Legal

Privacy Policy

This policy describes the personal data actually processed by the US Market Intelligence application, why it is processed, and which service providers are involved.

Last updated: 2026-08-19

1. Controller

Controller for the processing described below: Tim Schwarz, Sole proprietor (Einzelunternehmer), Lindenstraße 29, 15370 Petershagen, Deutschland.

Contact for privacy requests: schwarz.tim@yahoo.com.

2. Data we process

  • Account data: email address, password (stored only as a hash by our authentication provider), display name, interface language and report language preference.
  • Company profile data you enter: company name, website, country, industry, product description, current markets, target U.S. market, business model, size and revenue ranges, U.S. presence answers, timeline and research objectives.
  • Analysis data: the analyses you start, their status, language, tier and the generated results, scores, opportunities, risks and research sources.
  • Uploaded documents: files you upload (for example company presentations), stored in a private storage bucket together with file name, type and size.
  • Anonymous Opportunity Check data: the company details you submit without an account, stored with a one-time claim token so the check can later be linked to an account you create.
  • Order and billing data: product purchased, amount, currency, payment status, payment provider identifiers and optional billing details you provide.
  • Technical data: server-side error and operational logs, and rate-limiting counters keyed to a request identifier.
  • Purchase acknowledgement records: the statement you confirm before payment, stored with its wording version, language, the exact text shown, the time of confirmation and the related order/payment reference.

3. Purposes

  • Providing user accounts and authentication.
  • Producing the market research reports and PDF documents you request.
  • Processing purchases and granting the corresponding report entitlements.
  • Securing the service against abuse (rate limits, quotas, logging).
  • Communicating with you about your account and your reports.

4. Legal bases (Art. 6 GDPR)

  • Account creation and authentication: performance of a contract or steps prior to a contract, Art. 6(1)(b) GDPR.
  • Company profile data you enter and the production of the ordered reports: performance of a contract, Art. 6(1)(b) GDPR.
  • Entitlements (report credits) and their consumption: performance of a contract, Art. 6(1)(b) GDPR.
  • Withdrawal requests and their records: compliance with a legal obligation, Art. 6(1)(c) GDPR, and performance of the contract, Art. 6(1)(b) GDPR.
  • Transactional emails (order confirmation, withdrawal confirmation): performance of a contract, Art. 6(1)(b) GDPR, and compliance with the duty to confirm the contract, Art. 6(1)(c) GDPR.
  • Payment processing through Stripe: performance of a contract, Art. 6(1)(b) GDPR, and compliance with legal payment and accounting duties, Art. 6(1)(c) GDPR.
  • Fraud prevention, rate limiting and abuse protection: legitimate interests, Art. 6(1)(f) GDPR.
  • Processing purchases, order confirmations, invoices and withdrawal declarations: performance of a contract, Art. 6(1)(b) GDPR, and compliance with commercial and tax retention duties, Art. 6(1)(c) GDPR.
  • Anonymous Opportunity Check submitted without an account: steps taken at your request prior to a contract, Art. 6(1)(b) GDPR.
  • Purchase acknowledgement records and consent to immediate performance: compliance with a legal obligation, Art. 6(1)(c) GDPR, together with our legitimate interest in evidencing the declaration, Art. 6(1)(f) GDPR.
  • Security, rate limiting, quotas and operational logging: legitimate interests in protecting the service against abuse, Art. 6(1)(f) GDPR.
  • Support correspondence you initiate by email: legitimate interests in answering your request, Art. 6(1)(f) GDPR, or contract performance where it concerns your purchase, Art. 6(1)(b) GDPR.

The mapping above reflects the processing actually carried out by this application. No other processing takes place.

5. Service providers (processors)

We use the following providers. No other providers receive your data from this application.

  • Supabase — database, authentication, file storage and transactional authentication emails (confirmation, password reset).
  • Cloudflare — hosting and delivery of the web application and its server-side functions.
  • OpenAI — processing of your company profile and collected research material to generate classifications and the report text.
  • Tavily and Exa — web research providers queried to discover public sources for your report.
  • U.S. Census Bureau — public statistical data retrieved for market metrics.
  • Stripe — payment processing and payment confirmations for paid products.
  • Resend — delivery of transactional emails (order confirmations and confirmations of withdrawal declarations).
  • Yahoo (Verizon Media / Yahoo EMEA) — the operator's support and contact mailbox is hosted with Yahoo, so email you send to the contact address above is processed there.

Uploaded documents are stored privately and are not shared with any third party other than the hosting and storage providers listed above.

6. International transfers

Some of the providers listed above are established in the United States or process data there. Where personal data is transferred outside the EEA, the transfer relies on the safeguards offered by the respective provider's data processing terms.

7. Cookies and local storage

The application does not use advertising or analytics cookies. Your browser's local storage is used to keep your session, your interface language, your currency preference and the details of a report you were about to purchase, so the flow can continue after a redirect. These entries are technically required for the features you actively use.

8. Retention

  • Account, company, analysis and report data is retained while your account exists.
  • Anonymous Opportunity Checks that are never linked to an account are deleted automatically after 30 days.
  • Order records are retained as required for accounting and tax purposes.
  • Rate-limiting counters are short-lived and cleaned up automatically.

9. Security

Data is isolated per account at database level, uploaded files are stored in a private bucket, all traffic is served over HTTPS, and server-side error information is reduced to non-sensitive failure codes.

10. Your rights

  • Access to the personal data we hold about you.
  • Rectification of inaccurate data.
  • Erasure of your data and your account.
  • Restriction of processing and objection to processing.
  • Data portability.
  • Complaint to a competent supervisory authority.

To exercise these rights, contact schwarz.tim@yahoo.com. You can also edit your profile data directly in your account.