Privacy policy

This site is static HTML and CSS. It sets no cookies, runs no scripts, loads nothing from anywhere else and has no form to submit. The only personal data processed is the server-log record that any web server keeps when it serves a page.

Pre-launch draft, pending legal review. The controller named below does not exist yet — no legal entity has been registered — so the identity, the contact route, the supervisory authority and the retention period are marked placeholders. The description of what this site does and does not do is accurate and was checked against the site’s own source; the legal framing around it has not been reviewed by a lawyer.

The short version

  • No cookies of any kind, and no consent banner because there is nothing to consent to.
  • No analytics, no tag manager, no tracking pixel, no advertising, no A/B testing.
  • No fonts, scripts, images, maps or embeds loaded from other servers.
  • No contact form, no newsletter, no account, no login, no payment.
  • No data of yours is uploaded by the free check — it never leaves your device.
  • The hosting provider that serves these pages records IP addresses and request metadata in its server logs, as every web server does. That is described in full below.

Who is responsible

The controller for the processing described here — the party that decides why and how it happens:

  • Controller: [PLACEHOLDER: registered legal name and legal form of the controller]
  • Address: [PLACEHOLDER: registered address of the controller]
  • Contact for data-protection questions: [PLACEHOLDER: e-mail address for privacy enquiries]
  • Data protection officer: [PLACEHOLDER: whether a DPO is required and, if so, their name and contact details — a decision for the owner and their lawyer]
  • Representative in the EU or Switzerland, where one is required: [PLACEHOLDER: representative under GDPR Art. 27 / revFADP, or confirmation that none is required]

Full provider details, once they exist, will also appear in the imprint.

Which law applies

[PLACEHOLDER: the applicable data-protection framework — Swiss revFADP, EU/EEA GDPR, or both. This follows from where the entity is registered and whom the site is aimed at, and neither is settled yet. The rights and legal bases below are written to the stricter of the two.]

What this site does not collect

These are properties of how the site is built, not promises about how it is administered, so you can verify them rather than trust them.

No cookies and no tracking

No cookie is set by these pages, and nothing is written to local storage or session storage. There is no analytics service, no tag manager, no tracking pixel, no advertising network, no social plug-in and no cross-site identifier. You are not profiled, and no automated decision-making takes place.

No scripts

The marketing pages of this site contain no JavaScript at all — not a single script element. A page that runs no code cannot quietly measure you. The site’s own build check fails the build if a script is ever added.

No third-party requests

The only file these pages load is one stylesheet served from this same site. There is no content delivery network, no remote web font, no remote image, no embedded video and no map. Because nothing is requested from another server, no other company learns your IP address from your visit here.

No forms and no accounts

There is no contact form, no sign-up, no newsletter subscription, no login and no payment. Nothing on this site submits anything anywhere, so there is no name, e-mail address or message for us to receive, store or lose.

You can confirm all of this in about a minute: open your browser’s network tab and load any page here, or read the page source. What you will see is the document itself and one stylesheet.

Hosting and server logs

This site is published with GitHub Pages, so GitHub’s servers deliver these pages to your browser. Like every web server, they process the technical data that a request necessarily contains in order to answer it, and record it in server logs. That typically includes:

  • the IP address the request came from;
  • the date and time of the request;
  • the address of the page or file requested, and the response status;
  • the amount of data transferred;
  • the browser and operating system reported by your browser (the user-agent string);
  • the referring page, if your browser sends one.

This is the only processing of personal data that actually happens when you use this site, and it is unavoidable: a server cannot send a page to an address it does not have. It is used to deliver the site, to keep it available, and to detect and defend against attacks and abuse. It is not used to identify you, to build a profile, or for marketing, and it is not combined with anything else — there is nothing else.

Legal basis

Where the GDPR applies, the legal basis is Art. 6(1)(f) — the legitimate interest in presenting a functioning, stable and secure website. Where Swiss law applies, the same processing is justified by the overriding private interest in the secure operation of the site. You can object to processing based on legitimate interests; see your rights below.

Who processes it

GitHub acts as the hosting provider for this site and, in data-protection terms, as a processor acting for the controller named above. The logs are generated and held by GitHub as part of operating its platform. We do not receive these logs, do not have an interface to query them, and cannot look up individual visitors.

Placeholder — owner and lawyer must settle before launch

[PLACEHOLDER: the data-processing agreement with the hosting provider — whether GitHub’s standard terms and data protection addendum are accepted as the processor agreement, and a reference to them here.]

[PLACEHOLDER: the actual retention period for the hosting provider’s server logs. This is set by the provider, not by us. It must be read out of the provider’s current documentation and stated here as a period, not guessed.]

Transfers outside your country

GitHub is a company established in the United States and operates a global network, so the server-log data described above may be processed outside Switzerland and outside the European Economic Area. There is no other recipient: nothing else on this site sends anything anywhere.

[PLACEHOLDER: the transfer mechanism actually relied on — e.g. standard contractual clauses in the provider’s terms, an adequacy decision, or another safeguard — and where a copy can be obtained. This must be checked against the provider’s current documentation, not assumed.]

The free check runs in your browser

Nothing is uploaded

Your CSV files never leave your device

The free planning check is a web page that reads the CSV files you choose, analyses them and displays the findings — all inside your browser, on your own machine. It has no network capability by construction: no upload, no background transmission, no telemetry, no error reporting, no “optional” cloud step.

Your files are never sent to us, never sent to the hosting provider beyond the ordinary request that fetched the page itself, and never stored by this site. Nothing is written to cookies, local storage, session storage or any browser database. The analysis lives in the page while the tab is open; closing the tab is the delete button.

Because your item master, vendor list and receipts are commercially sensitive, this is deliberately verifiable rather than merely promised: open the browser’s network tab while the check runs and nothing is requested, or disconnect from the network first and it still works.

The same claim, with the technical reasoning behind it, is on the how it works page.

Because the tool never transmits your data, we are not a controller or a processor of anything it reads. Whatever is in those exports remains entirely under your own control, on your own equipment, and under whatever obligations already apply to you as its controller.

Who receives your data

Nobody, apart from the hosting provider described above. Your data is not sold, rented, shared or disclosed. There is no advertising partner, no analytics vendor, no customer relationship system and no e-mail platform involved in this site, because there is no mechanism by which anything could reach them.

[PLACEHOLDER: disclosure to authorities. Whether and how a legally binding order for the hosting provider’s logs would be handled is a question for the lawyer once the entity and jurisdiction exist.]

How long anything is kept

We store nothing ourselves: there is no database, no log of our own and no back end. The only retention question is how long the hosting provider keeps its server logs.

[PLACEHOLDER: retention period for the hosting provider’s server logs, taken from the provider’s current documentation]

Your rights

In respect of personal data relating to you, you can ask to exercise the following rights. They are stated here in their broadest form, so that the answer does not depend on which framework finally applies.

  • Access — confirmation of whether data relating to you is processed, and a copy of it.
  • Rectification — correction of inaccurate data, and completion of incomplete data.
  • Erasure — deletion, where there is no overriding reason to keep it.
  • Restriction — that processing be limited rather than continued, in the cases the law provides for.
  • Objection — to processing based on legitimate interests, including the server logging described above, on grounds relating to your situation.
  • Portability — a structured, commonly used, machine-readable copy of data you provided, where that right applies.
  • Withdrawal of consent — at any time, where processing ever rests on consent. Nothing on this site currently does.
  • Complaint — to a data protection supervisory authority.

In practice the honest answer to most access requests about this site is that we hold nothing about you: the only record of your visit sits in the hosting provider’s logs, keyed to an IP address we cannot query. A request would be forwarded to the provider to the extent it can be.

  • To exercise a right, contact: [PLACEHOLDER: e-mail address for data-subject requests]
  • Competent supervisory authority: [PLACEHOLDER: name, address and contact details of the supervisory authority — this follows from the country of establishment, which is not decided; in Switzerland this would be the FDPIC, in the EU the authority of the member state concerned]

Is providing data required?

No. You are not asked for any data, and there is nothing to withhold. The technical data in the server logs is created by the act of requesting a page and cannot be separated from it, which is true of every website; if you would rather not generate it, do not open the page.

Changes to this notice

This notice describes the site as it is built today. It will change when the site changes — and in particular it must be rewritten before anything that collects data is added: a contact form, an account, a newsletter, a payment step, an embedded video, or the cloud reporting step described on the pricing page as not yet open.

The current version is always the one published on this page. There is no mailing list to announce changes through, because there is no mailing list.

[PLACEHOLDER: how material changes will be announced, and a version or effective date for this notice once it has been reviewed]

Related pages