Privacy Notice
This notice briefly explains how PipView processes personal data in connection with login, demo access, premium access, and payment handling. It is a technical overview and does not replace individual legal advice.
Version: 2026-06-25. For production use, operator details, contact address, and retention periods should be legally reviewed and finalized.
What data is processed
- Account data such as email address, password hash, account tier, and login timestamps.
- Session and security data such as session tokens and optional email confirmation and 2FA codes.
- Payment-related reference data from Stripe such as customer ID and subscription ID.
- Technical usage data for operations and security purposes, such as API usage and error logs.
Purposes of processing
- Providing demo and premium access.
- Fraud prevention, login security, and optional two-factor verification.
- Handling and managing premium subscriptions through Stripe.
- Error analysis, system stability, and traceability of security-relevant events.
Sharing with third parties
Stripe is used for payment processing. SMTP or email providers may be used for email confirmations or 2FA if configured in the environment. Any further transfer only occurs where technically necessary or legally required.
Legal basis and Switzerland context
Processing is carried out mainly for contract performance (demo/premium service delivery), service security, and consent where it is collected (for example, during registration). For operation in Switzerland, requirements of the revised FADP should be observed. For cross-border processing (for example, payments via international providers), appropriate safeguards and contractual protections should be in place.
Retention period
- Active account data is stored for the duration of the contract or usage period.
- Security codes for email confirmation and 2FA expire automatically after a short period.
- Billing and subscription references are stored for operational and accounting purposes.
Data subject rights
Depending on applicable law, rights may include access, correction, deletion, restriction, objection, and data portability. For production use, a specific contact point should also be provided here.
Technical safeguards
- Passwords are not stored in plain text; they are stored as hashes.
- Sessions are managed through HTTPS cookies only.
- Email confirmation and email-based 2FA can be enabled optionally.
Go to registration ยท Go to login