Privacy Policy / Datenschutzerklärung
Last updated: August 2026
1. Controller / Verantwortlicher
The controller responsible for data processing on this website is:
Johannes Tebbert
Auwaldstraße 7
79110 Freiburg im Breisgau
Germany
E-Mail: [email protected]
No Data Protection Officer (DPO) is required or appointed (§38 BDSG — threshold of 20 persons not reached).
2. Data We Collect and Why
We collect only what is necessary to provide the service. The legal basis for each processing activity is stated below.
2.1 Account Data
Data: Email address, hashed password, display name, shop name. If you arrived through an ad or campaign link and accepted marketing cookies, the campaign parameters of that link (see section 3) are stored with the account as well; if you declined, this stays empty permanently.
Purpose: Creating and managing your account; authenticating you on subsequent visits.
Legal basis: Art. 6(1)(b) GDPR — processing is necessary to perform the contract (provision of the service).
Required: Email and password are mandatory to create an account. Without them, the service cannot be provided. Shop name and display name are optional.
2.2 Etsy API Credentials and Shop Data
Data: Etsy OAuth access token, refresh token, shop ID; order data, listing data, and inventory data fetched from the Etsy API on your behalf.
Purpose: Syncing your Etsy orders and listings, tracking inventory, calculating profit margins, generating packing lists — the core functionality of the service.
Legal basis: Art. 6(1)(b) GDPR — processing is necessary to perform the contract. You initiate the OAuth connection; without it the service has no function.
Third-country transfer: Etsy Inc. is a US company. When we fetch data from the Etsy API on your behalf, your data passes through Etsy's servers in the United States. This transfer is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR) as maintained by Etsy. See Etsy's Privacy Policy.
2.3 User-Entered Data
Data: Material costs, production quantities, and other data you manually enter into the app.
Purpose: Powering profit calculations and production planning features.
Legal basis: Art. 6(1)(b) GDPR — contract performance. This data is entirely voluntary and you can leave any field blank.
2.4 Transactional Emails
Data: Your email address is transmitted to our email service provider when we send you a verification email or other service notifications.
Purpose: Email address verification; account-related service notices.
Legal basis: Art. 6(1)(b) GDPR — contract performance (email verification is required to activate your account).
Processor: Transactional emails are sent via Resend Inc. (USA), which is certified under the EU–US Data Privacy Framework (Art. 45 GDPR adequacy decision of 10 July 2023). A Data Processing Agreement (DPA) under Art. 28 GDPR is in place with Resend. See Resend's Privacy Policy.
2.5 Server Logs
Data: IP address, browser type, pages accessed, timestamps. Collected automatically by the web server.
Purpose: IT security, abuse prevention, and diagnosing technical errors.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure and reliable service. You have the right to object to this processing (see Section 6).
Retention: Server logs are retained for a maximum of 30 days, then deleted automatically.
2.6 Product Usage Analytics
Data: Which pages and features you use within the app — the route requested, the in-app action clicked, the response status and timing — together with your user ID. We do not record the content you view or enter, and we never store any of your buyers' personal data (names, addresses, order details) in this analytics data.
Purpose: Understanding which features are used and how, so we can prioritise improvements and fix usability problems. This is first-party analytics only — the data is never sold or shared with third parties.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in maintaining and improving the service. You have the right to object to this processing (see Section 6). No separate tracking cookie is used; this analytics relies solely on your existing session.
Retention: Usage analytics records are retained for a maximum of 180 days, then deleted automatically.
2.7 Your Buyers' Personal Data (Controller / Processor Roles)
Your Etsy orders contain your buyers' personal data (names, shipping addresses, order details). We fetch and store this data only to provide inventory, packing-list, and profit features to you.
Roles: With respect to your buyers' personal data, you are the controller and we act as your processor (Art. 28 GDPR) — we process that data solely on your documented instructions to deliver the service. With respect to your own account data (Sections 2.1–2.6), we are the controller.
CSV exports: The order and tax export features (receipts.csv / transactions.csv) let you download files that include your buyers' personal data. Once you download an export, that copy leaves our systems and is under your sole control. You are responsible, as controller, for storing, securing, and lawfully handling those files — including honouring your buyers' GDPR rights and deleting the files when no longer needed.
3. Cookies
One cookie is always set, because the service cannot work without it:
| Name | Purpose | Duration | Legal basis |
|---|---|---|---|
connect.sid |
Session management / authentication | Until browser closes or logout | §25(2) TDDDG — strictly necessary; Art. 6(1)(b) GDPR |
This cookie is strictly necessary to provide the service you requested (§25(2) TDDDG). No consent is required for strictly necessary cookies.
Marketing cookies — only with your consent
If you click "Accept" in the cookie banner, we set two further first-party cookies on .findig.app (so they are shared with our marketing site findig.app) and load the Google Ads tag:
| Name | Purpose | Duration | Legal basis |
|---|---|---|---|
findig_consent |
Remembers whether you accepted or declined, so we do not ask again on every page | 12 months | §25(2) TDDDG — strictly necessary to honour your choice |
findig_utm |
Campaign parameters of the link you arrived through (utm_source, utm_medium, utm_campaign, utm_term, gclid); stored with your account if you sign up, so we can see which campaign the signup came from |
30 days | Art. 6(1)(a) GDPR / §25(1) TDDDG — your consent |
Google Ads: after consent we load gtag.js from Google (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) to measure ad conversions. This transfers your IP address and browser data to Google and may involve a transfer to the USA under the EU-US Data Privacy Framework. If you click "Decline", nothing from Google is loaded at all.
Withdrawing consent: delete the findig_consent cookie in your browser (site settings → cookies) and the banner will ask again. Withdrawal does not affect processing that already took place.
4. Data Storage and Security
All data is stored on a self-hosted server located in Germany. Etsy OAuth tokens are stored encrypted in our database and are used solely to fetch data from Etsy on your behalf. We use HTTPS (TLS) for all data in transit.
5. Automated Decision-Making
We do not use automated decision-making or profiling as defined in Art. 22 GDPR. No decisions with legal or similarly significant effects are made about you automatically.
6. Your Rights under GDPR
If you are in the EU/EEA, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): Request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): Request deletion of your personal data ("right to be forgotten"). You can also delete your account directly in the app.
- Right to restriction of processing (Art. 18 GDPR): Request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20 GDPR): Receive your data in a structured, commonly used format where processing is based on contract performance.
- Right to object (Art. 21 GDPR): Object to processing based on our legitimate interest (Art. 6(1)(f)), including server logs. We will cease that processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3) GDPR): Where any processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent data protection supervisory authority (Art. 13(2)(d) GDPR):
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20, 70173 Stuttgart
Tel.: 0711 / 615541-0
E-Mail: [email protected]
www.baden-wuerttemberg.datenschutz.de
8. Data Retention
We retain your data for as long as your account is active. If you delete your account, all personal data associated with your account is permanently deleted from our live systems within 30 days. Server logs are deleted after 30 days, and product usage analytics after 180 days, regardless of account status.
Encrypted backups: We keep encrypted, offline database backups so the service can be rebuilt after data loss. Daily backups are kept for 90 days. After that we keep one backup per week, and those weekly copies are retained indefinitely — so a copy of your data may remain in a long-term backup after your account is deleted.
These backups are archives, not live data. They are encrypted at rest, stored separately from the running service, and are never read, searched, exported or analysed in normal operation — their only purpose is restoring the service after data loss. If we ever do restore from a backup, we re-apply every outstanding deletion immediately afterwards, so data you asked us to delete is not returned to the live service. Until such a restore, that data is held solely for restoration and is not otherwise processed (restricted processing, Art. 18 GDPR).
9. Changes to This Policy
We may update this policy as the service evolves. Material changes will be communicated via email at least 14 days before they take effect. The date at the top of this page always reflects the most recent update.