02 · GDPR

Privacy notice

How Restage processes account data, listing photographs, and billing information under the GDPR.

Effective
7 September 2026
Operator
Restage · Spain

Art. 1

Who is the controller

The controller of personal data processed through getrestage.com is the operator of Restage, established in Spain. Contact the controller at privacy@getrestage.com. We will publish the registered company name, NIF, and registered office on this page once the Spanish entity is on file.

If you invite colleagues into a studio, you may also be a controller of their workplace contact data. Restage then acts as processor for that organisational use, and as controller for account security, billing, and product improvement as described below.

Art. 2

What we process

CategoryExamplesSource
Identity and accountName, email, password hash, plan, organisation, seat roleYou; invited by a colleague
Listing workProperty photos you upload, prompts, style, mode, quality, outputs, certificates, job idsYou, in the studio
BillingStripe customer id, subscription and pack purchases, IVA invoicesYou and Stripe
UsageCredit ledger, job status, device/session cookie, basic server logsYour use of the service
SupportEmails you send usYou

We do not want special-category data, children’s data, or identity documents. Listing photographs can still contain people, number plates, or GPS. Treat them as personal data and only upload what the listing requires.

Art. 3

Why we process it, and on which legal basis

  • Contract (GDPR art. 6(1)(b)): creating your account, running jobs, granting credits, issuing exports and certificates, providing seats, and sending transactional mail such as invites.
  • Legal obligation (art. 6(1)(c)): IVA invoices, bookkeeping, and answering a lawful request from a Spanish or EU authority.
  • Legitimate interests (art. 6(1)(f)): securing the service, preventing fraud and abuse, debugging failed jobs, and understanding how the product is used in aggregate. You may object; see article 10.
  • Consent (art. 6(1)(a)): only if we later send optional marketing mail. We do not run advertising pixels on Restage today. You can withdraw consent without affecting the studio.

Art. 4

Photographs and EXIF

When you upload a JPEG, PNG, or WebP (maximum 10 MB), we re-encode it to JPEG. That process drops GPS and other EXIF. Object files live in Cloudflare R2 under opaque keys; they are not stored as PocketBase file fields. We keep the original (stripped) ingest, the generated output, an optional clean staging file for paid plans, and a PDF certificate.

Do not upload photos of identifiable people unless you have a lawful basis (for example the owner instructed you to list the home, and occupants are not the focus). Occupied interiors are your compliance problem before they are ours.

Art. 5

AI processors and international transfers

To generate an image we send the prompt and the reference photograph to OpenRouter, which routes the job to model providers (currently including Google and Black Forest Labs). Those providers may process data in the United States or other countries outside the EEA.

Where we transfer personal data out of the EEA, we rely on an adequacy decision if one exists, otherwise on Standard Contractual Clauses and the vendor’s transfer tools. Image generation cannot run without that transfer. If you cannot accept it, do not upload photographs.

We do not sell your listing photos. We do not grant vendors a right to train their foundation models on your files beyond what their processor terms already disclose. Read those vendors’ terms if that residual risk matters to your brokerage.

Art. 6

Payments

Card data is collected and stored by Stripe, not by Restage. Stripe Ireland is a separate controller for payment data. We receive a customer id, billing email, tax status, and whether a charge succeeded. Invoices may contain your name, email, and billing address.

Art. 7

Cookies

Restage sets one essential cookie, pb_auth: an HTTP-only session token, SameSite=Lax, Secure in production, lasting seven days. It is necessary to keep you logged in. We do not set analytics, advertising, or social-sharing cookies. No consent banner is required for this essential cookie under the ePrivacy rules as applied in Spain. If we add non-essential cookies later, we will ask first.

Art. 8

Who receives data

RecipientRoleWhere
PocketBase on our EU hostAccount, listings, ledgerEuropean Union
Cloudflare R2Image and certificate objectsCloudflare (EU-oriented bucket; global edge)
OpenRouter and model vendorsImage generationUnited States and vendor regions
StripePayments and IVAIreland / EEA, with Stripe’s transfers
ResendTransactional emailUnited States, under processor terms
Your invited seatsShared listings and walletYour organisation

We may also disclose data if required by law, or to a buyer of the business under a confidentiality undertaking.

Art. 9

How long we keep it

  • Account and organisation: for the life of the account, then a short wind-down.
  • Photographs, outputs, certificates: while the listing remains in the studio, then until you delete them or the account is closed, unless a dispute or legal hold applies.
  • Credit ledger and invoices: as required for Spanish commercial and tax records (generally six years for tax-related records).
  • Server logs: typically under 90 days unless we are investigating abuse.
  • Session cookie: seven days, or until you log out.

Art. 10

Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. You may also withdraw consent where we relied on it. Use privacy@getrestage.com. We will need to verify the account. Some rights give way to invoices we must keep or to jobs already sent to a model vendor.

You may complain to the Agencia Española de Protección de Datos (AEPD) (aepd.es), or to your local EU supervisory authority. We would rather fix the issue first.

Art. 11

Children

Restage is not directed at anyone under 18. We do not knowingly create accounts for minors.

Art. 12

Security

We use HTTPS, hashed passwords, an HTTP-only session cookie, object storage with signed access, and least-privilege admin credentials. No method of transmission is perfectly secure. Tell legal@getrestage.com if you find a vulnerability. Do not publicly weaponise it.

Art. 13

Changes to this notice

The date at the top is the effective date. Material changes will be posted here and, where appropriate, emailed to the account address.