Legal
Privacy Policy
Last updated: 9 June 2026
This page explains, in plain English, what personal data Be-Freelance collects, why we collect it, who we share it with, and the rights you have over it. We follow the General Data Protection Regulation (GDPR) and equivalent UK rules.
1. Who we are
Be-Freelance is operated by Stan Stoyanov ("we", "us"). We provide 1:1 coaching sessions, the Deal Room membership, and related content for freelancers and consultants. For any privacy question, write to stanpstoyanov@gmail.com.
2. What we collect and why
- Account & contact data — name, email, password hash (we never see your password), and any details you share via the contact form. Used to deliver our services, reply to you, and operate your account.
- Booking data — session type, date/time, topic you'd like to discuss, and any pre-call notes. Used to schedule and run the session.
- Payment data — billing name, address, tax ID, card last-4, and transaction history. Handled by Stripe; we never see or store full card numbers.
- Subscription data — Deal Room plan, status, billing period, retention activity. Used to grant access and bill you.
- Communication data — emails we send you (confirmations, reminders, replies), and your replies. Used to support you.
- Marketing opt-in — recorded only if you tick the marketing box. You can opt out at any time.
- Technical data — IP address, browser, device, and basic page-view information needed to keep the site running and secure.
3. Legal bases
We rely on the following GDPR legal bases:
- Contract — to deliver sessions, the Deal Room, and related services you've purchased.
- Legitimate interests — to operate, secure, and improve the site, prevent abuse, and handle support.
- Consent — for optional marketing emails and any non-essential cookies (you can withdraw at any time).
- Legal obligation — to keep invoices and tax records for the period required by law.
4. Who processes data on our behalf (sub-processors)
We use trusted providers, each acting as a data processor under contract:
- Supabase — database, authentication, and file storage for the platform.
- Stripe — payment processing and billing. Stripe is the controller of cardholder data; see their privacy policy.
- Google (Calendar, Meet, Gmail) — to schedule sessions, send calendar invites, and host video calls.
- Mailgun (via Lovable Emails) — to deliver transactional emails such as confirmations and reminders.
- Cloudflare — to serve and protect the website.
Some of these providers may process data outside the EU/EEA. When they do, transfers rely on Standard Contractual Clauses or equivalent safeguards.
5. How long we keep data
- Account data — for as long as your account exists, plus up to 6 months after deletion for backup rotation.
- Booking and session records — up to 3 years after the session, for reference and dispute handling.
- Invoices and tax records — for the period required by applicable law (typically 7–10 years).
- Marketing list — until you unsubscribe, after which we keep a minimal suppression record so we don't email you again.
- Contact-form messages — up to 24 months after the last reply.
6. Cookies and similar technologies
We use a small number of cookies and equivalent local-storage entries. The strictly necessary ones keep you signed in, remember your cookie choice, and protect against abuse — these run without consent because the site cannot function without them. Any non-essential analytics or marketing cookies are loaded only after you accept them in the cookie banner. You can change your choice at any time by clearing your browser storage for this site.
7. Your rights
Under GDPR you have the right to:
- Access the data we hold about you
- Have inaccurate data corrected
- Have your data deleted (subject to legal retention rules)
- Restrict or object to certain processing
- Receive a copy of your data in a portable format
- Withdraw consent for marketing or non-essential cookies at any time
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email stanpstoyanov@gmail.com from the address linked to your account. We respond within 30 days.
8. Security
We use industry-standard practices: encrypted connections (HTTPS), encrypted storage at rest, role-based access, and least-privilege keys. No system is perfectly secure — if you suspect a problem, contact us immediately.
9. Children
Be-Freelance is intended for professionals and is not directed at anyone under 18. We do not knowingly collect data from minors.
10. Changes to this notice
If we make material changes we'll update the "last updated" date above and, where appropriate, notify you by email. Continued use of the service after a change means you accept the updated notice.
See also our Terms & Conditions.
