Privacy Policy

Last updated 15 July 2026

This Privacy Policy explains how Peter Kracik, an individual sole proprietor operating RateHive (“RateHive”, “we”, “us”), collects, uses and protects personal data when you use RateHive at ratehive.app(the “Service”). We are the data controller for that personal data. It is written with the EU/UK GDPR and the Swiss Federal Act on Data Protection (FADP) in mind.

1. Data we collect

Account data

When you sign in with Google, GitHub or an emailed link, we collect your name, email address, the provider account identifier and, where provided, your profile image. We do not receive your Google or GitHub password.

Workspace and content data

The content you create in the Service — workspaces, projects, rate cards, estimates and versions, templates, comments, and branding assets such as a logo and company details — and its membership and role structure. This may include personal data you choose to put into it.

Billing data

If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your payment details. We do not store full card numbers; we retain a Stripe customer and subscription identifier, your plan and subscription status, and billing-period and trial dates.

Technical and usage data

Like most online services, we and our infrastructure providers process technical data such as IP address, browser/device information, and request and error logs, in order to operate, secure and debug the Service.

Communications

Emails we send you (such as sign-in links and, where applicable, billing or service notices) and any messages you send us.

2. How and why we use your data

We use personal data to:

  • provide, maintain and secure the Service and your account;
  • authenticate you and send one-time sign-in links (performance of a contract);
  • process subscriptions, payments and trials (performance of a contract; legal obligation for tax/accounting records);
  • operate, monitor, debug and improve the Service and prevent abuse (legitimate interests);
  • communicate with you about the Service and respond to your requests; and
  • comply with legal obligations and enforce our Terms of Service.

Where we rely on consent (for example, any optional communications), you may withdraw it at any time. We do not sell your personal data, and we do not use it for advertising or automated decision-making that produces legal effects about you.

3. Processors we share data with

We share personal data with service providers who process it on our behalf and under contract, only as needed to run RateHive:

ProviderPurposeWhere
NeonApplication database hostingEU / US
NetlifyApplication hosting and deliveryUS / global
StripePayment processing and subscription billingUS / global
ResendTransactional email delivery (sign-in links)US
SentryError monitoring and diagnosticsUS
GoogleOptional sign-in (OAuth) when you choose itUS / global
GitHubOptional sign-in (OAuth) when you choose itUS / global

We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a corporate transaction (such as a merger or acquisition), subject to appropriate safeguards. This list may change as our infrastructure evolves; we will keep it current here.

4. International transfers

Some of our processors are located outside your country, including in the United States. Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and their Swiss and UK equivalents) or an applicable adequacy decision.

5. How long we keep it

We keep account and content data for as long as your account or workspace is active, and for a reasonable period afterwards to allow for recovery, dispute resolution and legal compliance. When you delete your account or a workspace, we delete or anonymize the associated personal data in the ordinary course, except where we must retain it to meet legal obligations (for example, billing and tax records). Backups are cycled out on a rolling basis.

6. Your rights

Subject to applicable law, you have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it. Many of these you can exercise directly — you can edit your profile and content in the app, and delete workspaces you own. For anything else, contact us at [email protected].

If you are in the EEA, the UK or Switzerland, you also have the right to lodge a complaint with your local data protection authority.

7. Security

We use technical and organizational measures to protect personal data, including encryption in transit, access controls and role-based permissions, and reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please use a strong, private email account, since sign-in links are sent there.

8. Cookies

We use a small number of strictly-necessary cookies to keep you signed in, and browser storage for interface preferences. We do not use advertising or third-party tracking cookies. See our Cookie Policy for details.

9. Children

The Service is not directed to children, and you must be at least 16 (or the age of digital consent in your country) to use it. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you.

11. Contact

For any privacy question or to exercise your rights, contact us at [email protected].