hashed, daily-rotated form of your IP address used to rate-limit the problem-report form.
- Data stored on your device
- Your sign-in session token, interface preferences, and, when you use the planner without an account, the gardens themselves. This data stays in your browser and is not transmitted to us until you sign in and choose to save to your account. See Section 11.
We do not process special categories of personal data (Article 9 GDPR), and we ask you not to enter such data into the Service.
4. Purposes and legal bases
Each processing operation rests on one of the legal bases in Article 6(1) GDPR:
- Providing the Service
- Creating and securing your account, storing and synchronising your projects, producing estimates and exports, sending transactional emails (confirmation, password reset, billing notices). Legal basis: performance of a contract, Article 6(1)(b).
- Subscription billing
- Applying plan limits, processing payments and renewals through Stripe, issuing invoices. Legal basis: performance of a contract, Article 6(1)(b), and compliance with accounting and tax law, Article 6(1)(c).
- Security and abuse prevention
- Authenticating sign-ins, rate limiting, detecting and blocking automated abuse, investigating incidents and protecting against data loss through backups. Legal basis: our legitimate interest in keeping the Service and its users safe, Article 6(1)(f). You may object under Section 10; we will then assess whether compelling grounds override your objection.
- Support and communication
- Answering problem reports and enquiries and telling account holders about material changes to the Service or these terms. Legal basis: performance of a contract, Article 6(1)(b), and our legitimate interest in responding to people who contact us, Article 6(1)(f).
- Service improvement
- Reviewing aggregated, non-identifying usage figures and error reports to fix faults and prioritise features. Legal basis: legitimate interest, Article 6(1)(f). We do not build individual profiles.
- Legal obligations and claims
- Retaining records required by law and establishing, exercising or defending legal claims. Legal basis: Article 6(1)(c) and 6(1)(f).
We do not use personal data for advertising, we do not send marketing emails, we do not sell data, and we do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Article 22 GDPR). Should we ever wish to send product news, we will ask for your consent first and every message will carry an unsubscribe link.
5. Where the data comes from
Almost all personal data comes directly from you, when you register, design, upload or write to us. Stripe returns your subscription status and identifiers to us after a payment. Our hosting and database providers generate technical logs automatically. We do not obtain data about you from data brokers or social networks.
6. Recipients and processors
We share personal data only with the service providers below, each bound by a data processing agreement under Article 28 GDPR and acting on our documented instructions, unless stated otherwise:
- Supabase, Inc.
- Database, authentication, file storage and server functions. Your account, projects and attachments are stored in the European Union (Frankfurt, Germany) data-centre region of our Supabase project.
- Stripe Payments Europe, Ltd. and Stripe, Inc.
- Subscription payments and invoicing. Stripe is an independent controller for the payment data you give it directly and processes it under its own privacy policy, available at stripe.com/privacy.
- Hostinger International Ltd.
- Web hosting for veete.app and the transactional email service through which confirmation, reset and support messages are sent. Hostinger records standard access logs.
- Cloudflare, Inc.
- Where enabled, the Turnstile bot check on the problem-report form. Turnstile evaluates browser signals to distinguish people from scripts and does not set tracking cookies.
- Public authorities and advisers
- Courts, regulators or law-enforcement bodies where we are legally required to disclose data, and our professional advisers under duties of confidentiality, where necessary to protect our rights.
If Veete is ever acquired or merged, personal data may be transferred to the successor, who will be bound by this Policy until it is amended in accordance with Section 13.
7. International transfers
We store account and project data within the European Union. Some providers, notably Stripe and Cloudflare, are headquartered in the United States and may process limited data there. Such transfers rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses adopted by the Commission (Decision (EU) 2021/914), supplemented where necessary by additional safeguards. You may request a copy of the relevant safeguards at info@veete.app.
8. How long we keep personal data
- Account and project data
- For as long as your account exists, then deleted within 30 days of account closure.
- Attachments
- Until you delete them or the project, or your account is closed; then deleted with the account.
- Backups
- Rolling encrypted backups are retained for up to 30 days, after which deleted data is no longer recoverable.
- Billing records
- Invoices and payment records for 10 years from the end of the financial year in which they were issued, as required by the Law on Accounting of the Republic of Lithuania and tax legislation.
- Support correspondence
- 24 months after the matter is closed, so that we can refer back to it if the issue recurs.
- Security and access logs
- Up to 12 months, unless an incident requires longer retention for investigation.
- Problem-report rate-limit hashes
- The salt rotates daily; hashes are unusable after 24 hours and purged within 7 days.
- Data on your device
- Until you sign out, clear your browser storage, or the browser evicts it.
Where a legal claim is pending or reasonably anticipated, we may retain the relevant data until the claim is resolved.
9. Security
We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR, including:
- Encryption in transit (TLS 1.2 or higher, HSTS) on every connection between your browser and our providers.
- Passwords stored only as salted bcrypt hashes; sign-in attempts and password-reset emails are rate limited.
- Row-level security in the database, so that a query can never return another person’s projects even if the application were to misbehave.
- Server-side validation of every saved project and of the type and size of every uploaded file.
- Least-privilege access: production credentials are held by the minimum number of people and are rotated on departure.
- Encrypted backups, dependency vulnerability monitoring and security headers (Content Security Policy, frame denial).
No system is perfectly secure. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and the supervisory authority within 72 hours, as Articles 33 and 34 GDPR require. You can help by using a unique password and by telling us at info@veete.app if you suspect your account has been accessed by someone else.
10. Your rights
Subject to the conditions in the GDPR, you have the right to:
- Access the personal data we hold about you and receive a copy (Article 15).
- Rectify inaccurate or incomplete data (Article 16). You can change your password at any time through “Forgot your password?”; to change your name or email address, write to us.
- Erase your data (Article 17). Ask us to close your account and we delete your account and project data within 30 days, subject to the retention obligations in Section 8. Individual projects and attachments can be deleted in the planner at any time.
- Restrict processing in the circumstances set out in Article 18.
- Port the data you provided to us in a structured, machine-readable format (Article 20). Every project can be exported from the planner at any time.
- Object to processing based on legitimate interests (Article 21).
- Withdraw consent at any time where processing relies on consent, without affecting the lawfulness of prior processing.
To exercise a right, email info@veete.app from the address registered to your account, or describe how we can verify your identity. We respond within one month, extendable by two further months for complex requests, in which case we will tell you why. Requests are free unless manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. Our lead authority is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, 10312 Vilnius, Lithuania, ada@ada.lt, vdai.lrv.lt. We would appreciate the chance to address your concern first.
11. Cookies and storage on your device
Veete sets no advertising, analytics or tracking cookies, and we do not embed social-media widgets. The Service stores the following in your browser because it cannot work without them; under Article 5(3) of the ePrivacy Directive, strictly necessary storage of this kind does not require consent:
- Session token
- Keeps you signed in between page loads and refreshes your session. Removed on sign-out.
- Interface preferences
- Render quality, panel layout, whether you have seen the welcome tour, the last project opened.
- Local projects
- When you use the planner without an account, your gardens are saved only in this storage.
- Anti-abuse state
- When Turnstile is enabled on the problem-report form, Cloudflare may set a short-lived challenge cookie scoped to that widget.
Clearing your browser’s site data for veete.app signs you out and removes any locally stored gardens.
12. Children
The Service is not directed at children. You must be at least 16 years old, or the age at which you can validly consent to information-society services in your country if higher, to create an account. We do not knowingly collect personal data from children; if you believe a child has provided us with data, contact us and we will delete it.
13. Changes to this Policy
We review this Policy at least annually and whenever our processing changes. Amendments take effect when published on this page, with the “last updated” date revised. For material changes, such as a new purpose, category of recipient or transfer mechanism, we will notify account holders by email at least 14 days before the change takes effect. Earlier versions are available on request.
14. Contact
Rokas Stulga, Pylimo g. 19, Lapainios k., LT-56301 Kaišiadorių r. sav., Lithuania. Data protection enquiries: info@veete.app. General enquiries: info@veete.app.