Legal

Privacy Policy

Last updated: August 2, 2026

This policy explains what data SPACEBAR processes, what we deliberately never do, and the controls you — and your site's visitors — have. It covers the SPACEBAR application and this website. SPACEBAR is operated by BOOTHIC SMPC, a single-member private company incorporated in Greece, VAT No. EL801264656 (“we”, “us”).

Our two roles

For most of what SPACEBAR holds about you — your account, your sites, your billing status and the messages you send us — we decide how and why it is processed. Under the GDPR we are the controller for that data, and this policy describes what we do with it.

Your published site is different. When a visitor fills in a contact or newsletter form on a site built with SPACEBAR, that submission is addressed to the site's owner: the owner decides why it is collected and what happens to it, so the owner is the controller and we are their processor — we store the submission and deliver it on the owner's instructions. If you submitted a form on a site made with SPACEBAR and want to exercise rights over that data, the quickest route is the business that runs the site — and we help them respond.

What we process

  • Account data — your name and email address, with sign-in handled through Clerk.
  • Profiles you submit — when you paste an Instagram, Facebook Page or Google Business Profile link, we scrape that public profile through Apify on your instruction: business details, bio, services, opening hours, reviews and photos. Photos are re-hosted on our infrastructure so your site never depends on expiring links.
  • Your site content— the pages you build and edit, the copy and design the AI generates from your profile content, and the images in your site's media library.
  • Form submissions— the name, contact details and message a visitor sends through a form on a published site, processed for the site's owner as described above.
  • Usage and log data — IP address, browser and device information, timestamps and security logs.
  • Billing data — which of your sites are paid and their subscription status. Payments are handled by Polar as merchant of record; we never see full card numbers.
  • Messages you send us — by email or through this website.

What we never do

We do not sell personal data. Your content and your visitors' data are never used to train AI models — ours or anyone else's. SPACEBAR adds no cookies, trackers, analytics scripts or ad pixels to published sites (third-party content a site owner embeds — maps, videos, booking widgets — may set its own; see Cookies below). And the review data shown on a generated site is the business's own public Google data — we never invent it.

Why we process it

Where we are the controller, we rely on: performance of a contract (Art. 6(1)(b) GDPR) to run your account, generate and host your sites and handle billing; legitimate interests (Art. 6(1)(f)) to secure the service, prevent abuse and improve SPACEBAR; legal obligations (Art. 6(1)(c)) for tax and accounting records; and consent (Art. 6(1)(a)) where the law requires it — which you can withdraw at any time. Profile scraping only ever runs on your instruction: we fetch a profile when you submit it, and again only when you ask us to re-sync. As the site owner's processor, we process visitor submissions on the owner's documented instructions.

Subprocessors and recipients

We share personal data only with the providers needed to run SPACEBAR. Each is bound by a data processing agreement and processes data only to provide its service to us:

  • Clerk (US) — authentication and sign-in.
  • Convex (US) — database and backend infrastructure storing your sites and submissions.
  • Cloudflare (US/EU) — edge hosting, image storage (R2) and Turnstile spam protection on forms.
  • Apify — scraping of the public business profiles you submit.
  • Google / OpenAI(US) — AI models generating your site's copy and design from your profile content.
  • Resend (US) — form-notification and transactional email.

One recipient acts for itself rather than for us: Polar, our merchant of record, is the seller at checkout and an independent controller of payment data under its own privacy policy.

We update this list on this page and give you at least 30 days' notice before adding a new subprocessor. We may also disclose data where the law requires it; and if we are ever part of a merger or acquisition, this policy continues to protect the data that transfers.

International transfers

Our subprocessors are mainly in the United States. When personal data leaves the EEA, we rely on the safeguards the GDPR provides for: the EU–US Data Privacy Framework where the provider is certified, and the European Commission's Standard Contractual Clauses otherwise, alongside measures such as encryption in transit and at rest.

Retention

Deleting a site deletes its content and form submissions and schedules deletion of its hosted images. Deleting your account cascades the same across all your sites, and active subscriptions are cancelled; image cleanup runs asynchronously, so a stray copy (for example an image you replaced mid-edit) may persist briefly until routine cleanup. Account data is otherwise kept while your account is active, and billing records are kept as long as tax and accounting law requires. Contact and support messages are kept as long as needed to help you.

Search engines and AI crawlers

Every site comes with its own crawler controls. As a site owner you can hide a site from search engines entirely, and separately block AI crawlers (GPTBot, ClaudeBot, PerplexityBot and similar) from reading it — each with a per-site toggle in your site's settings.

Security

Data is encrypted in transit and at rest. Sign-in is secured through Clerk, incoming webhooks are signature-verified, custom-code blocks run in a sandboxed frame isolated from the rest of the page, and public form endpoints are verified server-side against spam and abuse. No system is perfectly secure — if a breach ever puts your rights at risk, we will notify you and the supervisory authority as the GDPR requires.

Cookies

The SPACEBAR app and this website set only the strictly necessary cookies needed to keep you signed in. SPACEBAR adds no cookies of any kind to published sites — no analytics, no advertising, no cross-site tracking. If a site owner embeds third-party content (an interactive map, a video background, a booking widget, or custom code), that provider may set its own cookies — the owner chooses whether such content appears and is responsible for any notice it requires.

Your rights

You can ask for access to your personal data, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent at any time. Write to support@withspacebar.com; we may need to verify your identity, and we respond within one month. If the data lives on a customer's published site — for example a form you submitted there — we may refer you to the site's owner, since they control that data, and we will help them respond. You can also lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local EU supervisory authority. If you are in California or another jurisdiction with its own privacy law, we honor those rights too — and we do not “sell” or “share” personal information as the CCPA defines those terms.

Children

SPACEBAR is a tool for businesses. It is not directed to anyone under 18, and we do not knowingly process children's data.

Changes

If we make material changes to this policy, we will notify you — by email or in the app — before they take effect.

Contact

BOOTHIC SMPC — single-member private company incorporated in Greece
29 Tavoulari Str., Greece · GEMI No. 153029403000 · VAT No. EL801264656
Operating SPACEBAR · support@withspacebar.com