Privacy Policy
Last updated: [date]
Maker Badge is built to collect as little as possible: no accounts, no cookies, no analytics on this website, and badge stats without visitor identifiers. This page explains what data is processed, why, and your rights.
1. Who is responsible
[Your full name], [Street and number, or c/o address service], [Postcode and city], Germany. Email: [contact email]
2. Hosting
This website, its API and the stored badges are hosted by Netlify, Inc. (USA). When you open a page or a website loads a badge, Netlify processes your IP address, the page requested, date and time, and browser information in server logs, to deliver the content and keep the service secure (Art. 6(1)(f) GDPR). [Check and name the legal basis for the transfer to the USA, e.g. Netlify's EU-US Data Privacy Framework certification or Standard Contractual Clauses, and Netlify's log retention.]
3. The editor
Your badge is saved in your browser (localStorage), not on our servers. Nothing you enter in the editor is sent to us unless you use one of these features:
- Publish (updatable badge): we store your badge's content, including any uploaded photo, a hash of its edit key (never the key itself), and its last 10 versions, until you unpublish it. Published badges are public: anyone who knows the badge id can see its content.
- Start from your website / Match my website: we fetch the website address you enter from our servers and return what it says about you (name, photo, profiles, colors, fonts). We don't store the result.
- Page check (for "Show a page"): we check from our servers whether the page you entered allows being shown in a popup. We don't store the result.
- Shared badge links: the badge is inside the link itself (after the #) and is not sent to our servers.
Legal basis: providing the features you ask for (Art. 6(1)(b) GDPR).
4. Badge stats
On websites that use an updatable badge, the badge counts page views (about 1 in 10), popup opens and link clicks, and sends the totals to us when the page is closed. We store, per badge and day, only these counts and the addresses of clicked links. No cookies, no storage in the browser, no IP addresses or other visitor identifiers are stored. Daily counts are kept for 30 days. Makers can turn stats off with data-stats="off". Legal basis: our and the maker's legitimate interest in knowing that the badge is used (Art. 6(1)(f) GDPR).
5. Visitors of websites that show a badge
The website owner who added the badge is responsible for their website. When a badge is shown:
- Updatable badges load from our servers (see Hosting and Badge stats).
- If the maker chose a Google font, the font is loaded from Google (fonts.googleapis.com, fonts.gstatic.com), which receives the visitor's IP address.
- Photos, videos, calendars, forms and pages that the maker added are loaded from their providers (e.g. YouTube in privacy-enhanced mode, Calendly, Tally).
- Emails entered into a badge's signup form go directly to the maker's own tool (webhook or form provider), not to us.
6. This website
- No cookies and no analytics.
- The Inter font is loaded from Google Fonts, which receives your IP address. [Consider hosting the font yourself to avoid this.]
- The landing page shows photos of makers loaded from unavatar.io and Amazon CloudFront.
- "Buy me a coffee" links go to coff.ee (Buy Me a Coffee). Nothing is sent to them unless you click.
7. Email
If you email us, including to report a badge, we use your email address and message to reply and to handle your request, and delete them when they're no longer needed (Art. 6(1)(b) and (f) GDPR).
8. Your rights
You have the right to access, correct and delete your data, to restrict or object to its processing, and to data portability (Art. 15–21 GDPR). Contact us at the email above. You also have the right to complain to a data protection supervisory authority, for example the one where you live.
As there are no accounts, we usually can't tell which data is yours. To have a published badge deleted, unpublish it in the editor, or email us its id.
9. Changes
We update this policy when the Service changes. The date on this page shows the latest version.