Sentinel Spend

Privacy Policy — Sentinel Spend

_Last updated: please update on publish_

This Privacy Policy describes how Sentinel Spend (operated by Ironhazel Labs (pending Osek Murshe registration, Israel), registered in Israel, registration number pending; the "Data Controller") collects, uses, and protects personal data when you use https://sentinel.ironhazel.com (the "Service").

1. Data controller

  • Data controller: Ironhazel Labs (pending Osek Murshe registration, Israel)
  • Registered address: Israel — registered address pending
  • Contact: hello@ironhazel.com
  • Privacy contact: privacy@ironhazel.com

2. Personal data we collect

  • When you join a waitlist or create an account: your email address.
  • When you use the Service: product-usage events (page views, feature clicks) processed through PostHog as a data processor.
  • When you pay: transaction metadata (not full card details) processed by Paddle.com Market Ltd. or Lemon Squeezy (as our merchant of record and data processor).
  • Logs: standard server logs (IP, user-agent, timestamp) retained for 30 days for security and abuse prevention.

We do not knowingly collect data from children under 16.

3. Legal basis for processing (EU / UK)

  • Consent: for waitlist signups and marketing emails.
  • Contract performance: to deliver the Service once you pay.
  • Legitimate interests: for security logging and aggregated product analytics.

4. How we use your data

  • Deliver the Service to you.
  • Communicate about your account, billing, and material changes.
  • Improve the Service through aggregated analytics.
  • Respond to support requests.

We do not sell your personal data. We do not share it with third parties except the processors named above and when required by law.

5. International transfers

Our infrastructure runs on Vercel (US + EU), Supabase (EU), Resend (US), and PostHog (US or EU depending on region). Where required, transfers are covered by appropriate safeguards including Standard Contractual Clauses.

6. Retention

  • Waitlist emails: until you unsubscribe.
  • Account data: for the life of your account plus 30 days after deletion.
  • Paid-transaction records: 7 years (tax law requirement).
  • Server logs: 30 days.

7. Your rights

Under the EU GDPR, UK GDPR, and the Israeli Privacy Protection Law (Amendment 13 / תיקון 13, 2024/2025) and Communications Law Amendment 40, you have the right to:

  • Access your personal data.
  • Rectify inaccurate data.
  • Erase your data (subject to legal-retention exceptions).
  • Restrict or object to processing.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local supervisory authority. For Israel: the Privacy Protection Authority (רשות להגנת הפרטיות).

To exercise any right, email privacy@ironhazel.com. We respond within 30 days.

8. Cookies & tracking

We use strictly-necessary cookies for authentication and preference storage. Analytics cookies (PostHog) run only with your consent where legally required.

9. Changes to this policy

We post changes here and, for material changes, email registered users. Continued use after changes constitutes acceptance.

10. Contact

Questions about this policy or your data: privacy@ironhazel.com

General contact: hello@ironhazel.com

Abuse / DMCA: abuse@ironhazel.com