Privacy Policy
Last updated: 14 August 2026
The short version: we collect an email address so you can log in, Paddle handles everything to do with payment, and we do not sell anything about you to anyone.
1. Controller
Joviano Miguel Ascenso Faria da Silva, Sole proprietor (empresário em nome individual), Portugal. Contact for any data protection question: [email protected]. No data protection officer is appointed; none is required at this scale.
2. What we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address | To create your account, send the receipt, and answer support | Performance of the contract (Art. 6(1)(b) GDPR) |
| Subscription state (plan, period, status) | To know what to show you | Performance of the contract |
| Billing details, card data, VAT number, billing country | Collected and held by Paddle, not by us; we see only the invoice metadata | Legal obligation and contract |
| Invoices and payment records | Tax and accounting law requires us to keep them | Legal obligation (Art. 6(1)(c) GDPR) |
| Server logs: IP address, timestamp, page requested, user agent | Security, abuse prevention, and diagnosing failures | Legitimate interest (Art. 6(1)(f) GDPR) |
| Aggregate usage counts | To know which pages are worth maintaining | Legitimate interest |
| Support correspondence | To answer you and to keep a record of what was agreed | Performance of the contract |
We do not run advertising trackers, we do not build behavioural profiles, and we do not use third-party analytics that follow you across other sites.
3. Cookies and local storage
One cookie, __Host-ms_session, is set by this service when you sign in. It holds a
random session identifier and nothing else — not your email, not your plan — it is
readable only by the server, only over HTTPS, and it lasts 30 days or until you sign out. It is not
set by Cloudflare Access, which guards only our own internal admin area and never the Pro
dashboard.
Your browser's local storage holds two things: bs-theme, which is light or dark, and
ms_conta, which holds your email address and the name of your plan so the
account button in the header does not flicker while the server is answering. It never authorises
anything — the cookie does that — and it is erased when you sign out or close the
account. Signing out on a shared computer therefore leaves nothing behind.
The site also caches its own pages in your browser so it works offline; that cache holds no personal data. All of this is strictly necessary for the service to work; none of it is used for advertising.
4. Who else processes it
| Processor | Role | Where |
|---|---|---|
| Paddle.com Market Ltd | Merchant of record: payment, invoicing, VAT, subscription management, customer portal | United Kingdom / EU |
| Cloudflare, Inc. | CDN, DNS, email routing, and the edge service that runs the login and the subscription checks; it also guards our internal admin area | EU edge, global network |
| Hetzner Online GmbH | Server hosting | Germany |
| Market data providers | Source of prices and macro series; they receive no personal data from us | Various |
Where a processor transfers data outside the EEA, that transfer relies on the European Commission's standard contractual clauses or an adequacy decision.
5. How long we keep it
Account data for as long as the account exists. When you close the account we erase it immediately — your email address, your sign-in history and your subscription record go at once, and we keep nothing to recognise you by if you come back. Invoices and payment records for 10 years, which Portuguese tax law requires; those are held by Paddle.com Market Ltd as merchant of record and closing the account here does not and cannot delete them. Server logs for 30 days. Support correspondence for 3 years.
6. Your rights
Two of these you can exercise yourself, on the same page and without waiting: My account has a button that downloads everything we hold about you as a file, and another that closes the account and erases it. The download never needs our permission and never waits. Closing does not either — unless a subscription is still running, and then it waits only for that subscription to be cancelled, because we may not erase the account of someone we are still charging. That same page tells you how to cancel, and one email to [email protected] is enough: we cancel it for you, and a cancellation counts from the day you ask, not from the day we reply.
Under the GDPR you may also request access to your personal data, its correction, its erasure, a restriction of processing, a portable copy, and you may object to processing based on legitimate interest. Write to [email protected]; we answer within 2 business days and complete the request within one month. You may withdraw consent at any time where consent is the basis, without affecting what was done before.
If you think we have handled your data badly, you may complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), or to the authority in your own EU country.
7. Security
Traffic is encrypted with HTTPS end to end. Card details never reach our servers. Access to the Pro area is authenticated at the edge. Backups are encrypted and their restoration is tested.
8. Children
MarketStage is not intended for anyone under 18 and we do not knowingly collect data from children.
9. Changes
The date at the top is the current version. Material changes are announced by email to subscribers before they take effect.