Privacy policy
This policy explains which data myfeedr processes when you have a website analysed, buy a banner set, or visit this site.
Controller
A data protection officer is not required under Art. 37 GDPR. Please send privacy requests to the email address above.
| Controller | Thomas Harnisch, Königskinderweg 74f, 22457 Hamburg |
|---|---|
| [email protected] |
What happens during an analysis?
When you enter an address, our server requests that page and reads publicly available design attributes: logo file, colour values, font families, page title, product names, prices, product images and a screenshot of the page. If that does not succeed completely, the page may be rendered in a headless browser or – if access is blocked and such a service is configured – fetched through a scraping service.
We store the entered address, the extracted attributes, the downloaded files and a timestamp. Without an account this data is deleted automatically after 7 days; with an account it stays attached to your project until you delete the project or your account.
- Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measure at your request).
- Anonymous analyses are limited to 3 per hour and IP address. This counter stores a hash of the IP address for 60 minutes (Art. 6 (1) (f) GDPR, abuse prevention).
- The analysed website is usually your own. Personal data of third parties published there (e.g. names in a legal notice) is not deliberately extracted and not stored.
AI-assisted evaluation of screenshots
If attributes are still missing after the automatic analysis (e.g. on pages built entirely in JavaScript), a cropped screenshot of the website may be sent to Anthropic PBC (San Francisco, USA) to detect logo position, colours or product details. Only the screenshot and the address are transmitted – no account data.
Anthropic processes the data as a processor under Art. 28 GDPR on the basis of the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and does not use API inputs to train models. The legal basis is Art. 6 (1) (b) GDPR.
Account and payment
To purchase a set we process your email address, password (as a hash), optionally name and company, billing address, and the time and amount of payment. For magic-link login we store a one-time token for 15 minutes.
Payment processing and invoicing are handled by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Stripe receives your email address, billing address and the purchase amount; full card or bank details never reach our servers. Stripe may transfer data to the USA; EU Standard Contractual Clauses and certification under the EU-US Data Privacy Framework are in place.
Billing records are retained for ten years (§ 147 AO, § 257 HGB). Voucher codes are stored with their redemption time to prevent double use.
- Legal bases: Art. 6 (1) (b) GDPR (contract), Art. 6 (1) (c) GDPR (retention obligations).
Hosting and server location
Application, database and generated graphics are hosted on servers in Germany. A data processing agreement under Art. 28 GDPR is in place with the hosting provider. Server log files (IP address, timestamp, requested resource, user agent) are deleted after 14 days (Art. 6 (1) (f) GDPR, secure operation).
Emails
We only send transactional emails: confirmation of your email address, magic link, password reset, purchase confirmation and completion of your set. There is no newsletter. Emails are sent through the SMTP server of our hosting provider in Germany.
Fonts and external content
All fonts on this website are self-hosted. No Google Fonts servers, no CDN scripts and no advertising pixels are embedded. A typeface you upload is used solely to generate your banners.
Advertising click identifier
If you arrive from a Google ad, Google appends a click identifier to the address (gclid, wbraid or gbraid). We read it from the address and store it with the project created, so we can later tell which ad led to an analysis or a purchase. The identifier is transmitted to Google Ads in aggregated form for that purpose.
No advertising cookie is set and no tracking script is loaded; nothing is stored on or read from your device. The legal basis is our legitimate interest in measuring the success of our own advertising under Art. 6(1)(f) GDPR. You may object under Art. 21 GDPR, in which case the identifier is deleted.
Showroom references
If you consent in your project to showing your set in the showroom, we publish the banners generated from it together with your website domain on myfeedr.com. The legal basis is your consent under Art. 6(1)(a) GDPR. You can revoke it at any time with future effect in your project; the banners are then removed from the public pages.
Retention
- Anonymous analyses and drafts: 7 days.
- Projects in an account: until you delete them.
- Account: until you delete it; deletion is possible at any time in your account area.
- Order and billing data: ten years (statutory retention).
- Server logs: 14 days. Mail logs (recipient, subject, time, delivery status): 90 days.
Your rights
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure, unless retention obligations apply (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Complaint to a supervisory authority, e.g. the Hamburg Commissioner for Data Protection and Freedom of Information