Privacy Policy

Last updated: August 28, 2026

At Refersend (d/b/a Refersend), accessible from https://refersend.com, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by Refersend and how we use it.

Data Controller

refersend.com
Operated by: solid native GmbH
Represented by: Niklas Babel
Address: Paulsborner Str. 85, 10709 Berlin, Germany

Contact for data protection matters: support@refersend.com

Legal Basis for Processing

We process your personal data based on:

  • Consent (Art. 6(1)(a) GDPR): When you explicitly consent to data processing
  • Contract performance (Art. 6(1)(b) GDPR): To provide our services
  • Legitimate interests (Art. 6(1)(f) GDPR): For website analytics and security

Data We Collect

Account Data

When you create an account, we collect your email address and encrypted password. This data is necessary for account access and service delivery under our contractual relationship (Art. 6(1)(b) GDPR).

Business Information

As you use Refersend, you may provide business details including company name, VAT ID, billing address, and partner relationships. We also process referral data (encrypted emails).

Technical Data

We automatically collect IP addresses, browser type, and device information for security and fraud prevention based on our legitimate interests (Art. 6(1)(f) GDPR). This data is retained in security logs for 30 days.

Payment Information

Payment data is processed directly by Stripe as a separate data controller. We only store Stripe customer IDs, subscription status, and payment references necessary for platform fee processing.

Cookies

We use essential cookies for session management and security. No third-party tracking or advertising cookies are used.

How We Use Your Data

  • Provide and maintain our services
  • Authenticate users and manage accounts
  • Improve website performance and security
  • Communicate important service updates
  • Comply with legal obligations

Data Sharing and Third Parties

We do not sell your personal data. We share data only as necessary for service delivery:

Service Providers

We work with trusted service providers to deliver our platform:

  • Stripe: Payment processing (separate data controller, USA-based)

Other Sharing

We may share data between partners according to partnership agreements, when required by law, or in case of business transfers (with prior notice). Any other sharing requires your explicit consent.

Data Processing Agreement for Business Customers

When you use Refersend as a business customer, we act as a data processor on your behalf under Article 28 of the GDPR. This means:

  • We process personal data only according to your instructions
  • We implement appropriate technical and organizational security measures
  • We assist you in fulfilling your GDPR obligations
  • We maintain strict confidentiality of all processed data

A comprehensive Data Processing Agreement (DPA) is available for all business customers. To receive your copy, please contact us at support@refersend.com.

Data Retention

We retain your data only as long as necessary for specific purposes:

  • Account data: Duration of active account plus 30 days after deletion
  • Transaction records and invoices: 10 years (German tax law requirements)
  • Commission and payment data: 10 years (accounting and tax obligations)
  • Security logs: 30 days for security monitoring
  • Email logs: 90 days for service quality assurance
  • Deleted referrals: 30-day soft delete period for recovery

Your Rights Under GDPR

You have the right to:

  • Access: Request copies of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Restriction: Limit processing under certain conditions
  • Portability: Receive your data in a structured format
  • Object: Object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent at any time

To exercise these rights, contact us at support@refersend.com. We will respond within 30 days.

Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption, secure servers, and regular security audits.

International Data Transfers

Your data is primarily processed within the EU. Any transfers outside the EU are protected by appropriate safeguards under GDPR (adequacy decisions or standard contractual clauses).

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. In Germany, contact your local data protection authority or the Federal Commissioner for Data Protection and Freedom of Information (BfDI).

Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, please contact us immediately.

Policy Updates

We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or website notice.

Contact Us

For any questions about this privacy policy or our data practices:

Email: support@refersend.com
Address: refersend.com (solid native GmbH), Paulsborner Str. 85, 10709 Berlin, Germany