Your private record and public Passport are separate by design.
Only selected public fields and card photos are copied to the public layer. Private documents, account identity and hidden fields are not intended to enter public exports.
Controller and scope
This Policy applies to IDee accounts, object records, photographs, public Passports, sharing tools and support interactions. The legal person responsible for deciding how personal data is processed is the data controller.
The controller’s legal name, postal address and privacy email must be inserted before unrestricted public registration. These facts depend on the final operating entity and cannot be safely inferred from the product name.
Data we process
We process account identifiers such as email address, authentication provider and account dates; optional profile details such as username, display name, profile photo, bio, location and website; security and technical information needed to maintain sessions and prevent abuse; object details, field visibility choices, photos, service history, reminders and other records you choose to add; and communications you send to support.
Account profile details remain in the authenticated account layer unless a separate public-profile option is clearly enabled in the future. Some object information may indirectly identify a person, especially photographs, precise descriptions, locations, serial numbers or documents. Add only what is relevant and use the private setting unless public disclosure is genuinely intended.
Purposes and legal bases
We process data to create and secure your account, store and display Passports, honour public/private choices, generate requested exports, provide account controls, respond to support, prevent misuse and meet legal obligations.
Depending on the activity and applicable law, processing is based on performing our contract with you, complying with law, our legitimate interests in security and reliable product operation, or consent where it is specifically requested. Consent can be withdrawn without affecting processing already carried out lawfully.
Public and private Passport layers
Private account data is available only through authenticated and authorised access. When you mark a field, event or photo as public, IDee creates a separate public payload that may be accessible to anyone with the Passport link. Public viewers are not given your account email, private notes, receipt paths, exact private location or full private identifiers through that payload.
You can revoke a public link. Revocation prevents future access through IDee but cannot erase copies or screenshots previously made by other people.
Service providers and international transfers
IDee uses specialist providers for hosting, databases, authentication and file storage. At launch these include Vercel for application hosting, Supabase for database, authentication and storage infrastructure, and Google when you choose Google sign-in. Providers process data under their own security measures and, where they act for IDee, under appropriate contractual obligations.
The final processor schedule, hosting regions and any transfer mechanism used for data sent outside the European Economic Area must be confirmed against the production accounts and published before unrestricted launch.
Retention and deletion
Account and Passport content is normally retained while the account remains active. Public Passport data is retained until the public record is revoked or the related account or object is deleted. Authentication, fraud-prevention and security records may be kept for a limited period after closure where necessary to protect users or meet legal obligations.
Account deletion is intended to remove the account, Passports and uploaded card photos, subject to short-lived backups, logs and retention required by law. Where immediate deletion from backups is not technically possible, the data remains isolated until overwritten.
Your choices and data-protection rights
You can edit Passport fields, change public choices, revoke public links and delete your account. Depending on applicable law, you may also request access, correction, erasure, restriction, portability or object to processing, and may withdraw consent. You may complain to the competent data-protection authority.
We may ask for information reasonably necessary to verify account control before fulfilling a request. Requests should be answered without undue delay and within the period required by applicable law.
Security and data minimisation
IDee separates public and private payloads, uses authenticated access and database access controls, and limits public cards and exports to an explicit allowlist. No online service can guarantee absolute security. You should use a unique password, protect your email account and avoid uploading information the service does not need.
Children
IDee is not directed to children below the minimum digital-consent age in their country. If we learn that an account was created without required authorisation, we may restrict it and take appropriate steps to delete the related personal data.
Changes, contact and complaints
We may update this Policy when features, providers or legal requirements change. Material changes will be communicated clearly and the effective date will be updated. The final privacy contact, controller identity and competent supervisory authority must be published before unrestricted registration opens.
- Data controller
- Required before public registration
- Privacy email
- Required before public registration
- Postal address
- Required before public registration
- Supervisory authority
- Depends on controller establishment