Privacy Policy
What Smart Widget Platform collects, why, who sees it, and the rights you and your visitors have. It also serves as the data processing terms for the booking data we handle on your behalf.
1. Who is responsible
Smart Widget — L. Thomas PR (smartwidget.app@gmail.com) operates Smart Widget Platform and is the data controller for the personal data of account holders and of visitors to this website. We are a sole trader (preduzetnik) established in the Republic of Serbia.
Two data-protection regimes apply to us at once, and we have written this policy to satisfy both. Serbia's Law on the Protection of Personal Data (Zakon o zaštiti podataka o ličnosti) governs us because we are established here; it follows the GDPR closely, almost article for article. The GDPR itself also applies directly, under its Article 3(2), because we offer the Service to customers in the European Union. Where the two differ we follow the stricter reading.
For the personal data your widget collects from your visitors (bookings), you — the account holder — are the controller and we are your processor. Section 3 explains what that means in practice.
2. Data we collect about account holders
We collect only what running the Service requires:
- Account data: name, email address, password (stored hashed), language, time zone, account currency, and the date and version of the terms you accepted.
- Billing data: your plan, subscription identifiers and status from PayPal or Stripe, and payment dates. We never see or store card numbers or bank details — those stay with the payment provider.
- Payout connections: the identifiers of the Stripe or PayPal account you connect to receive customer payments (never its credentials), and whether it can receive money.
- Widget configuration: everything you set up in the builder, including any images you upload.
- Support: the messages you send us through Support tickets.
- Technical data: IP address, browser type and request logs kept for security and troubleshooting; the theme and language you choose, stored in your browser.
3. Data your widget collects from visitors — where we are your processor
When a visitor uses your widget, it collects what a booking needs: the details they type (typically name, email, phone and any custom fields you add), the service and options they choose, the date and time, the calculated price, and the payment method and status. The widget also records anonymous usage events (a view, an estimate, a booking started) so your Analytics page can show how it performs.
We process this data only on your instructions and only to provide the Service: to store the booking, show it in your dashboard, send the confirmation emails you enable, and pass the amount to the payment provider you connected. We do not use visitor data for our own marketing, do not sell it, and do not combine it across accounts.
As your processor we keep it confidential, apply the security measures in section 9, engage only the sub-processors listed in section 5, help you respond to visitors exercising their rights, and delete or return the data when you close your account, except where the law requires us to keep it. You are responsible for having a lawful basis to collect it and for giving your visitors your own privacy notice.
4. Why we use the data and on what basis
Under the GDPR each use needs a legal basis. Ours are:
- Providing the Service you signed up for — account, widgets, bookings, dashboard, payments, support: performance of our contract with you.
- Billing and keeping accounting records: performance of the contract and our legal obligations (tax and accounting law).
- Security, fraud prevention, abuse handling and keeping logs: our legitimate interest in running a safe service.
- Service emails about your account, trial and subscription: performance of the contract. We send marketing emails only with your consent, and every one has an unsubscribe link.
- Improving the Service using aggregated, non-identifying usage statistics: our legitimate interest.
5. Who we share data with
We share personal data only with providers that help us run the Service, under contracts that bind them to protect it:
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A.) — subscription billing, and customer payments routed to your PayPal account.
- Stripe (Stripe Payments Europe Ltd.) — customer payments routed to your Stripe account.
- Google — delivery of transactional emails through Google Apps Script.
- DigitalOcean, LLC — hosting and infrastructure. Your account, widget and booking data is stored in its Frankfurt, Germany region.
- Authorities or courts where the law requires it.
Payment providers act as independent controllers for the payment itself, under their own privacy policies.
6. International transfers
The Service runs on DigitalOcean, LLC infrastructure in Frankfurt, Germany, so account, widget and booking data is stored inside the European Union.
Two kinds of transfer still happen. We ourselves are established in Serbia, which is outside the European Economic Area and for which the European Commission has not issued an adequacy decision; and some of the providers in section 5 (for example Google, Stripe, PayPal and our host's US parent) process data outside the EEA. For every one of those we rely on the European Commission's Standard Contractual Clauses — or on an adequacy decision where one covers the provider — together with the provider's own technical safeguards, and we keep the data transferred to the minimum the Service needs. You can ask us for a copy of the clauses we rely on at smartwidget.app@gmail.com.
7. How long we keep data
- Account and widget data: for as long as you have an account, then deleted within 30 days of closure (we can export your bookings on request in that window).
- Booking data: for as long as you keep it in your dashboard; deleted with your account.
- Billing and accounting records: for the period Serbian tax law requires — currently five years from the end of the year the record relates to.
- Request and security logs: 90 days.
- Support tickets: for as long as your account exists, so we can help with follow-ups.
8. Your rights
You can access, correct, export and delete most of your data yourself in Settings. Beyond that you have the right to ask us for access, rectification, erasure, restriction, portability, and to object to processing based on our legitimate interests; and, where processing is based on consent, to withdraw it at any time. Write to smartwidget.app@gmail.com and we will answer within one month.
If you believe we handle your data unlawfully you can complain to a supervisory authority. Ours is the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), poverenik.rs. If you are in the European Union you may complain instead to the supervisory authority of the country where you live or work, or where the issue arose.
Visitors whose data was collected through a widget should contact the business they booked with; we will assist that business in responding.
9. Security
Data is transmitted over TLS, passwords are stored hashed, sessions use secure cookies, access to production systems is limited to the people who need it, and payment details are handled entirely by the payment provider's own secure forms. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the authorities as the law requires.
10. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, contact smartwidget.app@gmail.com and we will delete it.
11. Changes to this policy
We will update this policy when our practices change and show the revision date at the top. For material changes we will email account holders in advance.