Privacy policy
Last updated: 12 August 2026
1. Controller
The controller responsible for processing personal data on this website is:
Niklas Lippertc/o IP-Management #10907
Ludwig-Erhard-Straße 18
20459 Hamburg, Germany
support@lippi.dev
2. Using the site without an account
When you open the public pages, we process the data your browser sends: IP address, date and time, the address requested and browser identification. This is technically necessary to deliver the page and keep it secure. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is the secure and stable operation of the service.
3. Account and sign-in
Using the service requires an account. We store your email address, a user identifier from the authentication provider, your plan and the time the account was created. Sign-in itself is handled by Clerk. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
4. Connected Etsy shops and reports
When you add an Etsy shop, we store its name, its public Etsy shop identifier and the time of the last retrieval. No Etsy sign-in is required for this; only publicly available data is retrieved.
From the shop’s publicly visible reviews we produce weekly reports. We store a sentiment score, the themes found together with their counts, a summary, and verbatim excerpts from individual reviews. Names, identifiers or other details about the people who wrote those reviews are not stored. The review texts themselves are not kept — they are processed only for the duration of the analysis. The legal basis is Art. 6(1)(b) GDPR towards you as a user, and Art. 6(1)(f) GDPR with regard to the publicly available reviews; the legitimate interest is the evaluation of publicly published feedback on behalf of the shop’s operator.
We additionally record publicly available shop figures each week — views, favourites, number of sales, and the title, address, price and stock of the most-viewed listings. These figures concern the shop, not individual buyers.
5. Automated analysis by an AI system
The substantive analysis of the reviews is performed automatically by an AI language model. For this, the shop name and the review texts of the relevant period are transmitted to the provider named in section 7. The resulting reports are AI-generated content and are identified as such.
No automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you.
6. Payment processing
The paid plan is handled through Stripe. You enter your payment details directly with Stripe; we do not receive full payment credentials. We store only the customer and subscription identifiers and the plan booked. The legal basis is Art. 6(1)(b) GDPR.
7. Recipients and processors
We use the following service providers. Data processing agreements under Art. 28 GDPR are in place with them.
Clerk Inc.
Sign-up, sign-in and session handling
Data: email address, sign-in credentials, user identifier · Place of processing: United States
Neon Inc.
The database holding account, shop and report data
Data: all stored data described in this policy · Place of processing: United States (us-east-1 region)
Vercel Inc.
Hosting and delivery of the application, server logs
Data: IP address, timestamp, requested address, browser identification · Place of processing: United States
Stripe
Processing of the paid subscription
Data: email address, payment and subscription data · Place of processing: Ireland and United States
Google (Gemini API)
Automated analysis of the retrieved review texts
Data: shop name and the review texts of the period being analysed · Place of processing: United States
Resend (Plus Five Five, Inc.)
Sending the email that tells you a new report is ready
Data: email address, shop name, and the opening of the report summary · Place of processing: Ireland (EU region)
An email delivery provider is additionally planned for sending the weekly notification. This policy will be updated once that is active.
8. Transfers to third countries
The providers listed in section 7 process data wholly or partly in the United States. Such transfers take place on the basis of an adequacy decision of the European Commission under Art. 45 GDPR where the provider has certified under the EU-US Data Privacy Framework, and otherwise on the basis of standard contractual clauses under Art. 46(2)(c) GDPR.
The United States does not offer a level of data protection equivalent to European law. In particular, authorities there may access data under certain conditions without effective legal remedies necessarily being available.
9. Retention
Account, shop and report data are stored for as long as your account exists. After deletion they are removed unless statutory retention obligations apply; invoicing data is subject to commercial and tax retention periods of up to ten years. Server logs are retained by our hosting provider according to its own policy.
10. Cookies and local storage
We use no cookies for analytics or advertising and embed no tracking services. Signing in requires technically necessary cookies set by the authentication provider. Your choice between the light and dark appearance is stored locally in your browser and is not transmitted to us.
11. Your rights
Subject to the statutory conditions, you have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
A message to support@lippi.dev is enough to exercise them. Any consent you have given can be withdrawn at any time with effect for the future.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for the controller is the Hamburg Commissioner for Data Protection and Freedom of Information.
13. Changes to this policy
We update this policy when the processing described here or the providers used change. The version published on this page is the one that applies.