— GDPR Art. 13 / 14
Privacy.
We process as little personal data as running Visybl technically requires. This policy describes completely and honestly which data that is, where it comes from, where it goes and how long we keep it.
This English version is provided for convenience. The German version is the authoritative one.
Controller
The controller within the meaning of the GDPR is:
VISYBL GmbH
Nordstraße 2, 24937 Flensburg, Germany
Represented by its Managing Director: Jens Thorben Diercks
Email: info@visybl.de
No data protection officer has been appointed, as the conditions of § 38 of the German Federal Data Protection Act (BDSG) are not met. Please address data protection enquiries directly to the email address above.
Hosting & server logs
When you open this website, the web server records data in so-called server log files by default: IP address, date and time of the request, the URL called up, referrer, user agent (browser and operating system information) and HTTP status code. This data is technically necessary in order to deliver the website and to ensure stability and security.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in trouble-free operation).
Storage period: as a rule no more than 14 days, after which the data is automatically deleted or anonymised.
Hosting: Website, application and database run at OVHcloud in a data centre inside the European Union (Germany). Your data is not stored outside the EU. OVHcloud acts as our processor within the meaning of Art. 28 GDPR and processes the data solely on our instructions for the operation of the systems, not for its own purposes.
Cookies & consent management
Technically necessary (no consent required): After you sign in to the application at my.visybl.de we set a session cookie (__Secure-better-auth.session_token) that keeps you signed in across page views. It contains no personal content, only a random, signed session identifier, and it is set as an HttpOnly and Secure cookie — it therefore cannot be read by JavaScript and leaves the browser only over an encrypted connection. We additionally keep your choice in the cookie banner locally in your browser (localStorage, key visybl-consent) so that we do not have to ask you again on every visit. Legal basis: § 25 (2) no. 2 TDDDG (strictly necessary for the service you requested) in conjunction with Art. 6 (1) (b)/(f) GDPR.
Statistics and marketing (only with your consent): On our website visybl.de we use Google Analytics 4 and Google Tag Manager in order to analyse how the website is used and to measure the effectiveness of our advertising. These services only set cookies or similar identifiers (e.g. _ga, _ga_*) once you have expressly agreed in the banner. We use Google Consent Mode v2 with the default value “denied” for all categories that require consent: without your agreement no analytics or marketing cookies are set and no personal identifiers are transmitted to Google. Legal basis: § 25 (1) TDDDG and Art. 6 (1) (a) GDPR (consent).
Your consent is voluntary and can be withdrawn at any time: you can deselect the categories “Statistics” and “Marketing” individually in the banner, change your selection later or delete the stored decision by resetting the website data in your browser. A withdrawal takes effect for the future; processing carried out until then remains lawful. We do not carry out any profiling of our own and no cross-site tracking.
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Transfers to the USA are safeguarded by EU standard contractual clauses and the EU-US Data Privacy Framework.
Account & sign-in (email/password or Google)
There are two ways to sign in to your VISYBL account: with an email address and password, or with your Google account. Both are equivalent — signing in with Google is not a prerequisite for using the service. Which data is collected depends on the route you choose; for storage periods see § 09.
Sign-in with email and password: We process your email address, your name and your password. We store the password exclusively as a cryptographic hash (§ 08); we never know it in plain text. If you reset your password, all existing sessions become invalid. Confirmation of your email address via a link is planned and will be activated as soon as sending these messages is available — at present it does not take place.
Sign-in with Google: When you sign in you are redirected to Google. Only after your consent there do we receive the following data:
- Your Google identifier (sub), email address and display name
- An access token and a refresh token with the scope openid · email · profile · content. The first three serve the sign-in itself, content serves to retrieve the list of your Merchant Centers via the Google Merchant API (§ 06)
This data is stored in our database in order to authenticate you and to enable the discovery of your Merchant Centers. The refresh token allows us to update that list later without you signing in again; we store it exclusively in encrypted form (§ 08). If you sign in with Google for the first time without already having an account, the account is created in the process. If you already have a VISYBL account, your Google account can be linked to it — even if it uses a different email address.
Disconnecting: Signing out only ends your session and does not revoke any authorisation. If you disconnect Google in the application or delete your account, we additionally revoke the authorisation granted to us directly at Google and delete the stored tokens — access then ceases on both sides. Independently of this, you can withdraw the authorisation yourself at any time in your Google account at myaccount.google.com/permissions.
Recipient (only when signing in with Google): Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for users in the EU). Transfers to third countries (USA) are safeguarded by EU standard contractual clauses and the EU-US Data Privacy Framework. Google's privacy policy: policies.google.com/privacy.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) for providing the service; additionally Art. 6 (1) (a) GDPR (consent) for granting the Google authorisation.
Limited Use (Google API Services User Data Policy): Our use of data received through Google APIs, and the transfer of that data to other apps, complies with the Google API Services User Data Policy, including its Limited Use requirements. In particular, we use the content scope exclusively to determine the Merchant Center accounts associated with your Google account and to provide the CSS link you selected. We do not use this data for advertising purposes, do not sell it and pass it on only to those recipients required to provide the service. Humans read it only where you consent to that, where it is necessary for security or to comply with applicable law, or where the data has been aggregated and anonymised for operational purposes. We also do not use Google user data to develop, train or improve generalised AI or machine learning models, nor do we pass it on to third parties for that purpose.
Payment via Stripe
Your monthly subscription is concluded and billed through Stripe Checkout. You are redirected to a payment page hosted by Stripe for this purpose. You enter payment details (card number, CVC, expiry date) exclusively there — we never see, store or process this data.
On that payment page Stripe collects your billing address on our behalf and — if you provide it — your VAT identification number. Both are required in order to determine the VAT owed by law and to issue your invoice correctly; for companies from other EU member states the VAT ID additionally serves to check whether the reverse charge applies. This information is stored at Stripe, not in our database.
From Stripe we only receive: a Stripe customer ID, the email address you used and the confirmation that the payment has been made. We store this data in order to unlock the service you paid for and to meet retention obligations under commercial and tax law.
Recipient: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Transfers to the USA are safeguarded by EU standard contractual clauses and the EU-US Data Privacy Framework. Stripe's privacy policy: stripe.com/privacy.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (legal obligation under the German Commercial Code / Fiscal Code).
Discovery of your Google Merchant Centers
When you open the selection of your Merchant Centers, we call the accounts.list endpoint of the Google Merchant API using your Google access token. This gives us a list of the Merchant Center IDs your Google account has access to. The IDs are shown to you so that you can select the one you want for the CSS link. Only the ID you select is stored permanently in our database.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
Disclosure to our technology partner
Not yet active: The transfer described here only begins once CSS activation goes live. At present it does not take place.
As soon as you select a Merchant Center ID and our operator triggers the activation, we transmit the following data by webhook to b-good GmbH, our technology partner for the CSS link:
- the selected Merchant Center ID
- the display name of the Merchant Center (where available)
- your email address as customer identifier
- your internal customer ID (Google sub) for allocation
This transfer is necessary so that b-good GmbH can link your Merchant Center to its CSS slot (CSS = Comparison Shopping Service under the EU antitrust remedy). Without this disclosure the service cannot be provided.
Recipient: b-good GmbH, our technology partner for the CSS link. You will find the privacy policy and the full provider details in our technology partner's privacy policy.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
Data security & protection of sensitive data
Principle of data minimisation: As a matter of principle we endeavour not to process and not to store sensitive data. Where providing the service makes it technically unavoidable, such data is stored in our database exclusively in encrypted form (encryption at rest). For the data received from Google this means in concrete terms: through the Google API we read only the list of Merchant Center IDs associated with your account; we do not retrieve any product, campaign, revenue or customer data from your Merchant Center or your Google Ads account, and accordingly we do not store such data either.
Encryption in transit: All connections to our website and to the application are available exclusively over HTTPS (TLS). Communication with the Google APIs, with Stripe and with our technology partner likewise takes place without exception over TLS-encrypted connections. Your data is never transmitted unencrypted.
Encryption at rest: The access and refresh tokens received from Google — that is, precisely the data with which your Google resources could be accessed — are stored by us only in encrypted form. Decryption happens exclusively in our server's memory at the moment of a specific API call; the corresponding key is not held in the database but separately from it in the protected server configuration. We never store passwords in plain text, only as a cryptographic hash that cannot be converted back into the original password. Payment details (card number, check digit) never reach our systems — they are entered and processed exclusively at our payment service provider (§ 05).
Restricted access: Our database cannot be reached from the internet; it is connected to the application solely through an internal network that is not publicly accessible. Within the application a role-based permission check applies: as a customer you see only your own data. Extended access exists only for a narrowly limited group of people at our company, and only in so far as it is required for operation, support and activation of your CSS link. Access and key material (API credentials, encryption keys) is not stored in the program code.
Withdrawal and deletion as a safeguard: If you disconnect Google or delete your account, we additionally revoke the Google authorisation granted to us directly at Google and delete the associated tokens at our end — access then ceases on both sides. After a password reset all existing sessions also become invalid, so that any access that remained unauthorised cannot persist.
Residual risk: No technical procedure offers absolute security. We continuously adapt our measures to the state of the art. Should a breach of the protection of your personal data nevertheless occur, we will inform the supervisory authority and — where the risk to you is high — you as well, in accordance with Art. 33, 34 GDPR. If you notice a security vulnerability, please report it to us at info@visybl.de.
Storage periods & deletion
We store your data only for as long as it is necessary for the purpose of the processing or as statutory retention obligations require:
- Server logs: max. 14 days
- Account and discovery data: until the account is deleted at your request
- Accounting-relevant data (invoices, payment confirmations): 10 years under § 147 of the German Fiscal Code
- Activation records (Merchant ID + status): until the business relationship ends, after which they are deleted or anonymised
You can request the deletion of your entire account at any time by email to info@visybl.de.
Your rights
You have the right at any time, vis-à-vis us, to:
- information about the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (“right to be forgotten”, Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to the processing (Art. 21 GDPR)
- withdraw a consent you have given, with effect for the future (Art. 7 (3) GDPR)
An informal message to info@visybl.de is enough to exercise these rights.
Complaint to the supervisory authority
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
www.datenschutzzentrum.de
Changes to this policy
We adapt this privacy policy when legal requirements or our service change. The current version is always available here. We announce material changes in advance in your account.