Back to home

Privacy Policy

Last updated: May 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

ecomhatch

E-Mail: privacy@ecomhatch.io

2. Overview of Processing Activities

EcomHatch is a platform where e-commerce founders can find co-founders and business partners. To provide this service we operate user profile, listing, and messaging features. This policy describes which personal data we process, on what legal basis, how long we retain it, and what rights you have.

3. Data Collected and Purposes

3.1 Registration and Account

When you register, we collect your email address and a password of your choosing. The email address is used to verify your account, for password recovery, and for transactional notifications (e.g. contact requests). Passwords are stored exclusively as a secure hash.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.2 Profile Data

After registration you may voluntarily add further information to your profile: display name, username, short bio, skills, location, website and social media handles, and a profile picture. This data is publicly visible to other users.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) where required for use of the platform; otherwise Art. 6(1)(a) GDPR (consent via voluntary input).

3.3 Listings

When you create a listing we store the title, description, category, project stage, desired partner roles, required skills, location, time commitment, remote status, and an optional cover image. Listings are publicly accessible and indexed by search engines.

Legal basis: Art. 6(1)(b) GDPR.

3.4 Messages and Contact Requests

Messages between users and the associated conversation history are stored in our database. Content is visible only to the parties involved. Once both parties delete a conversation it is permanently removed from the database.

Legal basis: Art. 6(1)(b) GDPR.

3.5 Favourites and Referrals

Listings you mark as favourites are stored linked to your account. If you invite other users via your referral link, the referral relationship is stored for the purpose of credit management.

Legal basis: Art. 6(1)(b) GDPR.

3.6 Server and Access Logs

When you access our website, the hosting services we use (Vercel, Hetzner) automatically record technical data: IP address, timestamp, requested URL, HTTP status code, bytes transferred, and browser and OS identifiers. This data is needed for secure operation, error diagnosis, and protection against abuse, and is deleted after the typical retention periods of the respective providers (generally 7–30 days).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

4. Cookies

We use only technically necessary cookies. Specifically, our authentication infrastructure (Supabase Auth) sets session cookies that are deleted on sign-out or session expiry. A separate cookie stores your language preference (German/English).

We do not use tracking, analytics, or advertising cookies. A cookie banner is therefore not required.

Legal basis: Art. 6(1)(b) and (f) GDPR.

5. Processors

We engage the following service providers as data processors under Art. 28 GDPR:

Contabo GmbH

Welfenstraße 22, 81541 München

Purpose: Operation of the VPS server hosting the database, authentication server, and file storage. All user data is stored exclusively on this server in Germany.

Legal basis: DPA under Art. 28 GDPR; EU server location, no third-country transfer.

Provider's Privacy Policy

Vercel Inc.

440 N Barranca Ave #4133, Covina, CA 91723, USA

Purpose: Hosting the Next.js web application (frontend, server-side rendering). Vercel processes access logs and serves the user interface.

Legal basis: DPA under Art. 28 GDPR; Vercel is a certified participant in the EU-US Data Privacy Framework (DPF) — third-country transfer on the basis of an adequacy decision by the European Commission (Art. 45 GDPR).

Provider's Privacy Policy

Cloudflare, Inc.

101 Townsend St, San Francisco, CA 94107, USA

Purpose: CDN, DDoS protection, and DNS resolution. Cloudflare may process IP addresses and request metadata in the course of this.

Legal basis: DPA under Art. 28 GDPR; Cloudflare is a certified participant in the EU-US Data Privacy Framework (DPF) — third-country transfer on the basis of an adequacy decision by the European Commission (Art. 45 GDPR).

Provider's Privacy Policy

Resend Inc.

USA (Delaware)

Purpose: Sending transactional emails (registration confirmation, password reset). Resend receives the recipient's email address and the content of the respective email.

Legal basis: DPA under Art. 28 GDPR; Resend is a certified participant in the EU-US Data Privacy Framework (DPF) — third-country transfer on the basis of an adequacy decision by the European Commission (Art. 45 GDPR).

Provider's Privacy Policy

A data processing agreement (DPA) pursuant to Art. 28 GDPR exists or will be concluded with each of the processors listed above before going live.

6. Retention and Deletion

We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations.

  • Active accounts: Data is stored for the duration of use.
  • Account deletion: Following a deletion request, all personal data will be permanently removed from our systems within 30 days.
  • Messages: Once both parties to a conversation delete it, it is permanently removed from the database.
  • Server logs: Deleted in accordance with the retention periods of the hosting providers used (typically within 7–30 days).

7. Your Rights

Under the GDPR you have the following rights:

  • Access (Art. 15): You may request information about the personal data stored about you.
  • Rectification (Art. 16): You may request the correction of inaccurate data.
  • Erasure (Art. 17): You may request deletion of your data, provided no statutory retention obligations apply.
  • Restriction (Art. 18): You may request restriction of processing.
  • Data portability (Art. 20): You may request your data in a machine-readable format.
  • Objection (Art. 21): You may object to processing of your data based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time with effect for the future.

To exercise your rights, contact the controller by email at the address above. We will respond within 30 days.

You also have the right to lodge a complaint with a data protection supervisory authority. In Germany, the competent authority is that of the federal state in which you reside.

8. Data Security

All data transmitted between your browser and our servers is encrypted via HTTPS. Our database is not directly reachable from the internet; access is exclusively through a secured API gateway. Passwords are never stored in plain text — only as a cryptographic hash. Database operations are subject to access controls that ensure users can only access their own data.

9. Minors

Our service is intended for persons aged 18 and over. We do not knowingly collect personal data from persons under 18. If we become aware that a minor has created an account, we will delete it without delay.

10. Changes to This Policy

We reserve the right to update this Privacy Policy to reflect changes to our services or legal requirements. The current version is always available at https://ecomhatch.io/privacy. Registered users will be notified by email of material changes.