Privacy Policy
Last updated: 12 August 2026
This policy explains what data uetr.ai (the "Service") collects, how it is used, and your rights. The Service is operated by Sempre Relevante - Unipessoal Lda, a private limited company incorporated in Portugal (the "Seller", "we", "us"), trading as uetr.ai. For privacy enquiries use our contact form. Our registered address is on the legal notice.
0. Controller
Sempre Relevante - Unipessoal Lda, trading as uetr.ai, acts as the data controllerfor personal data processed through the Service and decides the purposes and means of that processing. For payments, Stripe (Stripe Payments Europe, Limited and its affiliates) acts as merchant of record and as an independent data controller for billing and fraud-prevention data, see Stripe's privacy policy. See also our merchant-of-record disclosure.
1. Data we collect
- Tracking input: UETR, payment amount, currency, payment date, optional sender / beneficiary BIC and reference.
- Contact: email address (required to send status alerts and account communications).
- Account: if you sign in, your authentication identifier and basic profile.
- Billing: processed by our payment processor (Stripe); we receive transaction metadata but not full card details.
- Technical: standard request logs (IP, user agent, timestamps) for security and abuse prevention.
2. How we use it
- To query supported transfer-status sources for the UETR and payment details you provide and present available results to you.
- To send transactional emails (status changes, account, billing).
- To operate, secure and improve the Service.
- To meet legal, accounting and regulatory obligations.
- To compile and publish aggregated statistics about how transfers behave and how the Service is used, for example the share of tracked transfers reporting each status code and how long completion took. See section 2b.
2a. Legal basis for processing
- Performance of a contract (GDPR Art. 6(1)(b)), to provide the Service you have requested: looking up the UETR, running monitoring, sending status emails, providing access to your account.
- Legitimate interests (GDPR Art. 6(1)(f)), securing the Service, preventing abuse and fraud, keeping minimal request logs, and improving the product. We balance this against your rights and only process what is necessary.
- Legitimate interests (GDPR Art. 6(1)(f)) also cover compiling aggregated statistics from activity on the Service and publishing them. Our interest is in documenting how cross-border payments behave and in showing that the Service works. GDPR Art. 5(1)(b) provides that further processing for statistical purposes is not incompatible with the purpose for which data was first collected, where the safeguards in Art. 89(1) are applied. We apply those safeguards, which are set out in section 2b. You may object to this use at any time under GDPR Art. 21.
- Legal obligation (GDPR Art. 6(1)(c)), to keep accounting records and respond to lawful requests from authorities.
- Consent (GDPR Art. 6(1)(a)), where you opt in to optional communications. You may withdraw consent at any time.
2b. How we protect you in published statistics
Statistics we publish are aggregated and are designed so that they contain no direct identifiers and no single transfer. These are the controls we apply when producing them:
- Shares only, never counts, in transfer statistics. Every published figure about how transfers behave is a percentage, a median or a percentile. We do not publish counts of transfers, customers, institutions or countries in those statistics. Separately from them, we publish a small number of high-level reach figures about the Service itself, such as rounded total tracked volume, the number of currencies observed, and the number of countries the Service has been used from. These are aggregates with no per-transfer or per-customer detail, stated as rounded floors and refreshed periodically; they are derived from usage analytics and service records rather than from the per-transfer statistics, so the minimum-sample threshold below does not describe them, while the remaining safeguards (never a single record, never who paid whom, no re-identification) apply to them equally.
- Never a single record. No UETR, amount, payment date, email address or bank identifier belonging to one transfer appears in any published figure.
- A minimum sample threshold. A transfer statistic is not published at all unless it rests on at least one hundred transfers, and we group small categories together rather than showing them separately. Reach figures are not transfer statistics and are governed by the rounded-floor method described above instead.
- Never who paid whom. No statistic about who sent a payment, who received it, or the route between them is ever published.
- Dated snapshots, not a live counter. Transfer statistics are published as at a stated date and refreshed periodically, rather than as a running total that could be read twice and compared; reach figures are rounded floors refreshed periodically.
- No re-identification. We do not attempt to identify any individual from published statistics.
You may object to this use of your data at any time under GDPR Art. 21 using our contact form. We assess objections under applicable law.
3. What we do not do
- We do not sell your personal data.
- We do not share UETRs or transfer details with third parties for their own marketing or advertising. To perform the lookup you request, we may submit the UETR and related lookup details you provide to supported publicly available tracker endpoints.
4. Storage and retention
Data is stored on Lovable Cloud infrastructure (hosted on Supabase / Cloudflare). Retention is determined by the continued need for the purposes described in this Policy, applicable statutory retention requirements, and any scoped preservation duty. We assess valid erasure requests under applicable law. Three concrete rules apply today: billing data is held by Stripe under its own retention policy; accounting records are kept for 10 years where Portuguese tax law requires it; and the suppressed-email list is retained indefinitely to honour unsubscribes.
You may request deletion at any time, subject to legal-retention obligations, and we assess such requests under applicable law.
4a. Recipients and sub-processors
We share personal data only with the categories of recipients listed below, strictly to operate the Service:
- Hosting and database: Supabase (database, auth) and Cloudflare (edge runtime, CDN).
- Payment processor / merchant of record: Stripe Payments Europe, Limited and its affiliates (checkout, card processing, tax calculation and remittance where supported, invoicing, fraud screening, transaction support, dispute resolution).
- Transactional email: our email delivery provider, used to send account, status-alert and billing emails.
- Supported tracker sources: publicly available bank or payment-status tracker endpoints queried only to provide the lookup or monitoring you requested.
- Authorities: where we are required to disclose by law, court order or to respond to a lawful request from a competent authority.
We do not share personal data with advertisers or data brokers.
4b. Requests from authorities and from parties to legal proceedings
We sometimes receive requests for records from courts, regulators, law enforcement and parties to civil proceedings. Our procedure is on our records requests page and in section 11 of our Terms of Service. In summary: we assess every request for validity, authority, scope, necessity and proportionality, and we disclose personal data only where disclosure is lawfully required or permitted, and only to the extent required. We may, where legally permitted and operationally appropriate, tell you and give you an opportunity to object before we disclose; we do not promise advance notice. A request or order from an authority outside the EEA does not automatically bind us and is not, by itself, a lawful basis for disclosure (Article 48 GDPR); where an applicable treaty or cooperation procedure governs the request, we may require that it be used.
Where we are legally required to preserve records that would otherwise reach the end of their retention period, we preserve only those records, only for as long as required, and we return them to the normal retention schedule afterwards.
5. Your rights
Subject to applicable law (including GDPR and UK GDPR where relevant) you may request access, correction, deletion, portability, restriction, or object to processing of your personal data, and you may withdraw consent at any time, using our contact form or by writing to us at the registered address on our legal notice. We respond within one month of receiving a valid request unless applicable law permits an extension. You also have the right to lodge a complaint with your local data-protection supervisory authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt.
5c. Automated decision-making
We do not carry out automated decision-making producing legal or similarly significant effects on you (GDPR Art. 22).
5d. Children
The Service is not directed at, and we do not knowingly collect personal data from, children under 16.
5a. International transfers
Our infrastructure providers may process data outside your country, including in the EEA, the UK and the United States. Where data leaves the UK/EEA we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
5b. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), access controls, audit logging, and row-level security on our database. No method of transmission or storage is 100% secure; if you believe your account has been compromised, tell us immediately using our contact form.
6. Cookies
We use strictly necessary cookies plus, with your consent, analytics and marketing cookies. See our Cookie Policy for the full list and to change your preferences.
7. Contact
Sempre Relevante - Unipessoal Lda, trading as uetr.ai. Reach us through our contact form, or by post at the registered address on our legal notice.