1. Who We Are
Think & Feel Spaces operates the website at thinkandfeelspaces.com and provides AI-powered content generation tools. We are based in Málaga, Spain and operate under EU law, including the General Data Protection Regulation (GDPR).
Data controller contact: thinkandfeelspaces@gmail.com
2. What Data We Collect
We collect only the minimum data necessary to deliver the Service:
| Category | What | Why | Kept for |
|---|---|---|---|
| Payment data | Stripe customer ID, payment status, session ID | To verify payment before generating content | As required by EU financial regulations (7 years) |
| Product inputs | Text you submit in the product form (stored in Stripe session metadata) | To generate your personalised output | Deleted from our systems within 30 days of generation |
| Technical logs | IP address, browser type, request path, timestamp | Security monitoring and debugging | 7 days (rolling) |
| Social OAuth tokens | TikTok access token and refresh token (operator accounts only) | To enable autonomous content posting on behalf of platform operators | Until revoked or expired |
| Telemetry | Anonymous page-view events (no cookie, no fingerprint) | To understand which products attract visitors | 90 days (aggregated only) |
We do not collect: names, email addresses (unless you contact us directly), dates of birth, government IDs, or any sensitive special-category data under GDPR Article 9.
3. How We Use Your Data
- Delivering your product: Input text is passed to our AI pipeline to generate your output. It is not used to train models.
- Processing payment: Stripe handles all card data. We never see or store full card numbers.
- Improving reliability: Technical logs help us detect and fix errors.
- Autonomous social posting (operator feature): TikTok OAuth tokens are used solely to post content on behalf of the platform operator. End-user personal data is never shared with TikTok.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
4. Third-Party Processors
We share data with the following sub-processors, all bound by data-processing agreements:
| Processor | Purpose | Privacy policy |
|---|---|---|
| Stripe | Payment processing | stripe.com/privacy |
| OpenAI | AI content generation | openai.com/privacy |
| TikTok | Social media content posting (operator OAuth) | tiktok.com/legal/privacy-policy |
| Printify | Print-on-demand product fulfilment | printify.com/privacy-policy |
| Replit | Hosting and infrastructure | replit.com/privacy |
5. Cookies and Tracking
We do not use tracking cookies, advertising cookies, or third-party analytics scripts. Our anonymous telemetry beacon does not use cookies and does not fingerprint your device. No consent banner is required because we collect no cookie-based personal data from end users.
6. International Transfers
Your data may be processed in the United States (OpenAI, Stripe) and other countries. Where transfers occur outside the EEA, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR Chapter V.
7. Your Rights Under GDPR
If you are located in the EU/EEA, you have the following rights:
- Access: Request a copy of any personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure ("right to be forgotten"): Request deletion of your data (subject to legal retention obligations).
- Restriction: Ask us to restrict processing in certain circumstances.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Lodge a complaint: You have the right to complain to your national data protection authority. In Spain this is the Agencia Española de Protección de Datos (AEPD).
To exercise any of these rights, contact us at thinkandfeelspaces@gmail.com. We will respond within 30 days.
8. Data Security
We use HTTPS/TLS for all data in transit. Access to production systems is restricted to authorised personnel. Product inputs stored in Stripe session metadata are encrypted at rest by Stripe. We apply a principle of minimal data collection to reduce the attack surface.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data to us, contact us immediately and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will be updated accordingly. Continued use of the Service after changes constitutes acceptance of the revised policy. For material changes, we will make reasonable efforts to notify users.