Privacy Policy
This Privacy Policy explains what personal data thevones.com collects, why, and what your rights are. thevones.com is operated by Stage2 sp. z o.o., a company registered in Poland (EU), which is the data controller for the processing described here. We have designed the service to collect as little personal data as possible: analytics are pseudonymous by default, IP addresses are never stored in raw form, and your usage is only linked to your identity if you explicitly consent.
Last updated: 8 July 2026. We may revise this policy from time to time; the current version will always be published on this page with its update date.
Who we are and how to reach us
Data controller: Stage2 sp. z o.o., Poland. For privacy questions and all data-protection requests, email d.urbanski@thevones.com (also reachable at support@thevones.com).
What we collect
Pseudonymous analytics
- Session identifier: a random UUID generated in your browser and stored in localStorage (not a cookie). It is per-browser and is used only to group usage events. It is not linked to your identity unless you give the consent described below.
- Usage events: page views, opening the vendor portal, steps of the vendor-claim and workflow-share funnels, copying a prompt, clicking "compare to your context", clicks on vendor links, and searches. For searches, the analytics event records only the length of your query and the number of results — not the search text itself.
- Hashed IP address: for analytics, your IP address is hashed (SHA-256) with a salt that rotates daily. The raw IP address is never stored.
- Coarse device information: a broad user-agent bucket (e.g. mobile, desktop, or bot) and the host of the referring site only — never your full user-agent string or the full referring URL.
- Client error signals: if a front-end error occurs, we may record a hashed fingerprint of it so we can fix bugs. We never record the error message text or stack trace, and the number of such signals is capped per page load.
Product functionality data
Separately from analytics, the product's search-state and recovery feature may store your search context on our server so that the feature can work (for example, restoring where you left off). This is product functionality, not tracking, and is retained only as described in the retention section below.
Account and authentication data
You can sign in with LinkedIn (OpenID Connect) or with an email magic link. For login we process your email address and, if you use LinkedIn sign-in, the basic profile LinkedIn returns to us (name, email, profile information). A session token is stored in a cookie to keep you signed in.
Data you submit
If you use these features, we store what you send us in our database:
- Comments and workflow shares/submissions.
- Vendor claims: the tool name, a work email address, and a one-time verification code.
- Feedback and "Talk to founder" messages: your message and an optional email address.
Linking analytics to your identity — only with consent
By default, your usage events are not tied to your account; analytics stay aggregate and pseudonymous. Linking your usage events to your account identity happens only if you opt in via an explicit consent checkbox shown at sign-in. Your choice is stored as an analytics-consent flag on your account and as a flag in your browser's localStorage. You can withdraw this consent at any time by unticking the box on a later sign-in or by emailing us.
Do Not Track and Global Privacy Control
We honour both. If your browser sends a Do Not Track (DNT) or Global Privacy Control (GPC) signal, identifiers are stripped: the session id is replaced with an anonymous "dnt" marker, and the user id and IP hash are set to null. At most a fully anonymous aggregate count remains.
Legal bases for processing (GDPR Article 6)
- Legitimate interest (Art. 6(1)(f)) — aggregate/pseudonymous analytics, client error signals, and security and rate-limiting, all in the interest of running and improving the service. We balance this against your rights, which is why IPs are hashed, DNT/GPC are honoured, and identity is never linked to usage without consent.
- Consent (Art. 6(1)(a)) — linking analytics to your account identity. Withdrawable at any time as described above; withdrawal does not affect the lawfulness of processing before withdrawal.
- Performance of a contract / steps at your request (Art. 6(1)(b)) — providing paid briefs and fulfilling requests you make.
- Legitimate interest and/or contract necessity, as applicable — operating your account, authentication, and hosting the content you submit.
Who we share data with
We use a small number of service providers (processors) to run thevones.com:
- Resend — transactional email delivery (magic links, vendor verification codes, and our own internal notification when you send feedback or a vendor claim).
- Hetzner — hosting and our PostgreSQL database, in EU data centres.
- LinkedIn — only if you choose to sign in with LinkedIn (OpenID Connect authentication).
We do not sell personal data, and we use no third-party advertising or ad-tracking networks.
Cookies and local storage
- Session cookie: used for authentication, to keep you signed in.
- Browser localStorage: the pseudonymous analytics session id, your theme preference, and your analytics-consent choice. (A developer-mode flag exists only on localhost and is never used on the live site.)
There are no third-party advertising cookies.
How long we keep data
- Analytics events: retained for up to about 13 months, then deleted or reduced to aggregates. Fully aggregate statistics (which cannot identify you) may be kept longer. The salt used to hash IP addresses rotates daily.
- Search-context/recovery data: retained for a limited period to power that feature, then minimised.
- Account data and content you submit: kept for the life of your account or until you ask us to delete it, subject to any legal retention duties we may have.
In general, we minimise and delete data we no longer need.
Your rights under the GDPR
You have the right to access, rectification, erasure, restriction of processing, objection, and data portability, and the right to withdraw consent at any time. To exercise any of these rights, email d.urbanski@thevones.com.
One honest limitation: we can delete or return data linked to your account, but fully anonymous aggregate data cannot be tied back to you, so it cannot be individually retrieved or erased (GDPR Article 11).
You also have the right to lodge a complaint with a supervisory authority — in our case the Polish Data Protection Authority (UODO — Urząd Ochrony Danych Osobowych), or the data protection authority in your own EU country.
Changes to this policy
We may update this Privacy Policy as the service evolves. Material changes will be reflected on this page with a new "last updated" date. If a change would meaningfully affect how your data is used, we will take reasonable steps to bring it to your attention.