Skip to content
lexratesAccount

Privacy

What I store about you, and where it is.

There is very little of it, and that is deliberate rather than a promise: the design keeps personal data out of the parts of this service that do the work.

Who is responsible

Growing Peas — Lawrenza SRL, rue de Soignies 140, 7800 Ath, Belgium. RPM Tournai. Company and VAT number BE 0747.683.918. Write to info@growingpeas.dev.

What is stored, and why

  • Your e-mail address and sign-in record, held by Firebase Authentication, so you can sign in and recover your access. If you sign in with Google, that is the address Google gives and nothing else from your profile.
  • Your account row: an internal identifier, your Stripe customer reference, and the API key you bought. No address, no name and no password are stored here — only the link between the three.
  • Billing details, held by Stripe. I never see or store a card number.
  • Usage counts per API key, so the spend ceiling can stop a runaway client. They are counts, not a record of what you looked up.

The legal basis is the performance of the contract for everything needed to give you an account and a key, and a legitimate interest in keeping the service from being abused for the usage counts.

Where it lives

The account rows and the usage counts are in Cloud Firestore in europe-west4 (Netherlands), and the service that reads them runs in the same region. Firebase Authentication and Stripe are processors with their own infrastructure; transfers outside the European Union may happen through them under the standard contractual clauses they publish.

Who else sees it

Google (Firebase Authentication, Firestore, Cloud Run) and Stripe. Nobody else, and nothing here is sold, shared for advertising, or used to profile you. There is no analytics script on this site and no third-party host is contacted by these pages.

How long

Your account and its key for as long as you have an account. Delete it and they go with it. Invoices are kept for as long as Belgian accounting law requires, which is seven years, and that is Stripe’s copy rather than mine.

What you can do

Ask for a copy of what is held, have it corrected, have it deleted, or object to it. Write to info@growingpeas.dev and you will get an answer from a person, because there is only one. If that answer is unsatisfactory you can complain to the Belgian Data Protection Authority, autoriteprotectiondonnees.be.

The open tier

Everything published without a key is static files. No account, no cookie, no counter, and nothing that identifies who fetched them. That is not a policy choice that could be reversed quietly — it is what those files are.