Last updated: 5 August 2026
Fundamentals
Controller
Joshua Stieber
Auf der Geest 4, 30826 Garbsen, Germany
Phone: +49 151 62368185 · Email: [email protected]
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hannover, www.lfd.niedersachsen.de.
Data Processed and Data Subjects
Affected parties include website visitors, registered users and team members, newsletter recipients, course participants, marketplace users, and visitors to public SmartLink, BioLink, and PreSave pages.
- Master and contact data (name, email, profile picture)
- Withdrawal data (name, email, contract details, order date, optional reference number) when using the withdrawal function
- Contract and billing data (plan, credits, Stripe customer and Connect references)
- Usage and metadata (IP address, browser, access times)
- Content (SmartLinks, BioLinks, PreSaves, campaigns, uploads, forum, courses, newsletter, bug reports)
- Conversion/tracking data on public pages (e.g. IP, user agent, FBC/FBP, TTP, anonymous identifiers)
- Team data (invitations, member emails, permission scopes)
- Browser add-on data (access token, connection status, API requests for linked tracks/campaigns)
- Activity and support logs (e.g. activity feed, error reports)
Purposes and Legal Bases
- Provision of account, SmartLinks, campaigns, marketplace, courses, team, add-on, and support — Art. 6(1)(b) GDPR
- Processing of withdrawal declarations via the electronic withdrawal function — Art. 6(1)(b) and (c) GDPR
- Security, abuse prevention, bot protection — Art. 6(1)(f) GDPR
- Marketing analytics on smartsavvy.eu (PostHog, Google Ads, Vercel Analytics) — Art. 6(1)(a) GDPR (consent via cookie banner)
- Newsletter — Art. 6(1)(a) GDPR in conjunction with Section 7(2) No. 3 UWG
- Statutory retention (tax/commercial law) — Art. 6(1)(c) GDPR
Artificial Intelligence (EU AI Act)
SmartSavvy currently does not operate its own chatbots or systems for generating synthetic text, image, audio, or video content for end users. The transparency obligations under Article 50 of Regulation (EU) 2024/1689 (AI Act) therefore do not currently apply to our own product features.
For abuse prevention, we use, among other things, the Vercel BotID service (see Bot Protection section). This is a security-related access check, not interaction with a generative AI assistant. Rule-based indicators in the app (e.g. campaign traffic lights) are not AI systems within the meaning of the AI Act.
For Meta advertising campaigns, delivery may be optimised by Meta itself; SmartSavvy disables certain Meta creative AI features (e.g. Advantage+ Creative) by default where technically controllable. Details of Meta's processing are set out in Meta's privacy notices.
Platform & Account
Hosting and Server Log Files
The platform is hosted by Vercel Inc. (USA/EU). On access, IP address, timestamp, URL, user agent, and referrer are processed, among other data (Art. 6(1)(f) GDPR). Log data is generally retained for a maximum of 7 days for security reasons and then deleted — unless longer retention is required for evidentiary purposes.
Performance metrics may be collected via Axiom (Web Vitals/logging) and Vercel Speed Insights to improve stability and load times (legitimate interest, Art. 6(1)(f) GDPR). Background jobs may be triggered via Upstash QStash.
Bot Protection (SmartLinks / PreSave)
To protect public SmartLink and PreSave endpoints, we use rule-based pre-checks (e.g. user agent, rate limits) and — where enabled — Vercel BotID (possibly with deep analysis). Detected bots are denied access to link content (Art. 6(1)(f) GDPR). No biometric identification of natural persons takes place.
Registration and User Account
On registration, we process email, name, and login data (Art. 6(1)(b) GDPR). Login via email (magic link/OTP) or Google OAuth is available. We store IP address and login time for abuse prevention (Art. 6(1)(f) GDPR); IP addresses are anonymised or deleted no later than after 7 days.
After cancellation, account data is deleted unless statutory retention obligations apply.
Team Workspaces
Account holders may invite team members and assign permissions (scopes). We process email addresses, invitation status, and access rights (Art. 6(1)(b) GDPR). Team members access workspace data on behalf of the account holder; the account holder remains responsible for the lawfulness of invitations and granted permissions.
Browser Add-on (SmartSavvy Add-on)
The optional browser add-on connects to your SmartSavvy API via an access token (e.g. song stats, Meta campaign metrics). Tokens are stored server-side and may be revoked. Legal basis is contract performance (Art. 6(1)(b) GDPR). Invalid tokens are deleted locally.
Payment Processing (Stripe)
Subscriptions, credits, course purchases, and comparable payments are processed via Stripe Payments Europe, Ltd. Stripe processes payment data (e.g. card, SEPA) as an independent controller. We receive only status and reference data from Stripe for contract performance (Art. 6(1)(b) GDPR). Privacy notice: stripe.com/de/privacy.
Payouts to playlist curators may use Stripe Connect. Stripe transmits onboarding and payout data; Stripe remains principally independently responsible for payment data.
Analytics and Marketing (smartsavvy.eu)
Only after cookie consent, we use:
Additionally, we may — to measure purchases and prevent fraud in the ads context — transmit server-side Google Ads conversion events (e.g. via the Google Ads Data Manager API) to Google when you complete a purchase. Where personal data is affected, we rely on Art. 6(1)(a) GDPR (consent) and/or Art. 6(1)(f) GDPR (legitimate interest in accurate performance measurement), depending on configuration.
Transfers to the USA are based on the EU-US Data Privacy Framework and/or standard contractual clauses (SCC). Object via cookie settings or Google Ads settings.
- PostHog (EU host) — product analytics, onboarding events
- Google Ads Conversion (Google LLC) — conversion measurement for our ads (browser)
- Vercel Analytics — aggregated visit statistics
SmartLinks, Tracking & Campaigns
SmartLinks — Conversion Tracking (Meta & TikTok)
Public SmartLink pages (/link/…) serve advertising measurement for the artist or label that created the link. That user is the data protection controller for processing visitor data in the context of their campaign. SmartSavvy (Joshua Stieber) provides the technical platform and processes data as a processor pursuant to Art. 28 GDPR.
Server-side conversion events (CAPI): To measure advertising campaigns, we send — independently of the visitor's cookie consent on the SmartLink page — server-side events (e.g. PageView, clicks) to Meta or TikTok on behalf of the link owner. Legal basis is performance of the contract with the link owner (Art. 6(1)(b) GDPR) or their legitimate interest in campaign evaluation (Art. 6(1)(f) GDPR). Processed data includes IP address, user agent, referrer, FBC/FBP (Meta) or TTP (TikTok), and pseudonymous identifiers.
Browser pixels (client): We set Meta and TikTok pixel scripts in the visitor's browser only if the visitor chose "Accept all" in the cookie banner (Art. 6(1)(a) GDPR).
Meta: facebook.com/privacy/policy. TikTok: tiktok.com/legal/privacy-policy-eea.
PreSave and BioLinks
PreSave and BioLink pages may include visitor statistics and — depending on configuration — tracking/newsletter functions. Where visitor data is processed on behalf of the respective account holder, the same role allocation applies as for SmartLinks (account holder = controller, SmartSavvy = processor). Legal bases correspond to Art. 6(1)(b)/(f) GDPR vis-à-vis the account holder or Art. 6(1)(a) for consent-based browser pixels.
Meta Connection (User Account)
If you connect Meta (Facebook/Instagram) to your SmartSavvy account, we store OAuth tokens server-side for campaign management (Art. 6(1)(b) GDPR). Tokens are not issued to your browser.
Meta Campaigns and Visitor Trails
For campaign evaluation, we store metrics (spend, clicks, conversions, etc.) and may assign visitor trails (e.g. IP, geo hint, user agent, click timestamps, cookie identifiers such as fbp/fbc) to the respective account holder. These are technical tracking identifiers, not biometric fingerprints. Purpose: campaign analysis and abuse detection (Art. 6(1)(b)/(f) GDPR).
Marketplace, Courses & Community
Playlist Marketplace and Credits
When pitching to curators, we process track/pitch data, credit balances, and status information (Art. 6(1)(b) GDPR). Payouts to curators may run via Stripe Connect (see Stripe section).
Online Courses and Services
For course purchases and booked services (e.g. mix/master), we process order data, access rights, and progress information (viewed/completed) for contract performance (Art. 6(1)(b) GDPR). Course videos and thumbnails may be delivered via AWS S3 and CloudFront.
Forum and Real-Time Chat
In the forum, we process posts, profiles, and chat messages. For real-time functions, we use Pusher (Art. 6(1)(b)/(f) GDPR). Please do not disclose sensitive data in public channels.
Content & Communication
Spotify and External Music APIs
To analyse artists, playlists, and statistics, we call the Spotify Web API and, where applicable, connected statistics services (e.g. Chartmetric) (Art. 6(1)(b)/(f) GDPR). Public metadata and artist/track IDs you provide are processed. These services are generally independent providers for their platform data; we transmit only identifiers required for queries.
File Uploads (AWS S3, CloudFront, UploadThing)
Profile pictures, covers, creatives, and other uploads are stored in Amazon Web Services S3 (EU region) and may be delivered via Amazon CloudFront. For certain uploads, UploadThing or Vercel Blob may be used. Access is limited to authenticated users or public SmartLink/marketing assets (Art. 6(1)(b) GDPR).
Newsletter Delivery (Brevo)
Delivery via Brevo (Sendinblue GmbH, Berlin). Brevo is engaged as a processor pursuant to Art. 28 GDPR. brevo.com/de/datenschutz-uebersicht
Affiliate Tracking (Digistore24 / Copecart)
For orders via partner links, tracking parameters and order references may be processed to attribute commissions (Art. 6(1)(f) or (b) GDPR). Digistore24 and Copecart process order data as independent controllers or under their terms; we receive information necessary for commission settlement.
Rights & Retention
Processors (Selection)
Data processing agreements pursuant to Art. 28 GDPR are or will be concluded with processors.
- Vercel — hosting, BotID, Analytics/Speed Insights
- AWS S3 / CloudFront — file storage and CDN
- UploadThing / Vercel Blob — alternative uploads
- Prisma/PostgreSQL — database
- Upstash — cache, queues (Redis/QStash)
- PostHog — analytics (EU, consent only)
- Brevo — email delivery
- Axiom — performance/security logging
- Pusher — forum real-time
Other Recipients (Independent Controllers / Platforms)
- Stripe — payments and Connect (independent controller for payment data)
- Google — OAuth login; ads/conversions after consent or purchase measurement
- Meta / TikTok — OAuth, pixels/CAPI in campaign context
- Spotify / Chartmetric — music metadata and statistics
- Digistore24 / Copecart — affiliate orders
- Cal.com — appointment booking, where integrated
- Notion — changelog/content sync (editorial)
Transfers to Third Countries
Where service providers outside the EEA are used (e.g. USA), transfers are based on the EU-US Data Privacy Framework, standard contractual clauses (SCC), and, where applicable, additional technical measures.
Retention Periods
Personal data is deleted when the purpose ceases and no statutory retention obligation exists. Commercial and tax records: up to 6–10 years. Newsletter proof data: up to 3 years after unsubscription, then deletion on request. Add-on tokens: until revocation or logout. Team invitations: until acceptance, expiry, or deletion.
Your Rights
Access, rectification, erasure, restriction, data portability, objection (in particular to advertising), and withdrawal of consent granted. Enquiries to [email protected].
Security
We use TLS encryption, access controls, tenant separation, and privacy-friendly default settings (privacy by design).
Changes
We update this policy when processing changes. The current version is indicated above. For material changes affecting your consent, we will inform you separately.
