Skip to content

Privacy Policy

Last updated: 1 August 2026

This Privacy Policy explains how Alacam IT (“we”, “us”), a sole proprietorship operating alacam.it and the PrintPilot desktop application, handles personal data. We designed our products to keep the amount of personal data we process to the minimum necessary to deliver the service and comply with EU GDPR and comparable US state privacy laws.

1. Data controller & contact

Alacam IT — sole proprietorship. Questions, access, deletion, or GDPR/CCPA requests: contact@alacam.it.

2. What we collect

  • Account data: email address, and — if you sign in with Google — your Google account email, name and profile picture URL provided by Google.
  • License data: your active plan, license key, subscription period, and monthly usage counter (number of print jobs sent). We do *not* keep a per-document history.
  • Device data: a hashed device identifier (SHA-256) for each machine you install PrintPilot on, used to enforce the one-trial-per-computer rule and the per-plan device limit.
  • Diagnostic reports: if you press “Send setup report” inside PrintPilot, the local installation log is emailed to us. You choose when to send it.

3. Google sign-in and Google API data

When you choose “Sign in with Google” in PrintPilot or on alacam.it, we request basic OAuth scopes (openid, email, profile) to authenticate you and create your account. Additionally, if you enable PrintPilot's automated email sending feature via Gmail, the desktop application requests the restricted Google OAuth scope https://www.googleapis.com/auth/gmail.send (gmail.send) solely to transmit printed PDF documents as email attachments directly from your own Gmail account without storing email message contents or inbox data on our servers. Alacam IT's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not allow humans to read it except with your explicit consent, for security investigations, or where required by law.

4. Google Workspace APIs Limited Use Disclosure

PrintPilot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not use, transfer, or sell Google user data (including raw, aggregated, or derived data) to create, train, or improve any foundational or generalized machine learning or artificial intelligence (AI/ML) models.
  • We do not share, transfer, or disclose Google user data to any third-party services.
  • PrintPilot operates as a local Windows service. All document processing, rule evaluation, and queue management happen entirely locally on the user's machine. Document contents and email recipient data are never transmitted to our cloud servers.

5. What we do NOT collect

  • We do not upload, read or store the contents of the documents you print.
  • We do not store the recipient email addresses you configure inside PrintPilot.
  • We do not track your Google Drive, Gmail, Contacts, or any other Google service.

6. How we use the data

  • Provide the service: authenticate you, issue and validate license keys.
  • Enforce plan limits (device count, monthly email quota, free trial per machine).
  • Send transactional emails (sign-up confirmation, password reset, receipts).
  • Respond to your support requests.

Performance of the contract with you (Art. 6(1)(b)) for account, license and usage data; our legitimate interest (Art. 6(1)(f)) in preventing abuse for the device hash and email blocklist; and your consent (Art. 6(1)(a)) for optional setup diagnostic emails.

8. Sub-processors

We use a small set of trusted vendors under Data Processing Agreements:

  • Lovable Cloud / Supabase — hosting, authentication, database (EU region).
  • Resend — transactional email delivery.
  • Paddle — payment processing and merchant-of-record for EU/US sales tax.
  • Google LLC — only when you actively use Google sign-in.

9. Retention

Account and license records are kept for as long as your account is active. If you delete your account, the record is marked as deleted and permanently erased no later than two (2) years afterwards. If an administrator hard-deletes the account, all associated data is removed immediately.

10. Your rights

You have the right to access, rectify, delete, restrict or export your personal data, and to object to processing. EU users may lodge a complaint with their national supervisory authority. California residents have equivalent rights under the CCPA/CPRA. To exercise any right, email contact@alacam.it. You can also delete your account at any time from your Alacam IT dashboard.

11. Security

Data is transmitted over TLS and stored in an EU-hosted managed Postgres database with Row-Level Security. Passwords are hashed by our identity provider. Device identifiers are only stored as SHA-256 hashes.

12. International transfers

Where personal data is transferred outside the EEA (for example to Google in the United States), we rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

13. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the latest version. Material changes will be communicated by email to registered users.