Version 2026.07.24.1 — effective 24 July 2026
1. Who we are
This policy explains how the HubLane.app platform operator handles personal data on the HubLane.app platform. Contact: contact@hublane.app.
2. Two roles
For account data of registered users (name, email, password hash, sign-in and audit history) we act as the data controller. For CRM content that merchants store about their own customers (clients, leads, contacts, appointments, calls, messages, files, shipments, property listings, property enquiries and related records) the merchant is the controller and we act only as a processor under the Data Processing Agreement. Privacy requests about a merchant's records should be addressed to that merchant; the platform gives merchants tools to fulfil them.
3. What we collect and why
- Account data — name, email, hashed password, role, two-factor preference: to operate your account (contract). When a Merchant Owner uses forgot-password, we send a reset email containing a single-use link and store only a hashed copy of that link token until it expires or is used (security / contract).
- Usage and audit records — sign-ins, administrative actions, application logs: for security and accountability (legitimate interest).
- Billing data — merchant name, billing email, business identification number (TIN / NIPT / VAT ID / company registration number), invoices and payments: to bill the subscription and identify the organisation controlling workspace data (contract, legal obligation).
- Calendar integration — if you connect Google or Microsoft, we store your account email and encrypted OAuth tokens, and sync event data both ways on your instruction (contract). You can disconnect at any time.
- Voice, SMS and WhatsApp (Twilio) — when a merchant enables Twilio, phone numbers, call metadata and message content needed to place calls or send SMS/WhatsApp are processed and passed to Twilio on that merchant's instruction; delivery and call logs are kept as evidence of the action (contract / legitimate interest).
- Card payments (Stripe) — when a merchant connects Stripe, payment status and references for invoices are stored in the platform; card details are handled by Stripe, not stored by us in full (contract).
- Emails and text messages — delivery logs of messages the platform sends on a merchant's behalf, including workflow and reminder automations (legitimate interest, evidence of delivery).
- Files and attachments — documents and images merchants upload to records (contract).
- Public surfaces — data submitted through lead-capture endpoints, public booking pages, the booking marketplace, HubLane Properties listing enquiries (interest, offer or buyer brief), or otherwise exposed via merchant-enabled tracking links and listing feeds, processed for the merchant (contract / merchant's lawful basis). Enquiry forms record privacy consent at submission.
- Published listing agents — when a merchant assigns a team member as listing agent, that member's name, email and phone may appear on the public listing detail page so visitors can contact the agency (contract / merchant's instruction to publish).
- Map location data — optional latitude/longitude and address text for properties and booking profiles; map display and reverse-geocoding may call third-party mapping providers (contract / legitimate interest in operating the map).
- API keys — hashed merchant API keys used to authenticate public lead capture (security, contract).
- Support chat (Tawk.to) — if you use the in-app support widget while signed in, chat content and technical data may be processed by Tawk.to to provide support (legitimate interest).
- Consented support access — when a Merchant Owner approves a temporary support session, platform support staff may access that workspace's CRM content and settings for a limited time to provide technical support. Each approval is logged (who consented, consent version, session start/end). Legal basis: the merchant's documented instruction / consent for that session (contract / Art. 6(1)(b) and the merchant's instructions as controller for CRM content).
- Platform account administration — platform staff may view merchant team-member directories (name, email, role, status) in the platform console and may reset passwords, revoke sessions, or deactivate/reactivate merchant users for security and support. These actions are audit-logged. Merchant CRM financial totals are not exposed in that console. Legal basis: legitimate interest in operating a secure multi-tenant platform / contract.
4. Where data lives, who sees it
Platform records are stored and processed in Albania, in one hosting region, unless a merchant-connected provider processes data elsewhere to deliver that feature. Data is disclosed only to: the merchant workspace it belongs to; our infrastructure and delivery subprocessors; providers the merchant or user explicitly connects (Twilio, Stripe, Google Calendar, Microsoft Outlook/Graph); the support chat provider when the widget is used; platform staff for account administration (team directory and account actions described above, without opening CRM content); platform support staff during a Merchant Owner–approved support session (visible in-app while open, ended when support exits or the session expires); and authorities where the law requires. When a provider processes data outside Albania or the EEA, transfers rely on that provider's appropriate safeguards (such as Standard Contractual Clauses). We do not sell personal data and we do not run third-party advertising.
5. Retention
Account data is kept while the account exists. Audit logs are purged after a configured retention period (365 days by default). Email/SMS delivery logs, call logs, expired sessions and used or expired password-reset tokens are purged on a schedule. Invoices and payment records are kept as long as required by accounting law. Full details are in the platform's data-retention schedule.
6. Your rights
You may request access to, correction of, export of, or erasure of your personal data, and object to or restrict certain processing. In the app: Settings → Privacy lets you download a complete export of your data and request account deletion (confirmed by email; the account is then anonymized — records required for financial integrity survive without any personal data). You may also lodge a complaint with your supervisory authority.
7. Security
Passwords are stored hashed (bcrypt), OAuth and integration secrets encrypted at rest (AES-GCM), API keys stored hashed, access limited by per-tenant isolation and role-based permissions, and administrative actions audit-logged. Merchant Owner password-reset links are single-use, short-lived and stored only as hashes; completing a reset signs the account out of all sessions.
8. Changes
Material changes bump the version above; you will be asked to review and accept the new version.