Privacy Policy
Last updated: May 2026
1. Who We Are
Thama (thama.app) is a virtual business card service operated by Franger Centeno, an independent professional based in Portugal. Franger Centeno acts as the data controller for all personal data processed through this service.
Contact: contact@thama.app
2. What Data We Collect
Account data
When you create an account, we collect your name, email address, and a securely hashed password.
Profile data
Information you choose to display on your virtual card: display name, job title, bio, profile photo, and social or contact links. This data is public by default — it is visible to anyone who views your card.
Usage data
We use Vercel Analytics to understand how the service is used. This includes aggregated, anonymized data such as page views, referrer URLs, device type, and country. No personally identifiable information is collected at this level.
Payment data
All payments are processed by Polar.sh, who acts as the Merchant of Record. Thama does not store, process, or have access to your payment card details at any point.
Technical data
Standard technical information such as browser type and IP address may be processed transiently as part of serving the application. This data is not stored or used for profiling.
3. How We Use Your Data
We use the data we collect to:
- —Create and manage your account
- —Display your virtual business card to visitors
- —Process your subscription through Polar.sh
- —Understand aggregate usage patterns to improve the service
- —Send transactional emails (account confirmation, password reset)
- —Respond to support requests sent to contact@thama.app
We do not sell your data. We do not use your data for advertising purposes.
4. Legal Basis (GDPR)
For users in the European Economic Area, we process your data under the following legal bases:
| Data | Legal Basis |
|---|---|
| Account & profile data | Performance of contract (Art. 6(1)(b)) |
| Payment processing | Performance of contract (Art. 6(1)(b)) |
| Usage analytics | Legitimate interest (Art. 6(1)(f)) |
| Transactional emails | Performance of contract (Art. 6(1)(b)) |
| Support communications | Legitimate interest (Art. 6(1)(f)) |
5. Third-Party Services
Polar.sh — Payments & Billing
Polar.sh acts as the Merchant of Record for all Thama subscriptions. This means Polar handles payment processing, invoicing, and tax compliance on our behalf. When you purchase a subscription, you are entering into a transaction governed in part by Polar's Terms of Service and Privacy Policy.
Vercel Analytics — Usage Analytics
We use Vercel Analytics to collect anonymized, aggregated data about how visitors use Thama. Vercel Analytics does not use cookies, does not perform cross-site tracking, and does not build individual user profiles. It is designed to be privacy-friendly and compliant with GDPR without requiring user consent. Learn more at vercel.com/docs/analytics/privacy-policy.
Vercel — Hosting
Thama is hosted on Vercel's infrastructure. Vercel processes request data as part of serving the application. Vercel is certified under Standard Contractual Clauses for international data transfers.
6. Data Retention
| Data type | Retention period |
|---|---|
| Account & profile data | Retained while your account is active. Deleted within 30 days of account deletion. |
| Usage analytics | Aggregated only — no individual retention. |
| Payment records | Retained by Polar.sh according to their legal and tax obligations. |
| Support emails | Retained for up to 2 years for reference and quality purposes. |
7. Your Rights
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- —Access — request a copy of the data we hold about you
- —Rectification — correct inaccurate or incomplete data
- —Erasure — request deletion of your data (“right to be forgotten”)
- —Portability — receive your data in a structured, machine-readable format
- —Objection — object to processing based on legitimate interest
- —Restriction — request that we limit how we use your data
To exercise any of these rights, contact us at contact@thama.app. We will respond within 30 days.
You also have the right to lodge a complaint with the Portuguese data protection authority: CNPD — Comissão Nacional de Proteção de Dados · www.cnpd.pt · +351 213 928 400
8. International Transfers
Thama uses services that may transfer or process data outside the European Economic Area, specifically Vercel (hosting and analytics) and Polar.sh (payments). Both providers rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for international data transfers, ensuring your data receives an equivalent level of protection.
9. Contact
For any questions about this Privacy Policy or how we handle your data, contact: