Privacy Policy
Last updated: [INSERT DATE].
1. Controller
The data controller is [YOUR LEGAL NAME / COMPANY], [YOUR ADDRESS], Switzerland. Contact: [YOUR EMAIL]. This policy complies with the Swiss Federal Act on Data Protection (revFADP/nLPD) and, for users in the EU/EEA, the GDPR.
2. What we collect
(a) Information you provide: the display name, message, and color you attach to a pixel, and your email if you contact us. (b) Payment data: handled directly by Stripe — we do not see or store your full card number. (c) Technical data: standard server logs and, if enabled, privacy-friendly analytics (approximate region, device type, pages viewed).
3. Why we use it (legal bases)
To provide the Service and display your pixel (contract performance); to process payments (contract performance); to send you the email you requested or respond to inquiries (consent / legitimate interest); to prevent abuse and keep the Service secure (legitimate interest); and to comply with legal and accounting obligations.
4. Public display
The name, message, and color you submit are shown publicly on the Service by design. Do not submit anything you are not comfortable making public. Do not include sensitive personal information.
5. Sharing and processors
We use trusted processors solely to run the Service: Stripe (payments), Supabase (database hosting), our hosting provider (e.g. Vercel), and an email provider (e.g. Resend) for transactional and operational emails. Some processors may store data outside Switzerland/the EU; where they do, appropriate safeguards (such as Standard Contractual Clauses) apply. We do not sell your personal data.
6. Retention
Pixel content is retained while displayed and may be archived afterward. Payment and accounting records are kept for the period required by Swiss law (generally up to 10 years). You may request earlier deletion of personal content subject to those obligations.
7. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, and (for EU users) request data portability. EU users may lodge a complaint with their supervisory authority; Swiss users may contact the Federal Data Protection and Information Commissioner (FDPIC). To exercise any right, email [YOUR EMAIL].
8. Cookies
We use only cookies strictly necessary to operate the Service and process payments. If we later add non-essential analytics or marketing cookies, we will request your consent first via a cookie banner.
9. Children
The Service is not directed at children under 16. We do not knowingly collect their data. If you believe a child has provided data, contact us for removal.
⚠️ Template notice: replace every [BRACKETED] field and confirm the list of processors matches what you actually deploy. Have a Swiss data-protection professional review before launching at scale.