Privacy Notice
Last updated: 20 August 2026
This notice explains how Henrik Hansen, trading as iPlya (iplya.io), handles personal data. For the data you provide when using iPlya, Henrik Hansen is the data controller and decides how and why that data is processed. Where you use iPlya to manage your own guests, you are the controller of your guest data and we process it on your behalf.
Personal data we collect
- Account data — name, email address, login credentials (stored hashed) and, if you sign in with Google, the basic profile Google shares.
- Business data — beach names, locations, spot layouts, products, prices, reservations and orders you enter.
- Support data — messages, attachments and correspondence you send us.
- Usage and technical data — pages viewed, feature usage, device and browser information, IP address and log/telemetry data.
- Subscription status — plan, renewal state and identifiers returned by our payment provider. We do not receive or store your card details.
Why we use it and on what legal basis
- Creating and administering your account, and providing the service — performance of our contract with you.
- Managing subscriptions and entitlements — performance of contract and legal obligation (accounting, tax).
- Security, fraud prevention and abuse detection — legitimate interests in keeping the service safe.
- Customer support — performance of contract and legitimate interests.
- Product improvement and aggregated statistics — legitimate interests.
- Marketing emails, where sent — consent, which you can withdraw at any time.
Who we share data with
- Service providers / subprocessors — hosting, database and authentication infrastructure, email delivery, error monitoring and analytics tooling.
- Merchant of Record — Paddle.com, which sells our subscriptions and handles payments, subscription management, tax compliance and invoicing.
- Professional advisers — legal and accounting advisers where needed.
- Authorities — where required by law or to defend legal claims.
We do not sell personal data.
International transfers
Some providers process data outside the EEA/UK. Where that happens we rely on adequacy decisions or EU Standard Contractual Clauses together with appropriate technical safeguards.
Retention
We keep account and business data for as long as your account is active, and for up to 12 months after closure to handle disputes and reactivation requests. Billing and tax records are kept as long as the law requires. Logs and telemetry are typically kept for up to 12 months. After these periods data is deleted or anonymised.
Your rights
Under the GDPR you can request access to your data, rectification, erasure, restriction of processing, portability, and object to processing based on legitimate interests. You can withdraw consent at any time, and you can complain to your local data protection supervisory authority. We respond to requests within one month. Contact support@iplya.io.
Security
We use appropriate technical and organisational measures, including encryption in transit, encrypted storage, row-level access controls so each manager only reaches their own beach data, and least-privilege access for administrators.
Cookies
We use essential cookies and local storage to keep you signed in and remember your language choice — these are required for the service to work. Any analytics cookies are used only to understand aggregate usage, and we do not use advertising or cross-site marketing cookies. You can clear or block cookies in your browser settings, though signing in will not work without the essential ones.
Contact
Henrik Hansen — support@iplya.io
