Privacy Policy
Last updated: 2026-05-06
1. Overview
StringIt ("the Platform") is operated by Concepts for You GmbH, Am Tiefen Graben 2, 85757 Karlsfeld, Germany. We take the protection of your personal data very seriously. This privacy policy explains what data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR).
2. Data Controller
Concepts for You GmbH
Am Tiefen Graben 2
85757 Karlsfeld, Germany
Email: info@conceptsforyou.de
Commercial Register: München, HRB 174336
VAT ID: DE263733130
3. Data We Collect
We collect the following categories of personal data:
- Account Data: Name, email address, and authentication credentials (processed via Firebase Authentication by Google).
- Usage Data: Stringing orders, customer profiles, inventory data, and analytics stored in our database (hosted on Supabase, EU region).
- Payment Data: Payment and billing information processed by Stripe Inc. StringIt does not store credit card numbers.
- Location Data: Approximate location for the Shop Finder feature, processed by Mapbox Inc.
- Support Data: Support ticket content may be processed by the Google Gemini API for automated assistance.
4. Third-Party Processors
We use the following third-party services, all bound by data processing agreements:
- Firebase Authentication (Google LLC): User authentication and identity management. Privacy: firebase.google.com/support/privacy
- Supabase Inc.: Database hosting (EU-based servers). Privacy: supabase.com/privacy
- Stripe Inc.: Payment processing (PCI DSS Level 1 compliant). Privacy: stripe.com/privacy
- Mapbox Inc.: Geolocation and map services for Shop Finder. Privacy: mapbox.com/legal/privacy
- Google Gemini API: AI-powered support ticket processing. Privacy: ai.google.dev/terms
5. Legal Basis for Processing
We process your data based on: (a) performance of a contract (Art. 6(1)(b) GDPR) when providing our services; (b) legitimate interests (Art. 6(1)(f) GDPR) for analytics and security; (c) your consent (Art. 6(1)(a) GDPR) for optional features like the Shop Finder location services.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services. After account deletion, data is removed within 30 days, except where legally required to retain it (e.g., tax records for 10 years).
7. Your Rights
Under the GDPR, you have the right to: access your data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict processing, data portability, object to processing, and withdraw consent. To exercise any of these rights, contact us at info@conceptsforyou.de.
8. Data Transfers
Our primary database is hosted within the EU. Some third-party processors (Firebase, Stripe, Mapbox, Gemini) may transfer data to the United States under appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission.
9. Cookies
StringIt uses only essential cookies required for authentication and session management. We do not use tracking or advertising cookies.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification.