Privacy Policy — pleaseopen.me
Last updated: [30.07.2026]
This Privacy Policy explains how Eighteen1 Studios ("we," "us," "our") collects, uses, and protects information when you use pleaseopen.me (the "Service"), whether as a visitor clicking a redirect link or as a creator with an account.
Because we are based in Germany, this policy is written to comply with the EU General Data Protection Regulation (GDPR). If you are located outside the EU/EEA, additional local rights may apply to you; nothing here limits rights you have under your local law.
We are not lawyers speaking on your behalf when you read this — if you need this policy reviewed for a specific jurisdiction or edge case, we recommend consulting a qualified privacy lawyer before relying on it for compliance purposes.
1. Who is responsible for your data (Data Controller)
Eighteen1 Studios Owned by Raphael Pappalardo Website: eighteen1.com Contact: contact@pleaseopen.me
For any privacy-related questions, requests, or complaints, please contact us at the email address above.
2. What data we collect
2.1 Visitors clicking a redirect link (e.g. pleaseopen.me/yourslug)
We collect limited, aggregated analytics on redirect pages so that creators can see how their links are performing. Specifically:
- Button/action click counts — e.g. how many times the "Open in browser" step or the final store redirect was triggered.
- Country of the visitor — derived from the visitor's IP address at the moment of the click (via hosting edge geo headers). We do not store the IP address itself; it is used momentarily to look up the country and is then discarded.
- Anonymous visit id — a random id kept in the browser's
sessionStoragefor the duration of a tab session so we can count unique visits and funnel steps without identifying a person.
We do not collect or store names, email addresses, device identifiers, precise location, or any other information that could identify an individual visitor. The data shown to creators is aggregated (e.g. "42 clicks from Germany"), not tied to any individual person.
If this changes in the future (e.g. we begin storing IP addresses, or add more granular tracking), we will update this policy and, where legally required, request consent before doing so.
2.2 Creators with a pleaseopen.me account
When you create an account and use our dashboard, we collect:
- Account/authentication data: your email address, and — if you choose to sign in via Google or Apple — the basic profile information those providers share with us (typically name and email address) to create and manage your account.
- Content you provide: the slugs, App Store / Google Play URLs, template choices, and any custom copy or branding you configure for your redirect links.
- Payment information: if you purchase a premium upgrade, payment is processed by Stripe. We do not receive or store your full card details — Stripe handles this directly. We retain records of your purchase (e.g. transaction status, plan purchased) for accounting and support purposes.
We do not knowingly collect any special categories of personal data (e.g. health, religious, or political information) — please do not include such information in any custom copy or content you submit through the Service.
3. Why we process your data (Legal basis)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating and securing your account | Email, auth provider data | Contract (Art. 6(1)(b)) |
| Operating your redirect links | Slug, store URLs, custom content | Contract (Art. 6(1)(b)) |
| Processing payments | Purchase/transaction records | Contract (Art. 6(1)(b)) |
| Responding to support requests | Email, message content | Legitimate interest (Art. 6(1)(f)) |
| Providing creators with link performance stats | Click counts, country (derived from IP, not stored) | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations (e.g. tax records) | Payment/transaction records | Legal obligation (Art. 6(1)(c)) |
4. Who we share data with (Processors & recipients)
We use the following third-party service providers to operate pleaseopen.me. Each acts as a data processor on our behalf under a data processing agreement, or as an independent controller for their own purposes (e.g. fraud prevention), as noted below.
- Supabase — database hosting and authentication (email, Google, Apple sign-in). Supabase may store data on servers located outside the EU/EEA depending on project configuration; where this applies, transfers are safeguarded via Standard Contractual Clauses (SCCs) or equivalent mechanisms.
- Vercel — application hosting and content delivery. May process data on infrastructure located outside the EU/EEA, safeguarded via SCCs or equivalent mechanisms where applicable.
- Stripe — payment processing. Stripe acts as an independent controller for fraud prevention and regulatory compliance purposes in addition to processing payments on our behalf. Stripe may set its own cookies during checkout (see Section 5).
- Google / Apple — only if you choose to sign in using these providers, in which case they act as independent controllers for the authentication data they share with us.
We do not sell your personal data, and we do not share it with third parties for advertising purposes.
5. Cookies and similar technologies
We do not use advertising or cross-site tracking cookies. Our redirect-link analytics (click counts and country, see Section 2.1) do not use advertising cookies. To group events from the same browser tab session we store an anonymous visit id in sessionStorage on your device; it is not a cross-site tracker and clears when the tab session ends.
We do use cookies/tokens that are strictly necessary for the Service to function, including:
- Authentication session cookies (via Supabase Auth) — to keep you logged in.
- Payment security cookies (via Stripe) — set automatically during checkout for fraud prevention (e.g.
__stripe_mid,__stripe_sid).
Because these cookies are strictly necessary for the Service to work, and because our visitor analytics do not use advertising cookies or retain personal identifiers beyond an anonymous session visit id, none of this requires a cookie consent banner under GDPR/ePrivacy rules. If we introduce non-essential cookies or start retaining personal identifiers in the future (e.g. storing IP addresses, advertising), we will update this policy and implement a consent mechanism as required by law.
6. How long we keep your data
- Account data: retained for as long as your account is active. If you delete your account, we will delete your account data within a reasonable period, except where we are required to retain certain records (e.g. transaction records) for legal or tax purposes.
- Analytics events (click/redirect counts for creators): retained for 7 days on Free plans and 1 year on Premium plans, then automatically deleted. Upgrading does not restore already-purged history.
- Payment/transaction records: retained as required by applicable tax and accounting law (typically up to 10 years in Germany for financial records), even after account deletion.
- Support correspondence: retained only as long as reasonably necessary to resolve your inquiry and for a limited period afterward for quality/reference purposes.
7. Your rights (GDPR)
If you are located in the EU/EEA (or otherwise protected by GDPR), you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten"), subject to legal retention obligations
- Restrict processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority — in Germany, the relevant authority depends on your state, or you may contact the authority local to you
To exercise any of these rights, contact us at contact@pleaseopen.me. We will respond within the timeframe required by GDPR (generally one month).
8. Children's privacy
pleaseopen.me is not directed at children, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. Data security
We rely on the security measures provided by our infrastructure providers (Supabase, Vercel, Stripe), including encryption in transit. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable steps to protect your data against unauthorized access, loss, or misuse.
10. Changes to this policy
We may update this Privacy Policy from time to time, for example if we add new features (such as analytics) or change service providers. We will update the "Last updated" date at the top of this page, and for material changes, we will make reasonable efforts to notify account holders (e.g. via email).
11. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact:
Eighteen1 Studios Raphael Pappalardo contact@pleaseopen.me eighteen1.com