Privacy

Last updated 24 August 2026

Who is responsible

Andreas Oberdammer, Beerengasse 4, 4616 Weißkirchen an der Traun, Austria. Questions about your data: [email protected].

What we store on your device

Everything below is strictly necessary — it exists to deliver something you asked for, such as staying signed in. Under §165(3) TKG 2021 that does not require your consent, but you are entitled to know about it. We run no analytics, no advertising and no tracking pixels, so there is currently nothing optional to accept or refuse.

NameTypeSet byPurposeLifetime
__session, __client_uat, __clerk_db_jwt, clerk_active_contextCookieClerkKeeps you signed in and identifies your session.Session to 1 year
ao-themelocalStorageTelagateRemembers whether you chose light or dark.Until cleared
ao-consentlocalStorageTelagateWould remember your cookie choice. Not created at present — there is nothing optional to decide about, so no banner is shown.Until cleared

Public pages — the link pages people share — set no cookies at all. If you only ever visit someone's page, nothing is stored on your device by us. Your IP address is still briefly handled on our server — see “Keeping the service usable” below.

Keeping the service usable

Every request to our API — including the one your browser makes to load someone's public page — is counted against a short-term limit, so that no single source can flood the service. Counting needs your IP address, which Cloudflare passes to us with the request. We use it for nothing else: it is held in memory on the server, never written to the database, never linked to an account, and discarded after two hours at the very latest. It is not used to identify you, to profile you, or to measure visitors. Legal basis: our legitimate interest in keeping the service available and resisting abuse (Art. 6(1)(f) GDPR).

What we hold in the database

If you create an account: your email address, an account identifier from Clerk, and whatever you put on your page — links, headings, your handle. If you subscribe: a subscription identifier, its status, and the brand and last four digits of your card. We never see or store your full card number. If you report a page: the report itself — which page, the reason, anything you wrote, and your email address if you chose to leave one for a confirmation. Reports are kept as long as moderation and legal obligations require (Art. 6(1)(c) and (f) GDPR, DSA Art. 16).

Who processes it

ProcessorPurposeLocationTransfer basis
Clerk, Inc.Authentication and session managementUnited StatesEU–US Data Privacy Framework (self-certified), plus SCCs in its DPA
Stripe, Inc.Payment processing and invoicing. Where Stripe’s Managed Payments programme applies to a purchase, Stripe’s Link entity acts as merchant of record on the receipt and handles VAT.United StatesEU–US Data Privacy Framework (self-certified), plus SCCs in its DPA
Hetzner Online GmbHApplication server and databaseGermanyProcessing within the EEA
Cloudflare, Inc.Network routing (tunnel), DNS and image delivery (R2)United States / EU edgeEU–US Data Privacy Framework (self-certified), plus SCCs in its DPA
Functional Software, Inc. (Sentry)Error monitoring — receives a report when something breaks: the page, browser type and the technical error trace. Configured to exclude IP addresses and identifiers.United States (reports stored in the EU — Frankfurt)EU–US Data Privacy Framework (self-certified), plus SCCs in its DPA
Resend, Inc.Transactional email — abuse-report confirmations and failed-payment notices. Nothing promotional; every mail is one you asked for or your subscription needs.United StatesEU–US Data Privacy Framework (self-certified), plus SCCs in its DPA

When something breaks

If a page errors in your browser or on our server, a technical report goes to our error-monitoring service (Sentry, stored in Frankfurt): which page, which browser type, and the error trace. We have configured it not to record IP addresses or identifiers, it stores nothing on your device, and reports are deleted after 90 days. This is fault diagnostics, not analytics — nothing at all is sent while pages are working. Legal basis: our legitimate interest in keeping the service running (Art. 6(1)(f) GDPR).

Transfers to the United States

Clerk, Inc., Stripe, Inc., Cloudflare, Inc., Functional Software, Inc. (Sentry) and Resend, Inc. are US companies, so signing in, paying, loading pages, error reporting and receiving our emails involve transferring personal data outside the EEA. All are self-certified under the EU–US Data Privacy Framework, which the European Commission recognised as providing adequate protection in July 2023 (Decision (EU) 2023/1795).

You should know that this framework is under legal challenge: the EU General Court upheld it in September 2025, and an appeal is pending before the Court of Justice. Its predecessors, Safe Harbour and Privacy Shield, were both struck down. If the decision is annulled we will move to standard contractual clauses or to an EU-based provider, and say so here.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to its processing, and take it elsewhere. Deleting your account removes your page and its contents. Write to [email protected].

You can also complain to the Austrian Data Protection Authority (dsb.gv.at), or the authority where you live.

How long we keep it

Your account and page for as long as the account exists, then deleted. Payment records for as long as tax law requires — in Austria, seven years. Webhook logs for 90 days.