Privacy policy
This page says what personal data this site handles, why, for how long, and what you can do about it. It is written to be read, not to be scrolled past. Last updated August 18, 2026.
Who is responsible
Stele Passport is a product of HunterTag S.r.l., VAT IT14244060969, Milano, Italy. HunterTag S.r.l. is the data controller for everything described on this page. For any question about your data, write to info@huntertag.com.
What this covers
This notice covers the public website, the pricing simulator, the public battery passport pages, account registration and sign-in, and the operator console. Where our customers put content into their own passports, a separate arrangement applies, described at the end of this page.
If you ask us to call you
The contact form asks for a company name, your name, a work email, and optionally a phone number and a message. We use these details to answer you and for nothing else. They are stored as a sales lead in our CRM so that whoever calls you back knows what you asked.
The legal basis is taking steps at your request before entering a contract, Article 6(1)(b) GDPR. Leaving the form empty has one consequence only: we cannot call you back.
If you run the pricing simulator
The simulator works without any personal data: you can read every number on the pricing page without telling us who you are. If you choose to leave contact details to continue the conversation, we store them with the estimate you generated, for the same purpose and on the same legal basis as a call request.
When a passport page is opened
Every time a passport page is served we keep an operational record: among other technical fields, a random trace code, the passport identifier, the path requested, whether the page was served or failed and with what message, the response time, and a coarse device class, meaning mobile, desktop or automated. That record exists to answer one question, “I scanned the battery and it did not work”, which cannot be answered without it.
What we deliberately do not put in that record: your IP address, your full browser signature, or anything that identifies you or your device. Reading a battery passport is anonymous. The legal basis for the record is our legitimate interest in keeping the service diagnosable, Article 6(1)(f) GDPR.
If you register for an account
To open an account you give us your company name, your VAT number, a billing address and a work email. We check the VAT number against the European Commission's VIES service and keep the receipt of that check.
We also verify a payment card, at a zero amount: no money is taken, and the card is kept on file with our payment provider for later billing. We never receive or store the card number ourselves, our payment provider handles it. At the same step we record which version of the terms you accepted and when.
The legal basis is taking steps at your request and performing the contract, Article 6(1)(b) GDPR, and, for the VAT check, compliance with a legal obligation, Article 6(1)(c). If you start a registration but do not finish it, the incomplete record is deleted after thirty days.
If you have a console account
Operators at our customers sign in to a console to manage their own passports. For those accounts we process a name, a work email, and sign-in events. Signing in uses a six digit code we email to you: there is no password to store or lose. A session is a row in our own database, not a token from a third party, and it is revoked the moment you sign out. The legal basis is the performance of the contract with your employer, Article 6(1)(b) GDPR.
Hosting logs
The providers that run our infrastructure keep standard server logs, which can include IP addresses, for security and operation of their platforms. We do not merge those logs with the records described above.
Cookies
The public pages of this site, passports included, set no cookies. There is no analytics script, no advertising, no tracking of any kind. The only cookies this site uses are the ones that carry a console sign-in: they appear when an operator signs in, they are strictly necessary for the session to exist, and they go away at sign-out. This is why there is no cookie banner: there is nothing to consent to.
Who processes data for us
We do not sell or share personal data with anyone for their own purposes. A short list of providers process it on our behalf, under data processing agreements:
- Railway, hosting of the application and its database
- Stripe, which verifies and, later, charges the payment card; Stripe handles the card details directly, we never receive them
- Brevo, which delivers our transactional email, the sign-in codes and account notifications; it processes the recipient address, name, subject and delivery events
- Odoo, the CRM and invoicing platform where contact requests and orders live
Some of these providers, or their sub-processors, are established outside the European Economic Area. Where personal data reaches them, it is protected by the European Commission's Standard Contractual Clauses or by the EU-US Data Privacy Framework, whichever applies to the provider concerned.
How long we keep things
| Data | Kept for | Why |
|---|---|---|
| Contact and call requests | 24 months, and on request | kept to follow up a slow procurement cycle, then deleted automatically; removed sooner whenever you ask |
| Pricing simulator leads | 24 months, and on request | same as contact requests, deleted automatically after 24 months or sooner on request |
| Registration details | account lifetime, or 30 days if abandoned | a completed registration becomes your account, an unfinished one is removed |
| Passport access records | 90 days | kept to diagnose failed scans, then no longer useful |
| Console accounts | duration of the customer contract | removed when the contract ends or the customer asks |
| Invoicing records | 10 years | required by Italian accounting law |
Your rights
Under the GDPR you can ask us for access to the data we hold about you, for a copy of it, for correction, for deletion, for restriction of processing, and you can object to processing based on legitimate interest. Write to info@huntertag.com and we will answer within one month. You can also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, at garanteprivacy.it, or with the authority of the country where you live or work.
We do not use automated decision making and we do not profile visitors.
Passport content belongs to its manufacturer
A battery passport describes a product, not a person. Where a manufacturer includes personal data in its own passport records, for example the name of a workshop that serviced a battery, the manufacturer is the data controller for that content and HunterTag S.r.l. processes it on the manufacturer's behalf, under a data processing agreement that is part of the customer contract.
Changes to this page
If what we collect or why changes, this page changes first, and the date at the top moves. We do not change this page to permit retroactively something it did not permit before.