Privacy Policy
1. Controller and roles
Controller within the meaning of Art. 4 (7) GDPR for this website, the dashboard and billing is: Vladislav Reshetnikov c/o Julia Andreyeva, Americanas 4, flat 404 4048 Limassol Cyprus Email: vladresh09@gmail.com Important distinction: for the withdrawal data of your end customers, you — the shop operator — are the controller, and we act solely as your processor (Auftragsverarbeiter) under a data processing agreement (AVV, Art. 28 GDPR). For your own account and billing data, we are the controller.
2. What this policy covers
We process personal data only to the extent necessary to provide a functional website and our service, and always in accordance with the GDPR. This policy explains what we process when you visit the site, run the dashboard or subscribe — and how we handle the withdrawal data your customers submit through the widget.
3. Legal bases (Art. 6 GDPR)
We rely on the following legal bases: • Performance of a contract / pre-contractual steps — Art. 6 (1)(b): operating your account and the service. • Legitimate interests — Art. 6 (1)(f): secure operation, hosting, abuse prevention and error monitoring. • Legal obligation — Art. 6 (1)(c): statutory retention duties (e.g. tax). • Consent — Art. 6 (1)(a): only where we explicitly ask for it (you can withdraw it at any time).
4. Hosting and server log files
The website and the service API are hosted on Vercel, with the application running in the EU region fra1 (Frankfurt). With every request the infrastructure processes server log data such as IP address, date and time, the requested resource and the user agent, for the purpose of secure and stable operation (Art. 6 (1)(f) GDPR).
5. Account and login (dashboard)
To use the dashboard you log in with your email address via a one-time code / magic link (passwordless). Authentication is handled by Supabase. We process your email address and authentication metadata to operate your account (Art. 6 (1)(b) GDPR).
6. Withdrawal widget data (processing on behalf of the shop)
When an end customer submits a withdrawal through the widget, we process their name, email address and order number in order to create the legally required confirmation (§ 356a BGB) on a durable medium (§ 126b BGB). Name and email are encrypted at rest with AES-256-GCM; only the order number is stored in plain text. The visitor's IP address is used transiently for rate limiting and is not stored in identifiable form; where an IP is recorded for audit purposes it is anonymised first. We process this data exclusively as your processor under the AVV, which you can review and accept in the dashboard.
7. Email delivery (durable medium)
Confirmation emails are sent via Resend as a durable medium pursuant to § 126b BGB. The recipient's email address and the message content are processed solely to deliver the confirmation; EU sending is enforced in the provider configuration.
8. Payment processing (LemonSqueezy as Merchant of Record)
Payments are handled by LemonSqueezy, which acts as the Merchant of Record. This means LemonSqueezy is the seller of record: it collects the payment, issues the invoice and handles VAT/taxes on its own responsibility. At checkout we pass only an internal organisation identifier (org_id). In return we receive the subscription status, the plan, the billing email address and a customer/subscription id — just enough to activate or deactivate your widget. We never receive or store full card data. The payment and billing data you enter is processed by LemonSqueezy under its own privacy policy: https://www.lemonsqueezy.com/privacy. Legal basis: Art. 6 (1)(b) GDPR.
9. Processors and subprocessors
We use the following service providers. We conclude a data processing agreement (AVV/DPA) with each of them; where a provider may process data outside the EU/EEA, transfers are safeguarded by the EU standard contractual clauses (SCC). • Vercel — hosting & delivery of the app/API (execution region fra1, Frankfurt, EU; company based in the USA) → DPA + SCC. • Supabase — database & authentication, including encrypted PII and account data (EU region; company based in the USA) → DPA + SCC. • Resend — transactional email delivery (EU sending configured; provider based in the USA) → DPA + SCC. • Upstash — rate limiting (Redis); IP processed transiently and not stored (EU region) → DPA, SCC if applicable. • Sentry — error and performance monitoring (USA) → DPA + SCC. • LemonSqueezy — payment processing / Merchant of Record (USA); own controller for payment data → see section 8, SCC for any transfer. • DigiCert (Time-Stamping Authority, RFC 3161) — qualified timestamp of the daily Merkle root only; no personal data is transmitted, only a cryptographic hash (USA).
10. Cookies and local storage
We do not use advertising or tracking cookies and we do not profile you. We only use: • a language cookie ("lang", valid ~1 year) that remembers your DE/EN choice, mirrored in your browser's localStorage; • essential authentication cookies set by Supabase when you log in to the dashboard, including a temporary PKCE login cookie. These are technically necessary or based on the contract (Art. 6 (1)(f) and (b) GDPR), so no consent banner is required for them.
11. Retention and deletion
Account and billing data are kept for the duration of the subscription and for as long as statutory retention periods require (e.g. tax law). Withdrawal records are anonymised automatically after the configured retention period (180 days by default); the cryptographic hash is retained so the proof remains verifiable without any personal data.
12. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object, as well as the right to withdraw any consent with effect for the future. You also have the right to lodge a complaint with a supervisory authority. To exercise your rights, contact: vladresh09@gmail.com. For end-customer withdrawal data, please address the shop where you placed your order — that shop is the controller, and we will support it as its processor.
13. Data security
All connections are encrypted via TLS. Personal data in the withdrawal log is additionally encrypted at the field level with AES-256-GCM, data is hosted in the EU, and access is restricted to what is technically necessary.
14. Contact for data protection
For any questions about data protection or to exercise your rights, contact us at: vladresh09@gmail.com.
Questions or suggestions?
Write to us: vladresh09@gmail.com