Privacy Policy

Effective Date: January 20, 2026

Tintly ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how our organization uses the personal data we collect from you when you use our website.

We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

1. What Data Do We Collect?

We collect the following categories of data:

Personal Identification Information

Collected only upon authentication via Google:

  • Name
  • Email address
  • Profile picture URL
  • User ID provided by Google

System & Usage Data

Collected automatically:

  • Browser type and version
  • Referrer URLs
  • Anonymous usage statistics (via GoatCounter)
  • Saved color palettes and configurations

2. How We Use Your Data

We process your data based on the following legal grounds:

  • Contractual Necessity: To provide the Tintly service, manage your account, and save your palettes.
  • Legitimate Interests: To improve our tool, detect fraud, and analyze usage trends (anonymously).
  • Consent: Specifically for voluntary feedback submission.

3. Cookies and Tracking Technologies

Strictly Necessary Only

We do not use tracking pixels, advertising cookies, or third-party marketing scripts.

  • Session State: We use local storage/session tokens to maintain your active login session via Supabase.
  • Preferences: We store a minimal local value to remember your "Light" or "Dark" theme preference.
  • Analytics: We use GoatCounter, a privacy-first analytics tool that does not set tracking cookies or collect Personally Identifiable Information (PII).

4. Data Storage and Subprocessors

Your data is securely stored and processed by our trusted third-party vendors:

ServiceRoleLocation
SupabaseDatabase & Auth ProviderUSA / Global (AWS)
Google AuthIdentity ProviderGlobal
GoatCounterAnalyticsEU
Dodo PaymentsPayment ProcessingUSA / Global

5. Your Data Rights (GDPR & CCPA)

Depending on your location, you may have the following rights:

The Right to Access

You have the right to request copies of your personal data.

The Right to Rectification

You have the right to request that we correct any information you believe is inaccurate.

The Right to Erasure

You have the right to request that we erase your personal data.

The Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data.

The Right to Object to Processing

You have the right to object to our processing of your personal data.

The Right to Data Portability

You have the right to request that we transfer the data that we have collected to another organization, or directly to you.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at our email: tesfayemusie48@gmail.com.

6. California Privacy Rights (CCPA)

For residents of California:

  • We do not sell personal information.
  • We do not share personal information for cross-context behavioral advertising.
  • You have the right to request disclosure of the specific pieces of personal information we store.

7. Contact Us

If you have any questions about Tintly's privacy policy, the data we hold on you, or you would like to exercise one of your data protection rights, please do not hesitate to contact us.

Data Controller Emailtesfayemusie48@gmail.com

8. Payment Processing (Dodo Payments)

We use Dodo Payments to process payments and manage subscriptions. We do not collect or store full payment card numbers or CVC codes. Such data is processed by Dodo Payments on our behalf as our data processor.

  • We receive non-sensitive billing metadata such as subscription status, plan, billing cycle dates, amount and currency, and transaction identifiers.
  • Legal bases: Contractual necessity (to provide the Service you purchase) and our legitimate interests (fraud prevention, accounting, and service improvement).
  • Dodo Payments may process data in the United States and/or other regions. Appropriate safeguards are applied where required by law.

9. International Data Transfers

Your personal data may be transferred to and processed in countries outside of your country of residence (including the UK, EU/EEA, and the United States) by our service providers (e.g., Supabase and Dodo Payments).

Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs), the UK IDTA/Addendum, and/or adequacy decisions to protect your data.

10. Data Retention and Deletion

  • Account & Profile: Kept while your account is active and for up to 12 months after inactivity, unless you request deletion earlier.
  • Saved Palettes & Configurations: Retained until you delete them or until account deletion.
  • Billing & Subscription Records: Retained for up to 7 years to comply with tax and accounting obligations.
  • Server Logs: Typically retained for up to 30 days.
  • Backups: May be retained for up to 30 days, after which they are cycled.

You may request deletion of your personal data by emailing us at tesfayemusie48@gmail.com or by using the in-app account deletion feature (if available). We will act on your request within one month, subject to data we must retain for legal reasons.

11. Security

We implement organizational and technical measures appropriate to the risk, including TLS in transit, encryption at rest provided by our infrastructure providers, role-based access controls, and row-level security in our database.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

12. Children’s Privacy

Our Service is not directed to children under the age of 13 (or 16 where applicable). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Effective Date” above. Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.

14. Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority. If you are in the UK, this is the Information Commissioner’s Office (ICO). We would appreciate the chance to address your concerns first—please contact us using the email above.

@musietesfayeFeedbackHow does it work?Terms of ServicePrivacy PolicyUpvote on Product Hunt