Data protection
Privacy Policy
This pre-launch policy explains, in plain language, how the current DinoBuilds application handles personal information. It must be updated when the formal operator identity and final deployment arrangements are confirmed.
Controller and contact
- Formal data controller
- [TO BE COMPLETED BEFORE COMMERCIAL LAUNCH]
- Trading name
- DinoBuilds
- Location
- Valencia, Spain
- Privacy contact
- support@dinobuilds.com
Information the application handles
- Account identifiers and profile details, including name, email address, authentication status and verification information.
- Contact and support requests, selected service, conversation messages, email metadata and attachments.
- Store orders, product and quantity information, order references, payment and fulfilment status, and shipping or billing addresses where applicable.
- Quotes, quote items, acceptance status, build progress, payment summaries, courier and tracking information.
- Technical and security information needed to operate the service, including authentication cookies and limited rate-limit identifiers. For unauthenticated contact requests, the application hashes an IP-derived identifier rather than storing the raw address in its rate-limit record.
DinoBuilds does not receive or store full payment-card numbers through this application. Stripe handles payment-card processing.
Why information is used
- To respond to enquiries and take steps requested before entering a contract.
- To create and fulfil orders, provide custom builds or services, take payment, communicate progress, and provide customer support.
- To create and secure customer accounts and private customer pages.
- To meet legal, accounting, consumer-protection and fraud-prevention obligations where applicable.
- To protect the website, enforce rate limits, diagnose failures and maintain service security.
The relevant legal basis will depend on the activity. It may include taking requested pre-contract steps, performing a contract, complying with a legal obligation, and legitimate interests in operating and securing the service. Consent will be used where the law specifically requires it; this application does not currently use the contact, checkout or account forms to collect marketing consent.
Service providers and recipients
- Supabase: database, customer authentication and file storage used for accounts, requests, orders, quotes, progress and attachments.
- Stripe: payment processing and hosted checkout. Stripe may collect payment, billing and shipping information under its own notices.
- Resend: inbound and outbound customer email, delivery metadata and email attachments.
- Discord: private operational notifications to the configured DinoBuilds administrator. A website contact request currently sends the submitted name, email, service and message in that private notification.
- Website hosting and delivery provider: processes requests and technical logs required to serve the Next.js application. The intended Vercel deployment must be confirmed before this draft becomes final.
- Couriers, professional advisers, public authorities or other recipients where needed for an order or required by law.
Providers may process information in countries outside Spain or the European Economic Area. Where required, DinoBuilds will rely on an applicable transfer mechanism or other lawful safeguard and will reflect the confirmed provider arrangements in the final policy.
Retention and security
Information is kept only for as long as reasonably needed for the purposes described, including customer service, order fulfilment, legal or accounting duties, dispute handling and security. Different records may require different periods. No unsupported fixed retention period is stated in this draft.
DinoBuilds uses access controls, authenticated customer and administrator areas, private-token links, signed attachment access, webhook signature checks and rate limiting where implemented. No internet service can promise absolute security.
Your rights
Subject to applicable data-protection law, you may have rights to access, correct or erase personal information; restrict or object to processing; receive portable data; and withdraw consent where processing relies on consent. Some rights may be limited by legal obligations or overriding lawful grounds.
To exercise a right, contact support@dinobuilds.com. You may also complain to the competent data-protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
Changes to this draft
This policy will be updated before commercial launch with the completed controller identity and confirmed hosting/provider details. Material future changes should be reflected on this page.
Last updated: 18 August 2026. This draft must be reviewed and completed before commercial launch.