Privacy Policy
Last updated: September 2026
Introduction
Your privacy matters to us. This policy explains what personal information we collect when you use ElGrupito, why we collect it, who we share it with, how long we keep it, and what control you have over it.
Personal information is any data that can identify you: your name and contact details, but also your device, your payment details, or the way you use the site. By using the service you accept the practices described here. Where our site links to third-party services, those services have their own policies: this one does not cover what you do after you leave ElGrupito.
Information We Collect
It splits into the information you give us voluntarily and the information collected automatically as you use the site.
Information you give us
We collect it when you:
- Create an account: name, email address, and password, which we store encrypted.
- Make a purchase: billing details and country. Your card details are captured and stored directly by the payment processor, not by us.
- Contact support through live chat, the contact form, or email.
- Subscribe to our newsletter or other communications.
- Take part in surveys, promotions, or giveaways, or leave a review.
- Join the affiliate program: the tax and payout details we need in order to pay you.
Information collected automatically
When you visit the site, our servers and tools record:
- Log data: IP address, browser type and version, pages visited, date and time, and time spent on each page.
- Device data: device type, operating system, identifiers, and settings.
- Approximate location derived from your IP, which we use to show prices in your currency and content in your language.
- Error data: what you were trying to do when something failed, and the technical details of the failure.
- Transaction data generated by normal use of the platform: orders, deliveries, renewals, wallet balance, and usage metrics.
- Cookies and browser local storage, as detailed below.
Some of this data does not identify you on its own, but may do so when combined with other information.
Why We May Process Your Data
We only collect and use personal information when we have a legitimate reason to, and only what is reasonably necessary. Depending on the case, that reason is:
- Performing our contract with you: creating your account, processing your order, delivering your access, and renewing it.
- Complying with legal, accounting, and tax obligations.
- Our legitimate interest in operating, securing, and improving the service, and in preventing fraud and shared-account abuse.
- Your consent, where we send you marketing communications or use non-essential cookies. You can withdraw it at any time.
How We Use Your Information
We use the information we collect to:
- Create and administer your account.
- Process payments, deliver your orders, and manage renewals and your wallet.
- Provide support and answer your questions.
- Send you operational notices: confirmations, deliveries, renewal reminders, and service changes.
- Send you promotional communications, where you have consented.
- Improve the site and our services, and analyse usage patterns in aggregate.
- Detect and prevent fraud, shared-account misuse, and payment disputes.
- Attribute referrals and calculate affiliate program commissions.
- Meet legal obligations, resolve disputes, and enforce our Terms of Use.
Security of Your Data
We apply proportionate technical and organisational measures to protect your information:
- Encryption in transit (TLS) across the site and our APIs.
- Encryption of sensitive data at rest, including payment provider credentials.
- Passwords stored as hashes, never in plain text.
- Role-based access control: only staff who need the data can reach it.
- Masking of sensitive fields and exclusion of payment pages from our analytics tooling.
- Audit logs and periodic security reviews.
Even so, no method of electronic transmission or storage is 100% secure and nobody can guarantee absolute security. Choosing a strong password and keeping it confidential is also your responsibility.
How Long We Keep Your Data
We keep your personal information only as long as we need it to:
- Provide the service, for as long as your account exists.
- Meet legal, accounting, and tax obligations: invoices and payment records are kept for the period the law requires.
- Resolve disputes, handle chargebacks, and enforce our agreements.
When you close your account we delete or anonymise your personal information within 30 days, except what we must keep by legal obligation or to defend a claim.
Cookies and Similar Technologies
We use cookies and browser local storage to keep you signed in, remember your cart, language, and currency, understand how the site is used, and attribute referrals correctly. The detail of what each cookie does, how long it lasts, and how to refuse it is in our Cookie Policy.
Who We Share Your Information With
We do not sell your personal information. We share it only in these cases:
Service providers
Companies that process data on our behalf and under our instructions so the service can work: hosting, database, payment processing, email delivery, analytics, support, and referral attribution. They are required to protect your data and to use it only to provide that service to us.
Business transfers
In a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, which will be bound by this same policy.
Legal requirements
Where the law requires it, or where it is necessary to establish, exercise, or defend legal rights — including authorities, courts, and our professional advisers.
With your consent
In any other case where you have given us explicit consent to share it.
The providers we use today
These are the third parties that process data on our behalf:
- Supabase — Platform database, authentication, and storage.
- Stripe — Card and subscription payment processing.
- 1D3 DIGITECH OÜ — Payment processing and invoicing as merchant of record.
- Resend — Delivery of transactional emails and the newsletter.
- PostHog — Product analytics and site usage metrics.
- Crisp — Live chat and the Help Centre.
- Dub — Attribution of referral and affiliate program links.
- Google and Meta — Sign-in with Google or Facebook, when you choose that option.
- Hosting and infrastructure providers — The servers, network, and attack protection the platform runs on.
International Transfers
Your data is stored and processed primarily in the European Union, and also wherever our providers maintain facilities, which may be outside your country of residence. Those countries may not have the same data protection laws as yours. When we transfer data outside the European Economic Area we do so in line with applicable law and with appropriate safeguards, and we protect the transferred information in line with this policy.
Your Rights
Depending on where you live, you may have the following rights over your personal information:
- Access — Request a copy of the information we hold about you.
- Correction — Ask us to correct data that is inaccurate, incomplete, or out of date.
- Deletion — Ask us to delete your personal information.
- Portability — Ask us to transfer your data to another service.
- Restriction — Ask us to limit how we use your information.
- Objection — Object to certain processing of your personal information.
- Withdrawing consent — Withdraw your consent at any time, where processing is based on it.
To exercise any of them, write to our support team from your account email. We may ask for additional information to confirm your identity, and we respond within the period applicable law sets: at most one month in the European Economic Area.
We will not discriminate against you for exercising your rights: we will not deny you products or charge you different prices for doing so.
If you believe we have breached data protection law, write to us and we will investigate. You can also complain to the supervisory authority in your country; in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon). We will comply with the laws applicable to us in the event of a data breach.
“Do Not Track” Signals
Some browsers send a “Do Not Track” signal. There is still no common standard for how to respond to it, so we do not act on it automatically. You can refuse or delete non-essential cookies from your browser settings, as explained in our Cookie Policy.
Children's Privacy
The service is intended for people aged 18 and over, and we do not knowingly collect personal information from minors. If you believe a minor has given us data, write to us and we will delete it.
Third-Party Links
Our platform may link to sites and services we do not operate, including the platforms whose subscriptions we offer. We do not control their content or their privacy practices and accept no responsibility for them: review their policies before giving them information.
Changes to This Policy
We may update this policy to reflect changes in our processes, in industry practice, or in the law. We will publish the new version on this same page with an updated revision date and, if the change is significant or the law requires it, we will tell you and ask for your consent where appropriate.
Contact Us
For any question about this policy, about your data, or to exercise your rights:
Data controller: Innovaly Services OÜ, Lootsa tn 5, 11415 Tallinn, Estonia (registry number 14935651).
Email support
Or visit our Contact page