clearable.

Privacy Policy

Draft — pending legal review
Written from how Clearable actually works, not from a template — but no lawyer has read it yet. Anything on an amber chip is a blank the founder still has to fill. Not legal advice.

Last updated: 29 August 2026

This describes what Clearable actually collects and does, written against the code that runs the site rather than from a template. Where something is not settled yet, it says so.

1. Who is responsible

The controller of your personal data is [Legal entity — fill before launch], established in the European Union. Contact: info@clearable.io. We have not appointed a data protection officer; that address reaches a person.

2. What we collect from buyers

Clearing a sound needs no account. When you send a request we collect:

When you accept an agreement we additionally record the accepting email address, the timestamp, your IP address, the Stripe payment reference and a SHA-256 hash of the exact terms. This is the evidence that makes the electronic signature meaningful, and it is stamped into the PDF. We keep it for exactly that reason.

3. What we collect from creators

4. Other things people send us

5. Technical data

We use your IP address to rate-limit the public forms — the ones that write to the database and send email — so they cannot be used as a spam relay. Those counters are short-lived and expire on their own. Our host and our processors keep ordinary server logs. Application errors are logged server-side and money-critical failures raise an alert email to the operator, which can include the details of the request that failed.

6. Cookies, and what we do not do

Clearable sets no analytics or advertising cookies. There is no analytics script, no tracking pixel and no advertising network on this site. The only cookies we set are the Supabase session cookies that keep a signed-in creator signed in — strictly necessary, and never set for a buyer who has not logged in, because buyers have no account. Stripe sets its own cookies on Stripe’s checkout pages, under Stripe’s policy.

We do not sell personal data, we do not share it with advertisers, and we do not profile you for marketing.

7. Why we process it (lawful bases)

On automated decisions: Clearable computes a suggested price from the numbers a buyer declares. It is a suggestion shown privately to the creator, who decides. Creators can set rules that automatically approve or decline a request at certain amounts, and those rules deliberately stay inert when the size figure is self-reported rather than verified. If a decision affects you and you want a person to look at it, email us.

8. Who processes it for us

We may also disclose data to a professional adviser, or where the law requires it.

9. International transfers

Some of those providers are based in, or process data in, the United States. Where data leaves the EEA we rely on the transfer safeguards those providers publish in their own data processing terms, including standard contractual clauses where they apply. We do not claim any certification or adequacy finding of our own, and our processor documentation is still being completed alongside the legal review noted at the top of this page.

10. How long we keep it

We have not yet published a full retention schedule with fixed periods for every category; it is being drafted with the review above.

11. Your rights

Under the GDPR you can ask for access to your data, correction of it, erasure, restriction of processing, or portability, and you can object to processing we base on legitimate interests. Email info@clearable.io and we will answer within a month.

Two honest limits. A signed agreement, its audit stamp and the payment behind it cannot simply be erased on request: they are the record of a transaction between two other people and are needed for legal claims and accounting. And we cannot delete from Stripe what Stripe is required to keep. Where we cannot delete, we will tell you what we are keeping and why.

12. Complaints

You can complain to your local data protection authority, or to the supervisory authority for the country where [Legal entity — fill before launch] is established. Any dispute about this policy follows the same law and venue as our terms: [Governing law — fill before launch].

13. Security

Storage buckets are private and reachable only through short-lived signed URLs. Database access is restricted by row-level security, and the public flows write through server-side code rather than letting a browser touch the tables. A buyer’s link is an unguessable token. Card data never reaches our servers. No system is perfect, and we do not claim any security certification.

14. Children

Clearable is not for under-18s. If you believe a minor has given us personal data, email us and we will remove what we can.

15. Changes

When this policy changes, the date at the top changes with it. Material changes will be flagged on the site.

16. Contact

info@clearable.io. Also see our Terms of Use.

← Back to clearable.io