Privacy Policy
Last updated: 25 July 2026
1. Controller
The Controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dominik Schimpf (Sophistication.io)
c/o IP-Management #2918, Ludwig-Erhard-Str. 18, 20459 Hamburg
Email: support@sophistication.io
2. Scope
This Privacy Policy applies to our own web offerings:
- sophistication.io (company website),
- app.sophistication.io (client portal).
For websites that we host and operate on behalf of our clients, the respective client is responsible under data protection law; in that respect we act as a processor (see Section 11). For visitors to such sites, the relevant policy is the privacy policy of the respective site operator.
3. Categories of Data Processed and Purposes
- Access data (including IP address, time of access, content retrieved, browser/device information) – for the secure and performant delivery of the pages (Sections 4 and 5).
- Contract and order data (email address, name or company, billing address, VAT identification number where applicable, selected plan, payment data) – for the establishment and performance of the contract (Section 6).
- Client portal account data (name, email address, authentication data, organization and role affiliation) – for the provision of the portal (Section 7).
- Connection and integration data (connected domain; access keys to shop and advertising accounts stored at the client's instruction, as well as order and expenditure data obtained from them) – for the technical setup and for the analysis functions activated by the client (Section 10).
- Communication data (content and sender data of your emails to us) – for handling your inquiries.
4. Server Log Files
When our pages are accessed, information transmitted by your browser is automatically processed in so-called server log files: IP address, date and time of access, the resource retrieved, the referrer, and details about the browser and operating system. This data is technically necessary in order to deliver the pages, ensure their stability and security, and defend against misuse. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and trouble-free operation). The log files are retained only for a short period necessary to achieve the purpose and are then deleted.
5. Hosting & Storage (Cloudflare)
Our web offerings are delivered and secured via the infrastructure of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (content delivery network, edge computing, key and object storage). Contract and connection data is stored in the Cloudflare infrastructure to provide the service. A data processing agreement (DPA) is in place with Cloudflare; the transfer to the USA is safeguarded by EU Standard Contractual Clauses (SCCs). Legal basis: Art. 6(1)(f) GDPR (secure and efficient operation) or Art. 6(1)(b) GDPR (performance of the contract).
6. Payment Processing (Stripe)
For processing paid services we use Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA). Stripe processes the data required for payment, including email address, billing address, and VAT identification number where applicable. A data processing agreement is in place; transfers to third countries are safeguarded via SCCs. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Stripe's privacy notices apply additionally (stripe.com/de/privacy).
7. Client Portal (app.sophistication.io)
For registration and management of organizations and users in the client portal we use Clerk, Inc. (USA). For this purpose Clerk processes name, email address, authentication and session data. Clerk is certified under the EU-U.S. Data Privacy Framework; additionally, EU Standard Contractual Clauses and a data processing agreement are in place.
Account, page and history data of the portal (page configurations, versions, change logs, editor chat histories, analysis data) is stored with Supabase, Inc. in the EU region (Frankfurt am Main). A data processing agreement is in place. Access is separated by organization (tenant-based access control).
The portal uses exclusively technically necessary cookies (session/login). Legal basis of the processing: Art. 6(1)(b) GDPR (performance of the contract).
8. AI-Assisted Editing (Anthropic)
If a client uses the portal's AI functions (editor, test suggestions), we transmit the page content to be edited and the instructions entered to Anthropic, PBC (USA) for processing by their language models. Content transmitted via the API is not used by Anthropic to train the models, in accordance with their terms of use. A data processing agreement is in place; transfers to third countries are safeguarded via SCCs. Legal basis: Art. 6(1)(b) GDPR (provision of the booked function). We recommend not entering any personal data of third parties in editor instructions.
9. Support Chat (Intercom)
For support inquiries we use the messenger of Intercom R&D Unlimited Company (Ireland; Intercom, Inc., USA). On our website the messenger is not loaded automatically: it is retrieved and set up only when you actively click the chat button, so no cookies or comparable information are stored on your device beforehand. Once opened, Intercom processes the content of your messages, the technical connection data of the session, and an identifier stored on your device that allows a conversation to be continued.
In the client portal the messenger is part of the booked service and is opened for logged-in users with a signed token. In that case we transmit to Intercom the identifier of your user account together with your booked plan, the status of your subscription, the number of funnels created, and your language setting, so that support requests can be answered in context. We also use Intercom to send product and onboarding emails relating to your account.
A data processing agreement is in place; transfers to third countries are safeguarded by EU Standard Contractual Clauses. Legal basis: Art. 6(1)(b) GDPR (performance of the contract, in the portal) and Art. 6(1)(f) GDPR (legitimate interest in answering inquiries made through the website). Intercom's privacy notice applies additionally (intercom.com/legal/privacy).
10. Services Connected by the Client (Shop and Advertising Accounts)
In the portal, clients can connect their own accounts with third-party services, currently Shopify (shop order data) and Meta (advertising expenditure). The connection is made exclusively at the active instruction of the client (storing an access key or authorization via the third-party service's login dialog).
- Shopify: We obtain order data (order identifier, amounts, currency, technical attribution characteristics) from the client's shop in order to attribute revenue to the pages we operate. We do not obtain or store names or addresses of the shop's end customers.
- Meta: With read permissions ("ads_read") we obtain campaign and expenditure data of the advertising account in order to attribute advertising spend to the pages.
Access keys are stored with restricted access and encrypted and cannot be read out in the portal. The client can disconnect a connection at any time in the portal settings; the respective access key is then deleted. Legal basis: Art. 6(1)(b) GDPR (function requested by the client). See also the data deletion notice.
11. Measurement on Client Pages (Processing on Behalf of the Controller)
On websites that we host and optimize on behalf of our clients, we process visitor data as a processor of the respective site operator on the basis of a data processing agreement (DPA, available on request): aggregated views and clicks, a pseudonymous visitor identifier and a day identifier, as well as a signed click identifier in follow-up links to attribute orders. No cross-site tracking takes place; no advertising networks are integrated and no data is sold. The respective site operator is responsible under data protection law for this processing; its privacy policy is authoritative.
12. SSL/TLS Encryption
For security reasons our pages use SSL/TLS encryption. You can recognize an encrypted connection by the „https://" in the address bar of your browser.
13. Cookies, Consent and Reach Measurement
When you first visit our website you are asked to make a choice. Until you do, nothing beyond the strictly necessary runs: no statistics, no marketing, no support chat. Rejecting is a single click on a button of the same size and prominence as accepting, nothing is pre-ticked, and the page works either way. Your choice is stored in a first-party cookie for six months, after which we ask again, and you can change or withdraw it at any time via Cookie settings in the footer. The legal basis for anything beyond the strictly necessary is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG); for the strictly necessary it is Sec. 25(2) TDDDG and Art. 6(1)(f) GDPR.
The categories are:
- Strictly necessary (cannot be switched off): login and session for the client portal, security and abuse protection, and the cookie that stores this very choice.
- Functional: the support chat (Section 9). Switched off, the chat still works, it simply loads at the moment you click it.
- Statistics: a more detailed analysis of how pages are used.
- Marketing: measuring which advertisement led to a visit.
Independently of this choice we count page views without cookies using Cloudflare Web Analytics. No information is stored on or read from your device for this, no identifier is created, and no profile is built; it is aggregate reach measurement only. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing which content is used).
Google Tag Manager. To load the services in the statistics and marketing categories we use Google Tag Manager (Google Ireland Limited, Ireland). Tag Manager itself stores no information on your device and sets no cookies; it is a loader for the services listed here. We load it only after you have consented to statistics or marketing, so before your decision no connection to Google is established at all. Legal basis: Art. 6(1)(a) GDPR.
Google Analytics 4. With your consent to statistics we use Google Analytics 4 (Google Ireland Limited, Ireland). Google processes usage data to give us aggregated reports on how our website is used. IP addresses are shortened by Google. We use Google Consent Mode, so the service is only loaded and only stores information after your consent. Google acts as our processor on the basis of Google's data processing terms, which incorporate the EU Standard Contractual Clauses for transfers to third countries. Legal basis: Art. 6(1)(a) GDPR.
Meta pixel. With your consent to marketing we use the Meta pixel (Meta Platforms Ireland Limited, Ireland) to measure the effectiveness of our advertising and to reach people who have already visited our website. Meta may process this data for its own purposes as well; to that extent we and Meta are joint controllers under Art. 26 GDPR. Transfers to third countries are safeguarded by EU Standard Contractual Clauses. Legal basis: Art. 6(1)(a) GDPR.
Payment processing takes place on the pages of Stripe.
14. Retention Period
We process personal data only for as long as is necessary for the stated purposes. Contract and order data is stored for the duration of the contract and beyond that within the scope of statutory retention obligations (in particular under commercial and tax law, generally up to 10 years). Server log files are retained only for a short period to ensure operation. Access keys of connected services are deleted when the connection is disconnected.
15. Obligation to Provide Data
The provision of the contract and order data is required for the conclusion and performance of the contract. Without this data we cannot establish the contract and cannot provide the service.
16. No Automated Decision-Making
Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place. Every visitor to a page is served the same published version of it.
17. Naming as a Reference Client (only with consent)
Only with your express consent do we name your brand and display the page we created for you – including your logo and screenshots of the publicly accessible page – as a reference project on our website sophistication.io as well as in comparable materials of our own advertising. The legal basis is your consent under Art. 6(1)(a) GDPR. You provide the consent voluntarily as part of the setup; withholding it has no effect on the contract. You can withdraw the consent at any time with effect for the future – by email to support@sophistication.io; we will then remove the reference promptly.
18. Your Rights
You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20 GDPR). You can withdraw any consent given at any time with effect for the future. Notes on the deletion of accounts and connected services can be found at sophistication.io/data-deletion.
19. Right to Object (Art. 21 GDPR)
Insofar as we process personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process the affected data unless we can demonstrate compelling legitimate grounds worthy of protection that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defense of legal claims.
20. Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg (LfDI)
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de
21. Currency and Amendment of This Privacy Policy
This Privacy Policy is currently valid and reflects the date stated above. Due to the further development of our services or as a result of changed statutory or regulatory requirements, it may become necessary to adapt it. The respective current version can be retrieved at any time on this page.
22. Contact for Data Protection Matters
For inquiries regarding data protection you can reach us at: support@sophistication.io