Privacy Policy
This policy explains what Mezaic (“we”) collects, why, and the choices you have. It covers the platform (mezaic.co), the portal, and websites published through the Service (“sites”).
1. What we collect
Account data – your name, email address, hashed password (we never store the password itself), and the one-time codes used to confirm your email or reset your password.
Content – everything you add to your sites: profile, links, posts, updates, work history, images, custom scripts, domains.
Billing data – your plan, subscription status and Stripe customer reference. Card details are entered on Stripe’s pages and never reach our servers.
Portal usage – server logs with IP address, browser, requested URL, status and timing, kept for up to 30 days for security and debugging.
Visitor analytics for sites – when someone views a site or opens a link we record the page, referrer, UTM parameters, country/region/city (derived from the IP address, which is then discarded), device type, browser, operating system and language, plus a visitor identifier derived from a daily-rotating salted hash of the IP and browser. We set no cookies on sites and do not store raw IP addresses. Raw events are kept for the period allowed by the site owner’s plan; aggregated daily statistics are kept longer.
2. Why we use it
To provide and secure the Service (accounts, publishing, custom domains, backups), to bill paid plans, to show site owners how their sites perform, to send transactional email (codes, receipts, payment problems, export notices), and to comply with legal obligations. We do not sell personal data and do not use it for advertising.
3. Processors we rely on
We share data only with providers that help run the Service, under contracts that limit their use of it: Stripe (payments, tax, receipts; Stripe may act as merchant of record), Cloudflare (DNS, TLS certificates, image and backup storage), Brevo (transactional email delivery), and DB-IP (offline IP-to-location database; no data is sent to them). Our servers are operated by our hosting provider in the European Union.
4. Site owners and their visitors
Site owners may embed third-party scripts (for example Google Analytics) in their sites; those scripts are governed by the site owner’s and the third party’s privacy practices, not by this policy. If you are a visitor to a site published with Mezaic, contact the site owner for questions about their processing.
5. Retention
Account data is kept while your account exists and deleted within 30 days of account deletion, except billing records, which we keep as long as tax and accounting law requires. Content is deleted when you delete it, the site, or the account; backups and exports expire on the schedule shown in the portal. One-time codes are deleted after 24 hours.
6. Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, to object to processing, and to complain to a supervisory authority. You can export your sites and delete your account from the portal at any time; for anything else email us and we will respond within 30 days.
7. Security
All traffic is encrypted in transit (TLS), passwords are hashed with Argon2id, sessions are bound to secure, HttpOnly cookies, and access to production systems is restricted. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
8. Cookies
The platform and portal use a single strictly necessary session cookie to keep you logged in. Published sites set no cookies of our own.
9. Changes and contact
We will post updates here and notify you of material changes by email or in the portal. Questions or requests: privacy@mezaic.co.