Data processing and subprocessors

What we do with data that belongs to you, who else touches it, and what notice you get before that changes.

The commitments

We process on your instructions
Where you are the controller of personal data you bring here — your client contacts, the audience data you upload — we process it to run the marketplace and for nothing else. We do not sell it, we do not use it to train models, and we do not use it to build a product that competes with you.
People who can see it are named and logged
Staff access is role-based and every consequential action writes a row naming who did it and why. Anything that moves money or changes an account asks for the password again, not only the session.
You can take your data out, and have it removed
Settings → Privacy exports everything held about you as JSON, and erases your account on request. Erasure keeps the bookkeeping — orders, ledger entries, invoices — because both the tax authority and your counterparty have a claim on those, and removes the person from it.
Retention is enforced, not documented
Per-visitor tracking rows are deleted after 180 days by a nightly job. Sign-in history keeps its shape for a year and loses its identifying half when an account is erased.
Breach notification
If personal data you control is exposed, we tell you without undue delay and in any case within 72 hours of becoming aware, with what we know at the time rather than after an investigation completes.

Subprocessors

Every third party that processes customer data on our behalf. We give 30days’ notice before adding or replacing one, and you may object in that window — write to us and we will tell you what your options are, including ending the contract if we cannot reach an arrangement.

WhoWhat forWhereWhat reaches them
Stripe Payments Europe, Ltd.Card payments, payouts to sellers, and the identity checks a regulated payment institution has to run.Ireland, with transfers to the United States under Stripe’s own safeguards.Name, email, billing address, bank or card details, payout amounts.
Resend, Inc.Transactional email — order notifications, receipts, password resets.United States.Email address, name, and the contents of the message sent.
goodsrv.de (VPS hosting)The servers this platform runs on, and the database it stores everything in.Germany.Everything held in the product: accounts, orders, messages, measurement.
Cloudflare, Inc.DNS, TLS termination and protection against denial-of-service traffic.Global edge network; traffic is served from the nearest location.IP address, request headers and the URL requested.
Object storage (S3-compatible)Files uploaded to the product: creatives, logos, dispute evidence.European Union.Whatever a customer uploads, plus the account that uploaded it.

Asking for a signed DPA

These terms apply to every account without anybody signing anything. If your legal team needs them on paper — or needs your own paper signed — write to us and we will do it. What we will not do is agree to terms the product does not actually meet, which is why the list above says what the code does rather than what sounds reassuring.

See also marketplace policies and platform status.