Privacy policy
Last updated: 21/07/2026
This policy explains what personal data we collect when you use Forest Maker, why we process it and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).
This is a translation for convenience. In case of discrepancy, the Italian version prevails.
1. Who processes your data
The data controller is:
HawkService — Sole Proprietorship
Via del Sarago, 1 — 97016 Pozzallo (RG), Italy
VAT no. IT01734340886
Email: privacy@forestmaker.app
We have not appointed a Data Protection Officer: the cases set out in Article 37 GDPR do not apply.
2. What we collect
| Data | When | Why |
|---|---|---|
| Email address | Sign-up | To identify you, let you sign in and recover your password |
| Password | Sign-up | Stored only as a bcrypt hash: we cannot read it |
| Your projects (field outlines, zones, trees, parameters) | When you save a project | So you find them again on your devices |
| IP address | On every request | Security: limiting abuse and automated attempts. Held in memory only, never written to disk or linked to your account |
| Usage events (date and type: calculation, export) | When you use the features | Aggregate statistics on how the service performs |
| Sign-up date and last sign-in | Automatic | Account management and spotting inactive accounts |
| Billing and payment data | If you subscribe to Premium | Handled by Stripe. We never see or store your card number |
We use no web analytics and no advertising or profiling tools, and we do not buy data from third parties.
3. Purposes and legal bases
- Providing the service (account, saving projects, calculation, exports) — performance of a contract, Art. 6(1)(b) GDPR.
- Service emails (address confirmation, password recovery, subscription notices) — performance of a contract, Art. 6(1)(b).
- Security (abuse limiting, technical logs) — our legitimate interest in keeping the service available and protected, Art. 6(1)(f).
- Tax and accounting obligations — legal obligation, Art. 6(1)(c).
Providing the data listed above is necessary to use the service: without it an account cannot be created.
4. Who we share data with
We do not sell your data and never share it for marketing purposes. We rely on the following providers, acting as processors under Art. 28 GDPR or as independent controllers where indicated:
| Provider | Role | Where |
|---|---|---|
| Railway Corp. | Application and database hosting | Servers in the European Union (Amsterdam) |
| Stripe, Inc. | Subscription payments and invoicing (independent controller for anti-money-laundering duties) | EU / USA, under standard contractual clauses |
| Resend | Sending service emails | EU / USA, under standard contractual clauses |
| Cloudflare, Inc. | DNS, protection and site delivery | Global network, under standard contractual clauses |
| Esri / Amazon Web Services | Satellite imagery and elevation data | Your browser requests map tiles directly from their servers, which therefore receive your IP address |
Cadastral data shown in the application comes from the public services of the Italian Revenue Agency: it is public data and contains no information about you.
We may also disclose data to judicial or other competent authorities where required by law.
5. Transfers outside the European Union
The application and databases are hosted on servers in the European Union. Some providers listed above are based in the United States; in that case transfers rely on the standard contractual clauses approved by the European Commission or other appropriate safeguards under Chapter V GDPR.
6. How long we keep data
- Account and projects: for as long as the account exists. If you request deletion, we remove them within 3 working days.
- Backups: data may persist in backups for up to 6 days, after which it is automatically overwritten.
- IP addresses: not retained. They are processed in memory only, for the few minutes needed to apply anti-abuse limits, and are never written to disk or linked to your account.
- Usage events: 24 months, then deleted automatically. We record only when and which feature was used (a calculation, an export), never the content of your projects. They help us understand how the service is used and improve it; the 24-month window lets us compare one growing season with the previous one, which a shorter period would not allow.
- Tax records: 10 years, as required by Italian tax law.
7. Your rights
At any time you may ask to:
- access your data and receive a copy (Art. 15);
- correct inaccurate or incomplete data (Art. 16);
- erase your data (Art. 17);
- restrict processing (Art. 18);
- receive your data in a machine-readable format and transfer it to another controller (Art. 20);
- object to processing based on legitimate interest (Art. 21).
How to exercise them. Write to privacy@forestmaker.app. We reply within one month.
Account deletion. You can request it directly in the app, under “Settings”. We handle the request and complete it within 3 working days. Your projects are deleted along with the account and cannot be recovered.
If you believe the processing infringes the GDPR you may lodge a complaint with the Italian Data Protection Authority or with the supervisory authority of the country where you live.
8. Cookies and browser storage
We use no profiling, advertising or analytics cookies. That is why you see no consent banner: the law requires one only for non-essential tools, which we do not use.
The app stores a few items in your browser’s local storage (localStorage and sessionStorage), strictly necessary for it to work. They stay on your device and are never sent to us:
| Name | Purpose |
|---|---|
fm_token | Keeping you signed in between visits |
forest-maker | Your work-in-progress drawing, so a page reload does not lose it |
fm-lingua | The language you selected |
fm-welcome-v1, fm-taa-visto, fm-verifica-rimandata | Remembering which notices you already dismissed |
fm-sheet-h | The panel height you set on mobile |
You can clear them at any time from your browser settings; you will then need to sign in again.
9. Security
Passwords are stored as bcrypt hashes, traffic is encrypted over HTTPS, database access is restricted to the infrastructure’s private network and we apply measures against automated access. No system is absolutely secure, however: please use a strong password that you do not reuse elsewhere.
10. Children
The service is aimed at professionals and landowners and is not intended for children under 16. We do not knowingly collect children’s data; if we become aware of it, we delete the account.
11. Changes
If we change this policy we will update the date at the top of the page and, for significant changes, notify you by email or with a notice in the app.