HummingTribe (hummingtribe.com)
Effective date: March 11, 2026 | Last updated: March 11, 2026
This Privacy Policy explains how HummingTribe (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you visit our website (hummingtribe.com) or use our services.
We are committed to protecting your privacy and processing your personal data in accordance with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and applicable Romanian data protection law.
The data controller for the purposes of the GDPR is:
HummingTribe
Email: hello@hummingtribe.com
When you create an account, we collect:
When you make a purchase, Stripe (our payment processor) collects:
We do not store your full payment card details. Stripe processes and stores this data under their own privacy policy. We receive from Stripe: your Stripe customer ID, subscription status, and the last four digits of your card.
In the course of providing our services, we process:
Data you store using our services (files in S3 buckets, website files on hosting, data on VPS/dedicated servers) is stored and processed solely for the purpose of providing the service. We do not access, read, or analyze your content except as necessary for technical support at your explicit request, or as required by law.
When you contact us via email, we collect:
We use Plausible Analytics, a privacy-focused analytics tool that:
We collect aggregate, anonymous data such as page views, referral sources, and browser types. This data cannot be used to identify individual visitors.
Our servers automatically record:
Log data is retained for security, troubleshooting, and abuse prevention purposes.
We process your personal data on the following legal bases under Article 6 of the GDPR:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of a contract (Art. 6(1)(b)) |
| Billing and payment processing | Performance of a contract (Art. 6(1)(b)) |
| Service provisioning and delivery | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails (order confirmations, service notifications, password resets) | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Server logs and troubleshooting | Legitimate interest (Art. 6(1)(f)) |
| Responding to support inquiries | Performance of a contract / Legitimate interest |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not process personal data for marketing purposes without your explicit consent. We do not send newsletters or promotional emails unless you explicitly opt in.
We use your personal data to:
We share personal data with the following third-party service providers (sub-processors) as necessary to deliver our services:
| Sub-processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Email, billing details, payment card data | EU (primary processing), US (corporate) |
| Brevo (Sendinblue) | Transactional email delivery | Email address, email content | EU |
| Hetzner Online GmbH | Infrastructure hosting (servers, storage) | Server metadata, IP addresses | Germany |
| Plausible Analytics | Website analytics | Anonymous aggregate data only | EU |
We do not sell, rent, or trade your personal data to third parties. We do not share your data with advertisers.
We may disclose personal data if required by law, court order, or governmental authority. We will notify you of such requests where legally permitted.
7.1. All customer data and service data is stored exclusively on infrastructure located in Germany (Hetzner data centers in Falkenstein and Nuremberg).
7.2. Our billing processor (Stripe) may process billing data in the United States. Stripe is certified under the EU-US Data Privacy Framework and maintains Standard Contractual Clauses for international data transfers.
7.3. Our email delivery provider (Brevo) processes transactional emails within the EU.
We retain your personal data only for as long as necessary for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account data (email, password hash) | Duration of account + 30 days after account deletion |
| Billing records | 10 years (Romanian fiscal law requirements) |
| Service data (server configs, access keys) | Deleted upon service cancellation and expiry of billing period |
| Content data (files, databases) | Deleted upon service cancellation and expiry of billing period |
| Support emails | 2 years after last communication |
| Server logs | 90 days |
| Website analytics | Aggregate data only, retained indefinitely (non-personal) |
9.1. We implement appropriate technical and organizational measures to protect your personal data, including:
9.2. While we take reasonable steps to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Under the GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you.
You have the right to request correction of inaccurate personal data.
You have the right to request deletion of your personal data, subject to legal retention requirements.
You have the right to request that we restrict processing of your personal data under certain circumstances.
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing based on legitimate interests.
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, România
Website: dataprotection.ro
Email: anspdcp@dataprotection.ro
To exercise any of these rights, contact us at hello@hummingtribe.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
11.1. We use only essential cookies necessary for the functioning of our services:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| session_id | User authentication (HttpOnly, Secure) | 7 days | Essential / Functional |
11.2. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
11.3. Plausible Analytics does not use cookies.
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it.
13.1. We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 30 days before the changes take effect.
13.2. The date of the last update is indicated at the top of this policy.
13.3. Your continued use of our services after the effective date constitutes acceptance of the updated policy.
HummingTribe
Email: hello@hummingtribe.com
Website: hummingtribe.com
This Privacy Policy was last updated on March 11, 2026.
Last updated: March 11, 2026