Privacy Policy
Last updated: 12 August 2026
This policy explains what personal data Refendr collects when you join our waitlist or use the founding-pilot product, why we collect it, who we share it with, and the rights you have over it. We minimise collection, keep our primary application and database in the EU, and use explicit consent and double opt-in for waitlist marketing.
Who we are
Refendr ("we", "us") is the data controller for the personal data described here. You can reach us about anything in this policy — including to exercise your rights — at hello@refendr.com.
What we collect
When you submit the waitlist form, we collect:
| Data | Why |
|---|---|
| Your email address | To send the confirmation email and, once confirmed, occasional updates and your beta invite. |
| Your consent — the fact you ticked the box, the exact wording shown, and the time | To prove we have a valid basis to email you (a GDPR record-keeping requirement). |
| Attribution — UTM parameters (source, medium, campaign, term, content), the referring page, and the page you signed up from | To understand which channels bring people to Refendr so we can improve. |
| Approximate country, where available | Coarse, optional analytics. Derived from request metadata — we do not store your IP address. |
| Technical timestamps (created/confirmed) | To operate the double opt-in flow. |
When an authorised founding-pilot user signs in and uses Refendr, we may also collect:
| Data | Why |
|---|---|
| Account and team data | To authenticate you, keep workspaces separate, and apply owner, admin, editor, and reviewer permissions. |
| Product, campaign, calendar, draft, review, comment, and publication records | To provide the collaborative growth workflow and preserve its audit history. |
| First-party product measurement events | To show whether your own campaign activity produced measurable visits and conversions. Refendr uses pseudonymous identifiers and does not intentionally store visitor IP addresses in the product database. |
| Connected destination metadata and approved content | Only when an authorised user chooses to connect a publishing destination. This can include the platform, account identifier or handle, granted permissions, the exact approved content, delivery status, and receipt. |
| Security and operational records | To prevent abuse, diagnose failures, honour consent and access changes, and demonstrate who performed a sensitive action. |
We do not collect payment-card details. Connected-platform credentials are kept by the selected publishing provider or in a dedicated secret store; they are not shown in the Refendr interface or stored in ordinary application records.
Legal basis
We use your consent (GDPR Article 6(1)(a)) for waitlist marketing. We process founding-pilot account and workspace data to provide the service you or your organisation asked us to provide (Article 6(1)(b)) and for proportionate security, reliability, and product-improvement interests (Article 6(1)(f)). Where a workspace connects a third-party destination, an authorised user must actively start that connection and approve what is published. You can withdraw marketing consent at any time (see Your rights).
Double opt-in
After you submit the form we send a confirmation email. Your address is only added to our mailing audience once you click the link in that email. If you never confirm, we don't email you again, and unconfirmed entries are not used for any broadcast.
Sub-processor disclosure and data-processing terms
We don't sell your data or share it for advertising. We use a small number of processors to run the service:
| Processor | Purpose | Location |
|---|---|---|
| Resend | Sending email + storing the confirmed contact list | United States (under appropriate data-transfer safeguards / a data processing agreement) |
| Google Cloud, including Firebase Authentication | EU application and database hosting, encrypted secret storage, and product authentication | Primary application and database: European Union (europe-west1) |
| Anthropic and Google Vertex AI | Generating or analysing content when you request an AI-assisted product feature | Provider-controlled processing locations under the applicable service terms |
| Post for Me (Day Moon Development LLC) | Optional social-account connection and delivery of content that an authorised user has approved | United States / provider-controlled infrastructure |
Our processor agreements and data-processing terms govern these services. Post for Me is a planned, default-off integration. We will not connect a customer account until our provider review—including its DPA, subprocessor list, retention, deletion, and incident posture—is complete and the integration is enabled for that workspace. If enabled, Post for Me may process connected account identifiers and handles, OAuth tokens, approved post content and media, delivery status, and basic usage or error records. Its current privacy policy describes its own subprocessors and deletion choices.
Where your data lives
Our primary database and application run in the EU (Google Cloud europe-west1). Some requested functions require limited data to be processed by the providers listed above outside the EU—for example, email delivery, AI assistance, or an optional social publishing connection. We limit what is sent to what that function needs and require an appropriate transfer and contract posture before customer activation.
Cookies
If you arrive via a campaign link, we set one first-party cookie (refendr_attr, about 90 days) to remember which campaign brought you. Signed-in product users also receive necessary first-party session, request-protection, and workspace-selection cookies. We do not use these cookies for advertising or cross-site tracking. You can clear them in your browser; clearing a required session cookie signs you out.
How long we keep it
We keep your waitlist entry until you unsubscribe, ask us to delete it, or we no longer operate the waitlist. Founding-pilot workspace records are kept while we provide the pilot and for a limited period needed for security, legal, and reliable offboarding. When a valid deletion request applies, we delete, unlink, or irreversibly anonymise eligible data and identify any narrow record we must retain. Disconnecting a publishing destination stops future access; it does not silently delete posts already published on the destination.
Your rights
Under the GDPR you can:
- Access the data we hold about you, and get a copy
- Correct it if it's wrong, or ask us to delete it ("right to be forgotten")
- Restrict or object to our processing, and ask for portability
- Withdraw consent at any time — every email has a one-click unsubscribe, or email us
- Disconnect a publishing destination and ask us to remove eligible connection records
- Complain to your local data protection authority if you think we've got it wrong
To exercise any of these, email hello@refendr.com and we'll respond within the timeframe the law requires.
Changes to this policy
If we change how we handle your data, we'll update this page and adjust the "last updated" date above. Material changes affecting how we email you will be communicated directly.