RepDB

Privacy Policy

Last updated: 2026-09-08

1. Controller

Sergei Argutin, Regener Str. 51, 10318 Berlin, Germany. Contact: support@repdb.co (see Impressum).

2. What we process

When you buy a RepDB bundle we process your email address, name, and billing country (for VAT), together with order and license details (public order number, tier, license version, amount, currency, timestamps). We keep a record of your order (including your email address, your name, and the public order number, as the licensee record for license administration) to validate downloads, resend links, and administer your license. If you use the resend form, we process the email address you enter to look up your order and trigger a new download email through Resend; to prevent abuse, resend requests are rate-limited for a short period. Browsing the site requires no account and no login. If you voluntarily tick the email-updates checkbox on the thank-you page or elsewhere on the site, we additionally process your email address, locale, consent record, and, where supplied, your IP address for the double-opt-in record. We use these details to request a subscription for occasional RepDB emails about product updates, technical articles, new products, and special offers. Buttondown sends the confirmation email and maintains the subscription status; only confirmed subscribers receive these updates. You can unsubscribe at any time (using the link in the email or by emailing support@repdb.co).

3. Legal basis

We process this data to deliver your purchase and license under Art. 6(1)(b) GDPR (performance of a contract), and we retain invoices/records under Art. 6(1)(c) GDPR (legal obligation under German tax law). Server and access logs (incl. IP addresses) that our hosting provider processes to operate and secure the site rely on Art. 6(1)(f) GDPR (legitimate interest). Sending optional product-update and marketing emails relies on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.

4. Recipients & processors

We do not sell your data. We use it for advertising only in the narrow sense described in section 5: measuring whether our own ads led to a purchase. We do not build advertising profiles and do not use your data to target ads at you.

5. Cookies & analytics

Cloudflare Web Analytics. For aggregated, privacy-first usage statistics we use Cloudflare Web Analytics, which is cookieless: it sets no cookies, stores or reads nothing on your device, does not fingerprint you, and does not track you across other sites. It collects only aggregated metrics (such as page URL, referrer, country, browser and device type, and page-load performance) and no information that identifies you personally. Because it stores nothing on your device, it needs no consent; this processing relies on our legitimate interest in understanding and improving how the site is used (Art. 6(1)(f) GDPR). Cloudflare acts as our processor (see section 4).

Google Ads conversion measurement. We advertise on Google Ads and need to know which ads lead to purchases. We use no advertising profiles, no remarketing, no ad personalisation and no cross-site tracking, and we do not sell your data. Three separate things are involved, with different legal bases:

  1. Server-side reporting — no cookies, always active. If you arrive from a Google ad, the ad click identifier (gclid, gbraid or wbraid) is carried in the page URL only; it is never stored on your device. If you buy, we store it with your order record and report the purchase to Google Ads from our server. Legal basis: legitimate interest in measuring our advertising (Art. 6(1)(f) GDPR).
  2. The Google tag — loads for every visitor, no cookies by default. Google's tag (gtag.js, provided by Google Ireland Ltd.) loads on every page regardless of your choice below. Unless you consent it sets and reads no cookies. On most pages it sends only limited, non-identifying signals to Google (timestamp, browser/user-agent, referrer, your consent state, and the page address; query parameters are removed from the page address before it is sent, except a Google Ads click identifier if one is present). On the order confirmation page it additionally sends a cookieless conversion signal telling Google that a purchase occurred, together with the purchase value and currency and a SHA-256 hash derived from your order reference (so Google can recognise repeat reports of the same purchase). This purchase signal is sent with or without your consent; even so, no cookies are set and your email address and the download link for your order are never transmitted. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
  3. Only with your consent — cookies and enhanced conversions. If you accept in the cookie banner, two additional things happen. First, the tag sets the first-party cookies below on our domain to link a later purchase back to your ad click. Second, on the order confirmation page it transmits a SHA-256 hash of your (normalised) email address to improve conversion matching. Your email address is never transmitted in readable form — only as that hash — and it is sent only if you consent. Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future via “Cookie settings” in the footer.
CookieProviderPurposeDuration
_gcl_auGoogleStores the ad click identifier so a later purchase can be attributed to the ad you clicked.90 days
_gcl_awGoogleStores the ad click identifier for conversion measurement after an ad click.90 days

These cookies are set only after you accept, and only on our own domain (first-party). Your choice is stored locally in your browser so we do not ask again.

Measurement diagnostics. We count banner displays, consent choices and technical stages of purchase-event reporting as daily totals on our server. These counters contain only the day, a fixed event name and the consent state (unknown, accepted or declined). They contain no email address, order identifier, ad click identifier, page address, IP address or browser description, and are not linked to your order. Diagnostic requests send no cookies or referrer and do not create additional browser storage. The hosting and security processing described above still applies.

6. Retention

Invoice and order records are kept for the statutory retention period under German tax law (8 years for invoices/accounting records since 2025, up to 10 years for other records; § 147 AO). Personal data not subject to a retention obligation is deleted once it is no longer needed. Newsletter signup and consent records are kept for as long as needed to operate the subscription and demonstrate consent; after an unsubscribe, we retain only what is needed to honour the opt-out and meet legal obligations.

7. Your rights (GDPR)

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). To exercise them, email support@repdb.co. You may also lodge a complaint with a supervisory authority — for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

8. International transfers

Some recipients, including Lemon Squeezy, Cloudflare, Resend, and Buttondown, are US companies or may process data in the United States. Transfers outside the EU/EEA rely on appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, where applicable.

9. Contact

Data-protection questions: support@repdb.co.

Want to see more from RepDB?

Add RepDB as a Preferred Source to find more of our exercise data in Google.