Privacy policy
Last updated: July 25, 2026
Data controller
Eclipses.app is the controller of the personal data we collect when you use the site: account registration, saved favourites and locations, purchases and, if you subscribe, email alerts. For any privacy enquiry: [email protected].
What we collect
Account: your email address and your profile preferences (language, timezone, email preferences). You can sign in with a magic link sent to your inbox or, where enabled, with your Google account — in that case Google passes us your email and, if available, your name and profile picture. We never store passwords.
Locations you save yourself: if you register, your favourites, recent searches and comparator store the coordinates of the points you choose, rounded to about 10 metres. Only you can see them, and you can delete them anytime from /account.
Usage activity: when you calculate a point's visibility, the cloud forecast, download the PDF or CSV, or save a shared plan, we log the endpoint used and coordinates rounded to ~1.1 km (not your exact location) so we can debug errors and enforce the free daily limit.
Security: we keep a log of server visits (what was requested and when) with your IP address turned into an irreversible code, so we can spot bulk copying of our content and attacks. If someone abuses the service, we keep their IP address only for as long as we need to block them.
Purchases: if you buy a plan, Stripe processes the payment; we store your email, the product and the amount to grant access and for accounting. We never see or store your card number.
Our own analytics: we use Umami, an analytics tool self-hosted on our own server. It doesn't use cookies or store persistent identifiers in your browser, and the data never leaves our database or gets shared with any third party. For each visit we store the browser, the operating system, the device, the screen resolution, the language and the approximate location at country, region and city level; your IP address is processed transiently to derive that location and a session identifier, and analytics does not store it. Because it doesn't rely on cookies, it always loads, without asking for your consent.
Third-party analytics: we load Google Analytics 4 and Microsoft Clarity via Google Tag Manager to understand which pages work and spot usage problems — Clarity includes aggregate session recording and heatmaps. In the EEA, the UK and Switzerland these tools start in denied mode: they store nothing in your browser until you accept the banner, and declining removes no product feature. Outside those countries the default mode is granted. The banner is shown to visitors browsing with a European timezone.
What we use it for
To give you access to your account and to what you save (favourites, recents, comparator, alerts), process your purchases, keep the service running without errors and understand aggregate site usage to improve it.
We never use your data for ad profiling or sell it to third parties.
Legal basis
Your consent (GDPR art. 6.1.a): general eclipse notices (without location, available to any plan) and, in the EEA, the UK and Switzerland, third-party analytics (GA4, Clarity).
Performance of a contract (art. 6.1.b): creating and running your account, your favourites/recents/comparator, processing your purchases, the email alerts for your saved plan, and the weather forecast for your favourites, as features included in what you purchase.
Legitimate interest (art. 6.1.f): logging technical calculation activity to debug errors, enforce the free daily limit, prevent abuse of the service, and our own aggregate analytics (Umami), which processes your IP address transiently to derive the location and a session identifier, and does not store it.
Retention
Usage activity (endpoint, rounded coordinates, status code): 90 days.
Security log of server visits, with your IP address turned into an irreversible code: 30 days.
IP address of anyone abusing the service, only for as long as needed to block them: 14 days.
IP address you sign in from, so that stopping an abuse doesn't block a customer by mistake: 14 days, and deleted as soon as you delete your account.
Login session: 30 days from last use.
Purchases: for as long as accounting and commercial regulations require.
Account, favourites, recents and comparator: for as long as your account stays active; deleted immediately if you delete your account.
Processors
Resend — email delivery (alerts, sign-in link). Signed GDPR DPA/SCC.
Stripe — payment processing.
Google — Google Tag Manager and Google Analytics 4.
Microsoft — Clarity, aggregate session recording.
Sentry — technical error logging so we can fix bugs, without your email.
Contabo — server and database hosting in Germany (EU).
Cloudflare — content delivery and attack protection. All site traffic passes through its servers, which see your IP address in order to filter attacks. Data processing agreement and standard contractual clauses signed.
Umami (our own analytics) isn't an external processor: it runs on the same server and database as the rest of the application, with no data shared with third parties.
We don't transfer your data outside the EEA beyond what these contracts cover.
Your rights
Access, rectification, erasure, objection, restriction and portability. You can exercise them yourself from /account: "Export my data" downloads a JSON file with your profile, purchases, favourites, recents and comparator, alerts and your activity from the last 90 days; "Delete account" permanently removes your account and everything tied to it (favourites, recents, comparator).
You can also reach us at [email protected] or use the unsubscribe link in any email we send. You may lodge a complaint with the Spanish DPA (aepd.es).
Changes
If we update this policy we will notify you reasonably in advance and request consent again if changes affect how your data is used.