Privacy policy
Last updated: April 20, 2026
Data controller
The controller of personal data collected on atalaya.watch is Xavier Huix Trenco (Spanish national ID 41649433K), domiciled at Carrer d'Aribau 140, 5, 08036 Barcelona, España. For any query reach out at admin@atalaya.watch. This notice complies with art. 10 of Spanish Law 34/2002 (LSSI-CE) and Regulation (EU) 2016/679 (GDPR).
1. Information we collect
When you create an account, we collect your name, email address, and payment information (processed securely via Stripe). We also collect usage data such as properties viewed, searches performed, and saved listings to improve our service.
2. How we use your information
- To provide and maintain our service, including personalized property recommendations
- To securely process your subscription payments via Stripe
- To send you alerts and notifications about new opportunities that match your criteria
- To improve our scoring algorithms and platform features
- To communicate important updates about the service
3. Data sharing
We do not sell your personal information. We only share data with:
- Stripe — for secure payment processing
- Supabase — for authentication and data storage
- Google Analytics (GA4) — aggregated and anonymized usage data, loaded only after you grant consent
4. Data security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest. Authentication is handled via Supabase Auth with secure JWT tokens. Payment data is processed by Stripe and never stored on our servers.
5. Your rights
Under the GDPR and Spanish data protection law (LOPD-GDD), you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your data in a portable format
- Object to data processing
To exercise any of these rights, contact us at privacidad@atalaya.watch.
6. Cookies
We use essential cookies for authentication and session management. We also use Google Analytics 4 (GA4) cookies to measure site usage in aggregate — these only load after you accept them in the consent banner. You can withdraw consent at any time by clearing your browser storage. We do not use advertising or remarketing cookies.
7. Data retention
We retain your account data for the duration of your subscription. If you delete your account, all personal data is permanently removed within 30 days. Aggregated and anonymized analytics data may be retained indefinitely.
8. Contact
For privacy enquiries or to exercise your rights (access, rectification, erasure, objection, restriction and portability), write to . admin@atalaya.watch