Legal and privacy

Privacy policy

How AgroForest Designer collects, uses, stores, and protects your personal data.

Updated August 2026 Version 1.2
Contact us

1. Introduction

AgroForest Designer ("we", "us", or "our") respects your privacy. This policy explains how we collect, use, store, and protect personal data when you use our software for agroforestry planning.

We process personal data in accordance with the European General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data controller

AgroForest Designer is the data controller. We are based in Antwerp, Belgium, and can be reached at contact@agroforestdesigner.com.

2. Data we collect

Information you provide

  • Name and email address
  • Telephone number, when provided
  • Language preference
  • Company name for business accounts
  • Payment information processed through Stripe

Project content

  • Agroforestry projects, including their name, description, and location
  • Planting plans, recipes, and customised plant cultivars
  • Map coordinates, geographic data, notes, and annotations

Information collected automatically

  • IP address and browser information in security and operational logs
  • Sign-in and sign-out timestamps
  • Pseudonymous visits, coarse device category, and allowlisted website and planner events, only when analytics consent is active
  • Identifier-free aggregate campaign-link redirects
  • Error logs and system data

3. Why and how we use your data

We rely on contractual necessity, legitimate interests, consent, and legal obligations as the applicable legal bases for processing.

  • Manage accounts and authenticate users
  • Provide project, plant, and map features
  • Process subscriptions and billing
  • Maintain security, detect fraud, and resolve errors
  • Analyse consented browser measurements and protected aggregate service data
  • Improve features, performance, and user experience
  • Provide service updates and support
  • Meet tax, regulatory, and other legal requirements

4. Third-party services

Stripe

Stripe processes payments and may receive your name, email address, and billing address. We do not store your credit card details on our servers.

Read Stripe's privacy policy

Google Maps

Map coordinates and location data are processed through the Google Maps API. Google may process geolocation data under its own privacy policy.

Read Google's privacy policy

Google Analytics 4

During a temporary migration period and only after analytics consent, Google Analytics 4 may receive the same sanitized website and product-usage measurements. Google Ireland Limited and, where applicable, Google LLC provide this service.

Read how Google safeguards Analytics data

Data is stored on secured servers in Europe. Transfers outside the EU take place only with appropriate GDPR safeguards, such as Standard Contractual Clauses.

5. Cookies and analytics

Essential cookies

We use essential cookies for authentication, security, and saving preferences that you explicitly request. This includes the common_name_language cookie, which stores only en, nl, or fr for up to one year so public plant pages can show common names in your chosen language. It contains no account or visitor identifier. When you are signed in, the account preference is authoritative. These cookies are required to provide the requested service and preferences.

Aggregate service database insights

Separately from browser analytics, we may calculate protected cohort-level insights from project, planting-plan and recipe records already processed to provide the service. This does not measure page visits, read browser identifiers or depend on the cookie-banner choice. Its intended legal basis is our legitimate interest in understanding and improving the service. User-derived categories are allowlisted and shown only for cohorts of at least five distinct account owners; direct identifiers, project names, coordinates and free text are excluded. Hardened aggregate snapshots are retained for up to 24 months. Pre-hardening snapshots that fail these rules remain quarantined from viewing and export until an authorised operator reviews and deletes them.

First-party analytics

Purpose and legal basis. With your consent, AgroForest Designer measures pseudonymous visits, fixed product actions, planner use, engagement, conversions, and campaign effectiveness on its own application infrastructure. Collection does not start before consent. Global Privacy Control and Do Not Track are treated as a refusal. Management traffic, recognised bots, and non-production environments are excluded where the service can identify them reliably.

Data categories and minimisation. After consent, the service can set random HttpOnly visitor and session identifiers. Analytics events contain a sanitized server route label, a fixed event name, time, language, coarse device category, and only explicitly allowlisted values such as a planner tool group or count bucket. A landing event may include a valid opaque campaign UUID. The analytics event store deliberately rejects raw URLs and query strings, referrers, share tokens, names, contact details, user-authored text, plan or project identifiers, exact coordinates, IP addresses, and complete browser strings. It does not use a direct account ID in event rows.

Campaign attribution. A campaign redirect may record an aggregate click without setting or reading a visitor identifier. Campaign links and UTM labels are cohort-level and must never encode a recipient name, email address, account/customer identifier, or hash. If analytics consent is active, the landing visit and later conversion can be associated with the campaign using first-touch and last-non-direct attribution for up to 30 days. Campaign reports use aggregated counts; small groups are suppressed to reduce identification risk.

What the reports mean. Visitor, session, funnel, retention, and behaviour reports describe the consenting tracked population, not every person who visits or uses AgroForest Designer. Historical visitor analytics starts when this system is deployed; we do not invent a visitor-history backfill.

Retention. Raw analytics events and pseudonymous sessions are retained for up to 90 days. A non-revoked pseudonymous collection-control record is retained for up to 180 days after its last analytics use so every still-valid identifier remains recognisable to the withdrawal endpoint. After withdrawal, its revocation marker remains for no more than 24 hours and the control record is then deleted. Unknown browser identifiers do not create control records. Campaign attribution remains eligible for 30 days; its pseudonymous touch reference may be retained for up to 38 days only so accepted late events can be included in the daily aggregate rebuild, and it is not used to extend attribution eligibility. Daily aggregated measurements are retained for up to 24 months. The analytics identifier and consent preference expire after no more than 180 days and are not extended on every visit.

Your choice. The versioned choice is stored in this browser's local storage for up to 180 days. When allowed, the secure host-only __Host-afd_analytics_consent cookie contains only v2-granted; it is not an account or visitor identifier. The application checks this preference before tracked actions are submitted so it can avoid queuing optional analytics unless the browser has already recorded explicit consent. If server cleanup must be retried, the non-identifying secure host-only cookie __Host-afd_analytics_revoke_pending contains only 1 for at most 24 hours. You can refuse or withdraw analytics at any time through . Withdrawal stops future collection, clears pending browser events, removes known GA cookies, and asks the server to delete its HttpOnly analytics identifiers.

Temporary Google Analytics dual measurement

During migration and only after consent, the same sanitized events may also be sent to Google Analytics 4 (GA4), provided by Google Ireland Limited and, where applicable, Google LLC. The request necessarily presents an IP address to Google; Google states that GA4 discards individual IP addresses before logging them. Google may process measurement data outside the EEA and describes using applicable adequacy decisions, the EU–US Data Privacy Framework, and Standard Contractual Clauses where required. Read Google's Analytics privacy information.

We do not use marketing cookies without explicit consent.

6. Retention and security

Retention periods by data type
Data type Purpose Retention Legal basis
Name and emailAccount and contactWhile the account is activeContract
Payment informationBilling7 yearsLegal obligation
IP address and logsSecurity90 daysLegitimate interest
Raw analytics events and sessionsProduct improvement90 daysConsent
Campaign attributionCampaign effectiveness30-day eligibility; touch reference up to 38 days for late-arrival aggregate rebuildsConsent
Daily analytics aggregatesTrend analysis24 monthsConsent; retained after raw-data expiry
Aggregate service database insightsService and catalogue improvement24 monthsLegitimate interest
Project dataService deliveryWhile your account exists; subscription cancellation does not delete itContract

Subscription cancellation does not automatically delete project data. Work above the active plan limits remains saved in a frozen, read-only state. We retain project content while your account remains open and remove it when you delete it or after we complete a valid erasure request, subject to limited backup retention and any legal or security obligation that requires us to keep specific records.

Database archives used for disaster recovery are encrypted and authenticated. The configured database-backup retention period is 30 days, and automatic rotation is scheduled to remove archives older than that period. Data erased from the live service may therefore remain in a protected backup until the relevant archive rotates out.

Users of Pro and Max can export project data before deletion. Anonymised, aggregated data may be retained for longer for research, statistical, and improvement purposes and cannot be traced back to you.

We use safeguards including TLS encryption, secure password hashing, limited staff access, security audits, and incident-response procedures. No internet-based service can guarantee absolute security.

7. Your GDPR rights

Depending on the circumstances, you may have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Erase your data
  • Restrict processing
  • Receive portable data
  • Object to processing
  • Withdraw consent at any time

Email your request to contact@agroforestdesigner.com. We aim to respond within 30 days.

8. Children and policy changes

AgroForest Designer is not intended for people under 18. We do not knowingly collect personal data from children and will remove an account if we learn that a minor registered.

We may update this policy. We will communicate significant changes by email or through a notice in the service.

9. Contact and complaints

Questions or requests about this policy can be sent to:

AgroForest Designer
Antwerp, Belgium
contact@agroforestdesigner.com

You can also lodge a complaint with your local data protection authority. In Belgium, this is the Data Protection Authority .

Privacy policy Version 1.2 · August 2026