NewMeet the Virtual Facility: your terminal, live in real time.See it in action
Logo Stowlog

Privacy Policy

Last updated: August 7, 2026


1. Identity of the Data Controller

This Privacy Policy applies to the digital services and platform operated by:

Estudio Cactus Media S.L.

Rda. Circunvalación 188, Castellón de la Plana, Spain

CIF: B12962957

Email: support@stowlog.com

Depending on the type of data and activity, Estudio Cactus Media S.L. (Stowlog", "we", "our", or "us") may act as either:


2. Scope of Application

This Policy applies to:

Each Facility that operates within Stowlog may define its own data collection requirements (e.g., ID photo, driver's license, or passport number). Stowlog processes that data on behalf of the Facility but does not determine its content or purpose.


3. Categories of Data Processed

A. Data Controlled by Stowlog (as Data Controller)

Collected when Users register, authenticate, or interact with the Platform at a general level:


B. Data Processed on Behalf of Facilities (as Data Processor)

Collected only when the User selects or interacts with a Facility:

Each Facility decides:

Stowlog stores and secures this data but does not use it for any purpose other than providing the contracted service.


4. Purpose and Legal Basis of Processing

PurposeLegal BasisController
Account creation, authentication, and user managementContract performance (Art. 6.1(b) GDPR)Estudio Cactus
Platform maintenance, analytics, and securityLegitimate interest (Art. 6.1(f))Estudio Cactus
Marketing and contact management (excluding mobile numbers provided for identity verification)Consent or legitimate interest (Art. 6.1(a)/(f))Estudio Cactus
Supplier management and billingLegal and contractual obligations (Art. 6.1(b)/(c))Estudio Cactus
Facility-specific data collection and processingExecution of contract between Facility and UserFacility (Stowlog acts as Processor)
Legal compliance and safety record retentionLegal obligation or legitimate interest (Art. 6.1(c)/(f))Facility / Estudio Cactus

5. Data Retention, Deletion, and Pseudonymization

5.1 General Retention

5.2 Account Deletion Requests

When a user requests the deletion of their account:

5.3 Dual Retention Model for Facility Records

5.4 Facility Notification and Autonomy

5.5 Legal Basis for Retention

This process complies with Article 17(3) GDPR, which permits retention or pseudonymization when:

All deletion and pseudonymization actions are logged for audit and accountability purposes.


6. Data Sharing and Recipients

Stowlog does not sell or rent personal data. Data may be shared only with:

All data is hosted in MongoDB Atlas (AWS) data centers located within the European Union or in countries with adequate data protection guarantees under GDPR. Where a sub-processor necessarily processes data outside the European Economic Area in order to perform its service — for example, transmitting a verification message to a mobile number — that transfer is governed by the mechanism stated for that sub-processor in the list below.

The current list of sub-processors involved in providing the Stowlog platform, together with their location and applicable transfer mechanisms, is available at https://www.stowlog.com/legal/sub-processors.

6.1 Mobile Numbers and SMS Consent Data

We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, except the communications provider that transmits the messages on our behalf and where disclosure is required by law.

Your mobile number is disclosed only to processors acting on our documented instructions — our hosting and database providers, and Twilio Inc. as our SMS delivery provider — and to your mobile network operator, which necessarily processes the message in order to deliver it. Twilio processes your mobile number and the message content for the sole purpose of transmitting the verification messages you have requested, under a written data processing agreement. Twilio may not use your mobile number for its own purposes and may not sell or rent it; it may engage its own sub-processors and route the message through mobile network operators, solely in order to deliver it and under equivalent contractual obligations.

Your mobile number and the content of the verification message are transferred to Twilio Inc. in the United Statesunder the European Commission's Standard Contractual Clauses (Decision 2021/914) together with Twilio's EU-US Data Privacy Framework certification. A copy of these safeguards is available on request from support@stowlog.com. Where a verification code is sent to a number outside the European Economic Area, the message necessarily transits the network of the destination operator in that country. The details of this engagement are listed at https://www.stowlog.com/legal/sub-processors.


7. Processor Obligations (Article 28 GDPR)

When acting as a Data Processor, Stowlog shall:


8. Rights of Data Subjects

Users may exercise the following rights under GDPR:

How to exercise your rights:

Stowlog will assist Facilities in responding to such requests when necessary.


9. Data Security

Stowlog applies security measures consistent with ISO 27001 certification and industry standards, including:

In the event of a data breach, Stowlog will notify affected parties and relevant authorities in compliance with GDPR Articles 33–34.


10. Cookies and Analytics

Stowlog uses necessary and analytical cookies to ensure functionality and improve user experience.

Details about cookie types and preferences are available in the Cookies Policy at https://www.stowlog.com/legal/cookies.


11. SMS and Text Message Communications

Purpose. Stowlog operates a single text messaging program: the delivery of one-time security codes used to verify your identity when you sign in to your Stowlog account or confirm a security-sensitive action. We do not send marketing, promotional, or operational text messages under this program.

Consent. You opt in inside the Stowlog App — during registration, or later when you add or change a mobile number in your account settings — when you provide your mobile number and affirmatively agree to receive verification messages at that number. The consent control is separate from acceptance of our Terms and Conditions and of this Policy, is not selected by default, and is optional: you may decline it, or withdraw it later, and continue to use Stowlog, with identity verification carried out by a one-time code sent to the email address on your account. We record the date and time of your consent, the mobile number you provided, the IP address from which the consent was submitted, the account it relates to, and the wording of the consent screen shown to you at that moment. Your consent applies only to the Stowlog verification program and is not transferable or assignable to any other sender.

Data processed. For this program we process your mobile number, the mobile network carrier and country associated with it, the delivery status of each message, and the consent and opt-out record described above. Mobile numbers provided for identity verification are not used to send marketing or commercial communications of any kind, under this or any other program. The legal basis is the performance of our contract with you (Article 6(1)(b) GDPR), as these messages form part of account authentication.

Retention. Your mobile number is deleted or anonymized together with your account under section 5.2 of this Policy. Message delivery logs are retained for the period needed to operate, secure, and troubleshoot the service, on the basis of our legitimate interest (Article 6(1)(f) GDPR). The record of your consent, and of any opt-out, is retained for the period needed to evidence it. An opt-out record is retained after account deletion, limited to what is strictly necessary so that no further message is sent to a number that has opted out.

Frequency and cost. Message frequency varies. You receive one message each time a verification code is requested for your account. Standard message and data rates may apply.

Opt-out and help. To stop receiving messages, reply STOP at any time; we also honor STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT. To start receiving them again, reply START or UNSTOP. For assistance, reply HELP to the number from which you received the message, or contact us at support@stowlog.com.

Delivery. Carriers are not liable for delayed or undelivered messages.

The full terms of this messaging program are available at https://www.stowlog.com/legal/sms-terms.


12. Relationship with Facilities

Each Facility operating within Stowlog is an independent organization that controls its own data. When you provide data through Facility forms or modules:

Facilities may have their own privacy notices — we recommend reviewing them for more details on their specific use of your data.


13. Source of Data

Personal data may be obtained directly from users, through Facility interactions, or via automated logs and cookies generated by use of the Platform. Optional geolocation data is only collected if the Facility enables it and the user consents.


14. Minors

The Stowlog Platform is intended for professional use only and is not directed at minors under 18 years old. If Stowlog becomes aware of accidental registration by a minor, the account will be deleted.


15. Updates to this Policy

Stowlog may update this Policy periodically to reflect legal, technical, or business changes.All updates will be published at https://www.stowlog.com/legal/privacy. Continued use of the Platform implies acceptance of the revised version.


16. Contact and Supervisory Authority

For questions or complaints regarding data protection, contact: support@stowlog.com

If you are not satisfied with our response, you may file a complaint with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es.


Estudio Cactus Media S.L.

Rda. Circunvalación 188, Castellón de la Plana, Spain

www.stowlog.com