1. Who is responsible
Andrii Krushelnytskyi operates the managed website service under the Alpaca One brand and is responsible for the personal data described here. Submit privacy requests through the Contact page or support@alpaca-one.com.
2. Data we collect
- Account data: name, email, encrypted credentials, role, company and session security data.
- Website data: business details, domains, configuration, supplied content, preview and service status.
- Billing data: payment status, subscription and transaction identifiers, billing dates, price and limited provider metadata.
- Technical data: IP address, browser/device details, timestamps, session identifiers, security events and diagnostics.
- Contact and AI-assistant data: name, email, business details, support messages, AI-assistant messages, and anti-abuse technical data. We use this information to answer the request and, where you explicitly ask, to follow up on a preview.
3. How we use data
- create and secure accounts;
- host, connect, maintain, and support websites;
- manage subscriptions, renewals, cancellations, payment status, and refunds;
- send service, security, billing, and password-reset messages;
- answer support and legal requests;
- prevent fraud and meet legal, accounting, and regulatory duties.
4. Legal bases
Depending on your location, processing is based on contract performance, steps requested before a contract, legal obligations, legitimate interests in operating and securing the service, or consent where required.
5. Providers and sharing
We share only the data needed by providers supporting website delivery, domain connection, SSL, authentication, payment, tax, fraud prevention, transactional email, AI processing, and professional services. AI-assistant messages are processed by an external AI infrastructure provider to generate the response. We do not sell personal data or use it for third-party behavioural advertising.
6. Payments
Checkout and full payment-card data are handled by a secure third-party payment provider under its own privacy terms. Alpaca One does not store full card details. We retain only provider customer, subscription, transaction, status, and billing-period identifiers required to activate and manage the subscription.
7. Cookies and security
Essential cookies and storage support sessions, CSRF protection, security, and dashboard operation. We currently use no advertising cookies on the public site.
Controls include encrypted connections, password hashing, limited permissions, signed payment events, rate limiting, and infrastructure protections. No system is entirely risk-free.
8. Retention and international processing
Data is retained while accounts or subscriptions are active and afterwards as reasonably needed for legal, accounting, security, dispute, and backup purposes. It is deleted or anonymised when no longer needed unless law requires retention.
Providers may process data in other countries. Contractual and organisational safeguards are used where required.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent and complain to a competent authority. We may verify identity before fulfilling a request.
10. Children, updates, and contact
The service is for business users and is not directed to children. This policy may be updated for service, provider, or legal changes.
For privacy questions, use the Contact page or email support@alpaca-one.com.