Aestro
PrivacyData rightsDPASubprocessorsTermsSign in

Last updated August 9, 2026

Privacy Policy

This policy explains how Aestro handles personal information for its website, accounts, private workspaces, public sharing, quote requests, support, and product reliability measurements.

Who controls your information

Justin Marroquin, operating Aestro, operating Aestro, is the controller for account, website, security, support, and service-operation information. For project, contact, crew, client, invoice, and other workspace records entered by a customer, the workspace owner normally decides why that information is used and Aestro processes it on the owner's behalf.

The controller mailing address must be added before EU production release.

A dedicated privacy contact must be configured before production release.

Information we collect

Account information includes name, email, username, optional phone number, account identifiers, authentication events, invite status, workspace membership, and security events handled through Supabase.

Workspace users may store projects, contacts, companies, phone numbers, email addresses, schedules, notes, gear, packages, quote and rental records, invoices, payroll records, expenses, receipts, profile media, agreement files, settings, backups, and document metadata.

Public visitors may submit quote requests with project details, selected gear, rental dates, name, email, and phone number. Public contact cards, profiles, project links, and gear lists show only information a workspace user chooses to publish.

Support and issue requests may include the text you submit, the page path, app version, device or browser type, request time, and limited rate-limit or security context. Aestro does not use advertising identifiers and does not sell personal information.

Why we use information and our legal grounds

  • Contract: to create and authenticate accounts, provide workspaces, save and export records, generate documents, process invitations and quote requests, and provide requested support.
  • Legitimate interests: to secure the service, prevent abuse, diagnose failures, measure anonymous page performance, maintain backups, and improve reliability without overriding individual rights.
  • Legal obligations: to respond to lawful requests, preserve records when legally required, and meet tax, accounting, security, or regulatory duties that apply to Aestro.
  • Consent: when you deliberately enable an optional public feature, choose optional communications where consent is required, or otherwise give a specific choice that can be withdrawn.

Aestro does not use personal information for automated decisions that produce legal or similarly significant effects.

Sharing and processors

Aestro uses Supabase for authentication, database, and file storage, and Vercel for website hosting, server routes, security delivery, and anonymous Speed Insights performance measurements. The current list, purpose, location, and change process are on the Subprocessors page.

Information may also be shared with workspace members and recipients you direct Aestro to share with, or when needed to comply with law, protect people or the service, investigate abuse, or complete a business transfer subject to appropriate safeguards.

Workspace owners that use Aestro to process other people's information can rely on the Data Processing Addendum, which forms part of the Terms for that processing.

International transfers

Aestro is operated from the United States and currently uses infrastructure that may process information in the United States and other countries. Where European personal information is transferred outside the EEA, the service relies on applicable provider data-processing terms, the European Commission's Standard Contractual Clauses, adequacy decisions where available, and additional technical and organizational safeguards.

Aestro documents its provider locations and safeguards on the Subprocessors page. A copy or summary of relevant transfer safeguards can be requested through the privacy contact.

Cookies and performance measurements

Aestro uses first-party authentication and security cookies to keep users signed in and protect account access. First-party browser storage remembers functional choices such as theme and accent, onboarding progress, calendar display preferences, phone-code resend timing, and demo sharing data created on that device. These technologies are used to provide or secure features the user requests, not for cross-site advertising or behavioral profiling.

Vercel Speed Insights is cookie-free and receives anonymous performance measurements such as an approved public page route, load timing, country, browser, operating system, network type, and device category. Aestro excludes query strings and account, invite, shared-link, workspace, admin, and other sensitive routes from these measurements and does not use them to reconstruct an individual's browsing session.

Retention

  • Active account and workspace records are kept until the workspace owner deletes them, the account is deleted, or the service relationship ends.
  • The maximum production backup-retention period must be confirmed and published before EU production release.
  • Closed support and issue requests are automatically deleted after 24 months.
  • Application rate-limit records are automatically deleted after 30 days. Infrastructure security and access logs follow the shorter of operational need or each provider's published service retention, unless a specific incident requires preservation.
  • Public quote requests remain under the receiving workspace owner's control and are deleted with that workspace or earlier when the owner removes them.
  • Session-only browser values expire with the browser session. Persistent functional preferences and demo data remain on that device until Aestro replaces or removes them, or the user clears the site's browser storage.
  • Exports downloaded by a user are controlled by that user and are not automatically deleted by Aestro.

Information may be retained longer only when reasonably necessary for a legal claim, fraud or security investigation, or a legal obligation. It is then isolated from ordinary use where practical.

Security

Aestro uses account authentication, workspace-scoped access checks, database row-level security, private server credentials, same-origin protections, rate limits, restrictive browser security headers, encrypted transport, and access-controlled file storage. No online service can guarantee absolute security.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your information, and to withdraw consent without affecting earlier lawful processing. You may also complain to your local data protection authority.

Signed-in users can export their account data, and workspace owners can export each workspace, in Settings. Account deletion is available in Aestro account settings and permanently removes the account and owned workspace from active systems. Full instructions, file-export limits, and request routes are on the Data Rights page.

Children

Aestro is a professional production workspace and is not directed to children. Do not create an account if you are under 16, and do not store information about a child unless you have a lawful work-related reason and the authority required in the relevant country.

European representative

EU representative details must be added before Aestro regularly offers the service to people in the EEA unless a documented GDPR Article 27 exception applies.

Changes and contact

Material changes will be dated here and, when appropriate, communicated in the product or by email. Questions and privacy requests should be sent to the privacy contact shown here once production configuration is complete.