UltraCurly — Love your curls

Privacy Policy

Last updated: April 16, 2026

1. Data Controller

UltraCurly.com is operated by BEST WEB LED SHOP SRL, a company registered in Romania (CUI: RO36971470, Reg. Com.: J2017000135294), located at Str. Cristianul nr. 24, Ploiesti, Prahova County, Romania.

Data Protection Contact: contact@ultracurly.com

2. Data We Collect

Account data: When you create an account, we collect your name, email address, and (if using social login) your Google or Apple ID. We store a hashed version of your password — we never store plain text passwords.

Ingredient checks: When you use the ingredient checker, we store the ingredient text (anonymously, without linking to your account) to improve our database and track unknown ingredients. Photo uploads are processed in real-time and are not stored after analysis.

Payment data: Payments are processed by Stripe. We do not store your credit card details. We only store your Stripe customer ID and subscription status.

Usage data: We use cookies and similar technologies to understand how you use the site (see Cookies section below).

3. Legal Basis for Processing (Art. 6 GDPR)

We process your personal data based on the following legal grounds:

  • Contract performance (Art. 6(1)(b)): Account creation, subscription management, payment processing, and providing the ingredient checker service.
  • Consent (Art. 6(1)(a)): Analytics cookies, marketing cookies, and any optional data collection. You can withdraw consent at any time via Cookie Settings in the footer.
  • Legitimate interest (Art. 6(1)(f)): Service improvement through anonymous, aggregated usage data; fraud prevention and security.
  • Legal obligation (Art. 6(1)(c)): Retaining payment and tax records as required by Romanian law.

4. How We Use Your Data

  • To provide and maintain the ingredient checker service
  • To manage your account and subscription
  • To process payments through Stripe
  • To improve our ingredient database (anonymous aggregated data only)
  • To send essential service communications (password reset, subscription changes)
  • To analyze site usage and improve the service (with your consent)

We do not sell your personal data to third parties. We do not send marketing emails unless you explicitly opt in.

5. Cookies

Essential cookies (always active):

  • uc_com_token — authentication session token (JWT, expires after 2 hours)
  • uc_com_cookie_consent — stores your cookie preferences

Analytics cookies (require your consent):

  • _ga, _ga_* — Google Analytics 4 — anonymous traffic statistics, session tracking. Retention: 14 months.

Marketing cookies (require your consent):

  • _fbp — Facebook Pixel — advertising measurement. Retention: 90 days.
  • _gcl_* — Google Ads — conversion tracking. Retention: 90 days.

We implement Google Consent Mode v2. No analytics or marketing cookies are set until you give explicit consent. You can change your preferences at any time via Cookie Settings in the footer.

6. Data Retention

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Ingredient check logs: Anonymous verification logs are retained for up to 24 months for service improvement, then automatically purged.
  • Payment records: Retained for 10 years as required by Romanian fiscal legislation.
  • Cookie consent records: Retained for 12 months, then consent must be re-obtained.
  • Analytics data: Google Analytics data retention is set to 14 months.

7. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access (Art. 15) — request a copy of the personal data we hold about you
  • Rectification (Art. 16) — request correction of inaccurate data
  • Erasure (Art. 17) — request deletion of your data ("right to be forgotten")
  • Portability (Art. 20) — request your data in a machine-readable format
  • Restrict processing (Art. 18) — request that we limit how we use your data
  • Object (Art. 21) — object to processing based on legitimate interests
  • Withdraw consent (Art. 7(3)) — withdraw consent for analytics/marketing cookies at any time via Cookie Settings in the footer, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at contact@ultracurly.com. We will respond within 30 days (extendable to 60 days for complex requests, with prior notification).

8. International Data Transfers

Your data may be processed by third-party services located outside the European Economic Area (EEA):

  • Stripe (USA) — EU-US Data Privacy Framework certified
  • Google (USA) — EU-US Data Privacy Framework certified
  • Anthropic (USA) — processes ingredient photos temporarily for OCR; no data is stored after analysis

All transfers rely on adequacy decisions or Standard Contractual Clauses (SCCs) as required by Chapter V of the GDPR.

9. Sub-processors

  • Stripe Inc. (payments) — Privacy Policy
  • Google LLC (Analytics, OAuth, Ads) — Privacy Policy
  • Apple Inc. (Sign In with Apple) — Privacy Policy
  • Anthropic PBC (photo OCR processing) — Privacy Policy
  • HostX / Elara (web hosting, Romania) — data remains within EU
  • Hetzner Online GmbH (backup hosting, Germany) — data remains within EU

10. Data Security

We use HTTPS encryption (TLS 1.3), secure password hashing (bcrypt), and JWT tokens for authentication. Payment processing is handled entirely by Stripe (PCI DSS Level 1 compliant). We do not store credit card numbers or CVVs. Access to personal data is restricted to authorized personnel only.

11. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with:

ANSPDCP

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania

Email: anspdcp@dataprotection.ro

Website: www.dataprotection.ro

12. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will notify registered users by email.