Privacy Policy
Information on the processing of personal data on helllo.me
Last updated: August 2026
1. Data Controller
The controller responsible for the processing of personal data in accordance with the General Data Protection Regulation (GDPR) is:
Alec Winter Blumenau 89 22089 Hamburg Germany
Email: contact@helllo.me
We have not appointed a Data Protection Officer. The numerical appointment threshold in § 38 BDSG is not reached; the separate appointment duties under Art. 37 GDPR and § 38 BDSG are reviewed if our processing changes.
2. General Information on Data Processing
Scope of Processing
We generally process personal data of our users only to the extent necessary for providing a functional platform and our content and services. Processing is carried out exclusively in accordance with the applicable legal provisions (GDPR, BDSG, TDDDG).
Legal Bases
The processing of personal data is based on the following legal grounds:
- Art. 6 (1) (a) GDPR - Consent
- Art. 6 (1) (b) GDPR - Performance of a contract or pre-contractual measures
- Art. 6 (1) (c) GDPR - Legal obligation
- Art. 6 (1) (f) GDPR - Legitimate interest
3. Collection and Processing of Personal Data
a) Hosting, Delivery & Web Analytics (Vercel)
Vercel hosts and delivers helllo.me. For delivery, troubleshooting, and protection against abuse, Vercel processes technical request and log data such as IP address, requested URL, date and time, referrer, user agent, and security events. Vercel may process this data on global infrastructure.
We also use Vercel Web Analytics for aggregate usage statistics. According to Vercel, Web Analytics does not use third-party cookies, does not associate analytics data with an individual or IP address, and discards its temporary visitor-session identifier after 24 hours. Analytics data can include the URL without unfiltered query parameters, referrer, approximate location, device, operating system, browser, and timestamp.
Legal basis: Art. 6 (1) (f) GDPR (Legitimate interest in optimizing the platform).
b) Own Visitor Statistics for Business Cards
For registered users, we collect limited access statistics for their public and successfully unlocked private business cards. This data is stored in our database (Supabase project region: Stockholm).
- Data collected: Country (from Vercel header, no IP storage), device type (Desktop/Mobile/Tablet), browser type, timestamp of access.
- Purpose: Providing usage statistics for card owners.
- No profiling: No personal profiles of visitors are created.
Legal basis: Art. 6 (1) (f) GDPR (Legitimate interest of users in access statistics).
c) Strictly Necessary Authentication Cookies (Better Auth)
We use Better Auth, operated within our application, for magic-link and Google sign-in. A secure, HTTP-only session cookie is technically necessary to keep users signed in. Account, provider, and session records are stored in our PostgreSQL database hosted by Supabase.
- Purpose: Maintaining the login status.
- Storage duration: Until logout or the configured session expiration.
- Necessity: The service cannot be provided securely without this cookie. Consent is therefore not required under applicable telecommunications laws (§ 25 (2) No. 2 TDDDG).
Legal basis: Art. 6 (1) (b) GDPR (Performance of contract).
d) Registration and Business Card Management
When you create an account, we process:
Magic-link sign-in:
- Email address and authentication/verification records
Google OAuth:
- Google account identifier, email address, name, profile picture URL, and provider tokens required to maintain the connection
Account and service records:
- Account ID, account creation/update times, sign-in provider, session token, session expiry, IP address and user agent associated with a session
- Subscription plan/status, Creem customer ID, terms-acceptance flag, and newsletter preference
Business card content (entered by user on the business card):
- Contact details (name, phone, email, website)
- Address data (street, house number, postal code, city, country)
- Personal information (date of birth, nationality, languages)
- Social media links (Instagram, LinkedIn, X, Facebook, YouTube, TikTok, GitHub, Discord, Telegram, Signal, WhatsApp)
- Profile picture and business card image
- Biography/description text
Important Notice Regarding Public Disclosure:
All content you enter on your public business card (e.g., name.helllo.me) is publicly accessible worldwide and may be indexed by search engines. You decide which information to publish. Private business cards are only accessible with an access code.
Legal basis: Art. 6 (1) (b) GDPR (Performance of contract).
e) Image Storage
Uploaded images (profile pictures, business card images) are stored in Supabase Storage (location Stockholm, AWS).
- Processing: Images are compressed client-side and validated again on the server before upload. Supported server-side formats are JPEG, PNG, and WebP with a maximum upload size of 2 MB.
- Storage duration: Until deletion by user or account deletion.
- Access: Profile pictures via signed URLs (24h validity); business card images publicly accessible.
Legal basis: Art. 6 (1) (b) GDPR (Performance of contract).
f) Contact Form
When using our contact form, the following data is processed:
- Name (required)
- Message (required)
- Email address (optional, only if response requested)
Processing: The message is transmitted via a Discord webhook to our internal communication channel to process inquiries promptly. Discord Inc. is a US company.
Storage duration: For as long as necessary to answer the inquiry and handle reasonable follow-up or legal claims. Discord may retain technical and backup data under its own retention rules.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (Legitimate interest in responding to inquiries).
g) Security Measures (Rate Limiting)
To prevent abuse (e.g., brute-force attacks on private business cards), we use a rate-limiting system.
- Data collected: Salted, pseudonymous hash derived from IP address and subdomain, plus timestamp.
- Use period: Attempts are considered for 60 minutes. Expired records are removed during routine cleanup and are not used for access decisions.
- No plain-text IP storage: The source IP is processed transiently to calculate the hash but is not stored in this table.
Legal basis: Art. 6 (1) (f) GDPR (Legitimate interest in platform security).
h) Email Communication
For magic-link sign-in and other transactional emails, we use Brevo (Sendinblue, France) as our SMTP provider.
- Data processed: Email address, time of dispatch.
- Purpose: Authentication and account security.
Legal basis: Art. 6 (1) (b) GDPR (Performance of contract).
i) Newsletter
Users may optionally subscribe to our newsletter in the account settings. The newsletter service is provided by Brevo (Sendinblue, France).
- Data processed: Email address only.
- Purpose: Sending information about new features, updates, and tips for using helllo.me.
- Subscription: Requires explicit opt-in via the settings page. A confirmation dialog is shown before subscribing.
- Unsubscription: Possible at any time via the settings page or through the unsubscribe link in each newsletter email.
- Storage duration: Until unsubscription or account deletion.
Legal basis: Art. 6 (1) (a) GDPR (Consent).
j) Optional Wallet Passes
Authenticated users can optionally generate Apple Wallet or Google Wallet passes for their own cards. A pass can contain the card title, subtitle, card URL, theme colors, and card image. Apple passes are generated on our server and delivered to the user; Google Wallet passes are signed on our server and then transferred to Google when the user follows the save link. Use of the wallet provider is voluntary and is also subject to the provider's privacy terms.
Legal basis: Art. 6 (1) (b) GDPR (requested service) and, for the transfer initiated by the user, Art. 6 (1) (a) GDPR (consent).
4. Recipients, Processors & Independent Controllers
We use the following recipients. Depending on the service, they act as processors under Art. 28 GDPR or as independent controllers (in particular payment and optional wallet services). Applicable DPAs and transfer safeguards must be maintained with the relevant processors.
| Service Provider | Purpose | Role / Location | Information |
|---|---|---|---|
| Vercel Inc. (USA) | Hosting, Analytics, CDN | Processor; global infrastructure including EU/USA | Privacy · DPA |
| Supabase Inc. (USA) | PostgreSQL database and image storage | Processor; project region Stockholm (AWS) | Privacy |
| Google Ireland Ltd. | Optional Google sign-in and Google Wallet | Independent controller; international | Privacy |
| Apple | Optional Apple Wallet | Independent controller; international | Privacy |
| Discord Inc. (USA) | Contact form forwarding | Processor; USA/international | Privacy |
| Creem (UK) | Payment processing (MoR) | Independent controller; UK/international | Privacy |
| Brevo (Sendinblue, France) | Transactional email and newsletter | Processor; EU (France) | Privacy |
International Data Transfer: Insofar as data is transferred to the USA, this is done on the basis of the EU-U.S. Data Privacy Framework (DPF) or EU Standard Contractual Clauses (SCCs). The adequacy of the level of data protection in the USA for certified companies was established by the EU Commission's adequacy decision of July 10, 2023.
5. Payment Processing (Merchant of Record)
For paid services, Creem acts as the Merchant of Record (MoR). Creem is your direct contractual partner for the purchase and is independently responsible under data protection law for payment processing (including taxes).
- Data processed: Payment information, billing address, email.
- Sub-processor: Creem uses Stripe for payment processing.
- Privacy information: Creem Privacy Policy, Stripe Privacy Policy.
Note: We do not store any payment data (credit card numbers, bank details) ourselves.
6. Storage Duration and Deletion
We store personal data only as long as necessary for the respective purposes or as required by statutory retention obligations:
| Data Category | Storage Duration | Legal Basis |
|---|---|---|
| Account, provider, and session data | Until account deletion | Art. 6 (1) (b) GDPR |
| Business card content | Until deletion by user | Art. 6 (1) (b) GDPR |
| Uploaded images | Until deletion by user | Art. 6 (1) (b) GDPR |
| Visitor statistics | Until account deletion | Art. 6 (1) (f) GDPR |
| Rate limiting data | Max. 60 minutes | Art. 6 (1) (f) GDPR |
| Invoice data (at Creem) | 10 years (tax law) | Art. 6 (1) (c) GDPR |
| Newsletter subscription | Until unsubscription | Art. 6 (1) (a) GDPR |
When you delete your account, the account and associated application data (profiles, cards, visit statistics, sessions, linked-provider records, and stored images) are scheduled for deletion. Data held by independent controllers, processor backups, or under statutory retention duties may remain for their applicable retention periods.
7. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
Right of Access (Art. 15 GDPR)
You may request confirmation as to whether personal data is being processed and obtain information about such data.
Right to Rectification (Art. 16 GDPR)
You may request the immediate rectification of inaccurate data.
Right to Erasure (Art. 17 GDPR)
You may request the deletion of your data, unless statutory retention obligations apply. Account deletion is possible at any time in the settings.
Right to Restriction of Processing (Art. 18 GDPR)
You may request the restriction of processing under certain conditions.
Right to Data Portability (Art. 20 GDPR)
You have the right to receive your data in a structured, commonly used, and machine-readable format.
Right to Object (Art. 21 GDPR)
You may object at any time to the processing of your data based on Art. 6 (1) (f) GDPR (legitimate interest). We will then no longer process your data unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7 (3) GDPR)
You may withdraw any consent given at any time with effect for the future.
Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
The Hamburg Commissioner for Data Protection and Freedom of Information Ludwig-Erhard-Str. 22, 7th floor 20459 Hamburg, Germany Phone: +49 40 428 54 - 4040 Email: mailbox@datenschutz.hamburg.de
8. Automated Decision-Making
Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place.
9. Data Security
We implement technical and organizational measures to protect your data against manipulation, loss, destruction, or unauthorized access. These include:
- Encrypted data transmission (TLS/SSL)
- Primary database and image storage in the selected EU project region (Stockholm)
- Application-level authorization and deny-by-default row-level security for direct database roles
- Regular security updates
- Client-side image compression plus server-side file type, signature, and size validation
Our security measures are continuously adapted to technological developments.
10. Updates to this Privacy Policy
This privacy policy is currently valid as of August 2026.
Due to the further development of our platform or changes in legal or regulatory requirements, adjustments to this privacy policy may become necessary. The current version is always available on our website.
11. Contact
If you have questions about the processing of your personal data or wish to exercise your data subject rights, please contact:
Email: contact@helllo.me