Skip to main content

Privacy Policy

Last updated: 3/30/2026

Introduction

At Product Legends, we respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect your information in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

Data Controller

The data controller responsible for your personal data is:

Data We Collect

We collect different types of personal data depending on how you interact with our game:

Account Data

  • Email address
  • Name (optional)
  • Password (stored encrypted)

Payment Data

  • Billing address
  • Credit/debit card information

Note: Card data is processed directly by Stripe and we never store complete card numbers on our servers.

Game Usage Data

  • Game progress, levels and unlocked achievements
  • Interactions with lessons and exercises
  • Device and browser information
  • Service activity log: date of visit to the platform (no analytics consent required)

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: To provide you access to the service and manage your account.
  • Consent: For analytics and marketing cookies, and for commercial communications.
  • Legitimate Interest: To improve our services, prevent fraud, ensure security, and maintain an operational service activity log (date of visit, 90-day retention).
  • Legal Obligation: To comply with tax and accounting obligations.

How We Use Your Data

We use the collected data for the following purposes:

  • Provide you access to Product Legends and its learning features
  • Manage your account, progress and game preferences
  • Process payments and manage your subscription
  • Send you communications related to the game and your learning
  • Improve and personalize your gaming experience
  • Comply with legal obligations

Who We Share Your Data With

We may share your data with the following service providers:

  • Supabase: Database and authentication (servers in the EU)
  • Stripe: Payment processing (PCI DSS certified)
  • Google Analytics: Traffic analysis (with consent)
  • Hotjar: Behavior analysis (with consent)
  • Meta (Facebook): Advertising and conversion (with consent)

All our providers are contractually obligated to protect your data and can only use it for the specified purposes.

International Transfers

Some of our service providers may be located outside the European Economic Area. In these cases, we ensure appropriate safeguards are in place:

  • European Commission adequacy decisions
  • EU-approved Standard Contractual Clauses
  • EU-US Data Privacy Framework

Data Retention

We retain your personal data for as long as necessary to fulfill the purposes described in this policy:

  • Account data: While your account is active plus 30 days after deletion
  • Billing data: 5 years for tax obligations
  • Analytics data: Maximum 26 months
  • Service activity log: 90 days
  • Legally required data: According to legally established periods

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request correction of inaccurate or incomplete data.
  • Right to Erasure: You can request deletion of your personal data.
  • Right to Data Portability: You can request your data in a structured, commonly used format.
  • Right to Object: You can object to the processing of your data for specific purposes.
  • Right to Restriction: You can request the restriction of processing your data.
  • Right to Withdraw Consent: You can withdraw your consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, you can contact us at: hola@productlegends.app

If you believe we have not adequately addressed your rights, you can file a complaint with your local data protection authority.

Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Role-based access control
  • Monitoring and threat detection
  • Regular backups and disaster recovery

Cookies

We use cookies and similar technologies in our application. For more information, please see our Cookie Policy

Children's Privacy

Product Legends is intended for users aged 16 and over. We do not knowingly collect data from children under this age. If we discover that we have collected data from a minor without verifiable parental consent, we will delete that information as soon as possible.

Changes to This Policy

We may update this privacy policy periodically. We will notify you of any significant changes through an in-app notice or by email. We recommend reviewing this page regularly.

Contact

If you have questions about this privacy policy or about the processing of your personal data, please contact us:

Product Legends
Email: hola@productlegends.app