Privacy Policy

Effective date: July 27, 2026 · Last updated: July 27, 2026

Emberfeed is a hosted service that renders designed product images for e-commerce catalog feeds, operated by Daniel Šilha, registered sole trader (IČO 05377595) ("we", "us"). This policy explains what personal data we collect when you use emberfeed.com, why we collect it, and the rights you have over it. We keep it short because we collect little.

Who is responsible (data controller)

The data controller is Daniel Šilha, sole trader registered in the Czech Trade Licensing Register (živnostenský rejstřík), IČO 05377595, Letenské náměstí 76/3, 170 00 Prague 7, Czech Republic. For anything related to your data, contact us at [email protected].

What we collect and why

  • Account data — your e-mail address, display name and password (stored only as a modern salted hash, never in plain text). Legal basis: performance of the contract — we need it to run your account.
  • Session security data — for each active login session we record the IP address and browser identifier (user-agent). You can see and revoke your active sessions in your account settings; this data is deleted together with the session. Legal basis: legitimate interest in keeping accounts secure.
  • Feed and catalog content — the feed URL you import and the product data it contains (titles, prices, images), plus templates, uploaded assets and fonts you add. Product catalogs normally contain no personal data; we process this content solely to provide the service. Legal basis: performance of the contract.
  • E-mails we send you — we keep a record of which onboarding and trial e-mails were sent to your account, and your opt-out preference. Legal basis: our legitimate interest in onboarding our own users, within the limits of Czech Act No. 480/2004 Coll. §7(3): the e-mails concern only our own similar services, and you can refuse them both at registration and via the unsubscribe link in every message. Transactional e-mails (such as password resets) are sent as part of the contract and are unaffected by the opt-out.
  • Upgrade requests — if you submit the upgrade form, we store your name, e-mail and message so we can respond. Legal basis: steps prior to entering a contract.
  • Billing data — if you upgrade, we process the details needed to invoice you (name, billing address, company/VAT ID, payment records). Legal basis: performance of the contract and our legal obligations under Czech tax and accounting law.
  • Server logs — like almost every web service, our infrastructure keeps short-lived access logs (IP address, requested URL, timestamp) for security and troubleshooting. Legal basis: legitimate interest.

Providing your e-mail address, a display name and a password is a contractual requirement — without them we cannot create or operate your account. Everything else (the upgrade-form message, uploaded assets) is up to you.

Cookies

We set exactly one cookie ourselves: mf_session, a strictly necessary, httpOnly cookie that keeps you signed in. Our CDN and security provider (Cloudflare, including the Turnstile bot check on registration) may set its own strictly necessary security cookies; these are not used for tracking or advertising. We set no advertising, preference or cross-site tracking cookies — which is why you see no cookie banner here.

Analytics

We measure page visits with a self-hosted instance of Umami, a privacy-focused, cookieless analytics tool. It stores aggregate statistics (page views, referrers, browser type) on our own infrastructure, sets no cookies, keeps no cross-site identifiers, and shares nothing with third parties. Legal basis: our legitimate interest in understanding how the site is used — Umami briefly processes your IP address and browser type to count visitors, but stores neither and keeps no persistent identifier.

Who else touches the data (processors)

  • Hetzner Online GmbH (Germany) — server hosting. All application data lives in an EU data centre.
  • Cloudflare, Inc. (USA) — CDN, DDoS protection and the Turnstile bot check in front of the site. Transfers are covered by the EU-US Data Privacy Framework and standard contractual clauses.
  • Google Ireland Limited / Google LLC (EU/USA) — e-mail infrastructure for the messages we send you and for our support inbox. US transfers are covered by Google LLC's EU-US Data Privacy Framework certification.

We do not sell personal data and we do not share it with advertisers. You can request a copy of the applicable transfer safeguards (e.g. the standard contractual clauses) at [email protected]; the EU-US Data Privacy Framework participant list is at dataprivacyframework.gov.

How long we keep it

  • Account, feed and template data: for as long as your account exists. If you delete your account (or ask us to), we delete your data within 30 days.
  • Sessions (incl. IP/user-agent): until they expire or you revoke them.
  • Server logs: rotated daily and deleted after at most 14 days.
  • Backups: daily database snapshots kept for 7 days, then overwritten — deleted data leaves the backup cycle automatically within that window.
  • Invoices and related tax records: for as long as Czech tax and accounting law requires (up to 10 years).

Your rights

Under the GDPR you can ask us for access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest. E-mail [email protected] and we will respond within one month; where a request is complex, the GDPR allows us to extend this by up to two further months — we would tell you within the first month if so. You can also lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ, uoou.gov.cz) or your local supervisory authority.

We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning you.

Your customers' data

Product feeds normally contain products, not people. If a feed you import does contain personal data, you remain the controller of that data and we act as your processor, handling it only to provide the rendering service. Our data processing agreement applies automatically in that case; a countersigned copy is available on request.

Children

Emberfeed is a business tool for merchants and is not directed at children under 16.

Changes

If we make a material change to this policy, we will note it here with a new effective date and tell registered users by e-mail.

Questions? Write to [email protected] — a human founder reads and answers every message. Back to Emberfeed.