Data processing and subprocessors
What we do with data that belongs to you, who else touches it, and what notice you get before that changes.
The commitments
- We process on your instructions
- Where you are the controller of personal data you bring here — your client contacts, the audience data you upload — we process it to run the marketplace and for nothing else. We do not sell it, we do not use it to train models, and we do not use it to build a product that competes with you.
- People who can see it are named and logged
- Staff access is role-based and every consequential action writes a row naming who did it and why. Anything that moves money or changes an account asks for the password again, not only the session.
- You can take your data out, and have it removed
- Settings → Privacy exports everything held about you as JSON, and erases your account on request. Erasure keeps the bookkeeping — orders, ledger entries, invoices — because both the tax authority and your counterparty have a claim on those, and removes the person from it.
- Retention is enforced, not documented
- Per-visitor tracking rows are deleted after 180 days by a nightly job. Sign-in history keeps its shape for a year and loses its identifying half when an account is erased.
- Breach notification
- If personal data you control is exposed, we tell you without undue delay and in any case within 72 hours of becoming aware, with what we know at the time rather than after an investigation completes.
Subprocessors
Every third party that processes customer data on our behalf. We give 30days’ notice before adding or replacing one, and you may object in that window — write to us and we will tell you what your options are, including ending the contract if we cannot reach an arrangement.
| Who | What for | Where | What reaches them |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Card payments, payouts to sellers, and the identity checks a regulated payment institution has to run. | Ireland, with transfers to the United States under Stripe’s own safeguards. | Name, email, billing address, bank or card details, payout amounts. |
| Resend, Inc. | Transactional email — order notifications, receipts, password resets. | United States. | Email address, name, and the contents of the message sent. |
| goodsrv.de (VPS hosting) | The servers this platform runs on, and the database it stores everything in. | Germany. | Everything held in the product: accounts, orders, messages, measurement. |
| Cloudflare, Inc. | DNS, TLS termination and protection against denial-of-service traffic. | Global edge network; traffic is served from the nearest location. | IP address, request headers and the URL requested. |
| Object storage (S3-compatible) | Files uploaded to the product: creatives, logos, dispute evidence. | European Union. | Whatever a customer uploads, plus the account that uploaded it. |
Asking for a signed DPA
These terms apply to every account without anybody signing anything. If your legal team needs them on paper — or needs your own paper signed — write to us and we will do it. What we will not do is agree to terms the product does not actually meet, which is why the list above says what the code does rather than what sounds reassuring.
See also marketplace policies and platform status.