Legal & more

Privacy policy

How Redtail handles your account data, the passports you track, and technical logs.

0. Controller & Contact

Controller: Hubert Szymański, sole proprietor

Address: Spółdzielcza 22/30, 26-110 Skarżysko-Kamienna, Poland

NIP (Tax ID): 6631718187

Contact: contact@redtail.id

1. What We Collect

Redtail aggregates digital product passports published by other issuers and checks the issuer's signature. We keep the data needed to run your account and the list of passports you choose to track. Nothing else.

  • Account data: your email address, your authentication state, and an optional display name. Sign-in credentials are handled by Supabase (see Processors below); we do not see or store your password.
  • Tracked passports: for each passport you save, we store the reference you supplied (for example a passport URL), the issuer identifier stated in the passport, the product name it declares, the outcome of our signature and revocation check, the method used for that check, a content fingerprint of the fetched passport used to detect changes, and the timestamps of when it was saved and last checked.
  • Technical logs: standard server logs, which may include IP address, timestamps, and browser and device information, kept for security and reliability. We also record account security events (sign in, sign out, sign up) with the IP address and browser string of the request.
  • Messages you send us: if you write to us, we process the content of your message and your email address so we can reply.

Redtail does not host files you upload, does not process payments, and does not run automated profiling or advertising.

2. How We Use the Information

  • To create and operate your account and keep you signed in.
  • To fetch the passports you track, check the issuer signature, and show you the result.
  • To detect whether a tracked passport has changed since we first captured it.
  • To keep the service secure, prevent abuse, and debug faults.
  • To answer messages you send us.

We do not sell your data and we do not use it to train models.

3. Legal Bases (GDPR)

  • Contract (Art. 6(1)(b)): to give you an account and to fetch, verify, and track the passports you ask us to track.
  • Legitimate interests (Art. 6(1)(f)): to keep the service secure and available, prevent abuse, and fix faults.
  • Legal obligations (Art. 6(1)(c)): where we must comply with law or respond to a lawful request.

4. Processors & Third Parties

We use the following providers to run the service:

  • Supabase (USA): database and authentication. Supabase processes your account data and your tracked passports on our behalf, under the provider's applicable data processing terms.
  • Vercel (USA): hosting. Vercel processes the technical logs (IP address, request metadata) required to serve the site, under the provider's applicable data processing terms.
  • Resend (USA): delivery of email that the service sends on our behalf, such as a message you submit to us through the site.

Some of these providers are located in the United States, so your data may be transferred outside the EEA. Where required, we rely on appropriate safeguards for such transfers, including the EU-U.S. Data Privacy Framework where the provider is certified, Standard Contractual Clauses, and technical measures such as encryption in transit and at rest.

5. Requests to Issuers

When you track a passport, our servers fetch it from the address you supplied and, where the issuer publishes one, fetch the issuer's public key and revocation list. Those requests come from our servers, not from your browser, so the issuer does not receive your IP address or browser data through us. The address you supply is sent to the issuer's server as part of the request.

Redtail does not send the issuer any information about you, and does not tell the issuer that a particular user is tracking a particular passport.

6. Cookies & Local Storage

We use no advertising cookies and no behavioural tracking. The following technical storage is used:

  • Authentication cookies (httpOnly, set by Supabase): keep you signed in.
  • rt_sid (cookie): identifies a guest session before you create an account.
  • NEXT_LOCALE, REDTAIL_LOCALE (local storage): remember your language choice.
  • sidebar-collapsed (local storage): remembers whether you collapsed the navigation.

These are strictly necessary or functional. If we later introduce optional analytics, we will ask for consent where required.

7. Retention & Deletion

  • Account data: kept while your account exists. You can delete your account yourself in account settings.
  • Tracked passports: kept until you remove them or delete your account. Deleting the account removes them with it.
  • Account security events: kept while the account exists and removed with it.
  • Server logs: up to 90 days.
  • Messages you send us: up to 24 months, unless a longer period is needed to deal with the matter, or you ask us to delete them sooner.

Backups may retain copies for a short period after deletion. To ask about deletion, write to contact@redtail.id.

8. Your Rights

Under the GDPR you may request access to your data, correction, deletion, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is the Urząd Ochrony Danych Osobowych (UODO).

To exercise your rights, write to contact@redtail.id. We normally respond within one month, and will tell you within that period if a complex request needs longer.

Last updated: 12 July 2026