Legal

Privacy Policy

How ProductByte handles personal data, which providers are involved, and what rights users have under GDPR and applicable Dutch law.

Last updated: March 25, 2026

01

Scope and Applicable Law

This Privacy Policy explains how ProductByte processes personal data when you use this website, registration flows, and product features. We apply the EU GDPR and applicable Dutch privacy law.

02

Controller Identity and Contact

Controller: ProductByte. Registered address: Molenmaker 33, 2761ME Zevenhuizen, Netherlands. KvK: 98942719. BTW: NL003112540B37.

For privacy requests or questions, contact info@productbyte.com. No separate DPO contact is currently published.

03

Data We Collect

Depending on service usage, data may include account details such as first name, last name, and email, authentication data, technical request metadata, and product or workspace content you create.

04

How We Use Data

We process personal data to provide account access and features, secure the platform, prevent abuse, enforce plan limits, communicate service-related messages, and improve service reliability.

05

GDPR Legal Bases

Depending on activity, we rely on contractual necessity (Article 6(1)(b)), legal obligations (Article 6(1)(c)), legitimate interests such as security and fraud prevention (Article 6(1)(f)), and consent where legally required (Article 6(1)(a)).

06

Sharing and Service Providers

We may share personal data with processors and infrastructure providers that help us host, secure, and operate the service, and where required by law or to protect users and platform security.

Providers used in our stack include, depending on the feature set you use: Cloudflare, Stripe, OpenAI, Replicate, and FAL, plus optional user-enabled integrations such as Google or Apple sign-in and connectors like WooCommerce, Meta, TikTok, X, and Spotler.

07

Retention and Security

We retain account and billing records for as long as required by Dutch law. Session and token data is short-lived by design, for example refresh sessions or cookies are currently configured for about 3 hours, access tokens for about 10 minutes, and asset access cookies for about 24 hours.

Project assets and connector-related data are retained while the account remains active, unless deletion is requested or required by law. Operational logs follow provider default retention settings where relevant. We apply technical and organizational security measures appropriate to risk.

08

International Transfers

We use service providers that may process data outside the EEA, including in the United States. Where relevant, we rely on lawful transfer mechanisms such as adequacy decisions or Standard Contractual Clauses (SCCs), as applicable.

09

Cookies and Similar Technologies

We use essential cookies for security and session continuity, including refresh and auth cookies. When a ProductByte page is opened with campaign parameters, we may also set a short-lived first-party attribution cookie that stores those UTM values with an anonymous session id so we can measure signup conversion. These cookies use security-oriented attributes such as HttpOnly, Secure where available, and SameSite controls. Blocking cookies may impact service behavior or attribution measurement.

10

Your Rights and Choices

Under GDPR, you may have rights to access, rectify, erase, restrict, object, and data portability, subject to legal conditions. You can request a personal data export in the app via Account > Privacy > Data export; we send the export JSON to your account email.

Other rights requests can be sent to info@productbyte.com. We may ask for reasonable identity verification before processing requests.

11

Children and Business Context

ProductByte is designed for business use by organizations and is not directed to children.

12

Complaints, Updates, and Contact

If you have concerns, contact us first at info@productbyte.com. You also have the right to lodge a complaint with your supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. We may update this policy and reflect changes by updating the date on this page.

Continued use of the platform means acceptance of this policy and our Terms of Use.