Privacy policy
Introduction
Last Updated: April 2025
Chlorobase ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
Chlorobase is operated by Anthony Ferreol. For complete legal information about site ownership and hosting, please refer to our Terms and Conditions.
By accessing or using Chlorobase, you agree to this Privacy Policy. If you do not agree with our policies and practices, please do not use our service.
Information we collect
Account information
We collect information necessary to create and manage your account. The specific information collected depends on your chosen sign-up method:
- Sign-up via Email/Password:
- Email address: Provided directly by you during registration. We use this for account creation, email verification, authentication, account security (like password resets), and essential communication.
- Password: Provided directly by you during registration. We do not store your raw password; instead, we store a secure, hashed version.
- Username: Initially assigned randomly upon account creation. You have the option to customize this username later in your profile settings.
- Profile picture: You may optionally upload a profile picture later via your profile settings.
- Preferred language: We save the language used while browsing during registration to send transactional emails (such as email verification and password reset notifications) in the user's preferred language.
- Sign-up via Social Sign-in (Google or Discord):
- OAuth authentication information: Your unique User ID provided by Google or Discord, used to link your social account to Chlorobase.
- Email address: Retrieved directly from your linked Google or Discord account. We use this primarily for authentication, account security, and essential communication purposes.
- Username: Initially assigned randomly upon account creation. You have the option to customize this username later in your profile settings.
- Profile picture: Retrieved from the public profile picture associated with your linked Google or Discord account. This picture is displayed within Chlorobase to personalize your experience.
User-generated content
We collect content that you voluntarily provide, including:
- Plant collections and wishlists data
- Plant information submissions
- Images you upload
- Comments and contributions to plant pages
Technical information
We automatically collect certain information when you visit our website:
- Browser and device information
- Usage data and site interaction
- Browser storage technologies (cookies and local storage)
Legal basis for processing (GDPR)
We process your personal data based on the following legal grounds:
- Consent: When you explicitly agree to the processing of your data. For email/password sign-up, providing your email and password constitutes agreement to process this data for account creation and authentication.
- Performance of contract: Processing necessary to provide our services as outlined in our Terms and Conditions, including creating your account, verifying your email address, and authenticating you.
- Legitimate interests: When necessary for the legitimate interests of operating, improving, and securing our services, such as sending email verification links to ensure account security and data integrity.
How we use your information
We use the information we collect to:
- Create and maintain your account
- Authenticate you via your chosen method (email/password or social sign-in).
- Verify your email address ownership via a confirmation link sent to your provided email (for email/password sign-ups).
- Facilitate password resets if you use the email/password method.
- Provide and improve our services
- Personalize your experience
- Process and display your user-generated content
- Analyze usage patterns to enhance functionality
- Protect against unauthorized access and abuse
- Communicate with you regarding your account or service updates, if necessary (using your email address).
Data sharing and third Parties
Service providers
Our analytic provider only process anonymized data unrelated to your account. We use third-party service providers to assist with essential functions like sending transactional emails (e.g., email verification, password resets). These providers are only permitted to use your information as necessary to provide these services to us.
Business transfers
If Chlorobase is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
Legal requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities.
Cookies & local storage
We use functional cookies and local storage to enhance your experience on our website. For detailed information about what we use, their purposes, and how to manage them, please refer to our Cookie Policy.
Your privacy rights
Depending on your location, you may have the following rights regarding your personal data:
GDPR rights (European users)
- Right to Access: Request a copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data.
- Right to Restrict Processing: Limit how we use your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to our processing of your data.
- Right to Withdraw Consent: Withdraw previously given consent.
CCPA rights (California residents)
- Right to Know: Request categories and specific pieces of personal information collected.
- Right to Delete: Request deletion of personal information.
- Right to Opt-Out: Opt-out of the sale of personal information (note: we do not currently sell personal information).
- Right to Non-Discrimination: Receive equal service and pricing even if you exercise your privacy rights.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within the timeframe required by applicable law.
Data security and retention
Security measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, accidental loss, or destruction. This includes using strong hashing algorithms to protect stored passwords.
Data retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law.
Account information (including your email address and hashed password) is retained until you request deletion of your account. Email verification tokens or links may have a shorter, specific expiry period for security purposes. After account deletion, we may retain certain information in anonymized form for analytical purposes.
International data
Your informations are stored in Germany where our hosting service provide its service.
Changes to our privacy policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us at: [email protected].