Privacy policy
The brand “Dozen” and https://getdozen.dev are operated by Kasalo Digital (paušalni obrt), Tvrtkova 1, Knin, Croatia, Republic of Croatia, OIB 05372595966. Contact: hello@getdozen.dev.
This notice is given under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and the Croatian Act Implementing the GDPR. We do not appoint a data-protection officer. We do not sell personal data. We do not run advertising or analytics cookies.
What we process
- Waitlist: email, confirmation time, and when you asked to join.
- Account: email, display name, avatar if you add one, login identifiers from email or Google.
- Use of the product: posts, reviews, tester check-ins, the Google account email you give for a closed test, messages you send other users, and credit-ledger rows needed to run the marketplace.
- Payments: we receive Stripe customer and session identifiers, payment status, and pack/subscription/boost metadata. We do not store full card numbers.
- Transactional email: your email when we send board boost offers or other service messages you can opt out of where the law allows.
- Security: IP address and basic request metadata processed by our host for abuse prevention and delivery.
- Bug reports: what you type in the report form, the page you were on, and an email if you add one. We store these in our database and email them to the operator so we can fix the product.
- Operator administration: authorised staff access user, waitlist, payment, and bug-report records through a protected admin console for support, moderation, and billing.
Why, and on what legal basis
- Waitlist and launch email: your consent (Art. 6(1)(a)). You can withdraw it by writing to hello@getdozen.dev. Withdrawal does not affect processing already done.
- Account, board, reviews, tester slots, dots, checkout : performance of a contract (Art. 6(1)(b)).
- Invoices, tax, and dispute records: legal obligation (Art. 6(1)(c)), including Croatian bookkeeping rules.
- Fraud, abuse, and keeping the service up: legitimate interests (Art. 6(1)(f)). You may object; we stop unless we have compelling grounds or need the data for a legal claim.
Who we use (processors)
- Supabase: database, authentication, and confirmation emails.
- Stripe: checkout, cards, and subscriptions. Stripe is an independent controller for much of the payment data it collects. See Stripe's privacy notice.
- Vercel: hosting and delivery of this website.
- Resend: transactional email (bug-report alerts, board-boost offers, and similar service mail when configured).
- FormSubmit: alternative path for delivering bug-report emails to the operator when Resend is not configured.
- Google: only if you choose “Continue with Google”, or when you sign in to a poster's Google Play test track as part of a tester program.
- Cloudflare: DNS for getdozen.dev, and Turnstile bot checks on sign-in, signup, password reset, waitlist, and bug report forms. Turnstile is used only to tell humans from automated clients (legitimate interests, Art. 6(1)(f)).
Some of these providers may process data outside the EEA. Where that happens we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, plus the provider's extra safeguards.
How long we keep data
- Waitlist: until you withdraw consent, or until 24 months after launch if you never open an account.
- Account and product data: while the account is open.
- After deletion we keep only what Croatian or EU law still requires (typically payment and accounting records, up to 11 years).
- Auth cookies last for the session length set by Supabase.
Your rights
You may request access, rectification, erasure, restriction, portability, and, where we rely on legitimate interests or consent, objection or withdrawal. Ask at hello@getdozen.dev. We reply without undue delay and within one month (extendable as the GDPR allows).
You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb; azop@azop.hr; https://azop.hr; or the form at azop.hr/zahtjev-za-utvrdivanje-povrede-prava. You may also complain to the authority in your EU country of residence.
Children
Dozen is for people 16or older (Croatia's GDPR age of digital consent). We do not knowingly take waitlist or account data from children under 16.
Automated decisions
We do not make decisions that produce legal or similarly significant effects solely by automated means (GDPR Art. 22).
Cookies
Only cookies needed to run the site and keep you signed in. A short notice explains this on first visit. Details: cookie notice.
Terms of use · Payment terms · Privacy policy · Cookie notice
Last updated 29 August 2026