1. Data Controller
Anthony Claverie, founder of Mastrmine, based in Butembo, North Kivu, Democratic Republic of the Congo. Contact: info@mastrmine.app.
2. Data hosting
All your data is hosted in the European Union, on
Supabase (region eu-central-1,
Frankfurt, Germany). No data transfer to third countries
outside the EEA.
3. Data we collect
3.1 User account
- Email address (mandatory for authentication)
- Password (hashed, never stored in clear text)
- UI preferences (language, theme)
3.2 Monitoring data
- Bridge and miner identifiers (network IDs, MAC, local IP)
- Per-minute aggregated telemetry (hashrate, power, temperature)
- Automation configurations (PMAX thresholds, Thermal Guard)
- Alert and event history
3.3 Payment data
Payment data (card, IBAN) never transits through Mastrmine. It is handled exclusively by our partners:
- NOWPayments (crypto USDT/BTC)
- Lemon Squeezy (card/SEPA, EU Merchant of Record)
4. Legal basis
- Contract performance (GDPR art. 6.1.b): account data, monitoring, payment.
- Legitimate interest (art. 6.1.f): technical logs, anonymous analytics.
5. Retention period
- Active account: as long as you use the service
- Closed account: 30 days then permanent deletion
- Telemetry history depends on your tier:
- Free: 7 days
- Home: 30 days
- Pro: 1 year
- Studio: 2 years
- Operator / Corporate: unlimited
- Audit log of guest actions: 1 year
- Invoices: 10 years (applicable accounting obligation)
6. Your GDPR rights
You have the following rights, exercisable by email at info@mastrmine.app:
- Access to your data
- Rectification
- Erasure ("right to be forgotten")
- Portability (JSON export)
- Objection to processing
- Complaint to your national data protection authority (e.g., CNIL for France)
7. Cookies and trackers
The mastrmine.app website uses no tracking or advertising cookies. No Google Analytics, no Facebook Pixel. Any analytics in use is via Plausible or Cloudflare Web Analytics — both anonymous and cookie-free.
The web app (app.mastrmine.app) uses a session cookie to keep your authentication active — strictly necessary for operation.
8. Subprocessors
List of subprocessors potentially accessing your data:
- Supabase — DB hosting + auth (EU Frankfurt)
- Cloudflare — CDN + DNS
- Firebase Cloud Messaging — push notifications (Google, GDPR DPA-compliant)
- NOWPayments — crypto payments (EU/UK)
- Lemon Squeezy — card/SEPA payments (Merchant of Record)
⚠️ Simplified V1 document. A legal review is planned before the public V1 launch.