Winetra Space logo winetra.space

Transparency by Design

Your data isn't an abstraction. It's your work, your voice, your creative process. This policy outlines our simple, respectful approach to handling what you share with winetra.space.

Effective Date: June 15, 2026

🔒

No Hidden Data Sales

We do not sell, trade, or share your personal information with third parties for marketing purposes. Ever.

🛡️

EU & GDPR Compliant

Based in Rome, we adhere to strict Italian and EU data protection regulations by design.

Annotation: These principles act as our internal guardrails. Every feature decision filters through this lens.

What We Collect & Why

1. Essential Account Data

Email address for account creation, password (stored encrypted), and username. Required to save your game presets and session data.

Legal Basis: Contractual necessity (providing the service you request).

2. Creative Content

Your submitted game designs, screenshots, and description text. This content remains your intellectual property.

Legal Basis: Contractual necessity. We store it to display your portfolio and for our shared creative archive.

3. Technical & Usage Data

Anonymous analytics (pages visited, session duration) and device type. This helps us fix bugs and improve performance for Italian indie devs working on older laptops.

What We Do NOT Collect

  • Payment information (we use third-party processors who handle that directly).
  • Real-world names or contact details beyond email.
  • Location data beyond country (for regional language support).
  • Any data for advertising purposes.
Data flow sketch
Fig 1. Data flow model sketched by our lead developer, 2025.

"If we can't explain a data point's purpose in one sentence to a developer friend over espresso, we don't collect it."

— Winetra Space Internal Guideline, Article 1

Your Rights, Your Control

We believe you should own your data. Here's how you can exercise your rights under Italian Law and the GDPR.

👀

Right to Access

Request a copy of all personal data we hold about you. We'll provide it in a common, machine-readable format within 30 days.

🗑️

Right to Erasure

Request deletion of your account and associated data. Some anonymized analytics data may be retained for legal compliance.

✏️

Right to Rectify

Correct inaccurate personal data. Update your email, username, or game portfolio entries anytime from your account dashboard.

To exercise any of these rights, please contact our Data Protection Officer.

Contact Us Via Form →

Or email: privacy@winetra.space

A Due Diligence Lens

For partners, investors, or privacy-conscious users, these questions frame our approach to data stewardship.

Question 1

Where is user data physically stored?

Primary servers are in Frankfurt, Germany (GDPR compliance). Backups are encrypted and held within the EU Economic Area.

Question 2

What third-party processors do you use?

We use Stripe (payment), SendGrid (transactional email), and Vercel (hosting). Each is vetted for GDPR compliance.

Question 3

How do you handle data breaches?

We have a 72-hour notification protocol. Affected users are informed via email with clear steps to secure their accounts.

Question 4

Can users export their creative portfolio?

Yes. All uploaded games and assets can be downloaded as a single ZIP archive from the user dashboard.

Question 5

What happens to data if the platform shuts down?

We provide a 90-day window for data export before any irreversible deletion. A 6-month advance notice is given to all users.

Question 6

Do you use data for AI training?

No. User-submitted creative content is never used to train any machine learning models, internal or external.

Policy Foundations & Realities

Core Assumptions

  • Users are fellow creatives who value control, not consumers to be monetized.
  • Simplicity beats complexity; our tools should work without legal teams.
  • Trust is built through transparency, not lengthy legalese.

Operational Constraints

  • We must comply with Italian DPA and EU GDPR mandates exactly.
  • Limited resources mean we prioritize security audits over fancy features.
  • Cross-border server hosting requires extra legal vetting.

What Changes Our View

  • A major, confirmed data breach in our infrastructure.
  • Legal ruling that redefines "consent" for hobbyist platforms.
  • Community feedback demanding a feature that requires a new data category.

Field Note: We review this policy every 6 months. The last major update was in March 2026, after implementing the 'Right to Rectify' dashboard feature.

Questions About Your Data?

Our Data Protection Officer is based in our Rome office. For urgent privacy concerns, email privacy@winetra.space directly.

Winetra Space SRL

Via Roma 123, 00100 Rome, Italy

+39 06 1234 5678

info@winetra.space

Mon-Fri: 09:00 - 18:00 CET