Privacy Policy
Last updated 15 July 2026
This Privacy Policy explains how Peter Kracik, an individual sole proprietor operating RateHive (“RateHive”, “we”, “us”), collects, uses and protects personal data when you use RateHive at ratehive.app(the “Service”). We are the data controller for that personal data. It is written with the EU/UK GDPR and the Swiss Federal Act on Data Protection (FADP) in mind.
1. Data we collect
Account data
When you sign in with Google, GitHub or an emailed link, we collect your name, email address, the provider account identifier and, where provided, your profile image. We do not receive your Google or GitHub password.
Workspace and content data
The content you create in the Service — workspaces, projects, rate cards, estimates and versions, templates, comments, and branding assets such as a logo and company details — and its membership and role structure. This may include personal data you choose to put into it.
Billing data
If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your payment details. We do not store full card numbers; we retain a Stripe customer and subscription identifier, your plan and subscription status, and billing-period and trial dates.
Technical and usage data
Like most online services, we and our infrastructure providers process technical data such as IP address, browser/device information, and request and error logs, in order to operate, secure and debug the Service.
Communications
Emails we send you (such as sign-in links and, where applicable, billing or service notices) and any messages you send us.
2. How and why we use your data
We use personal data to:
- provide, maintain and secure the Service and your account;
- authenticate you and send one-time sign-in links (performance of a contract);
- process subscriptions, payments and trials (performance of a contract; legal obligation for tax/accounting records);
- operate, monitor, debug and improve the Service and prevent abuse (legitimate interests);
- communicate with you about the Service and respond to your requests; and
- comply with legal obligations and enforce our Terms of Service.
Where we rely on consent (for example, any optional communications), you may withdraw it at any time. We do not sell your personal data, and we do not use it for advertising or automated decision-making that produces legal effects about you.
3. Processors we share data with
We share personal data with service providers who process it on our behalf and under contract, only as needed to run RateHive:
| Provider | Purpose | Where |
|---|---|---|
| Neon | Application database hosting | EU / US |
| Netlify | Application hosting and delivery | US / global |
| Stripe | Payment processing and subscription billing | US / global |
| Resend | Transactional email delivery (sign-in links) | US |
| Sentry | Error monitoring and diagnostics | US |
| Optional sign-in (OAuth) when you choose it | US / global | |
| GitHub | Optional sign-in (OAuth) when you choose it | US / global |
We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a corporate transaction (such as a merger or acquisition), subject to appropriate safeguards. This list may change as our infrastructure evolves; we will keep it current here.
4. International transfers
Some of our processors are located outside your country, including in the United States. Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and their Swiss and UK equivalents) or an applicable adequacy decision.
5. How long we keep it
We keep account and content data for as long as your account or workspace is active, and for a reasonable period afterwards to allow for recovery, dispute resolution and legal compliance. When you delete your account or a workspace, we delete or anonymize the associated personal data in the ordinary course, except where we must retain it to meet legal obligations (for example, billing and tax records). Backups are cycled out on a rolling basis.
6. Your rights
Subject to applicable law, you have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it. Many of these you can exercise directly — you can edit your profile and content in the app, and delete workspaces you own. For anything else, contact us at [email protected].
If you are in the EEA, the UK or Switzerland, you also have the right to lodge a complaint with your local data protection authority.
7. Security
We use technical and organizational measures to protect personal data, including encryption in transit, access controls and role-based permissions, and reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please use a strong, private email account, since sign-in links are sent there.
8. Cookies
We use a small number of strictly-necessary cookies to keep you signed in, and browser storage for interface preferences. We do not use advertising or third-party tracking cookies. See our Cookie Policy for details.
9. Children
The Service is not directed to children, and you must be at least 16 (or the age of digital consent in your country) to use it. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you.
11. Contact
For any privacy question or to exercise your rights, contact us at [email protected].