Privacy Policy

Last updated: February 1, 2026

Introduction

Material Labs LLC, operating as Schengen Safe ("we", "our", or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

We are GDPR compliant and respect your rights as a data subject. By using Schengen Safe, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Account Information

When you create an account, we collect:

  • Email address (used for authentication and communication)
  • Password (encrypted and never stored in plain text)
  • Account creation and last login timestamps

Travel Data

To provide our Schengen compliance tracking service, we collect and store:

  • Trip entry and exit dates
  • Countries visited
  • Trip notes (optional, user-provided)
  • Passport information (if you choose to track multiple passports)

This data is necessary to calculate your Schengen Area compliance status and provide accurate tracking.

Payment Information

We use Stripe as our payment processor. We do not directly collect or store your payment card details. Stripe collects:

  • Credit/debit card information
  • Billing address
  • Payment transaction history

We store a Stripe customer ID to link your account to your subscription. All payment processing is handled securely by Stripe in accordance with PCI DSS standards. For more information, see Stripe's Privacy Policy.

Usage Data

We automatically collect certain information when you use our service:

  • Browser type and version
  • Device information
  • IP address (for security and fraud prevention)
  • Pages visited and features used
  • Time and date of access

How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: Calculate Schengen compliance, display your travel history, and provide trip management features
  • Account Management: Create and maintain your account, process authentication, and manage your subscription
  • Payment Processing: Process subscription payments, issue invoices, and handle refunds through Stripe
  • Communication: Send important service updates, subscription notifications, and respond to your inquiries
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Service Improvement: Analyze usage patterns to improve features and user experience
  • Legal Compliance: Comply with legal obligations and respond to lawful requests

Data Storage and Security

Your data security is our top priority:

  • Encryption: All data is encrypted in transit using HTTPS/TLS and at rest in our database
  • Infrastructure: We use Supabase, a secure PostgreSQL database platform with enterprise-grade security
  • Access Control: Row-level security ensures users can only access their own data
  • Authentication: Passwords are hashed using industry-standard bcrypt algorithms
  • Regular Security Audits: We conduct regular security reviews and updates

While we implement strong security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.

Data Retention

We retain your information as follows:

  • Active Accounts: Your data is retained while your account remains active
  • Inactive Subscriptions: If your subscription expires, your data is retained for 1 year to allow easy reactivation
  • After Retention Period: Data is automatically deleted 1 year after subscription end, unless you reactivate
  • Account Deletion: If you delete your account, all personal data is permanently deleted within 30 days
  • Legal Requirements: We may retain certain data longer if required by law or for legitimate business purposes (e.g., resolving disputes, preventing fraud)

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

Service Providers

  • Stripe: Payment processing and subscription management
  • Supabase: Database hosting and authentication services

These service providers are contractually obligated to protect your data and use it only for the services they provide to us.

Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government or regulatory requests
  • Protection of our rights, property, or safety
  • Investigation of potential fraud or security issues

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email before your data is transferred and becomes subject to a different privacy policy.

Cookies and Tracking

We use essential cookies only to provide our service:

Essential Cookies

  • Authentication: Session cookies to keep you logged in
  • Security: Cookies to prevent CSRF attacks and ensure secure connections
  • Preferences: Cookies to remember your settings (timezone, date format)

These cookies are necessary for the service to function and cannot be disabled. We do not use advertising or analytics cookies that track you across websites.

Third-Party Cookies

Stripe may set cookies during the payment process. These are governed by Stripe's privacy policy.

Email Communications

We may send you emails for the following purposes:

Transactional Emails (Cannot Opt Out)

  • Account verification and password reset emails
  • Subscription confirmations and payment receipts
  • Trial expiration and subscription renewal notices
  • Important service updates and security notifications

Marketing Emails (Opt-In)

  • Product updates and new feature announcements
  • Travel tips and Schengen compliance insights
  • Occasional newsletters

You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email or updating your preferences in your account settings.

Your Rights (GDPR)

If you are a resident of the European Economic Area (EEA), you have the following rights:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data (subject to legal obligations)
  • Right to Restrict Processing: Request limitation of how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing of your data for certain purposes
  • Right to Withdraw Consent: Withdraw consent for data processing at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

To exercise any of these rights, please contact us at privacy@schengensafe.com. We will respond to your request within 30 days.

Children's Privacy

Schengen Safe is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will delete it.

International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, to protect your data in accordance with GDPR requirements.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page with an updated "Last updated" date
  • Sending you an email notification (for significant changes)
  • Displaying a prominent notice in the application

Your continued use of Schengen Safe after changes are posted constitutes your acceptance of the updated Privacy Policy.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@schengensafe.com

Data Protection Officer: dpo@schengensafe.com

We take your privacy seriously and will respond to all requests within 30 days.