Privacy notice
Effective:
Nightly Software (“Nightly”, “we” or “us”) is responsible for the personal data described in this privacy notice. It explains what we collect, why we use it, who we share it with and how to exercise the rights granted by Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), published in the Official Gazette of the Federation on March 20, 2025.
It applies to nightlysoftware.com, our free tools, the Moneta plugin and the services you hire us for. It doesn’t apply to data we handle on behalf of our clients inside the systems we build or run for them: in those cases we act as a processor, and each client’s own privacy notice applies.
1.Who is responsible
The data controller is Nightly Software, a software development studio based in the state of Guanajuato, Mexico. We don’t have an office open to the public: we meet clients in person in the Bajío region and by video call everywhere else.
- Privacy email. contacto@nightlysoftware.com. Send ARCO requests, consent withdrawals and any questions about this notice here.
- WhatsApp. +52 462 221 2236, for general questions.
- Who handles requests. Nightly’s founders handle privacy requests directly.
2.Personal data we collect
We only collect what each interaction needs. Most of it comes from you; some is generated when you use the site or our tools. We don’t ask for sensitive personal data, such as information about your health, ethnic origin, beliefs, political opinions or sexual orientation, and we ask you not to send it to us.
- Visiting the site. Cloudflare, which hosts and protects the site, processes technical data about each visit: your IP address, browser and device type, the page requested and the date and time. We don’t use analytics or advertising tools, and we don’t build visitor profiles.
- Forms and WhatsApp. Our forms don’t store anything. They open WhatsApp with a pre-filled message containing what you typed (name, company, email or phone, the service you’re interested in and your message). We only receive it if you choose to send it, along with your number, your WhatsApp profile name and any files you share.
- Email. When you write to us, we receive your email address, the name attached to it and the content of your message and any attachments.
- Booking a consultation. The calendar on our booking page is provided by Cal.com and loads from its servers, which receive technical data about your visit. When you book, you share your name, email, the date and time you chose, your time zone and any notes you add. Calls take place on Google Meet.
- Payments. Website packages and Moneta licenses are paid on Stripe’s secure checkout page. Stripe processes your card details, and we never see them in full. Stripe shares your name, email, the product or plan, the amount, the currency, the payment status, transaction references and, where applicable, your billing country or postal code with us, and shows us limited card details such as the brand and last four digits.
- Moneta licenses. For each license we record the plan, billing cycle, currency, language, amount, status and expiry date, the buyer’s name and email, the Stripe references and the domains where it’s activated. Our database stores the license key only as a hash, a fingerprint that can’t be turned back into the key.
- The Moneta plugin. When the plugin activates, deactivates or checks a license, or looks for updates, it sends our server the license key, the WordPress site address and the plugin version; update checks also include the PHP and WordPress versions. Moneta doesn’t send us your media files, your storage credentials or any data about your site’s visitors.
- Free tools. Depending on the tool, we receive the files, links or searches being processed. See “Free tools” below for details.
- Clients. When you hire us, we handle the contact details of the people we work with (name, role, email and phone), project messages and documents and, if you ask for an invoice, your tax details: RFC, legal name, tax regime and postal code.
3.How we use personal data
We use personal data for these primary purposes, which we need to provide what you ask for:
- Answering your messages and questions on WhatsApp or by email.
- Scheduling, holding and following up on your free consultation.
- Preparing proposals and quotes, and entering into and performing service contracts.
- Taking payments, sending purchase confirmations and delivering and managing Moneta licenses: activations, renewals, updates and support.
- Running the free tools.
- Issuing invoices when you ask for them and meeting our tax and legal obligations.
- Protecting the site, our servers and the people who use them from fraud, abuse and attacks.
Unless you object, we may also use your contact details for these secondary purposes, which the service doesn’t need:
- Occasionally sending news about our services, tools and Moneta.
- Asking for feedback on our work or inviting you to share a testimonial. We never publish a testimonial with your name without your express permission.
4.Consent and legal basis
We process personal data with your consent. Under Mexican law, that consent is tacit when, with this notice available to you, you write to us, book a call or buy something without objecting (article 7 of the Law).
Our primary purposes don’t require consent when they’re needed to fulfill our legal relationship with you or a legal obligation, such as processing a payment, delivering a license or issuing an invoice (article 9). That’s also why the payment data we receive from Stripe, limited to what each purchase needs, doesn’t require additional express consent. Secondary purposes, on the other hand, rely only on your consent, and you can turn them down without affecting the service.
You can withdraw your consent at any time, without retroactive effect, as explained below.
5.Free tools
- Dither Studio. Runs entirely in your browser: your images and videos never leave your device. Settings you want to keep are downloaded as a file.
- Metadata Inspector. The file you choose travels over an encrypted connection to our server, where it’s stored temporarily while ExifTool reads, edits or cleans it, and it’s deleted once you get the result. Its metadata may contain personal data such as GPS location, names or dates. We don’t keep files in any database, we don’t look at them and we don’t use them for anything else.
- Media Downloader. Our server receives your links, fetches the media from the source platform and sends you the file; the server’s copy is deleted once it’s sent. We don’t keep a history of links tied to you. The thumbnail shown in the tool loads directly from the source platform, which may see your IP address.
- Map Generator. Your searches go through our server, which forwards them to OpenStreetMap’s public services (Nominatim and Overpass) without your IP address. The map itself is drawn in your browser.
The tools don’t require an account. As on the rest of the site, our servers may log technical data about each request for security and to prevent abuse.
6.Who we share it with
We don’t sell or rent personal data. We share it only with providers that help us operate and handle it on our behalf, or with services you use yourself to reach us:
| Provider | What we use it for | Data it receives |
|---|---|---|
| Cloudflare | Hosting and protecting the site, and receiving and forwarding email sent to us | Technical browsing data and incoming email |
| Cloud server provider | Running our payments and licensing API and the free tools | API requests and the files, links and searches the tools process |
| Stripe | Processing payments and subscriptions | Name, email, payment details, product and amount |
| Convex | Moneta license database | License details, name, email and activated domains |
| Email provider | Our inbox and sending purchase confirmations and licenses | Email address, name and message content |
| Cal.com | Booking calendar | Name, email, date, time, time zone and notes |
| Google Meet video calls and our calendar | Name, email and anything shared during the call | |
| WhatsApp (Meta) | WhatsApp conversations | Number, profile name, messages and files |
| OpenStreetMap | Map Generator searches | Only the search text |
Stripe, Cal.com, Google and WhatsApp also process data as controllers of their own services, under their own policies: Stripe, Cal.com, Google and WhatsApp.
Transfers. We don’t make any transfers that require your consent. We could only disclose data to third parties without it in the cases allowed by article 36 of the Law; for example, when a law or a competent authority requires it, or when it’s needed to perform our contract with you or to defend a right in court.
7.Data stored outside Mexico
Several of these providers run servers outside Mexico, mainly in the United States and Europe, so your data may be stored or processed there. We choose well-established providers with security measures suited to their scale, and we share only what each service needs.
8.How long we keep it
We keep personal data only while it serves the purposes in this notice. After that we block it, meaning we keep it unused and only to deal with possible liabilities, and we delete it once the legal periods end.
| Data | Period |
|---|---|
| Messages from people who don’t become clients | Up to 2 years after the last contact |
| Consultation bookings | Up to 2 years after the call |
| Client details, contracts, payments and invoices | For the whole relationship and 5 years after it, for tax and commercial obligations |
| Moneta licenses | While the license exists and up to 5 years after it ends |
| Files and links processed by the tools | Deleted when each job finishes |
| Server technical logs | Short periods; overwritten automatically |
9.Your ARCO rights
You have the right to access your data and learn how we use it, to rectify it if it’s inaccurate or incomplete, to cancel it so we no longer hold it, and to object to its use for a legitimate reason. These are your ARCO rights, and using one doesn’t stop you from using the others.
To exercise them, you or your representative can email contacto@nightlysoftware.com with the subject “ARCO rights” and include:
- Your name and an email address or other way to receive our answer.
- A copy of your ID or, if someone represents you, proof of their authority and their ID.
- The right you want to exercise and the data it concerns; for access, just tell us what you’d like to know. For a correction, include the change and any document that supports it.
- Anything that helps us find your data, such as the email you used to buy or the Stripe reference.
We’ll reply within 20 business days of receiving your request. If it’s granted, we’ll carry it out within 15 business days of our reply. When justified, each period can be extended once by the same length, and we’ll let you know. For access requests, we send your data as an electronic file through the same channel you used.
Exercising your rights is free; we could only charge for reproduction or shipping if you ask for physical copies. We may turn down a request in the cases the Law allows, for example if your identity can’t be verified or a legal obligation requires us to keep the data, and we’ll always explain why.
10.Withdrawing consent and limiting use
You can withdraw your consent at any time by emailing contacto@nightlysoftware.com with the subject “Withdraw consent” and the same details as an ARCO request; we reply within the same periods. Withdrawal isn’t retroactive and, if it covers data we need for an active service such as a Moneta license, we may no longer be able to provide it.
You can also limit how your data is used or disclosed:
- Ask us to stop sending news or feedback requests. We add you to an internal opt-out list.
- Use our free tools without giving us any contact details, since they don’t require an account.
- Clear local storage and block cookies in your browser, as explained in our Cookie policy.
11.Cookies and local storage
Our site doesn’t set its own cookies or use analytics or advertising tools. It only keeps two preferences in your browser’s local storage: your language and your theme (light or dark). Cloudflare, Cal.com and Stripe may use their own cookies for security and to make their services work. See our Cookie policy for details.
12.Security
We use reasonable administrative, technical and physical measures to protect personal data from damage, loss, alteration, destruction and unauthorized use, access or processing. For example, the site and our API run over encrypted connections (HTTPS), access to information is limited to the people who need it, license keys are stored as hashes and our most sensitive endpoints have limits against abuse.
No measure is foolproof. If a security breach significantly affects your rights or interests, we’ll tell you right away so you can take the steps you need. Everyone involved in handling your data must keep it confidential, even after their relationship with us ends.
13.Children
Our services are meant for businesses and adults, and we don’t knowingly collect data from anyone under 18. If you’re a parent or guardian and believe a minor has given us personal data, contact us and we’ll delete it.
14.If you’re outside Mexico
Nightly operates from Mexico and handles personal data under Mexican law. If you live elsewhere, your local law may give you additional rights. In the European Economic Area, the United Kingdom and places with similar laws, these generally include data portability, restricting processing and lodging a complaint with your local data protection authority. Where those laws ask for a legal basis, we rely on performing our contract with you, our legitimate interest in running and securing our services, our legal obligations and, for optional messages, your consent.
To exercise any of these rights, email contacto@nightlysoftware.com and we’ll handle your request under the law that applies to you.
15.Changes to this notice
We may update this notice when our services, our providers or the law change. The current version will always be on this page with its effective date, and if a change is significant and we have your email, we’ll also let you know there. If we ever want to use your data for a new purpose, we’ll ask for your consent again.