Skip to content
Pricing Blog Changelog Contact Documentation
Sign in Start Building
Pricing Blog Changelog Contact Documentation
Sign in Start Building

Legal

Privacy Policy

Last updated: April 14, 2026

This Privacy Policy describes how Refract, operated by Yoann Jaspar (Arc Lab), collects, uses, and shares personal data when you use userefract.io and related services.

This policy is provided for general information and should be reviewed by qualified legal counsel before publication.

1. Data controller

Yoann Jaspar, operating as Arc Lab, Matosinhos, Portugal, is the data controller for personal data processed in connection with Refract.

Privacy contact: [email protected]

2. Data we collect

  • Order and billing data: name, billing address, email address, VAT/NIF data where required for invoicing and tax compliance.
  • Account and access data: GitHub username and Discord ID when needed to grant repository and community access linked to your license.
  • Transactional communication data: email and message metadata needed to send license, account, invoice, and product-update communications.
  • Analytics and technical data: consent status, pseudonymous cookie identifiers, page views, and device/browser metadata collected through analytics tools.
  • Support data: information you submit in support conversations and contact requests.

Refract does not store raw payment card details. Payments are processed by Stripe.

3. How we use your data and legal bases (GDPR)

  • Fulfill your order and provide license access (contractual necessity), including access provisioning through GitHub and Discord.
  • Process payments and issue invoices (contractual necessity and legal obligation), including compliance with Portuguese tax and accounting requirements.
  • Send transactional and service communications (contractual necessity and legitimate interests), such as license delivery and operational notices.
  • Measure and improve the site and product experience (consent for non-essential analytics; legitimate interests for strictly necessary service security and reliability).
  • Send optional marketing updates (consent), only when you explicitly opt in, with unsubscribe options in each message.
  • Detect fraud and abuse (legitimate interests) to protect the service and customers.

4. Data sub-processors

Refract shares personal data only with trusted processors needed to operate the service:

  • Stripe: payment processing and billing events.
  • GitHub: repository access management and seat assignment.
  • Discord: community access and support channel management.
  • Brevo: transactional and opt-in marketing email delivery.
  • Google Analytics and PostHog: privacy-aware analytics and product improvement insights.

5. International data transfers

Some providers may process data outside the EEA. When this happens, transfers are handled under GDPR safeguards, such as adequacy decisions or Standard Contractual Clauses (SCCs), as made available by the relevant provider.

6. Data retention

  • Invoices and tax records: retained for 10 years under Portuguese legal requirements.
  • License access data (GitHub/Discord identifiers): retained while your license access is active, and for up to 12 months after access removal for compliance and dispute handling.
  • Transactional email logs: typically retained for short operational periods (for example, up to around 30 days) according to provider policies.
  • Optional marketing email data: retained until you unsubscribe or withdraw consent.

7. Cookies and analytics

Refract uses essential cookies for core functionality and may use non-essential analytics cookies when you provide consent through the cookie controls.

  • Google Analytics and PostHog tracking is enabled only when consent is granted.
  • You can withdraw consent at any time through available cookie controls.
  • Withdrawing consent stops future non-essential analytics collection on this site.

8. Your rights (EEA residents)

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing

To exercise these rights, contact [email protected]. You may also lodge a complaint with your local supervisory authority, including the Portuguese Data Protection Authority ( CNPD).

9. Security

Reasonable technical and organizational measures are used to protect personal data against unauthorized access, loss, misuse, or alteration. No system can guarantee absolute security.

10. Changes to this policy

This policy may be updated from time to time. Material updates will be communicated through product communication channels, and the Last updated date on this page will be revised.

11. Contact

Yoann Jaspar (Arc Lab)
Matosinhos, Portugal
Email: [email protected]

12. Related legal pages

Terms of Service · License Agreement

Every SaaS pivots.
Most codebases don't survive it.

userefract.io

Built by Indies
Featured on Fazier

Product

  • Home
  • Pricing
  • Changelog

Resources

  • Documentation
  • Contact
  • Blog
  • Sitemap

Legal

  • Terms of Service
  • Privacy Policy
  • License Agreement
© 2026 Refract. All rights reserved. Made with 🧡 for developers