Privacy Policy

Effective date: 19 July 2026 · Last updated: 19 July 2026

This policy covers the entire Numibo service: the public website at numibo.com and the application at app.numibo.com. The website itself processes very little personal data (a newsletter email address and, with your consent, analytics cookies); accounts, payments and exercise data are processed in the application.

1. Data controller

The data controller is Amar Hidić s.p., a sole trader registered in Slovenia, Maroltova ulica 10, Ljubljana 1000, Slovenia, registration number 7501226000, VAT ID 42804213 ("Numibo", "we", "us"). For any privacy-related questions, contact us at info@numibo.com.

2. Data we collect

  • Account data: first and last name, email address, password (stored only in hashed form) and preferred language.
  • Google sign-in: if you sign in with Google, we receive your name, email address and Google account identifier from Google.
  • Payment data: payments are processed by Stripe. We never store card numbers ourselves; we store your Stripe customer identifier, the payment method type and last four digits, your subscription status and invoices (including the billing details on them).
  • Usage data: the worksheets (exercises) you generate and your solving attempts (correct/incorrect counts, duration, submitted answers).
  • Newsletter: if you subscribe on the website, we process your email address in order to send the newsletter. Subscribing is voluntary and you can unsubscribe at any time via the link in every email.
  • Technical data: session records containing your IP address and browser information, and cookies essential for the website and application to work.
  • Security data: passkey credentials, two-factor authentication settings and email verification codes.

We do not sell personal data, and we do not use it for advertising profiles.

3. Purposes and legal bases

  • Performance of contract (Art. 6(1)(b) GDPR): operating your account, generating exercises, billing your subscription.
  • Legal obligations (Art. 6(1)(c) GDPR): keeping accounting and tax records.
  • Legitimate interest (Art. 6(1)(f) GDPR): application security, abuse prevention and error diagnostics.
  • Consent (Art. 6(1)(a) GDPR): analytics cookies on the public website and sending our newsletter; you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

4. Cookies and analytics

We use Google Analytics on the public website to understand site traffic, and only with your consent given through the cookie banner (managed by CookieYes). We do not use analytics inside the logged-in area of the application. See our cookies policy for the full list of cookies and how to manage them.

5. Processors and international transfers

We share personal data only with processors we need to run the service, under data processing agreements:

  • Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.) – payment processing.
  • Google (Google Ireland Ltd.) – Google sign-in and Google Analytics on the public website.
  • Brevo (Sendinblue GmbH, Germany) – sending the newsletter and transactional emails, and managing the subscriber list.
  • CookieYes – the cookie consent banner on the public website.
  • Zoho Mail (Zoho Corporation) – hosting our email inbox and correspondence with you.
  • Hetzner (Hetzner Online GmbH, Germany – Frankfurt data centre) – hosting the website, application and database.

Data is stored in the EU/EEA wherever possible. Where a processor transfers data outside the EEA (for example Stripe or Google to the USA), the transfer relies on the EU–US Data Privacy Framework or standard contractual clauses.

6. Retention

  • Account and usage data: for as long as your account is active. When you delete your account, it is deactivated and can no longer be used to sign in.
  • Invoicing and tax records: as long as applicable law requires — as a rule, 10 years for issued invoices.
  • Newsletter: until you unsubscribe or ask us to remove you.
  • Session and technical records: pruned automatically after a short period.

7. Data security

All traffic between your browser and Numibo is encrypted (TLS). Passwords are stored only as one-way hashes, payment card data never touches our servers, and access to production data is restricted to the operator. No method of transmission or storage is completely secure, but we review and update our safeguards regularly.

8. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict processing, data portability and objection, and the right to withdraw consent at any time. Send requests to info@numibo.com; we respond within 30 days. You may also lodge a complaint with the Slovenian supervisory authority, the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si. The EU online dispute resolution platform is available at ec.europa.eu/consumers/odr.

9. Children

Numibo is made for practising math with children, but accounts may only be created by adults (parents, guardians or teachers). The application does not create child profiles, does not ask for any child's personal data and does not link generated exercises to any child's identity. If you believe a child has provided us personal data, contact us and we will delete it.

10. Changes to this policy

We will notify you of material changes to this policy by email or in the application at least 30 days before they take effect. The published version, with its effective date, always applies.