Privacy Policy

Last updated: April 10, 2026

1. Introduction

Welcome to Spread. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.

2. Data Controller

Company: TenSeven UG (haftungsbeschränkt)

Address: Tannenstr. 10a, 85764 Oberschleißheim, Germany

Represented by: Tammo Elsner, Valentin Spörk

Email: hello(at)go-spread.com

For any data protection inquiries, please contact us at the email address above.

3. Data We Collect

3.1 Event Organizers

  • Account information: Name, email address, organization name
  • Authentication data: Securely hashed password
  • Subscription data: Plan type, payment status, usage limits
  • Event data: Event names, descriptions, dates, locations, branding assets
  • Template data: Uploaded frame templates and configurations
  • Usage statistics: Download counts, event views (aggregated)

3.2 Event Attendees

Photos: When attendees upload a photo to create an event visual, the photo is processed entirely in your browser. We do not upload, store, or have access to your photos on any server. The generated visual exists only in your browser until you download it.

  • LinkedIn connection: If you choose to connect LinkedIn, we store your LinkedIn name and access token to enable posting (see Section 6)

3.3 Website Visitors

  • Contact form submissions: Name, email, message content
  • Feedback submissions: Message content, optional email for response

4. Legal Basis for Processing

We process your data under the following legal bases (GDPR Article 6):

  • Contract fulfillment (Art. 6(1)(b)): Processing necessary to provide our service to organizers, including account management and subscription handling
  • Consent (Art. 6(1)(a)): For optional features like LinkedIn connection, contact form submissions, and feedback. You can withdraw consent at any time
  • Legitimate interest (Art. 6(1)(f)): For aggregated analytics to improve our service, and to ensure security and prevent fraud

5. Third-Party Services

5.1 Payment Processing (Stripe)

We use Stripe for payment processing. When you subscribe to a paid plan, your payment information is handled directly by Stripe. We do not store your credit card details. See Stripe's Privacy Policy.

5.2 LinkedIn Integration

If you choose to connect your LinkedIn account for sharing event visuals, we store a temporary access token that expires after 60 days. You can disconnect LinkedIn at any time, which immediately deletes the stored token. See LinkedIn's Privacy Policy.

5.3 Hosting

Our service is hosted on servers located in the European Union, ensuring your data remains within the EU.

6. Cookies & Local Storage

We use Google Analytics (GA4) for website analytics. Google Analytics cookies are only loaded after you give consent via our cookie banner. If you reject cookies, no analytics data is collected.

We also use browser storage (localStorage and sessionStorage) for essential functionality:

  • Authentication tokens: To keep you logged in to your organizer account
  • LinkedIn session: To maintain your LinkedIn connection during a session
  • Editor state: To preserve your work if you accidentally close the browser (cleared after session)
  • Cookie consent: To remember your analytics cookie preference

Browser storage items listed above are strictly necessary for the service to function and are not used for tracking or advertising purposes.

6.1 Affiliate Device ID

If you arrive on our website via an affiliate referral link (e.g. ?ref=...), we generate a random anonymous device ID and store it in your browser's localStorage. This ID contains no personal data — it is purely a random identifier used to (a) count unique visitors per affiliate without inflating numbers across browser tabs, and (b) attribute your potential signup and purchase to the correct affiliate. Anonymous device IDs that are never linked to an account are automatically deleted after 90 days. You can clear it any time by clearing your browser storage.

6.2 Product Analytics (Funnel Tracking)

To improve our product, we record which steps organizers complete in our own application (for example sign-up, campaign creation, and checkout). This data is stored first-party on our own EU-hosted servers and is never shared with third parties. We do not use cookies, IP addresses, device fingerprints, or any form content for this. Sessions are identified by a random ID stored in sessionStorage, which is automatically deleted when you close the browser tab. Once you create an account, these step events are linked to your account so we can offer support if you get stuck. Funnel events are automatically deleted after 12 months. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in improving our service. This works independently of your GA4 cookie choice.

7. Data Retention

  • Organizer accounts: Retained until you delete your account
  • Event data: Retained until you delete the event or your account
  • Contact messages: Retained for up to 2 years, then deleted
  • Feedback: Retained for up to 2 years, then deleted
  • Product analytics (funnel events): Automatically deleted after 12 months
  • LinkedIn tokens: Auto-expire after 60 days or upon disconnection
  • Attendee photos: Never stored (processed only in browser)

8. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right to Access (Art. 15): You can request a copy of all data we hold about you. Organizers can export their data from Account Settings.
  • Right to Rectification (Art. 16): You can update your personal information in your Account Settings at any time.
  • Right to Erasure (Art. 17): You can delete your account and all associated data from Account Settings. This action is irreversible.
  • Right to Data Portability (Art. 20): You can export your data in a machine-readable format (JSON) from Account Settings.
  • Right to Object (Art. 21): You can object to processing based on legitimate interest by contacting us.
  • Right to Withdraw Consent (Art. 7): Where we process data based on consent, you can withdraw it at any time (e.g., disconnect LinkedIn, delete account).

To exercise any of these rights, please contact us at hello(at)go-spread.com.

9. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data is transmitted over encrypted HTTPS connections
  • Passwords are securely hashed using industry-standard algorithms
  • Database access is protected by row-level security policies
  • Regular security reviews and updates

10. International Data Transfers

Your data is stored on servers located in the European Union. Some third-party services (Stripe, LinkedIn) may transfer data to the United States. These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

11. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. As we are based in Bavaria, Germany, the competent authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht).

12. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this page. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: hello(at)go-spread.com