Privacy

Privacy Policy

Controller

Roast My Funnel OÜ operates Roast My Funnel. Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia.

Privacy contact: [email protected]. General inquiries: [email protected].

Scope

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit the website, create an account, request a magic link, submit a URL, buy or redeem an audit, receive a report, contact support, or interact with our marketing.

Roast My Funnel is a business-to-business service. Do not submit private portals, customer files, health data, payment card data, government identifiers, children's data, or other sensitive personal information through URL submissions or support messages.

Personal data we collect

Account and contact data may include name, email address, company details, login events, magic-link delivery data, support messages, and communication preferences.

Audit data may include submitted URLs, visible website content, screenshots, metadata, page copy, pricing information, forms, calls to action, selected buyer personas, audit configuration, report outputs, and related processing logs.

Payment and commercial data may include plan selected, checkout session ID, Stripe customer/payment metadata, purchase amount, credits, invoice or receipt records, refunds, chargebacks, and tax or fraud-prevention information. We do not store full payment card numbers.

Technical and security data may include IP address, approximate country or region, device/browser information, cookies, local storage, consent records, request logs, bot-prevention signals, rate-limit events, error logs, and security telemetry.

Analytics and advertising data may include page views, campaign source, conversion events, cookie identifiers, consent mode signals, and ad-attribution events, subject to your choices and applicable law.

Sources

We collect data from you, your browser or device, submitted public URLs, payment providers, email providers, hosting and security providers, analytics and advertising tools, and service vendors that help operate the product.

How we use personal data

We use personal data to provide audits, generate synthetic buyer persona feedback, create reports, process checkout and credits, deliver magic links and service emails, maintain accounts, provide support, prevent abuse, secure the service, debug errors, improve product quality, measure marketing performance, comply with law, enforce terms, and handle disputes or chargebacks.

We do not use private customer audit data for public marketing unless you give permission or the data is anonymized or aggregated so it does not reasonably identify you.

Legal bases

Where GDPR or similar law applies, our legal bases may include contract performance, legitimate interests, consent, and legal obligation. Legitimate interests include product security, fraud prevention, customer support, service improvement, analytics, business operations, legal claims, and abuse prevention. You may object to processing based on legitimate interests where applicable law gives you that right.

Cookies, analytics, ads, and Global Privacy Control

We may use Google Analytics, Google Tag Manager, Meta Pixel, consent mode signals, and similar tools to measure website usage and campaign performance. Non-essential analytics and advertising storage starts denied until you make a choice through the cookie banner. Closing or dismissing the banner is treated as essential-only.

If your browser sends a Global Privacy Control signal, we treat it as an opt-out of ad personalization and cross-context behavioral advertising for this site. See the Cookie Policy for details and controls.

We do not knowingly sell personal data for money. Some advertising, pixel, or attribution activity may be considered "sharing" or targeted advertising under California or other US privacy laws. You can opt out by choosing essential-only cookies, sending a Global Privacy Control signal, or emailing [email protected] with the subject "Do Not Sell or Share."

Disclosures and service providers

We may disclose personal data to vendors and subprocessors for hosting, CDN/security, database, storage, payment processing, email delivery, analytics, advertising measurement, browser automation, AI model processing, customer support, observability, legal compliance, and fraud prevention.

Current or expected vendors include Vercel, Cloudflare, Neon, Stripe, ZeptoMail, Google, OpenAI or other AI model providers, Google Cloud Platform, Cloudflare R2, and Sentry for frontend observability. Vendors may change as the service evolves. The Data Processing Agreement describes processor/subprocessor terms for business customers where applicable.

We may also disclose information if required by law, to protect rights and safety, to enforce terms, to handle disputes or chargebacks, or in connection with a merger, acquisition, financing, restructuring, or sale of assets.

California and US state privacy notice

Depending on your state and whether the law applies to us, you may have rights to know or access personal information, correct inaccurate information, delete personal information, obtain a portable copy, opt out of sale, sharing, targeted advertising, or certain profiling, limit use of sensitive personal information, and avoid discrimination for exercising privacy rights.

In the past 12 months, we may have collected the categories listed in "Personal data we collect" above and disclosed them to the service provider categories listed in "Disclosures and service providers." We do not knowingly sell or share personal information of anyone under 16. We do not intentionally collect sensitive personal information except limited account-security, payment-provider, or user-submitted content needed to provide and protect the service.

We do not use sensitive personal information to infer characteristics about you or for purposes beyond providing, securing, billing, supporting, improving, and legally protecting the service unless a separate lawful basis or permission applies. We do not use automated decision-making or profiling that produces legal or similarly significant effects about individuals.

We do not offer financial incentives or different prices for exercising privacy rights unless a legally compliant notice is provided first. We will not retaliate or discriminate against you for making a valid privacy request.

Authorized agents may submit requests as described on the Your Privacy Choices page. We may verify your identity and the agent's authority before acting on access, correction, deletion, or portability requests.

Retention

We keep personal data only as long as needed for the purposes described above, unless a longer period is required or reasonably needed for legal, tax, accounting, security, billing, dispute, chargeback, backup, abuse-prevention, or fraud-prevention reasons.

Typical retention periods are: account and audit records for the life of the account plus a reasonable post-closure period; billing and tax records for legally required periods; security logs for a limited operational period unless needed for investigation; consent records while relevant to prove choices; and support messages while needed to answer, document, and improve support.

Your rights

Depending on your location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, opt-out of marketing, opt-out of sale/share/targeted advertising, or review of certain automated decisions. You can make a request at Your Privacy Choices or by emailing [email protected].

We will not discriminate against you for exercising privacy rights, but some data may be necessary to provide the service, complete payments, secure accounts, comply with law, or defend legal claims.

If applicable law gives you an appeal right and we deny your request, you may appeal through the process on Your Privacy Choices. EEA, UK, and Swiss residents may also contact their local data protection authority, including the Estonian Data Protection Inspectorate for our Estonian establishment.

Email communications

Transactional emails, such as magic links, receipts, report delivery, account notices, and security messages, are sent as part of the service. Marketing emails, if used, will identify the sender, include a valid business contact method, and provide an unsubscribe or opt-out process where required.

International transfers

If data is processed outside the European Economic Area, United Kingdom, Switzerland, or your home jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, data processing terms, or other lawful transfer mechanisms.

Security

We use technical and organizational measures designed to protect data, including access controls, security headers, encrypted transport, vendor safeguards, monitoring, least-privilege operational practices, abuse-prevention controls, and separation of duties where practical. No internet service can be guaranteed completely secure.

Children

The service is not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information, contact us so we can review and delete it where appropriate.

Contact

Privacy questions can be sent to [email protected].