Scope
This policy applies to pricecannon.com and every subdomain operated by us. It explains what personal data we process when you browse the spotlight board, submit a product or pay for a boost.
Who is responsible
The controller within the meaning of the General Data Protection Regulation is:
- Jetlic UG (haftungsbeschränkt)
- Werinherstraße 3, 81541 München, Germany
- Managing Director: Alexander Otten
- [email protected]
SSL or TLS encryption
This site uses SSL or TLS encryption for every request. You can tell it is active because the address bar shows https:// and a closed padlock. While encryption is active, the data you send us cannot be read by third parties.
Handling of personal data
We collect personal data only where you give it to us or where processing it is necessary to run the service. We do not sell personal data, and we pass it to third parties only where this policy says so or where we are legally obliged to.
Collection of general data and information
Each time a page is requested, our servers record technical information: the browser type and version, the operating system, the referring page, the pages visited, the date and time of the request, an abbreviated IP address and the internet service provider.
We use this data to deliver the site correctly, to keep it secure and to investigate abuse. It is never combined with the data you submit with a listing. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.
Data we process when you advertise
Pasting a URL and previewing a listing stores the URL and nothing about you. Creating a campaign means creating a business account, and from that point we process the business email, trading name, country, store URL and VAT ID where you give one.
The listing itself is public by design: the product, the advertiser name and the Cannon Power it holds all appear on the board, because EU advertising rules require a sponsored placement to say who paid for it.
The legal basis for all of this is Article 6(1)(b) GDPR, since it is necessary to provide the advertising service you bought.
The campaign record
Alongside the campaign we keep a record of what was bought and what ran: login timestamps and the IP each session came from, the terms version accepted, the submitted URLs and a preview of the product, the Stripe payment ID and authentication result, invoices, campaign start and end, boosts, positions held, impressions, outbound clicks and the emails we sent.
We keep it to show that an advertising service was delivered, to answer payment disputes and to investigate abuse. The legal basis is Article 6(1)(b) and Article 6(1)(f) GDPR, and the advertiser can see the record for their own campaigns at any time.
Payments
Payments are processed by Stripe. Card numbers and bank details are entered on Stripe’s systems and never reach our servers. We receive the payment status, the amount, the currency, the billing country and a transaction reference, and we keep them for as long as tax law requires.
Product data fetched from the URL you submit
When you submit a product URL, our servers request that page once to read its title, description and preview image, and keep a copy of how the page looked at that moment. We store only what is needed to render and evidence the listing. If the page blocks automated requests, we fall back to the details you typed in yourself.
Click tracking and outbound links
Clicks on a listing are counted so that merchants can see what their boost delivered. We record the listing, the timestamp and a coarse referrer. We do not build a profile of you across sites, and outbound links carry rel="sponsored nofollow".
Cookies
We use a session cookie that is required for the site to work and is deleted when you close your browser, and two that do nothing but remember a choice you made yourself: the country you switched to, and whether you asked a comparison to show only the shops selling from it. Both are written only when you work the control, and neither is used to recognise you anywhere else. Where we set anything beyond that, we ask for your consent first and you can withdraw it at any time.
The Cookie Policy explains every cookie in detail.
Contacting us
If you write to us by email, we store your message and your address so that we can answer and follow up. We delete this correspondence once it is no longer needed and no retention obligation applies.
Third-party links
Every listing links to a site we do not control. Once you follow such a link, this policy stops applying and the privacy policy of the site you land on takes over. We are not responsible for the content or the data practices of linked sites.
Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you and receive a copy of it
- have inaccurate data corrected
- have your data deleted where no retention obligation stands in the way
- have processing restricted
- receive your data in a portable format
- object to processing based on our legitimate interest
- withdraw a consent you gave us, with effect for the future
- complain to a supervisory authority
Write to [email protected] to exercise any of these rights. Note that a campaign you paid for stays public for its whole run, including the advertiser name on it, because that is what the payment bought and what advertising law requires us to show.
Who else processes your data
We keep the list short, and everyone on it acts on our instructions under a data processing agreement.
- Stripe, for payments, fraud checks and authentication.
- Our hosting provider, whose servers are inside the European Union.
- Our email provider, for verification links, receipts and campaign notices.
- Google, for reCAPTCHA on the “tell me when it opens” form. It receives your IP address and how you interacted with the page, and returns a score telling us whether you are likely a person. We use that score to stop the form being used to send mail automatically, and for nothing else.
- Google, for Google Analytics, which we load through Google Tag Manager to count visits and see which categories are worth expanding. It receives your IP address, the page you are on, the site that sent you and rough details of your browser and device. None of that happens unless you accept the cookie notice: until then no Google Analytics script is fetched and it learns nothing about you. The reCAPTCHA above is a separate service and still loads on the two pages carrying that form whatever you choose. We never grant it advertising or personalisation consent, so it is not used to profile you or to build an advertising audience.
We do not sell personal data, and we do not pass one advertiser’s data to another. Where a payment is disputed, the campaign record goes to the card issuer through Stripe, because that is what answering a dispute requires.
How long we keep things
- Server logs: 30 days, then deleted.
- The user-level and event-level records Google Analytics holds: 14 months, then deleted by Google. The aggregate reports built from them, which count visits rather than describe people, Google keeps for longer.
- A submitted URL with no campaign behind it: 30 days, then deleted.
- Campaign records, including impressions and clicks: 3 years from the end of the campaign, which covers the window in which a payment can be disputed.
- Invoices and payment records: 8 years, the retention period German tax law sets for booking vouchers.
- Business correspondence and other commercial records: 6 years.
- Accounts with no live campaign: deleted on request, apart from what the retention periods above hold back.
Where your data is stored
On servers inside the European Union. Stripe processes payment data, and Google processes reCAPTCHA and analytics data, under their own safeguards, which may involve transfers outside the EU on the basis of the European Commission’s standard contractual clauses.
Children’s privacy
Spotlight is sold only to businesses, and we do not knowingly process data from anyone under 18. Browsing the public board requires no account and no personal data. If you believe a minor has given us data, contact us and we will delete it.
Changes to this policy
We review this policy regularly and update it when the service changes. The date at the top always shows the current version.