Privacy Policy
Effective 28.08.2026
1. Controller
The controller for data processing is:
Florian Haase
Im Langen Hahn 33
58515 Lüdenscheid
Germany
Email: support@launchbert.com
Contact form
2. Hosting, Logs, and Backups
We host the Service with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner acts as our processor under a data processing agreement (Art. 28 GDPR).
When you visit the Service, server log files may store browser type and version, operating system, referrer URL, host name, time of the request, and IP address. This is necessary for security and a technically reliable operation (Art. 6 Para. 1 lit. f GDPR). Logs are deleted after 30 days.
We store database backups on Hetzner Object Storage for disaster recovery (Art. 6 Para. 1 lit. f GDPR). Backups are retained for about 30 days and may contain personal data then present in the database.
Hetzner privacy policy: https://www.hetzner.com/legal/privacy-policy/
3. Cookies and Access to Your Device
We use strictly necessary session and CSRF cookies to operate the website, keep you signed in, and prevent abuse. This is based on § 25 Para. 2 TDDDG and Art. 6 Para. 1 lit. b and f GDPR.
On the sign-in flow we use Cloudflare Turnstile to block bots. Cloudflare may process IP address, browser and device data, and interaction data needed for the check (§ 25 Para. 2 TDDDG, Art. 6 Para. 1 lit. f GDPR). Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/
Your browser may load fonts from Bunny Fonts and, on some pages, icon or flag images from content delivery networks. Those providers receive your IP address (Art. 6 Para. 1 lit. f GDPR: fast and reliable presentation).
4. Contact
If you contact us by email or the contact form, we process your message and the email address you provide in order to handle your request (Art. 6 Para. 1 lit. b GDPR if the request relates to a contract; otherwise Art. 6 Para. 1 lit. f GDPR). We keep this data until the request is resolved, unless a longer legal retention period applies.
5. User Accounts
An account is required to use the Service. We process your name (if provided), email address, and acceptance of our Terms and this Privacy Policy (Art. 6 Para. 1 lit. b GDPR). Without this data we cannot create or operate an account.
You can sign in with an email one-time code or with Google. We send one-time codes through Resend (Plus Five Five, Inc.). Resend processes the recipient address and the content needed for delivery (Art. 6 Para. 1 lit. b GDPR). Processing may take place in the USA; we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Resend privacy policy: https://resend.com/legal/privacy-policy
If you sign in with Google, Google transmits your Google user ID, name, email address, and profile photo URL. We store the photo URL to display your avatar in the signed-in interface. Google acts as an independent controller for its sign-in service. Processing may take place in the USA, with the safeguards above. Google privacy policy: https://policies.google.com/privacy
You may optionally consent to us showing your profile picture on launchbert.com and in marketing materials (Art. 6 Para. 1 lit. a GDPR). This is not required to use an account. You can withdraw consent at any time in your profile. We store the time and IP address of consent for accountability (Art. 7 GDPR).
You can schedule account deletion in your profile. After a 30-day grace period, the account and associated data are deleted from live systems, unless legal retention periods apply. Copies may remain in backups until those backups expire.
6. Products, Listings, and Related Features
When you create products, we process the product and builder information you enter (including name, website, descriptions, links, pricing, badge settings, launch status, and optional logo and screenshot image URLs) in order to provide the Service (Art. 6 Para. 1 lit. b GDPR). We store the image URLs, not the image files.
On the public launches page we may publish product name, website, tagline, domain rating, and launch progress. Builder email addresses are not shown there.
We look up domain ratings via Ahrefs’ public domain rating API (Art. 6 Para. 1 lit. b and f GDPR). Ahrefs may process technical request data. Ahrefs privacy policy: https://ahrefs.com/privacy
If a website fetches our badge embed, technical connection data may be processed in server logs as described above (Art. 6 Para. 1 lit. b and f GDPR).
If you use the Chrome extension, your product and user data stay on our servers and on your device. The extension stores an authentication token locally until you log out or uninstall it. It reads the active tab URL and the current form’s labels, options, and values on your device to match directories and provide autofill; this page and form data is not sent to LaunchBert, third parties, or any AI model. Autofill inserts your saved product details into the selected third-party form but never submits it automatically. Data you choose to submit is processed under that directory’s privacy policy. If you save image URLs, your browser may load them from the respective image host for previews, and the extension may fetch them on your device to fill directory file fields. The image hosts receive your IP address and process it as independent controllers under their own privacy policies. This access is necessary to provide the preview and autofill you request (§ 25 Para. 2 TDDDG, Art. 6 Para. 1 lit. b GDPR). We do not download or store these image files on our servers.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
7. Payments
Paid purchases are processed by Creem.io (Armitage Labs OÜ, Telliskivi Street 57b/1, Tallinn 10412, Estonia) as merchant of record and independent controller. Creem processes payment and billing data needed to complete the transaction (Art. 6 Para. 1 lit. b GDPR). We do not store full payment card or bank details. We receive only what we need to manage your purchase (for example status, invoice information, and internal identifiers).
Creem privacy notice: https://www.creem.io/privacy
8. Analytics
Where configured, we use Umami, a cookieless analytics tool, to collect aggregated usage statistics such as page views and referrers (Art. 6 Para. 1 lit. f GDPR: understanding and improving the website). Umami privacy policy: https://umami.is/privacy
9. Recipients and Third-Country Transfers
We share personal data only with the providers named in this policy, where required by law, or with processors bound by a data processing agreement (Art. 28 GDPR).
Transfers outside the EEA (in particular Google, Resend, and Cloudflare in the USA) take place only with an adequacy decision (including the EU-US Data Privacy Framework, Art. 45 GDPR) and/or Standard Contractual Clauses (Art. 46 GDPR).
10. Retention
Unless a more specific period is stated above, we store personal data only as long as needed for the purpose, then delete it, unless a legal retention period (for example commercial or tax law) requires longer storage.
- Account and product data: while the account is active, then as described under account deletion
- Contact requests: until resolved
- Sign-in codes: a few minutes
- Server logs: 30 days
- Backups: about 30 days
- Analytics: according to our Umami configuration
- Consent-based processing: until you withdraw consent
11. Your Rights
You have the following rights under the GDPR, subject to the statutory conditions: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and withdrawal of consent with effect for the future (Art. 7 Para. 3). Withdrawal does not affect processing that already took place.
Right to object (Art. 21 GDPR). If we process your data on the basis of Art. 6 Para. 1 lit. f GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise, or defense of legal claims.
If we process your data for direct marketing, you may object at any time. We will then no longer use the data for that purpose.
You may lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in your place of residence or with the authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), https://www.ldi.nrw.de/.
We do not use automated decision-making including profiling within the meaning of Art. 22 GDPR.
To exercise your rights, contact us using the details in section 1.
Transmission over the internet cannot be completely secured. We use TLS encryption in transit.