Privacy policy
Last updated:
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) is Smoosh, Dorfstr. 42, 88527 Unlingen, Germany. Email: hello@getsmoosh.app. More in the imprint.
If you email us, we use your address and your message only to answer you. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in answering you; for requests about your rights, Art. 6(1)(c) GDPR together with Arts. 12 to 22 GDPR. Your email reaches us through Cloudflare's Email Routing, which forwards it to our mailbox at Google (Gmail); Cloudflare processes it on our behalf under a data processing agreement (section 8). Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, stores it in our Gmail mailbox. Google LLC may also process it in the USA; it is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). We delete your emails once your matter is settled, unless the law requires us to keep them longer.
2. Overview
We process personal data on getsmoosh.app for four purposes:
- delivering the website (every visit),
- the waitlist (only if you join it),
- remembering your privacy choice (every visit),
- analytics (only if you allow it).
We don't sell data, and the site has no advertising trackers or social media plugins. Fonts and everything else it shows come from our own server. The one exception is Matomo, which loads from its own server, and only if you allow analytics (section 7). Without your consent, the site stores nothing in your browser except your privacy choice (section 6).
3. Hosting
The website, the waitlist and our API run in German data centers, on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes data on our behalf under a data processing agreement (Art. 28 GDPR). To deliver the pages, our servers process your IP address, the address requested, the time and the technical details your browser sends, such as its type and language. Our servers keep no access logs, so these details are only used to answer the request. Our API logs the address requested, the result and how long it took, without your IP address. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in a working, secure website.
4. The waitlist
What we store and why
When you join the waitlist, we store your email address, the language of the page, the version of the consent text you saw, the campaign link you came from (for example "ig-bio"), and the time and IP address of your signup and of your confirmation. We use the address to email you about Smoosh's launch, to send your early-supporter discount code and to send occasional news about Smoosh, at most about twice a month. The times, IP addresses and text version document your consent. The campaign link tells us which of our posts bring people to the waitlist.
Double opt-in
We only add you after you open the link in our confirmation email and confirm. Until then we keep your address only to send you the confirmation email and to be able to show what was requested. A signup you don't confirm expires after 30 days: a new address is then deleted, and if you were on the list before, your earlier record stays as described under "How long we keep it".
Legal basis and withdrawal
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future, with the unsubscribe link in every email we send after you confirm, or by email to us; this doesn't affect what we did before. Keeping the record of your consent is based on Art. 6(1)(c) GDPR together with Art. 7(1) GDPR, which requires us to be able to prove consent. We store the campaign link based on Art. 6(1)(f) GDPR: our legitimate interest in knowing which posts work. You must be at least 16 years old to join.
Who processes the data
The list runs on our own installation of the open-source software Listmonk at lists.getsmoosh.app, on the Hetzner servers described above. Sendinblue SAS (Brevo), 17 rue Salneuve, 75017 Paris, France, delivers our emails on our behalf under a data processing agreement. Brevo stores the data in the European Union; where its group companies or service providers outside the EU (for example in the USA or India) can access it, the EU standard contractual clauses apply (Art. 46(2)(c) GDPR). Our emails contain no tracking pixels and no tracked links.
How long we keep it
Until you unsubscribe. After that we keep your address, the time, IP address, text version, language and campaign link of your latest signup, the time and IP address of its confirmation and the times you unsubscribed for three more years, only to be able to prove your consent and its withdrawal, and then delete them. The legal basis is Art. 6(1)(c) GDPR together with Art. 7(1) GDPR, and Art. 6(1)(f) GDPR: our legitimate interest in being able to defend ourselves against claims.
If you sign up again after unsubscribing, we keep the details of your earlier signups (text version, time and IP address of each signup and confirmation, time of each unsubscribe, campaign link and language) with the new ones. They prove your consent to the emails we sent before, and we delete them with the rest, three years after you last unsubscribe. If you don't confirm such a new signup within 30 days, you're simply unsubscribed again, and the three years start then.
The page the unsubscribe link opens also has "Delete my data", which deletes everything at once. Deleted data is removed from the list right away; the daily backups that still contain it are overwritten within 14 days.
Joining is voluntary. Without an email address we can't put you on the waitlist.
5. Protection against abuse
To keep bots away from the waitlist, our API counts requests per IP address for 10 minutes and confirmation emails per email address, in hashed form, for 24 hours. Then the counters delete themselves. For a signup, the API's log notes only the language and the result, without your IP address or email address, so we can trace errors. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in protecting the service and the people whose addresses are entered, and in finding and fixing errors.
6. Your privacy choice (c15t)
We ask for your consent to analytics with c15t, an open-source consent manager that we operate ourselves at c15t.jrxmedia.de on servers in Germany. Your browser reaches it only through this website: our server passes the requests on through Cloudflare without your IP address (section 8). To document your decision, c15t stores a random ID, the categories you allowed or refused, the time, the website, the version of the consent request and your browser's user agent (the name and version of your browser and operating system).
So the banner doesn't come back on every page, c15t also keeps your choice and the ID in your browser: in the cookie c15t for one year, and under the same name in the browser's local storage until you delete it there. A choice that couldn't be sent yet waits in local storage (c15t-pending-consent-submissions or c15t:pending-consent-sync) and is sent and removed on your next page view.
Storing and reading your choice on your device is strictly necessary to respect it (§ 25(2) No. 2 TDDDG). Keeping the record of a consent is based on Art. 6(1)(c) GDPR together with Art. 7(1) GDPR. Keeping the record of a refusal, and passing on your browser details for the banner, are based on Art. 6(1)(f) GDPR: our legitimate interest in asking for consent reliably and in showing that we respect your choice. We delete each record four years after it was made: a choice is valid for one year, and claims relating to it can be brought, and fines imposed, for three more years (§ 195 BGB, § 31 OWiG).
7. Analytics (Matomo)
If, and only if, you allow "Analytics", this website loads Matomo, an open-source analytics tool that we operate ourselves at analytics.jrxmedia.de on servers in Germany. We use it to see which pages and which of our posts bring people to the site and to the waitlist, so we can improve both. The data isn't shared with Matomo's makers or with advertising networks.
Matomo records the pages you view, the time and length of your visit, the website you came from, clicks on links to other websites, a signup for the waitlist (without your address) and technical details such as browser, operating system, device type, screen size and language. If you came through one of our campaign links (for example "ig-bio" from our Instagram bio), Matomo counts your visit toward that campaign. Like everything in this section, that happens only with your consent. Your IP address is shortened by two bytes before it is stored. Address parameters that often carry personal data (names, email addresses, phone numbers and the like) are removed before a page address is sent to Matomo. Raw visit data is deleted after six months; only aggregated reports remain.
Matomo sets these cookies:
_pk_idrecognizes your browser on later visits by a random ID, for 13 months,_pk_sesholds the current visit together, for 30 minutes,_pk_refnotes the website or campaign link you came from, for 6 months; it's only set when you come from another website or through a campaign link.
The legal basis for storing and reading information on your device is § 25(1) TDDDG, and for the processing that follows Art. 6(1)(a) GDPR: your consent. You can withdraw it at any time under "Privacy settings" at the bottom of every page. Withdrawing stops Matomo, deletes its _pk_ cookies and reloads the page; it doesn't affect what was recorded before. Matomo then sets the cookie mtm_consent_removed, which only notes the withdrawal (§ 25(2) No. 2 TDDDG). We delete it right after the page has reloaded, because the consent manager keeps your choice anyway. If you never allow analytics, Matomo isn't loaded and sets no cookies.
8. Cloudflare
The consent manager (section 6) and Matomo (section 7) are reached through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare passes requests on to the servers of both services and protects them from attacks. Our server sends requests for the consent manager to Cloudflare without your IP address; for Matomo, once you allow it, your browser connects to Cloudflare directly. Emails to our address also pass through Cloudflare: its Email Routing forwards them to our mailbox (section 1). Cloudflare processes what this involves (for the consent manager, the content of the requests and your browser's technical details, and for Matomo also your IP address; for emails your address, your message and its delivery details), possibly also in the USA, as a processor under a data processing agreement. Cloudflare is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). The legal basis is, for the consent manager, our legitimate interest in asking for and proving consent reliably (Art. 6(1)(f) GDPR), for Matomo, your consent (Art. 6(1)(a) GDPR), and for emails, our legitimate interest in receiving and answering them (Art. 6(1)(f) GDPR).
9. Links to other services
We link to Instagram and TikTok but don't embed anything from them, so they learn nothing about your visit unless you follow a link. Their own privacy policies apply from there.
10. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR),
- have it corrected (Art. 16) or deleted (Art. 17),
- have its processing restricted (Art. 18),
- receive it in a portable format (Art. 20),
- object to processing based on our legitimate interests (Art. 21),
- withdraw any consent at any time for the future (Art. 7(3)).
Your right to object: where we process your data based on our legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). We then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Email us at hello@getsmoosh.app. For the waitlist, the page the unsubscribe link opens also lets you have a copy of your data emailed to you or delete it yourself; for a complete copy, including the record of your confirmation, email us. You can also complain to a data protection authority (Art. 77 GDPR).
11. Automated decisions
We don't make decisions based solely on automated processing, including profiling, that have legal effects on you or affect you in a similarly significant way (Art. 22 GDPR).
12. Changes
We update this policy when the website or the waitlist changes. The current version is always on this page.