NOVANCE Privacy Policy
Version: 1.0 — Effective date: August 17, 2026
1. Data Controller
The controller responsible for personal data processed directly by NOVANCE is:
- Marco Atilio Robbiano Taboada
- Operator of NOVANCE
- Jr. Inambari 755 Int. 8, Lima, Lima, Peru
- Email: support@novance.app
- Phone: +51 932 466 327
NOVANCE processes personal data in accordance with applicable law, including Peruvian Law No. 29733 and its Regulations approved by Supreme Decree No. 016-2024-JUS.
2. What Data We Collect
Registration data
When you create an account we may collect:
- email address;
- name, if you choose to provide it;
- password, stored only as a secure hash;
- preferred language;
- email verification date;
- date and version of your acceptance of the legal documents.
NOVANCE does not store passwords in plain text.
Profile data
You may provide:
- your name;
- a profile picture;
- information related to your business or site.
Site data
We may store information you enter or generate through NOVANCE, including:
- site name;
- configuration;
- SEO content;
- categories;
- products;
- images;
- banners;
- logos;
- domains.
3. Security and Session Data
To keep accounts secure, NOVANCE uses session information.
A session may include a session identifier and the browser's User-Agent.
NOVANCE does not store users' IP addresses in the database.
IP addresses may be used temporarily in security and abuse-prevention systems, including Redis, with limited retention periods.
4. Data From Visitors to Public Sites
Sites created with NOVANCE do not require a visitor to create an account to browse products.
When a visitor clicks Buy, NOVANCE records aggregate interaction statistics.
PostgreSQL does not store an individual identifier that would reveal who made the click.
The IP address may be used temporarily to prevent abuse through a control mechanism that expires automatically.
5. Statistics
NOVANCE's statistics use aggregate click counters.
There is no table of individual events that identifies each visitor.
Site owners can view their statistics from their authenticated account.
6. Purposes of Processing
We use the data above to:
- create and manage accounts;
- authenticate users;
- verify email addresses;
- provide the contracted features;
- store and display content;
- manage subscriptions;
- process payment-related operations through Paddle;
- send transactional communications;
- provide support;
- prevent fraud and abuse;
- protect the Platform's security;
- comply with legal obligations;
- maintain and improve NOVANCE's operation.
7. Acceptance of Legal Documents
During registration, NOVANCE requests express acceptance of the Terms and Conditions and the Privacy Policy.
We record the date and version of the documents accepted so we can demonstrate which version was in effect when the account was created.
8. Providers and Third Parties
Paddle
Paddle acts as the Merchant of Record for the corresponding transactions.
Checkout is carried out through Paddle, and NOVANCE does not receive or store the full card number, CVV, or payment credentials.
NOVANCE receives the information necessary to manage the subscription and the transaction status.
Paddle maintains its own privacy policies and terms for buyers.
Resend
NOVANCE uses Resend to send transactional communications.
This may include the recipient's email address and the content necessary to send:
- verification codes;
- password recovery;
- cancellation-related confirmations;
- refund-related communications;
- grace-period communications.
Firecrawl
NOVANCE uses Firecrawl to extract a product's public data (name, price, images, specifications) from the URL the site owner provides when importing a product for the first time.
The flow is: product URL → Firecrawl → data extraction → NOVANCE → product card in the catalog. The only thing sent to Firecrawl is the product's public URL, never personal data about users or buyers.
Firecrawl is not involved in any other NOVANCE process: it plays no role in login, passwords, password recovery, checkout or payments (Paddle), sending emails (Resend), sessions, or any tracking cookie.
File storage
Images you upload (avatars, banners, logos) are stored through the file storage system configured for the environment NOVANCE runs on. Depending on that environment, storage may be an external S3-compatible provider (for example, Cloudflare R2) or the application's own server. When you delete your account or a site, NOVANCE attempts to delete the associated files as well, to the extent the storage configured in that environment allows it.
9. Payment Information
NOVANCE does not store:
- full card numbers;
- CVV;
- payment credentials.
The system may retain limited information associated with the subscription, such as the card brand and last four digits when Paddle provides them masked, in addition to billing information such as amount, currency, status, and date.
10. Cookies and Local Storage
NOVANCE uses only technologies necessary to operate the Platform.
session_id
Cookie used to keep you signed in.
It is httpOnly and uses sameSite=lax, with a duration of approximately 30 days.
NEXT_LOCALE
Cookie used to remember your preferred language.
localStorage
Public sites may use the browser's local storage to:
- remember the last product visited;
- temporarily keep the comparison tool's product selection.
This information stays on the user's browser until it is removed by the browser itself or by the user.
NOVANCE does not currently use advertising cookies, fingerprinting, or third-party analytics tools.
11. We Do Not Use Tracking-Based Advertising
NOVANCE does not currently use:
- Google Analytics;
- Meta Pixel;
- fingerprinting;
- behavioral advertising systems;
- AI/LLM providers to process users' personal data.
12. Data Retention
Deleted accounts remain in a 30-day grace period before permanent purging.
Other retention periods currently defined by the system include:
- pending registration: 24 hours;
- verification code: 15 minutes;
- continuation credential: 30 minutes;
- active session: 30 days;
- recovery token: 1 hour;
- temporary abuse-control data in Redis: between 60 seconds and 1 hour depending on the mechanism.
Retention periods may differ where a legal or contractual obligation requires keeping certain information.
13. Account Deletion
When a user requests deletion of their account:
- the account enters a pending-deletion state;
- a 30-day grace period is set;
- active sessions are revoked;
- at the end of the period, the account's data is removed from the database through an automatic purge.
Deletion may include users, sessions, tokens, sites, domains, categories, products, imports, subscriptions, and other associated data.
Shared product data that is not personal data is not necessarily deleted if it continues to be used by other accounts.
14. Data Subject Rights
Under applicable Peruvian law, you can exercise the rights of:
- access;
- rectification;
- cancellation;
- objection.
Peru's National Personal Data Protection Authority recognizes these as ARCO rights.
To exercise them, you can write to:
- support@novance.app
Your request may require reasonable information to verify the requester's identity.
If you believe your request has not been handled properly, you can appeal to the National Personal Data Protection Authority under the applicable procedure.
15. Security
NOVANCE implements technical measures aimed at protecting data, including:
- passwords stored via secure hashing;
- protected sessions;
- access controls;
- data isolation between accounts;
- abuse-prevention mechanisms;
- protection of communications and service credentials.
The infrastructure uses database-level isolation mechanisms to separate different accounts' data.
No system connected to the internet can guarantee absolute security.
16. Internal Access
Administrative access to data is limited to the functions necessary to operate, maintain, protect, and support NOVANCE.
Accounts with administrative privileges may access account information when necessary for those functions.
17. International Transfers
By using international technology providers, certain data may be processed or stored outside of Peru.
NOVANCE will seek to use providers that implement appropriate protective measures and will process data in accordance with applicable law.
18. Children's Privacy
NOVANCE is not specifically designed for minors.
We do not knowingly collect personal data from minors as part of a service specifically directed at them.
If you believe a minor has provided personal data to NOVANCE inappropriately, you can contact:
- support@novance.app
19. Changes to This Policy
We may update this Policy when our practices, features, providers, or legal requirements change.
The version and update date will be shown at the beginning of the document.
Where applicable, we will request acceptance of a modified version again.
20. Contact
- Marco Atilio Robbiano Taboada
- Operator of NOVANCE
- Jr. Inambari 755 Int. 8, Lima, Lima, Peru
- support@novance.app
- +51 932 466 327