Privacy Policy
Last updated: July 31, 2026
1. Controller
DigitalToolsList Extended UG (haftungsbeschränkt), Paalende 26, 22149 Hamburg, Germany.
Email: bdoerffer@digitaltoolslist.com
No data protection officer has been appointed, as the statutory requirements do not apply. The German version of this policy is legally authoritative.
2. Overview
This policy explains the processing of personal data (a) when visiting this website including the waitlist and (b) when using the ScanToPitch application ("tool"). Sections concerning the tool apply once you use it.
Note: information about the processing of data of the businesses analyzed inside the application can be found in our separate Data Subject Notice.
3. Hosting and server logs
This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA) and served from an EU data center (Frankfurt region). When you visit the site, Vercel processes technically necessary connection data (IP address, date and time, requested resource, user agent) to deliver the site and keep it secure.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, performant operation). A data processing agreement is in place with Vercel; US transfers are safeguarded via the EU-US Data Privacy Framework and/or Standard Contractual Clauses.
4. Waitlist
When you join the waitlist, we process your email address, your waitlist position, and the signup time. The purpose is informing you about the product launch and access to the application.
Signup via the free website check: if you optionally enter your email address under a result of the free website check (/audit), we additionally store the checked domain and the displayed result. The purpose is sending you the report link as well as related tips and product information. Viewing the result itself does not require an email address. The same double-opt-in procedure and the same revocation and deletion options apply; on unsubscribe, the domain and result are deleted as well.
Legal basis: Art. 6(1)(a) GDPR (consent). You give consent before submitting via a checkbox and then confirm via double opt-in: we first store your signup as unconfirmed and send a confirmation email (via Resend, see section 9); your signup counts as confirmed only after you click the confirmation link. Before storing the address, we check the technical deliverability of the email domain via a DNS lookup; no emails are sent in the process.
You can revoke your consent and request deletion at any time (an informal email is sufficient). The data is stored until revocation, at most until 12 months after the product launch, in our database at Supabase (EU region).
5. Cookies, local storage and analytics
This website sets no marketing or tracking cookies. For privacy-friendly, aggregate analytics we use — where enabled — Plausible Analytics, a cookieless, EU-hosted web analytics tool. Plausible sets no cookies, builds no cross-device profiles and stores no persistent personal data; consent is therefore not required (§ 25(2) no. 2 German TDDDG). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimizing analytics).
Beyond that we only store functional settings in your browser’s localStorage (e.g. waitlist status pcf_waitlist_v1, color scheme s2p_theme, cookie-notice acknowledgement s2p_cookie_ack). In the application, Supabase additionally sets technically necessary session cookies for sign-in (essential, no tracking). This data is required for the respective function; a consent banner is therefore not required. A short, non-blocking notice informs you about these essential cookies.
6. Fonts
The fonts used on this website are hosted locally on our own server ("self-hosting"). No connections to Google or other third-party servers are established for font delivery when you visit the site.
7. User account and sign-in (tool)
Using the tool requires an account. Sign-in is passwordless via a magic link sent to your email address, or optionally via an OAuth provider (Google or GitHub). With OAuth sign-in we receive your verified email address from the provider to associate the account; association is by email address (the same address via magic link and OAuth resolves to the same account). Google’s and GitHub’s privacy policies apply in addition. We process your email address, sign-in timestamps, and technically necessary session cookies (essential, no tracking). Authentication and data storage run on Supabase (EU region) on the basis of Art. 6(1)(b) GDPR (performance of contract).
On account creation we record your consent to the Terms and Privacy Policy (accepted version and timestamp) and the grant of free starter credits ("trial credits"). Content stored in your account (scans, lists, notes, reminders, sender profile, credit/usage data) is processed to provide the service (Art. 6(1)(b) GDPR). When you delete your account, all account data is deleted immediately and permanently (except for the pseudonymized email hash described below); the deletion function is available directly in the account.
We additionally evaluate account usage and log data for abuse and fraud prevention and the security of the service (e.g. detecting unusual usage patterns, temporary account suspension); the legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, abuse-free operation).
To prevent repeated claims of the free starter credits, we store a salted SHA-256 hash of the normalized email address for up to 12 months when the credits are granted — including after account deletion. The hash is pseudonymized, is not linked to any other data, and cannot be traced back to the email address without knowledge of that address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention).
To fend off automated or excessive requests we use rate limiting: short-lived request counters (including the IP address or account identifier) are stored with Upstash, Inc. in a database in the EU region Frankfurt and are deleted automatically after a few seconds up to at most one hour. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention and service stability).
Referral program ("refer a friend"): if you register via a personal referral link or refer other persons yourself, we store the association between the referring and the referred account as well as the reward status (credit grant and any reversal) in order to credit the reward credits on both sides and to prevent abuse. We do not send invitation emails to referred persons; participation takes place exclusively via the personal sharing of the link. Legal basis: Art. 6(1)(b) GDPR (carrying out the promotion) and Art. 6(1)(f) GDPR (abuse prevention).
Processing on your behalf for stored lead data: where you store and manage data of the researched businesses in your account (e.g. lists, your own notes, and manual edits), you are the controller for that data and we process it as your processor. Our data processing agreement pursuant to Art. 28 GDPR applies, available at /dpa.
8. Payments (Polar)
Paid plans and credit packages are sold via our payment provider Polar Software Inc. acting as merchant of record. Polar becomes the contracting party of the purchase and processes the data required for payment (name, email, payment details, billing data) under its own responsibility; we do not receive full payment details from Polar, only order and subscription status. Polar’s privacy policy applies in addition.
Automatic top-up (auto top-up): if you enable the optional automatic top-up, we record your consent (time, chosen threshold, and chosen credit package) and, when the balance falls below the threshold, initiate a charge via Polar without further action on your part ("off-session"). Legal basis: Art. 6(1)(b) GDPR (performance of contract). You can revoke the consent at any time in your account with effect for the future; every automatic charge is documented in your account's credit ledger.
9. Transactional emails (Resend)
We send system emails (e.g. sign-in links, reminder notifications) via Resend Inc. (USA). Recipient address, subject, and delivery metadata are processed. Legal basis: Art. 6(1)(b) GDPR. US transfers are safeguarded via Standard Contractual Clauses and/or the Data Privacy Framework.
10. Scan features and APIs used (tool)
The core function of the tool is analyzing publicly accessible business websites. In doing so, we process data of the analyzed businesses (see the Data Subject Notice) via the following services:
- Google Places API and PageSpeed Insights API (Google Ireland Limited / Google LLC): finding business listings and measuring website performance.
- Anthropic PBC (USA): AI-based assessment of website screenshots and generation of outreach email and call-script drafts. Content of the analyzed, publicly accessible websites is transmitted, plus — for draft generation only — the details from the user’s sender profile. Under its commercial terms, Anthropic does not use content submitted via the API to train AI models.
- OpenRouter, Inc. (USA): routing service for individual AI helper tasks — translating search phrases and extracting contact data from the analyzed websites. These tasks are routinely processed by Google (Gemini models) and, only during outages, by OpenAI or Google as a fallback. We call OpenRouter with the "no data collection" setting (data_collection: deny); requests are then routed only to model providers that neither store inputs nor use them for training. OpenRouter itself does not store prompts or outputs by default. Draft generation (outreach emails, call scripts) runs exclusively on Anthropic; sender-profile data is never transmitted via OpenRouter.
- CARTO (map tiles based on OpenStreetMap data): rendering the map view; your IP address is transmitted to the tile service.
- Hetzner Online GmbH (Germany): operation of the scan server in a data center in Germany.
Google Maps (map view, consent only): the tool’s map view can display maps from Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA); the map shows the locations of the businesses found in your scans. Google Maps is loaded only after your express consent (Art. 6(1)(a) GDPR): a connection to Google is established only after you click "Load map"; in the process, data such as your IP address and browser data are transmitted to Google. US transfers are safeguarded via the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Your consent is stored locally in your browser (localStorage s2p_gmaps_consent) and can be revoked at any time with effect for the future via the link below the map; without consent, no connection to Google Maps is established.
11. Processors and recipients (overview)
| Service | Provider | Purpose | Seat | Transfer safeguard |
|---|---|---|---|---|
| Hosting (web) | Vercel Inc. | Serving the website/app (EU region fra1) | USA | DPF / SCC |
| Database, auth, storage | Supabase Inc. | Data storage, sign-in (EU region) | USA | DPF / SCC |
| Business/map data | Google Ireland Ltd. / Google LLC | Places API, PageSpeed | Ireland / USA | DPF / SCC |
| Maps (consent only) | Google Ireland Ltd. / Google LLC | Google Maps rendering after consent (IP address, browser data) | Ireland / USA | DPF / SCC |
| AI analysis and drafts | Anthropic PBC | Screenshot assessment, outreach/call-script drafts | USA | SCC |
| AI routing | OpenRouter, Inc. | Routing of translation and contact extraction; outage fallback (setting: no data collection) | USA | SCC |
| AI model providers (via OpenRouter) | Google LLC / OpenAI, L.L.C. | Translation and contact extraction (routinely: Google); outage fallback (OpenAI/Google) | USA | DPF / SCC |
| Transactional email | Resend Inc. | System emails | USA | SCC / DPF |
| Map tiles | CARTO | Map rendering (OSM data) | USA/ES | SCC |
| Sign-in (OAuth, optional) | Google Ireland Ltd. / GitHub Inc. | Optional login with Google/GitHub | Ireland / USA | DPF / SCC |
| Analytics | Plausible Analytics | Cookieless web analytics | EU | — |
| Payments | Polar Software Inc. | Merchant of record, billing | USA | SCC / DPF |
| Scan server | Hetzner Online GmbH | Running the scan pipeline | Germany | — |
| Rate limiting | Upstash, Inc. | Short-lived request counters incl. IP address (EU region Frankfurt; deleted after seconds up to max. 1 hour) | USA | DPF / SCC |
| Bot protection | Cloudflare, Inc. | Turnstile bot protection on the free website check and the signup forms, in invisible mode without a visible widget (IP address, browser signals for bot detection; Art. 6(1)(f) GDPR). Cloudflare's Turnstile Privacy Addendum applies in addition: https://www.cloudflare.com/turnstile-privacy-policy/ | USA | DPF / SCC |
| Error monitoring | Sentry (Functional Software Inc.) | Stability and diagnostics | USA | SCC / DPF |
SCC = EU Standard Contractual Clauses; DPF = EU-US Data Privacy Framework. Art. 28 GDPR data processing agreements are in place with all processors.
12. Third-country transfers
Where service providers process data outside the EU/EEA (in particular the USA), this takes place on the basis of an adequacy decision (EU-US Data Privacy Framework) and/or the EU Standard Contractual Clauses including supplementary measures (Art. 44 et seq. GDPR).
13. Retention
We store personal data only as long as required for the respective purposes: server logs 30 days; waitlist data until revocation or at most 12 months after launch; account data until account deletion; the pseudonymized email hash preventing repeated starter-credit claims for at most 12 months (see section 7); statutory retention obligations (e.g. for invoice data) remain unaffected. Location coordinates from map services are deleted after 30 days at the latest.
14. Your rights
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Revocation of consent with effect for the future (Art. 7(3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
An informal email to bdoerffer@digitaltoolslist.com is sufficient to exercise these rights.
15. No automated decision-making
No automated decision-making including profiling with legal effect within the meaning of Art. 22 GDPR takes place. The website scores calculated in the tool concern business websites and have no legal effect on natural persons.
16. AI-generated content (transparency)
The tool uses AI to generate text drafts — company summaries, outreach emails and call scripts — and an AI-based design assessment of website screenshots. This content is visibly labeled as AI-generated in the application (Art. 50 AI Act, Reg. (EU) 2024/1689).
AI providers used: drafts and the design assessment are produced by Anthropic (Claude). Individual helper tasks — translating search phrases and extracting contact data from the analyzed websites — are routed via the OpenRouter routing service and are routinely processed by Google (Gemini) and, only during outages, by OpenAI or Google as a fallback (details in sections 10–12). Under these providers’ applicable API terms, submitted content is not used to train AI models; we configure OpenRouter so that requests are routed only to model providers without data retention.
AI output can be inaccurate or incomplete; it is intended as a draft, and reviewing and approving it is your responsibility. ScanToPitch never sends messages on your behalf — you send every message yourself. No automated decision-making with legal effect (Art. 22 GDPR) takes place.
17. Changes to this policy
We update this policy when the service or the legal situation changes. The version published here applies.