Skip to content

Privacy Policy

Last updated: 31 August 2026

Data controller

The data controller within the meaning of the GDPR is Silvio Lindstedt. For address and contact details, see the Legal Notice.

Overview

This is a static landing page. It sets no cookies. Personal data is processed only as technically necessary by the hosting infrastructure and via a self-hosted, cookieless analytics service. If you create a Votepit Cloud account, your e-mail is additionally processed by the application backend (see below). No third-party tracking, no advertising networks.

Hosting (Cloudflare Pages)

This site is hosted via Cloudflare Pages (CDN). When pages are requested, Cloudflare processes technically necessary server and edge logs as a data processor; these may contain IP addresses, browser identifiers, and timestamps. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the service). For further information see Cloudflare's privacy policy: cloudflare.com/privacypolicy/

Analytics (Matomo)

This site uses self-hosted Matomo for aggregated usage statistics. Matomo is configured cookieless: no cookies are set; IP addresses are anonymised before storage (last two octets removed); no information is stored on or read from the device. No cross-device tracking, no profiling, no sharing with third parties. Data is used solely for aggregated statistics and cannot be linked to individuals. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding how the site is used). Because tracking is cookieless and IP-anonymised and no information is stored on or read from the device, no consent — and therefore no consent banner — is required under § 25 TDDDG.

External links

This site contains links to external services (e.g. GitHub). When you click these links, you leave this site. The respective provider is responsible for data processing on the linked pages.

Account sign-up (Votepit Cloud)

Votepit Cloud (app.votepit.com) is a separate application from this landing page. Signing up only requires an e-mail address — there are no passwords. Instead of storing your e-mail address in plain form, the application stores it exclusively as a keyed HMAC-SHA256 hash (the signing key is kept outside the database); the plaintext address is only used transiently to send you a magic sign-in link and is never itself persisted. Purpose: account authentication and service delivery. Legal basis: Art. 6(1)(b) GDPR (performance of the contract you enter into by signing up). Retention: for as long as your account exists, plus any legally required retention period after deletion. Subprocessor: Netcup GmbH (Germany) hosts the application backend; no additional subprocessor is introduced by signing up. The application sets one technically necessary session cookie on app.votepit.com to keep you signed in; it is not used for tracking, contains no third-party trackers, and requires no consent under § 25(2) TDDDG. Withdrawal/erasure: cancelling your subscription starts a 30-day deletion grace period after which your account and data are removed; to request earlier deletion, use the contact address in the Legal Notice.

Board pages (anti-abuse & view counts)

When you view a public board or an idea's detail page on app.votepit.com, the backend processes your IP address and browser User-Agent header transiently — to prevent abuse (rate limiting) and to avoid inflating the view counter shown on each idea. Neither is ever stored in plain text: only a keyed HMAC-SHA256 hash (the same signing-key architecture as the e-mail pseudonymization above) is kept, for at most 24 hours, after which it is automatically deleted. No cookie is set for this purpose. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service integrity and in meaningful, non-inflated usage statistics).

Moderation history (member standing)

Draft, pending attorney review. If you are a member of an account (not merely a public visitor) and a comment or idea you submitted is removed through the moderation process described in the Terms of Service and Acceptable Use Policy, we keep an internal record of that removal (the reason category, a snapshot of the removed content, and the date) for a limited retention period, and maintain a rolling violation count and standing state (normal, flagged, warned, or suspended) for you within that account. This is processed to operate the notice-and-appeal mechanism described above, to allow account moderators to recognise repeat violations, and — where your submissions are suspended as a result — to enforce that suspension. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in functioning, abuse-resistant moderation) and, for the account operating the board, its own obligations as controller for that board’s content. This data is only visible to that account’s moderators/admins and to Votepit where necessary for platform-wide abuse handling; it is not shared with other accounts.

Payment processing (paid plans)

If you subscribe to a paid plan (Lite or Pro), your payment is processed by Paddle.com Market Limited, which acts as Merchant of Record and as an independent controller for your billing data (name, billing address, payment method, tax details). Paddle's own privacy policy governs that processing — see the link below. We never receive or store your payment card data ourselves; we only receive your plan/tier status from Paddle's cryptographically verified webhook. paddle.com/legal/privacy

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and to object. For questions about Cloudflare's processing (hosting), please contact Cloudflare directly. For questions about Paddle's processing (payment), please contact Paddle directly. For analytics data (Matomo), you may object at any time (Art. 21 GDPR) via the opt-out option on this privacy page.