Last updated: 24/04/2026
This privacy policy explains how TestiPull ("we", "us") collects, uses, and protects personal data when you use our service at this website. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) as well as relevant US privacy laws (CCPA, VCDPA, CPA, CTDPA, UCPA).
The controller responsible for data processing on this site is Christopher Kurr (address and contact details: see Imprint).
Account data (when you sign up):
Testimonial data (submitted by your clients via a collect link):
Usage data (automatically collected):
We use the following subprocessors to operate our service:
Account and testimonial data are kept for as long as your account is active. On deletion of your account or a specific testimonial, the data is permanently removed from our systems. Backups are retained for up to 30 days.
Under GDPR and applicable US state laws, you have the right to:
To exercise any of these rights, contact us at testipull@gmx.net.
We use Vercel Analytics and Speed Insights, both of which operate without cookies and do not track individual users across sites. Essential cookies (for authentication and session management via Supabase) are used only when you sign in. No third-party advertising or cross-site tracking is performed.
Our primary database and authentication infrastructure (Supabase) is hosted in the European Union (eu-west-1, Ireland). Your account data and testimonials are stored in the EU and not transferred outside the EU for storage.
Some of our other subprocessors (Vercel hosting, Polar payments, Resend transactional email) are based in the United States. Transfers to these providers are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46 and, where applicable, the EU-US Data Privacy Framework.
We may update this policy from time to time. The "last updated" date at the top reflects the most recent change. Material changes will be communicated via email or via a notice on this page.
Questions about this privacy policy or our data practices can be directed to testipull@gmx.net.
Note for Chris (remove before production):
This is a best-effort template. Generate a legally reviewed version via the datenschutz-generator.de (eRecht24) and paste it here. Verify the Supabase region to determine whether SCCs are truly needed. Confirm with your lawyer before accepting paying EU customers.