Sweetcase

Privacy Policy

Last updated: 22 September 2026.

1. Who is responsible for your data

Sweetcase is operated by Alessio Meroni, a sole trader (eenmanszaak) registered in the Netherlands, trading as Sweetcase, who is the controller of the personal data described here.

Verbeeklaan 3, 5644 DG Eindhoven, Netherlands
Chamber of Commerce (KvK) number: 89485106
Email: hello@sweetcase.app

We are a small independent project. We collect as little as the app can work with, we don't sell data, and we don't run advertising or analytics beyond what's described here — with your consent where the law requires it (see sections 4 and 5 below).

2. What we collect

  • Your email address — when you send a list to yourself, save a list or a traveler, start a trial, or subscribe to Sweetcase Lounge. It is the only identifier we use: there is no account and no password.
  • Your name — if you give it when subscribing or starting a trial. We use it to greet you in the app and to create your own traveler profile.
  • Trip details you enter — destination, length, season, number of participants, the names or descriptions of the people travelling with you, activities, and the items on your list.
  • Saved travelers — the names and favourite items you save for the people you travel with. If you save details about someone else, please only add what they would be comfortable with.
  • Approximate location — the city, country and rough coordinates that our host (Vercel) derives from your IP address when you generate a list. We store this only alongside the anonymous record of the generation, to see on a map where the app is being used. It is never linked to your email address.
  • A one-way hash of your IP address — used to count requests for anti-abuse limits. We never store your IP address itself, in any table, and the hash is salted with a secret key so it cannot be reversed.
  • Subscription data — if you subscribe: your Stripe customer and subscription identifiers, the plan, its status, the next renewal date, and how you first arrived at the site (see cookies and local storage below). We never see or store your card details — those stay with Stripe.
  • Newsletter status — whether you are subscribed to our monthly newsletter. This is held at Resend, our email provider, not in our own database.
  • Anonymous usage records — each list generation (destination, length, participants, language, approximate origin) and each item you add by hand, both stored without any identifier that links them back to you. We use them for aggregate statistics and for the content of the newsletter.

3. Why we use it, and on what legal basis

  • To provide the service — generating lists, saving and retrieving them, saved travelers, sending a list to your email, verifying your email with a one-time code or sign-in link. Legal basis: performance of a contract with you.
  • To take payment and manage your subscription — including trial reminders and billing emails. Legal basis: performance of a contract.
  • To keep the service working and prevent abuse — daily generation limits, rate limits on emails and codes. Legal basis: our legitimate interest in keeping a free service affordable and not letting it be used to spam other people.
  • To understand how the app is used, in aggregate — how many lists, from which countries, which destinations are popular. Legal basis: legitimate interest; the data used here does not identify you.
  • To send the monthly newsletter — only if you asked for it. Legal basis: your consent, which you can withdraw at any time (see below).
  • To keep our books — invoices and payment records. Legal basis: a legal obligation under Dutch tax law.

4. Cookies and local storage

Everything below is either necessary for a feature you asked for, a preference stored in your own browser, or — only if you actively accept it in the cookie banner — analytics and advertising measurement (Google Analytics and the Meta pixel). Nothing in the second group is loaded until you accept. Data we share from our own servers, which the banner does not control, is described in section 5.

Cookies

  • sc_bid — a random number identifying your browser, with no personal data in it, used to count your free generations for the day. Kept for 1 year.
  • sc_remember — set only if you sign in with a one-time code or sign-in link, so you don't have to do it again on every visit. Kept for 30 days; "Not you? Sign out" removes it.
  • sc_preview — set only if you follow a private preview link during maintenance. Contains no personal data.
  • sc_admin — the sign-in session for the owner's private statistics page. It is never set for visitors.
  • Google Analytics cookies (e.g. _ga, _ga_*) — set only if you click "Accept" in the cookie banner. See the Analytics paragraph below for what they do and how to withdraw consent.
  • Meta pixel cookies (e.g. _fbp) — set only if you click "Accept" in the cookie banner. See the Meta pixel paragraph below.

Local storage (stays in your browser)

  • sweetcase-locale — the language you picked, so we can use it again next time.
  • sc_cookie_ack — remembers your cookie banner choice ("granted" or "denied").
  • sc_attribution — if you arrived through a link with campaign parameters, or from another site, we keep that first origin in your browser. If you later subscribe, it is sent along so we can tell which channel brought subscribers. It contains no personal data on its own.

Analytics. We use Vercel Analytics to count page views. It does not set cookies and does not build a profile of you: measurements are aggregated and cannot be traced back to an individual visitor — no consent is required for it.

Google Analytics (optional). If you click "Accept" in the cookie banner, we also load Google Analytics, so we can link Sweetcase Lounge subscriptions back to the Google Ads campaigns that brought them and see more detailed traffic statistics. This sets cookies and sends data — including your IP address and pages viewed — to Google, which may process it in the United States. Legal basis: your consent. You can decline it in the banner, or withdraw it at any time by clearing sc_cookie_ack from your browser's site data and reloading the page (the banner will show again). See Google's Privacy Policy for how Google handles this data.

Meta pixel (optional). If you click "Accept" in the cookie banner, we also load the Meta pixel, so we can measure whether our ads on Facebook and Instagram actually bring people to Sweetcase. This sets cookies and sends data — including your IP address and the pages you view on this site — to Meta, which may process it in the United States. Meta may match this with an account you hold with them. Legal basis: your consent. You can decline it in the banner, or withdraw it the same way as above. See Meta's Privacy Policy for how Meta handles this data.

5. Who else processes your data

We use the following providers, each under a data processing agreement and only for what is described here:

  • Supabase — the database that holds your lists, travelers and subscription records.
  • Vercel — hosting, and the aggregate page-view analytics above.
  • Anthropic — generates the packing list from your trip details. Your email address is never sent to Anthropic.
  • Resend — sends our emails (one-time codes, sign-in links, your list, trial reminders, the newsletter) and holds the newsletter subscriber list.
  • Stripe — handles payments and holds your payment details, as controller for its own purposes as well.
  • Google (Analytics and Ads) — only if you accept the optional cookie, measures site traffic and lets us see which Google Ads campaigns led to a Sweetcase Lounge subscription.
  • Meta (Facebook and Instagram) — measures which of our Facebook and Instagram ads bring visitors and subscribers. Meta receives your page views only if you accept the optional cookie, and details of your subscription through Stripe whenever you subscribe (see below).

Subscription data shared with Meta. When you subscribe to Sweetcase Lounge, Stripe sends details of that subscription — the amount, the currency, the date, and identifiers derived from your email address and name — directly to Meta. We use this to measure which of our Facebook and Instagram ads lead to subscriptions, and to reach people with similar interests. This happens between Stripe and Meta on the server side: unlike the Meta pixel in section 4, it is not controlled by the cookie banner, and it applies to every subscription regardless of the choice you made there. Legal basis: our legitimate interest in measuring and improving our advertising (Art. 6(1)(f) GDPR). You can object at any time — write to hello@sweetcase.app and we will exclude your data from this sharing, with no effect on your subscription.

We do not sell your data. Apart from the advertising measurement described above, we do not share it for advertising, and we only disclose it to anyone else where the law requires it.

Transfers outside the EEA. Some of these providers are established in the United States or process data there. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, and where applicable by the provider's certification under the EU–US Data Privacy Framework.

6. How long we keep it

  • Saved lists and travelers — until you delete them, or ask us to. They are not deleted automatically when a subscription ends.
  • One-time codes and sign-in links — they expire after 10 minutes and are marked used as soon as they are used.
  • Sign-in sessions — up to 30 days.
  • Anti-abuse records (hashed IP, browser identifier) — up to 12 months.
  • Subscription and payment records — 7 years, as Dutch tax law requires.
  • Newsletter subscription — until you unsubscribe.
  • Aggregate usage statistics — kept indefinitely; they contain no email address and no IP address.

7. Your rights

Under the GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent — the newsletter — you can withdraw it at any time, without affecting what we did before.

You can do several of these yourself, straight away:

  • delete individual lists and travelers in the app;
  • subscribe to or unsubscribe from the newsletter from your account panel, or with the unsubscribe link in any newsletter;
  • sign out of a remembered browser with "Not you? Sign out";
  • cancel a subscription from "Manage subscription".

For anything else, write to hello@sweetcase.app. We reply within one month. Because your email address is the only identifier we hold, we may send a one-time code to that address before acting on a request, to be sure it is really you.

If you think we are handling your data wrongly, you can complain to the Dutch data protection authority, Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in the EU country where you live.

8. Children

Sweetcase is not intended for children under 16, and we don't knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

9. Security

Data travels over HTTPS. Our database is not reachable from the browser: every read and write goes through our server. One-time codes, sign-in links and session tokens are stored only as hashes, never in readable form, and the same is true of the IP hashes used for abuse limits.

10. Changes to this policy

We may update this policy. The date at the top always shows the current version; if a change is significant, we will point it out in the app or by email.

Privacy Policy — Sweetcase