Privacy Policy
Effective date: [EFFECTIVE DATE] · Last updated: [LAST UPDATED DATE]
Draft — pending legal review
This document is a working draft published for reference only. It is not yet legal advice and is subject to change before it takes effect. Placeholders shown in [BRACKETS] will be completed on publication.
This Privacy Policy explains how Machinery Twin (“we”, “us”) collects, uses, shares, and protects personal data when you use our website, web application, and Windows PLC Connector (collectively, the “Service”). It should be read together with our Terms of Service and Cookie Policy.
Who is responsible for your data
The data controller is:
Via delle Officine 1, 40069 Zola Predosa (BO), Italy
VAT / Partita IVA: IT04013141207
Privacy contact: privacy@machinerytwin.com
Our approach: local-first by design
The Service is built to keep your data on your own device wherever possible. Your Projects (3D models, kinematic configurations, motion cams, state machines, and variable mappings) are created and stored locally in your browser or on your computer. Live data exchanged with your PLCs and industrial equipment is processed only on your machine by the local backend and is never transmitted to us. We collect personal data only where we genuinely need it to run accounts, take payment, provide support, and keep the Service secure and reliable.
What data we process and why
Account and authentication
When you create an account, our authentication provider (Clerk) processes your email address, name if provided, and login/security metadata (e.g., sign-in timestamps, device and IP information for security). We use this to create and secure your account and to determine which subscription features you can access.
Guest mode
You can use the Free tier in guest mode without an account. In guest mode, your Projects stay in your browser's local storage only; we hold no copy and cannot recover them.
Billing and subscriptions
Paid subscriptions are sold and processed by Paddle, acting as merchant of record. Paddle collects and processes your billing details (name, billing address, VAT ID where applicable, and payment method). We do not receive or store your full card details; we receive limited transaction and subscription-status data needed to grant entitlements, issue receipts, and handle refunds and support.
Support and communications
When you contact us (e.g., support, bug reports, feature requests), we process your email address and the contents of your message to respond and to improve the Service. If you join the paid-tier waitlist, we process your email address and opt-in to notify you when paid tiers are available; you can unsubscribe from that notification at any time. Transactional and waitlist emails are sent via our email provider (Resend).
Diagnostics and error reporting
To keep the Service reliable, we use error-reporting tooling (Sentry) that may collect technical diagnostics when something goes wrong — such as error messages, stack traces, app version, and coarse device/environment data. We configure it to avoid collecting your Project content. This helps us find and fix crashes and bugs.
Analytics
We use Vercel Web Analytics for aggregated page views and limited conversion events, only after you opt in through the cookie banner. We do not send email addresses, contact-form content, Project data, or account identifiers in those events. See our Cookie Policy for details and controls.
Legal bases (GDPR)
We process personal data on the following bases:
- Performance of a contract (Art. 6(1)(b) GDPR) — to create your account, provide the Service and paid features, and support you.
- Legitimate interests (Art. 6(1)(f) GDPR) — to secure the Service, prevent abuse and fraud, keep the software reliable through error diagnostics, and communicate about the Service. We balance these against your rights.
- Consent (Art. 6(1)(a) GDPR) — for opt-in analytics and any non-essential communications. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR) — e.g., tax and accounting records related to payments (largely handled by Paddle).
Service providers we share data with
We share personal data only with providers who process it on our behalf under data processing agreements, or who act as independent controllers where required (e.g., Paddle as merchant of record). We do not sell your personal data.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Clerk | Authentication and account management | Email, name, login/security metadata | USA (SCCs) |
| Paddle (Merchant of Record) | Payments, invoicing, subscription management | Billing details, transaction and subscription data | UK / EU / USA (SCCs) |
| Vercel | Website and web-app hosting | Request/log metadata (e.g., IP, user agent) | USA / EU |
| Sentry | Error reporting and diagnostics | Error/diagnostic data, app version, coarse device info | USA / EU (SCCs) |
| Vercel Web Analytics | Aggregated page views and opt-in conversion measurement | Page path, referrer, coarse device/geographic data, and a limited event name with safe properties | USA / EU |
| Resend | Transactional email and paid-tier waitlist | Email address, message metadata, waitlist opt-in | USA (SCCs) |
International transfers
Some providers are located outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, adequacy decisions, together with supplementary measures as needed.
How long we keep data
We keep personal data only as long as necessary for the purposes above:
- Account data — for the life of your account, then deleted or anonymized.
- Billing records — retained by Paddle and by us as required by tax and accounting law (typically up to 10 years under Italian law).
- Support messages — for as long as needed to handle your request and our records.
- Diagnostics/error logs — short, rolling retention windows.
Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time (without affecting prior processing). To exercise these rights, email privacy@machinerytwin.com. You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority in your country of residence.
Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and least-privilege handling of secrets. No method of transmission or storage is completely secure; we work to protect your data but cannot guarantee absolute security.
Children
The Service is intended for professional and business use and is not directed to individuals under 18. We do not knowingly collect personal data from children.
Changes to this policy
We may update this Privacy Policy from time to time. For material changes we will provide reasonable notice by email or in-product notice. The “Last updated” date above reflects the latest revision.
Contact
Questions about this policy or your data? Email privacy@machinerytwin.com or our general contact at support@machinerytwin.com.