Legal
Privacy Policy
How Inertia Start handles personal data across the marketing website, documentation, demo, customer app, purchases, licenses, repositories, registry access, and support.
Last updated: July 22, 2026
This Privacy Policy explains how Inertia Start collects, uses, stores, and shares personal data when you visit any website or service in the Inertia Start ecosystem, use the documentation or demo, create an account, purchase Inertia Start or Inertia Table, access private repositories or registry endpoints, or contact support.
This Privacy Policy applies to all of the following websites and services:
- Inertia Start marketing website — https://inertiastart.com
- Inertia Table marketing website — https://inertiatable.com
- Customer account and purchase application — https://app.inertiastart.com
- Demo website — https://demo.inertiastart.com
- Documentation website — https://docs.inertiastart.com
Inertia Start is operated by Anthony Lajusticia, a self-employed professional registered in Spain under the Régimen Especial de Trabajadores Autónomos ("Inertia Start", "we", "us", or "our"). For GDPR purposes, Anthony Lajusticia is the controller of the personal data processed through our own websites, customer application, licenses, repositories, registry access, and support channels.
Controller contact details:
- Legal name: Anthony Lajusticia
- Trade name: Inertia Start
- Legal form: self-employed professional registered in Spain under the Régimen Especial de Trabajadores Autónomos
- NIF: Z0570202Z
- Business address: Calle de Alcalá 54, 4º izquierda, 28014 Madrid, Spain
- Email: contact@inertiastart.com
Additional business and regulatory information is available in our Legal Notice.
1. Scope
This policy applies to:
- the Inertia Start marketing website (https://inertiastart.com);
- the Inertia Table marketing website (https://inertiatable.com);
- the Inertia Start customer account and purchase application (https://app.inertiastart.com);
- the Inertia Start demo website (https://demo.inertiastart.com);
- the Inertia Start documentation website (https://docs.inertiastart.com);
- repository, registry, license, API-key, billing, account, and support features; and
- communications with us.
It does not apply to websites, applications, or services operated by third parties, even if they are linked from our websites.
2. Personal Data We Collect
Account and profile data. This may include your name, email address, username, preferred language, appearance settings, account status, email verification status, password hash, passkeys, two-factor authentication status, recovery-code metadata, profile photo if enabled, and account timestamps.
Purchase, license, and billing data. This may include the product purchased, license key, license status, purchase date, access expiration date, payment provider, provider customer ID, provider transaction ID, provider price ID, billing provider preference, discounts, invoice or subscription metadata, and limited customer details returned by Stripe or Paddle.
We do not intentionally collect or store full payment card numbers. Card and payment method data is handled by the applicable payment provider.
Repository, registry, and API-key data. This may include API-key names, hashed access tokens, token creation and revocation timestamps, token expiration timestamps, last-used timestamps, last-used IP address, last-used user agent, requested repository or component, and access-control results.
Authentication and security data. This may include IP address, user agent, browser and device information, approximate location derived from IP address where enabled, login/session timestamps, current and recent sessions, failed or throttled attempts, password reset and magic-link metadata, one-time password metadata, activity logs, audit logs, and security event context.
Demo, website, and usage data. This may include pages visited, referring page, approximate time of visit, browser/device details, server logs, documentation search requests, feature usage, error logs, and analytics events.
The application may create an anonymous visitor context before registration. This can use a browser fingerprint generated in the browser and combined with IP address on the server, then stored as a non-reversible hash. The context may be associated with a session, a 90-day context cookie, and a localStorage flag. If you later register or purchase, the context may be linked to your account to understand conversion and product usage.
Where configured, we may use Umami or similar privacy-focused analytics. We do not use advertising cookies or third-party behavioral advertising trackers in the product account application.
Communications and support data. This may include emails you send us, support requests, bug reports, feedback, attachments, and our responses.
3. How We Collect Data
We collect data:
- directly from you when you create an account, purchase a product, configure your profile, create API keys, or contact us;
- automatically from your browser, device, and requests;
- from payment providers such as Stripe and Paddle after checkout or through webhooks;
- from authentication, security, logging, analytics, and hosting systems; and
- from third-party services that you choose to use with our services, where applicable.
4. Why We Use Personal Data
We use personal data for these purposes:
- to provide accounts, authentication, product access, licenses, downloads, private repository access, registry access, and support;
- to process purchases, taxes, receipts, refunds where required, chargeback handling, fraud prevention, and billing-provider communications;
- to secure accounts, detect abuse, prevent unauthorized access, enforce license limits, investigate incidents, and protect infrastructure;
- to maintain audit logs and activity records for account, license, and security events;
- to send transactional emails such as login links, purchase-ready links, one-time passwords, security alerts, account deletion confirmations, password emails, and purchase communications;
- to operate, debug, improve, and measure the websites, documentation, demo, products, and customer application;
- to comply with legal, tax, accounting, consumer-protection, and regulatory obligations; and
- to enforce our Terms of Service and protect legal rights.
5. Legal Bases for EEA/UK Users
Where GDPR or UK GDPR applies, we rely on these legal bases:
- Contract: to create accounts, deliver products, provide licenses, support access, and process purchases.
- Legitimate interests: to secure the services, prevent fraud and abuse, keep audit logs, improve the products, answer support requests, and operate business records.
- Legal obligation: to keep accounting, tax, compliance, and transaction records where required.
- Consent: where we ask for consent, such as optional cookies, optional communications, or legally required consent for immediate digital-content access.
Processing necessary to create and operate your account and to deliver your purchase is based on Contract. Where our Terms of Service refer to your "consent" to such processing, this means your agreement to enter into the contract, not consent under Article 6(1)(a) GDPR.
You may object to processing based on legitimate interests where applicable, but we may continue processing if we have compelling legitimate grounds or need the data for legal claims.
6. Cookies, Local Storage, and Similar Technologies
This section explains how Inertia Start uses cookies, localStorage, session storage, browser fingerprinting, analytics technologies, and similar technologies across the Inertia Start websites, documentation, demo, customer account application, checkout flows, repository access, registry access, and support channels.
Cookies are small files stored on your device by your browser. Similar technologies, such as localStorage, session storage, pixels, browser fingerprinting, and server-side identifiers, can also store or retrieve information from your device or help recognize a browser, device, session, or account.
We may use the following categories of technologies.
Essential and Security Technologies
These are used to operate the services and keep them secure. They may include session cookies, CSRF tokens, authentication state, passkey/two-factor/security state, checkout/account flow state, Laravel/Inertia session data, localization routing state, and cookies or storage required to maintain security-sensitive actions.
Blocking these technologies may prevent login, checkout, account access, localization, security features, or product access from working.
Preference Technologies
These remember choices such as locale, appearance/theme, sidebar state, and similar interface preferences.
Anonymous Context and Product Analytics
The customer application may create an anonymous visitor context before registration.
This can include a browser/device fingerprint generated in the browser, an IP-address
component processed on the server, a non-reversible hash, a context cookie, a
server-side session reference, and a localStorage flag. This context may be linked to an
account if you later register or purchase.
The purpose is to understand product usage, conversion flows, account creation, security events, and product access. Anonymous guest contexts are typically retained for up to 90 days unless linked to an account.
Where configured, we may also use privacy-focused analytics such as Umami or similar tools. We do not use advertising cookies or third-party behavioral advertising trackers in the customer account application.
Payment Provider Technologies
Stripe, Paddle, card networks, banks, fraud-prevention providers, and other payment-related providers may use cookies or similar technologies during checkout, payment authentication, fraud prevention, tax handling, disputes, refunds, or billing-portal flows. Their own notices and controls may apply.
Stripe publishes its privacy policy here: https://stripe.com/privacy
Paddle publishes its privacy notice here: https://www.paddle.com/legal/privacy
Consent and Controls
Strictly necessary cookies and similar technologies may be used without consent where allowed by law because they are required to provide the service you request.
Where consent is required for optional analytics, fingerprinting, or other non-essential technologies, those technologies should be used only after the required consent has been collected. You should be able to accept, reject, or configure non-essential technologies with equal prominence where a consent banner or preference panel is provided.
You can also control cookies through your browser settings. Blocking or deleting cookies may affect service functionality.
Retention
Retention depends on the technology and purpose:
- session and security cookies may expire at the end of the browser session or after a short security period;
- appearance, locale, sidebar, and preference values may persist until changed or cleared;
- anonymous context cookies and related guest context records are typically retained for up to 90 days unless linked to an account;
- payment-provider cookies are retained according to the provider's own policies;
- analytics retention depends on the analytics configuration and provider.
7. Sharing Personal Data
We share personal data only as needed for the purposes described in this policy. Recipients may include:
- payment providers such as Stripe and Paddle, which may process payment, checkout, tax, dispute, and fraud-prevention data under their own privacy notices and data-processing terms;
- hosting, database, storage, email, queue, logging, analytics, and infrastructure providers;
- support, security, debugging, and monitoring tools;
- repository, registry, and code-delivery infrastructure;
- professional advisers, accountants, auditors, insurers, and legal advisers;
- public authorities, courts, regulators, or law-enforcement bodies where required by law; and
- another party in connection with a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell personal data for money. We do not share personal data for cross-context behavioral advertising.
8. International Transfers
Our own application databases and storage for account, license, API-key, repository/registry access, and support data are hosted on servers located in the European Union.
Some providers, including payment providers, financial institutions, fraud-prevention services, analytics providers, email providers, and support or infrastructure vendors, may process personal data in other countries. For example, payment data processed through Stripe or Paddle may be handled under the applicable provider's own privacy notices, data-processing terms, subprocessor arrangements, and international transfer mechanisms.
Stripe publishes its privacy policy here: https://stripe.com/privacy and data-processing terms here: https://stripe.com/legal/dpa
Paddle publishes its buyer terms here: https://www.paddle.com/legal/buyer-terms and its privacy notice here: https://www.paddle.com/legal/privacy
Where GDPR, UK GDPR, or similar laws require safeguards for international transfers, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, provider data-processing terms, Data Privacy Framework certification where applicable, or another lawful transfer mechanism.
9. Data Retention
We keep personal data only as long as reasonably necessary for the purposes described in this policy.
Typical retention periods include:
- account data for as long as your account exists;
- purchase, license, tax, accounting, and transaction records for the period required by law and as needed for disputes or fraud prevention;
- repository, registry, API-key, and access logs for as long as needed to operate licenses, secure access, and investigate abuse;
- active session and login data while sessions remain active and, for inactive session/security monitoring, typically no longer than 90 days unless needed for security, legal, or abuse investigations;
- anonymous guest contexts for up to 90 days unless they become linked to an account;
- one-time passwords and normal magic links for short security periods, typically about 15 minutes;
- purchase-ready magic links for up to 15 days;
- support emails for as long as needed to handle the request and maintain business records; and
- backups for a limited period according to our backup rotation and disaster-recovery needs.
When you delete your account, the application soft-deletes the user record and nullifies personal profile information where designed to do so. Some records may be retained where necessary for tax, accounting, fraud prevention, security, dispute handling, legal compliance, or backup integrity.
10. Security
We use technical and organizational measures designed to protect personal data, including access controls, hashed passwords, token hashing, two-factor authentication features, passkey support, activity logging, session management, throttling, and limited display of one-time secrets.
No system is perfectly secure. You are responsible for keeping your account credentials, API keys, repository tokens, and devices secure.
11. Your Rights
Depending on where you live, you may have rights to:
- access your personal data;
- export or receive a copy of your personal data;
- correct inaccurate data;
- delete personal data;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- opt out of sale, sharing, or targeted advertising where applicable; and
- lodge a complaint with a data-protection authority.
The customer application includes an account data export feature with security credentials and one-time secrets redacted. You may also update profile data and request account deletion through account settings where available.
To exercise privacy rights, contact us at contact@inertiastart.com. We may need to verify your identity before responding.
12. California and Other US State Privacy Notices
Where US state privacy laws apply, the categories of personal information we may collect include identifiers, customer records, commercial information, internet or network activity, approximate geolocation derived from IP address, professional or account-related information you provide, and inferences or analytics derived from product usage.
We collect this information from you, your browser/device, payment providers, authentication/security systems, and service providers. We use it for the business and commercial purposes described in this policy. We disclose it to the categories of recipients described above.
We do not sell personal information for money and do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics, except as needed for security, authentication, fraud prevention, or service delivery.
13. Children
The services and products are intended for software developers and businesses. They are not directed to children, and we do not knowingly collect personal data from children under 16. If you believe a child provided personal data, contact us so we can review and delete it where appropriate.
14. Third-Party Links and Services
Our websites and products may link to third-party websites, documentation, open-source projects, payment providers, or services. Their privacy practices are governed by their own policies.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date shows when the current version took effect. Material changes will apply prospectively unless a change is required immediately for legal, security, or operational reasons.
16. Contact
Questions or privacy requests can be sent to contact@inertiastart.com.