MikroTik Manager

Privacy Policy

Last updated: 20 September 2026

1. Data Controller

The controller of personal data processed via this website (mikr.app) is:

Ihor Hreskiv, sole proprietorship «mtik Ihor Hreskiv»
ul. Starowiślna 20/3, 31-032 Kraków, Poland
NIP: 6762659456
E-mail: ihor@hreskiv.pl

2. What we process and why

  • Billing data (name, e-mail, company, address, VAT/NIP) — provided at checkout. Purpose: issuing the licence and a VAT invoice. Legal basis: Art. 6(1)(b) and (c) GDPR (contract and legal obligation).
  • Licence-delivery data (e-mail) — to send the licence key and update notifications. Legal basis: Art. 6(1)(b) GDPR.
  • Technical / analytics data (IP address, browser, page usage) — collected via cookies, only with your consent. Legal basis: Art. 6(1)(a) GDPR.
  • Website usage statistics (pages visited, referrer, browser, screen size, country) — collected by our own Umami instance, which sets no cookies and stores nothing in your browser. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in knowing how the site is used).

MikroTik Manager is self-hosted software. Data about your routers and your network is processed entirely within your own installation — we never receive or store it.

3. Cookies

We use analytics cookies (Google Analytics 4), loaded only after your explicit consent. Umami analytics runs without cookies. See our Cookie Policy for the full list. You can change your choice anytime via “Cookie settings” in the footer, or .

4. Recipients and processors

  • Stripe Payments Europe, Ltd. (Ireland) — payment processing.
  • Amazon Web Services (SES, eu-central-1 / Frankfurt) — transactional e-mail delivery.
  • ifirma S.A. (Poland) — invoicing.
  • Hosting providers — the servers this website, the licence system and our analytics run on, located in the United Kingdom and in Poland. They hold the data described above on our behalf and do not use it for any purpose of their own.
  • Google LLC — only with your consent; data may be transferred outside the EEA under the European Commission’s Standard Contractual Clauses.
  • State authorities — to the extent required by law (e.g. the tax office).

5. Retention

  • Billing / invoice data — 5 years, in line with tax law.
  • Analytics cookies — up to 2 years, or until you withdraw consent.
  • E-mail correspondence — up to 3 years from the last contact.

6. Your rights

Under the GDPR you have the right to: access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal). You may also lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

To exercise any of these rights, write to ihor@hreskiv.pl.

7. Data Processing Agreement (B2B)

Enterprise customers who require a Data Processing Agreement (DPA) can request one at ihor@hreskiv.pl.

8. The iPhone app

The iPhone app is a client for a MikroTik Manager server that you or your organisation run. It connects only to the server addresses you enter. We, the controller named in section 1, do not receive, store or otherwise process any personal data through the app.

  • No collection. The app contains no analytics, advertising or tracking code and sends nothing to us or to any third party.
  • Your server. Your username, password and second-factor code are sent only to the server you enter, in order to sign in. Everything the app shows is read from that server. Processing on it is the responsibility of whoever operates it.
  • Stored on your phone. Sign-in tokens are kept in the iOS Keychain, readable only while the phone is unlocked and not carried over to another device from a backup. If you turn on Face ID in the app, the tokens can be read only after iOS confirms your face or passcode; the app never receives Face ID data. Outside the Keychain the app keeps the server addresses you saved, the username last used for each, the certificate fingerprints you accepted, and whether Face ID is on.
  • Removing it. Signing out of a server, or removing a server from the list, deletes its tokens from the phone. Deleting the app removes its other stored data. iOS may keep Keychain items after an app is deleted, so sign out first if you want the tokens gone as well.
  • Demo. The built-in demo uses sample data included in the app and makes no network connections.
  • Apple. If you allow sharing with app developers in your iPhone’s Analytics settings, Apple may give us aggregated usage statistics and crash reports. Apple controls this, and you can turn it off in Settings.

9. Changes to this policy

We may update this policy from time to time. The current version, with its date, is always available on this page.