Controller
The controller responsible for processing personal data through Best Icons is:
[Full registered company name and legal form]
[Street and house number]
[Postal code, city, Germany]
Email: [privacy contact email]
Data protection officer, if one has been appointed: [name/contact or “not appointed” after review].
Data at a glance
Depending on how you use Best Icons, we may process:
- technical request data such as IP address, timestamp, device, and browser details;
- account data such as email address, user ID, and authentication events;
- purchase records such as Stripe session identifiers, payment status, amount, currency, package version, and purchase date;
- download events needed to authorise and protect private package files; and
- messages you send to support or privacy contacts.
We do not receive or store your full payment-card number. Stripe handles card details on its own checkout pages.
Public icon search
You can search and browse icons without an account. Search terms, filters, and requested pages are sent to our servers to return results. They may appear temporarily in routine service or security logs.
Best Icons does not use public search terms to build advertising profiles, and the v1 service does not include third-party advertising or behavioural analytics.
Accounts and sign-in
Account and session management are provided through Supabase Auth. If you register with email and password, Supabase processes your email, encrypted password credentials, verification state, and session data. Passwords are not available to Best Icons in plain text.
If you choose “Continue with Google,” Google authenticates you and shares the account information shown in the consent flow, typically an account identifier, email address, and basic profile details. Google’s own privacy terms also apply to its service.
We use account data to authenticate you, prevent abuse, link purchases to the correct account, and provide secure re-downloads.
Payments through Stripe
One-time package purchases are processed through Stripe Checkout. Stripe collects the payment and billing information needed to complete the transaction. Best Icons receives confirmation and limited transaction data, including the checkout session, payment reference, amount, currency, status, and customer or receipt details made available by Stripe.
We keep the purchase record to deliver the package, support re-downloads, respond to payment questions, prevent fraud, and meet accounting and tax obligations. Stripe acts under its own privacy documentation for data it processes as a payment provider.
Package downloads
Package files are stored privately. When a paying user requests a download, Best Icons checks the signed-in account and purchase record, then issues a short-lived signed URL. We log the account, purchase, package version, object key, URL expiry, timestamp, and browser user-agent to secure the file and investigate misuse. Infrastructure security logs may also contain an IP address and technical outcome.
The signed link expires, but the purchased package remains available for later re-download from the account page.
Hosting and infrastructure
Best Icons uses the following processors for its planned v1 service:
- Supabase
- User authentication, purchase entitlements, and download authorization records.
- Cloudflare
- Public icon catalogue, SVG delivery, and private paid-package object storage.
- Stripe
- Checkout, payment processing, fraud prevention, and payment records.
- Optional OAuth sign-in, only when selected by the user.
- Hosting/CDN
- [Name the deployed web host and content-delivery provider]
Processor names, service locations, and contractual roles must be confirmed against the production configuration before this policy is published.
Cookies and local storage
Best Icons uses technically necessary browser storage to keep you signed in, protect authentication flows, and remember essential session state. These functions are needed to provide account and purchase features.
The planned v1 service does not set advertising cookies. If optional analytics, marketing tools, or other non-essential storage are added later, this policy and any required consent controls must be updated before those tools are enabled.
Purposes and legal bases
Where the EU General Data Protection Regulation applies, processing is based on:
- performance of a contract or steps requested before a contract for accounts, purchases, delivery, and support;
- compliance with legal obligations for accounting, tax, and legally required records;
- legitimate interests in secure, reliable service operation, abuse prevention, and resolving technical issues; and
- consent where a feature expressly asks for it and consent is legally required.
Where we rely on legitimate interests, we balance those interests against your rights and expectations.
How long data is kept
- Account data is generally kept while the account remains active and as needed to provide purchased downloads.
- Purchase, invoice, and tax records are kept for the legally required retention period.
- Security and request logs are kept only as long as reasonably needed for operations and incident investigation: [insert confirmed log-retention period].
- Support correspondence is kept until the request is resolved and any applicable legal retention period has ended.
Data may be retained longer where necessary to establish, exercise, or defend legal claims, or where law requires it.
Recipients and international transfers
Personal data is shared only where needed with contracted service providers, payment and authentication providers, professional advisers, and authorities when legally required. We do not sell personal data.
Some providers may process data outside the European Economic Area. Where required, we use an applicable legal transfer mechanism, such as an adequacy decision or approved contractual safeguards. The exact mechanism depends on the selected provider, entity, region, and production contract.
Your data-protection rights
Subject to the applicable law and its conditions, you may request access, correction, deletion, restriction, portability, or objection to processing. You may withdraw consent for future processing where consent is the basis. You may also complain to a competent supervisory authority.
Send requests to [privacy contact email]. We may need to verify your identity before acting on a request.
Lead supervisory authority, if applicable: [name and contact link for the competent German authority].
Security
Best Icons uses access controls, private object storage, short-lived download URLs, transport encryption, and service-role separation intended to protect personal data. No internet service can promise absolute security; we review safeguards in proportion to the data and risks involved.
Changes and contact
We may update this policy when the product, vendors, or legal requirements change. The date at the top identifies the current version. Material changes will be communicated where required.
Questions about privacy can be sent to [privacy contact email].