What Is Stored, What Is Not
Hosted in Frankfurt, Germany
The application, the database and the generated banners run on infrastructure in Frankfurt. Short links and the pixel endpoint run on the same stack.
IP Addresses Are Never Stored Raw
A visitor's IP address is hashed with SHA-256 for deduplication and used once, in memory, to resolve a country and city. The raw address is discarded. The same applies to the browser's user agent.
Attendees Are Never Asked for an Email
The attendee widget collects a name and, optionally, a job title, company and photo. There is no email field and no consent screen to design because nothing is collected that needs one.
Speaker Data Is What You Import
Name, job title, company, email and the columns you choose from your own spreadsheet, plus the photo they upload on their share page. Used to generate their banner and send their link; nothing else.
How Tracking Works Under GDPR
First-Party Tracking, Hashed Identifiers
Every share mints a short link. A click on it records a hashed IP, a hashed user agent, a coarse browser family, a country and city, and the referrer. Bot traffic from crawlers and link scanners is classified and kept out of your reports. There is no third-party tracking on the share page or the widget.
The Conversion Pixel Is First-Party and Minimal
The pixel on your ticket page stores one attribution id in the browser's local storage, with a cookie mirror so subdomains can read it, and reports the order id, value and currency you pass. It is not cookie-free, and we say so; it is first-party, single-purpose and does not build a profile.
Speakers and Attendees Keep Control
A speaker's share page shows what you imported and lets them change the fields you mapped. A photo they upload replaces the one you had. Attendees using the widget store nothing until they generate and share; opening the widget alone records only an anonymous impression.
For Your Data Protection Review
Data Processing Agreement
A DPA under Art. 28 GDPR is available on request. Ask before signing up if your process requires it first.
Processors You Should Know About
Payment through FastSpring; transactional email through a European email service; geo lookup with a locally hosted database, so no IP address leaves our servers for it. The full list comes with the DPA.
Retention Is Tied to the Campaign
Funnel rows (views, shares, clicks, conversions) live as long as the campaign. Deleting the campaign deletes them. There is no automatic purge schedule beyond that yet, which is why we say so here.
German-Speaking Support and Interface
The product interface, the share page and the widget are available in German, and so are we. The German version of this page speaks to DSGVO terms directly.
Privacy by Design, in Practice
A First-Party Pixel With One Purpose
Local storage plus a cookie mirror on your own domain, one attribution id, a thirty-day window. Documented so it goes straight into your cookie notice, and it loads after consent like any other tag.
Frame-Based Cropping, No Biometrics
Headshots are cropped to the frame you designed. No face recognition, no photo analysis, no avatars, nothing that would trigger a biometric assessment.
Minimal Attendee Data
A name and an optional photo, stored only when someone deliberately generates and shares. No email field exists, so there is nothing to ask consent for.
Every Decision Inspectable
The pixel has a debug mode that shows each step it takes and records nothing, so your developer or DPO can verify the behaviour instead of trusting a dashboard.
See It on Your Own Event
Twenty minutes with a demo campaign, or start free and import your first list today.
Related Pages
Frequently Asked Questions
On infrastructure in Frankfurt, Germany: the application, the database, the generated images, the short links and the pixel endpoint.