Privacy policy
Last updated: 26 August 2026
First, an important distinction: this policy covers YOUR data as a Cuotal user. For the data of YOUR clients that you enter in the app, you are the controller and Cuotal is your data processor: that data is governed by Annex I (Data Processing Agreement) of the Terms and Conditions. This is a courtesy translation: the Spanish version is the legally binding one and prevails in the event of any discrepancy.
1. Who is the controller of your data
The controller of your data as a user is Cuotal App, S.L.U., with tax ID (NIF) B93910081 and registered office at Calle Real 14, Navas de Tolosa, 23212 La Carolina (Jaén), Spain. For any privacy matter, write to us at hugo@cuotal.com.
Cuotal is not required to appoint a data protection officer (we do not carry out large-scale processing or process special categories of data); the email above is the contact channel for everything relating to this policy.
2. Your data and your clients’ data: who is responsible for what
For your data as a user (your account, your subscription, your communications with us), Cuotal is the controller, and it is governed by this policy.
For the data of your clients that you enter in Cuotal (names, tax IDs, addresses, emails, amounts), you are the controller; Cuotal only processes it on your behalf, in accordance with Annex I of the Terms. Privacy requests from your clients must be handled by you; we help you with whatever depends on the platform.
3. What data we process, what for and on what legal basis
We process your data in the following blocks:
- Account and profile (name, email, country, tax details of your business, logo) and the content you generate while using the app (invoices, expenses, movements, your “payslip”): to create and maintain your account and provide the service. If you sign up with Apple or Google, we receive your name and email from their identity service. Basis: performance of the contract (Art. 6(1)(b) GDPR).
- Billing of your subscription (payments, history): to charge for the service and comply with our accounting and tax obligations. Basis: performance of the contract and legal obligation (Arts. 6(1)(b) and 6(1)(c)).
- Support and transactional emails (service notices, confirmations): to assist you and keep you informed of the essentials. Basis: performance of the contract (Art. 6(1)(b)).
- Product communications (Cuotal news to existing users): legitimate interest basis (Art. 6(1)(f)) under Art. 21.2 LSSI, always with an unsubscribe option in every email.
- Security and technical records (access and activity logs): to protect the service and detect abuse. Basis: legitimate interest (Art. 6(1)(f)).
- Error diagnostics (Sentry): when the app fails, a technical report of the failure is sent (screens visited, device model, your user id) so we can fix it. Sensitive data is scrubbed from free text before it leaves (emails, tax IDs, IBANs, tokens). Basis: legitimate interest (Art. 6(1)(f)).
- Usage analytics (PostHog): pseudonymous events about which features are used and where people get stuck (for example, “signup step completed”), linked to your user id —never your email— and containing no invoice content or client data. Nothing is stored on your device. Basis: legitimate interest (Art. 6(1)(f)); you can object at any time from Settings → Data → Usage analytics.
- Tax compliance (VeriFactu invoicing records, legal retention): legal obligation basis (Art. 6(1)(c)).
- The cuotal.com website and waiting list: if you join the list, we store your email address (and your answers to the optional survey) to let you know about the launch and about product news. Basis: your consent (Art. 6(1)(a)), which you can withdraw at any time from the unsubscribe link in every email or by writing to us. On the website we measure visits in aggregate using PostHog, served from our own domain (cuotal.com/ingest) so that your browsing does not go directly to a third party. That measurement is anonymous: we do not send it your email address and we do not link it to your browsing. Basis: legitimate interest (Art. 6(1)(f)). The legal pages load no analytics at all.
4. Who we share data with
We do not sell your data. It is only processed by the providers we need in order to operate —under a data processing contract— and the recipients you choose or the law requires:
- Supabase: database, authentication and storage, with data hosted in the European Union (eu-west-1 region, Ireland).
- Resend: email sending (US, certified under the EU-US Data Privacy Framework).
- Vercel: hosting of the PDF generation service (US, certified under the EU-US Data Privacy Framework; does not retain content after rendering).
- Stripe: processing of your subscription payment. Your card details are handled directly by Stripe; Cuotal never sees or stores the full number.
- Sentry (Functional Software, Inc.): error diagnostics, with data processed and hosted in its European Union region (Germany). US company certified under the EU-US Data Privacy Framework.
- PostHog, Inc.: usage analytics, with data hosted in its European Union cloud (Frankfurt); any access from the US is covered by the standard contractual clauses (SCCs) of its data processing agreement.
- Apple and Google: only if you choose to sign in with your Apple or Google account; for that authentication they act as independent controllers, under their own policies.
- Your accountant: only if you enable the accountant portal or export data for them; you decide what you share and with whom.
- AEAT: if you have business activity in Spain, the law requires us to submit your invoicing records to it under the VeriFactu scheme. It is a legal recipient, not a provider.
5. International transfers
Your data is hosted in the European Union by default. The exceptions are the sending of emails through Resend (US), the PDF generation hosted on Vercel (US) and payment processing with Stripe (which may process data in the US), covered by the EU-US Data Privacy Framework —including its UK extension— or by standard contractual clauses (SCCs). Some sub-processors of our providers may occasionally access from third countries under SCCs.
6. How long we keep your data
We keep your account data for as long as your account is active. When you cancel, we apply the export period set out in the Terms (180 days) and then delete your data, with one exception: whatever the law requires us to retain is kept blocked (available only for legal obligations) for the following periods:
- Spain: invoices and invoicing records, at least 4 years (tax limitation period, Arts. 66-70 LGT) and 6 years as commercial documentation (Art. 30 Commercial Code).
- Germany: 10 years for invoices and accounting documentation (AO/HGB).
- United Kingdom: 6 years (HMRC requirements).
- Technical and security logs: 12 months.
- Error reports (Sentry): 90 days.
- Usage analytics events: pseudonymous and linked to your user id; if you object or delete your account they stop being generated, and you can ask us to erase the history at hugo@cuotal.com.
- Product communications: until you object or unsubscribe from them.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to hugo@cuotal.com. We will respond within the legal deadline (a maximum of one month, extendable in complex cases). In addition, from Settings you can export your data and close or delete your account directly, without having to ask us — and object to usage analytics instantly with the switch in Settings → Data.
If you believe we are not handling your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, aepd.es). If you use Cuotal from the United Kingdom, the UK GDPR also applies and you can complain to the Information Commissioner’s Office (ICO, ico.org.uk).
If you use Cuotal from the United States and your state’s law grants you additional privacy rights, you can likewise exercise them at hugo@cuotal.com.
8. Cookies and local storage
Cuotal does not use analytics, advertising or tracking cookies, which is why you will not see a cookie banner. We only store on your device what is strictly necessary for the app to work, which the AEPD’s cookie guidance exempts from consent (full details in the Cookie Policy):
- Your session (Supabase authentication tokens), so you do not have to log in every time.
- Your language, if you choose it manually.
- Your theme (light/dark), if you choose it manually.
- Your usage-analytics preference, only if you turn it off: we store the “no” in order to honour it.
- Usage analytics and error diagnostics work WITHOUT storing anything on your device (which is why there is still no banner). If we ever needed storage requiring consent, we would update this policy and ask you first.
9. Security
We protect your data with encryption in transit and at rest, isolation of each account’s data through row-level security (RLS) policies, access control and regular backups. No measure is infallible, but if we detect a breach affecting you we will notify you in accordance with the GDPR.
10. Minors
Cuotal is a service for professionals and is not aimed at anyone under 18. We do not knowingly create accounts for minors; if we detect one, we will delete it.
11. Changes to this policy
If we make substantial changes to this policy, we will notify you by email before they take effect. The date of the current version always appears at the top of the document.