Privacy Policy
Last updated: March 7, 2026
At MelonTag, we deeply value the privacy of our users and the organizations that trust us. This Privacy Policy comprehensively describes how we collect, use, process, and protect your personal data in full compliance with the General Data Protection Regulation (GDPR - EU 2016/679) and the Spanish Organic Law 3/2018 (LOPDGDD).
1. Data Controller Identification
In accordance with Article 10 of Spanish Law 34/2002 (LSSI-CE) and the GDPR, the owner and manager of the MelonTag platform is:
- Data Controller / Owner: Luis Giménez Álvarez (MelonTag)
- Tax ID (N.I.F.): 25164966E
- Registered Office: C/ Intxaurrondo Nogalera 12, 31100, Puente la Reina, Navarra, Spain
- Privacy & Contact Email: hello@melontag.com
- Activity: Development and operation of B2B SaaS software solutions for inventory and asset tracking.
2. Data Roles: Controller vs. Processor (Art. 28 GDPR)
Under applicable data protection laws:
- MelonTag as Data Controller: We process the personal data of registered administrators and account users for contract performance, billing, technical support, platform security, and service communications.
- MelonTag as Data Processor: Regarding inventory information, equipment specs, physical room locations, incident logs, asset photos, and borrower/student details entered into the platform by customer organizations, the client organization acts as the Data Controller and MelonTag acts as the Data Processor under Article 28 GDPR and our Data Processing Addendum (DPA) included in our Terms of Service.
3. Personal Data Collected
We collect and process the following categories of personal data:
- Account & Registration Data: Full name, corporate or institutional email, phone number (optional), job title, organization name, and password (stored using secure, irreversible Bcrypt hash).
- Geolocation & Device Data: One-time GPS coordinates (collected via the public web browser when scanning lost assets, only upon explicit and voluntary user authorization under GDPR Art. 6.1.a to assist in returning the item to its owner), public IP address, approximate geolocation derived from IP address, device type, operating system, and browser User-Agent.
- Push Notification Identifiers: Push notification tokens (Expo Push Token) generated for the user's mobile device to deliver operational system alerts and incident updates.
- Photographs & Attachments: Photographs of physical assets, images of purchase invoices/receipts, and attachments uploaded to inventory sheets and incident logs.
- Borrower & Assignment Data: Full name, email address, and classroom/department of staff or students assigned or borrowing physical assets.
- Technical Data & Public Asset Cards: Asset serial numbers, repair logs, and physical condition descriptions. Minimal inventory data may be publicly accessible via direct scanning of asset QR codes if configured by the institution.
4. Legal Bases for Processing (Art. 6 GDPR)
The processing of your personal data is grounded in the following legal bases:
- Contract Performance (Art. 6.1.b GDPR): Necessary for account creation, platform operation, customer support, and SaaS feature delivery.
- Legitimate Interest (Art. 6.1.f GDPR): Ensuring platform cybersecurity, fraud prevention, access control, technical audits, and application optimization.
- Legal Obligation (Art. 6.1.c GDPR): Accounting management, invoicing, tax compliance, and legal audit requirements.
- Consent (Art. 6.1.a GDPR): Capturing one-time GPS geolocation on the public website when reporting a found lost asset, optional commercial communications, and demo/contact inquiries.
5. Third-Party Service Providers (Sub-processors)
To provide our services efficiently, we share necessary data with trusted third-party providers under strict data protection agreements:
- DigitalOcean LLC: Cloud server infrastructure, encrypted persistent volumes for primary storage of asset photographs/files, and PostgreSQL database hosting located in data centers within the European Union (Germany / Netherlands).
- Stripe Payments Europe, Ltd. / Stripe, Inc.: Secure payment processing and automated subscription management.
- Brevo SAS (Sendinblue): Transactional email infrastructure for account verification, password resets, and automated alerts.
- Expo (650 Industries, Inc.): Mobile push notification delivery infrastructure for Android and iOS.
- Amazon Web Services (AWS, Inc.): Secure cloud storage (AWS S3) for secondary encrypted offsite backups of database dumps and media files.
- Google LLC (Google Fonts): Web typography services for the user interface.
- Product Hunt: Commercial exposure and product feedback platform.
- IP Geolocation Services (freeipapi.com / ipapi.co): Anonymized IP address lookups for security auditing and regional access logging.
6. International Data Transfers
Where any of our sub-processors process data outside the European Economic Area (EEA), we ensure international transfers are covered by an adequate level of data protection under the EU-U.S. Data Privacy Framework (DPF) or standard contractual clauses (SCCs) approved by the European Commission.
7. Security Measures (Art. 32 GDPR)
MelonTag implements robust technical and organizational security measures to protect data confidentiality, integrity, and availability:
- Data encryption in transit via HTTPS / TLS 1.3 with SSL certificates.
- Password hashing using the strong Bcrypt algorithm with individual salt.
- Strict logical multi-tenant isolation via unique
tenant_code. - Role-Based Access Control (RBAC) and expirable JWT session tokens.
- Audit logs tracking access and failed authentication attempts.
- Docker container isolation and regular encrypted database backups.
8. Data Retention Periods
Data is stored strictly for the time required for its processing purpose:
- Account & Contract Data: Retained for the duration of the active subscription + up to 5 years following termination to satisfy legal prescription periods for civil/commercial claims.
- Tax & Accounting Data: Retained for a minimum of 6 years (Spanish Commercial Code) and up to 10 years for tax compliance.
- Audit Logs & IP Connection Records: Retained for 30 to 90 days, after which they are automatically deleted or anonymized.
- Database & Media Backups: Continuous automated rotation with 7-day retention for database dumps and 14-day retention for media files.
- Marketing Leads & Support Inquiries: Retained for 12 months from last contact, unless deletion is requested earlier.
- Inactive Free / Starter Accounts: After 12 months of total inactivity, MelonTag reserves the right to delete or anonymize the account and inventory following a 30-day notice.
9. Your Data Rights
Under the GDPR, you have the following rights regarding your personal data:
- Access: Request copies of your personal data processed by MelonTag.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure ("Right to be forgotten"): Request deletion of your data when no longer needed.
- Restriction: Request restriction of processing under specified statutory conditions.
- Data Portability: Receive your data in a structured, machine-readable format (or export inventory in CSV/JSON).
- Objection: Object to processing based on legitimate interest.
To exercise these rights, email us at hello@melontag.com with proof of identity. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es or your local supervisory authority.
10. Changes to This Policy
MelonTag reserves the right to update this Privacy Policy to reflect legal or service updates. Notice of material changes will be communicated through our web portal or via email.