Privacy Policy
Last updated: 3 October 2026
1. Controller
The Controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dominik Schimpf (Sophistication.io)
c/o IP-Management #2918, Ludwig-Erhard-Str. 18, 20459 Hamburg
Email: support@sophistication.io
2. Scope
This Privacy Policy applies to our own web offerings:
- sophistication.io (company website),
- app.sophistication.io (client portal),
- assets.sophistication.io (free resources and email updates).
For websites that we host and operate on behalf of our clients, the respective client is responsible under data protection law; in that respect we act as a processor (see Section 12). For visitors to such sites, the relevant policy is the privacy policy of the respective site operator.
3. Categories of Data Processed and Purposes
- Access data (including IP address, time of access, content retrieved, browser/device information) – for the secure and performant delivery of the pages (Sections 4 and 5).
- Contract and order data (email address, name or company, billing address, VAT identification number where applicable, selected plan, payment data) – for the establishment and performance of the contract (Section 6).
- Client portal account data (name, email address, authentication data, organization and role affiliation) – for the provision of the portal (Section 7).
- Connection and integration data (connected domain; access keys to shop and advertising accounts stored at the client's instruction, as well as order and expenditure data obtained from them) – for the technical setup and for the analysis functions activated by the client (Section 11).
- Communication data (content and sender data of your emails to us) – for handling your inquiries.
- Email subscription data (email address, phone number, the resource requested, confirmation and unsubscribe status) – for sending the requested resource and the follow-up emails you agreed to (Section 10).
4. Server Log Files
When our pages are accessed, information transmitted by your browser is automatically processed in so-called server log files: IP address, date and time of access, the resource retrieved, the referrer, and details about the browser and operating system. This data is technically necessary in order to deliver the pages, ensure their stability and security, and defend against misuse. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and trouble-free operation). The log files are retained only for a short period necessary to achieve the purpose and are then deleted.
5. Hosting & Storage (Cloudflare)
Our web offerings are delivered and secured via the infrastructure of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (content delivery network, edge computing, key and object storage). Contract and connection data is stored in the Cloudflare infrastructure to provide the service. A data processing agreement (DPA) is in place with Cloudflare; the transfer to the USA is safeguarded by EU Standard Contractual Clauses (SCCs). Legal basis: Art. 6(1)(f) GDPR (secure and efficient operation) or Art. 6(1)(b) GDPR (performance of the contract).
6. Payment Processing (Stripe)
For processing paid services we use Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA). Stripe processes the data required for payment, including email address, billing address, and VAT identification number where applicable. A data processing agreement is in place; transfers to third countries are safeguarded via SCCs. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Stripe's privacy notices apply additionally (stripe.com/de/privacy).
7. Client Portal (app.sophistication.io)
For registration and management of organizations and users in the client portal we use Clerk, Inc. (USA). For this purpose Clerk processes name, email address, authentication and session data. Clerk is certified under the EU-U.S. Data Privacy Framework; additionally, EU Standard Contractual Clauses and a data processing agreement are in place.
Account, page and history data of the portal (page configurations, versions, change logs, editor chat histories, analysis data) is stored with Supabase, Inc. in the EU region (Frankfurt am Main). A data processing agreement is in place. Access is separated by organization (tenant-based access control).
The portal uses exclusively technically necessary cookies (session/login). Legal basis of the processing: Art. 6(1)(b) GDPR (performance of the contract).
8. AI-Assisted Editing (Anthropic)
If a client uses the portal's AI functions (editor, test suggestions), we transmit the page content to be edited and the instructions entered to Anthropic, PBC (USA) for processing by their language models. Content transmitted via the API is not used by Anthropic to train the models, in accordance with their terms of use. A data processing agreement is in place; transfers to third countries are safeguarded via SCCs. Legal basis: Art. 6(1)(b) GDPR (provision of the booked function). We recommend not entering any personal data of third parties in editor instructions.
8a. AI Image Generation and Background Removal (fal.ai)
If a client uses the portal's image functions (generating images for a page, removing the background of an image), we transmit the instruction and the images the client supplies or the page builder creates to Features & Labels, Inc. (fal.ai, USA) for processing. A data processing agreement is in place; transfers to third countries are safeguarded via SCCs. Legal basis: Art. 6(1)(b) GDPR (provision of the booked function).
9. Support Chat (Intercom)
For support inquiries we use the messenger of Intercom R&D Unlimited Company (Ireland; Intercom, Inc., USA). On our website the messenger is not loaded automatically: it is retrieved and set up only when you actively click the chat button, so no cookies or comparable information are stored on your device beforehand. Once opened, Intercom processes the content of your messages, the technical connection data of the session, and an identifier stored on your device that allows a conversation to be continued.
In the client portal the messenger is part of the booked service and is opened for logged-in users with a signed token. In that case we transmit to Intercom the identifier of your user account together with your booked plan, the status of your subscription, the number of funnels created, and your language setting, so that support requests can be answered in context. We also use Intercom to send product and onboarding emails relating to your account.
A data processing agreement is in place; transfers to third countries are safeguarded by EU Standard Contractual Clauses. Legal basis: Art. 6(1)(b) GDPR (performance of the contract, in the portal) and Art. 6(1)(f) GDPR (legitimate interest in answering inquiries made through the website). Intercom's privacy notice applies additionally (intercom.com/legal/privacy).
9a. Internal Operations Alerts (Slack)
For internal operations alerts we use Slack (Slack Technologies, LLC, a Salesforce company, USA). When certain events occur in the client portal, for example the first publication of a page, an alert reaches our internal workspace with the address of the published page, the name of the workspace, the booked plan and billing status, and the identifier of the user who published it. A data processing agreement is in place; transfers to third countries are safeguarded by EU Standard Contractual Clauses. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the service securely and stopping abusive pages quickly).
10. Free Resources and Email Updates (assets.sophistication.io)
On assets.sophistication.io we offer free resources, for example funnel templates. To receive a resource you enter your email address and your phone number. We process the email address, the phone number with its country code, the resource requested, the time of the request, whether you confirmed your address, and whether you unsubscribed. To protect the form against abuse we use Cloudflare Turnstile (see Section 5) and keep a one-way hash of your IP address for up to one hour to limit repeated requests.
We send the resource by email. The link in that email also confirms your address (double opt-in). After you confirm, we send you a small number of further emails about cold-traffic funnels and our services: the templates, the Sophistication software and our done-for-you partnership. Every one of these emails contains a link to unsubscribe with one click, and you can also unsubscribe by writing to support@sophistication.io. We store your phone number together with your request so that we can contact you about it.
To store contacts and send these emails we use Resend, Inc. (USA). Resend processes the data named above and technical delivery data (whether an email was delivered, bounced or marked as spam). Open and click tracking is switched off. Resend's data processing agreement applies; it incorporates the EU Standard Contractual Clauses for the transfer to the USA. Legal basis: Art. 6(1)(a) GDPR (your consent), which you can withdraw at any time with effect for the future; for the abuse protection Art. 6(1)(f) GDPR (legitimate interest in a form that cannot be misused).
If you unsubscribe or mark one of our emails as spam, we keep your address marked as unsubscribed so that no further emails are sent to it (Art. 6(1)(c) and (f) GDPR). Everything else is deleted when you ask us to.
10a. Booking a Call on Our Website
On our homepage you can book a call with us. To do so you enter your name, your phone number with its country code, your email address and, depending on the call, your website or your answers to a few questions about your business (for example monthly revenue, ad spend and what you are looking for). We also process the time you choose, your time zone, and the answers you gave before the booking form (who you are and your monthly volume). Your country is estimated from your IP address only to preselect the country code of the phone field; it is not stored.
Our server passes these details to Cal.com, Inc. (USA), which schedules the call, adds it to our calendar and sends you the invitation with the video call link. Your browser does not load anything from Cal.com. Cal.com's data processing agreement applies; it incorporates the EU Standard Contractual Clauses for the transfer to the USA. To protect the form against abuse we use Cloudflare Turnstile (see Section 5) and keep a one-way hash of your IP address for up to one hour to limit repeated bookings.
Legal basis: Art. 6(1)(b) GDPR (steps taken at your request before a possible contract); for the abuse protection Art. 6(1)(f) GDPR (legitimate interest in a booking form that cannot be misused). We keep the booking for as long as we need it to prepare and follow up the call, and delete it when you ask us to, unless we must keep it by law.
11. Services Connected by the Client (Shop and Advertising Accounts)
In the portal, clients can connect their own accounts with third-party services, currently Shopify (shop order data) and Meta (advertising expenditure). The connection is made exclusively at the active instruction of the client (storing an access key or authorization via the third-party service's login dialog).
- Shopify: We obtain order data (order identifier, amounts, currency, technical attribution characteristics) from the client's shop in order to attribute revenue to the pages we operate. We do not obtain or store names or addresses of the shop's end customers.
- Meta: With read permissions ("ads_read") we obtain campaign and expenditure data of the advertising account in order to attribute advertising spend to the pages.
Access keys are stored with restricted access and encrypted and cannot be read out in the portal. The client can disconnect a connection at any time in the portal settings; the respective access key is then deleted. Legal basis: Art. 6(1)(b) GDPR (function requested by the client). See also the data deletion notice.
12. Measurement on Client Pages (Processing on Behalf of the Controller)
On websites that we host and optimize on behalf of our clients, we process visitor data as a processor of the respective site operator on the basis of a data processing agreement (DPA, available on request): aggregated views and clicks, a pseudonymous visitor identifier and a day identifier, as well as a signed click identifier in follow-up links to attribute orders. No cross-site tracking takes place; no advertising networks are integrated and no data is sold. The respective site operator is responsible under data protection law for this processing; its privacy policy is authoritative.
13. SSL/TLS Encryption
For security reasons our pages use SSL/TLS encryption. You can recognize an encrypted connection by the „https://" in the address bar of your browser.
14. Cookies, Consent and Reach Measurement
When you first visit our website you are asked to make a choice. Until you do, nothing beyond the strictly necessary runs: no statistics, no marketing, no support chat. Rejecting is a single click on a button of the same size and prominence as accepting, nothing is pre-ticked, and the page works either way. Your choice is stored in a first-party cookie for six months, after which we ask again, and you can change or withdraw it at any time via Cookie settings in the footer. The legal basis for anything beyond the strictly necessary is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG); for the strictly necessary it is Sec. 25(2) TDDDG and Art. 6(1)(f) GDPR.
The categories are:
- Strictly necessary (cannot be switched off): login and session for the client portal, security and abuse protection, and the cookie that stores this very choice.
- Functional: the support chat (Section 9). Switched off, the chat still works, it simply loads at the moment you click it.
- Statistics: a more detailed analysis of how pages are used.
- Marketing: measuring which advertisement led to a visit.
Independently of this choice we count page views without cookies using Cloudflare Web Analytics. No information is stored on or read from your device for this, no identifier is created, and no profile is built; it is aggregate reach measurement only. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing which content is used).
Google Tag Manager. To load the services in the statistics and marketing categories we use Google Tag Manager (Google Ireland Limited, Ireland). Tag Manager itself stores no information on your device and sets no cookies; it is a loader for the services listed here. We load it only after you have consented to statistics or marketing, so before your decision no connection to Google is established at all. Legal basis: Art. 6(1)(a) GDPR.
Google Analytics 4. With your consent to statistics we use Google Analytics 4 (Google Ireland Limited, Ireland). Google processes usage data to give us aggregated reports on how our website is used. IP addresses are shortened by Google. We use Google Consent Mode, so the service is only loaded and only stores information after your consent. Google acts as our processor on the basis of Google's data processing terms, which incorporate the EU Standard Contractual Clauses for transfers to third countries. Legal basis: Art. 6(1)(a) GDPR.
Meta pixel. With your consent to marketing we use the Meta pixel (Meta Platforms Ireland Limited, Ireland) to measure the effectiveness of our advertising and to reach people who have already visited our website. Meta may process this data for its own purposes as well; to that extent we and Meta are joint controllers under Art. 26 GDPR. Transfers to third countries are safeguarded by EU Standard Contractual Clauses. Legal basis: Art. 6(1)(a) GDPR.
Payment processing takes place on the pages of Stripe.
15. Retention Period
We process personal data only for as long as is necessary for the stated purposes. Contract and order data is stored for the duration of the contract and beyond that within the scope of statutory retention obligations (in particular under commercial and tax law, generally up to 10 years). Server log files are retained only for a short period to ensure operation. Access keys of connected services are deleted when the connection is disconnected. Data from requests for free resources (Section 10) is kept until you unsubscribe or ask for deletion; after an unsubscribe only the block entry for the address remains.
16. Obligation to Provide Data
The provision of the contract and order data is required for the conclusion and performance of the contract. Without this data we cannot establish the contract and cannot provide the service.
17. No Automated Decision-Making
Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place. Every visitor to a page is served the same published version of it.
18. Naming as a Reference Client (only with consent)
Only with your express consent do we name your brand and display the page we created for you – including your logo and screenshots of the publicly accessible page – as a reference project on our website sophistication.io as well as in comparable materials of our own advertising. The legal basis is your consent under Art. 6(1)(a) GDPR. You provide the consent voluntarily as part of the setup; withholding it has no effect on the contract. You can withdraw the consent at any time with effect for the future – by email to support@sophistication.io; we will then remove the reference promptly.
19. Your Rights
You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20 GDPR). You can withdraw any consent given at any time with effect for the future. Notes on the deletion of accounts and connected services can be found at sophistication.io/data-deletion.
20. Right to Object (Art. 21 GDPR)
Insofar as we process personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process the affected data unless we can demonstrate compelling legitimate grounds worthy of protection that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defense of legal claims.
21. Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg (LfDI)
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de
22. Currency and Amendment of This Privacy Policy
This Privacy Policy is currently valid and reflects the date stated above. Due to the further development of our services or as a result of changed statutory or regulatory requirements, it may become necessary to adapt it. The respective current version can be retrieved at any time on this page.
23. Contact for Data Protection Matters
For inquiries regarding data protection you can reach us at: support@sophistication.io