Back to ThemePages.ai

ThemePages.ai

Privacy Policy

How ThemePages.ai processes personal data under GDPR and applicable Austrian/EU data protection rules.

Last updated: August 12, 2026

1. Controller

Robin Ekren, Bogengasse 2 Vorderhaus, 2630 Ternitz, Austria, is the controller for personal data processed through ThemePages.ai unless a specific feature names another controller.

For privacy requests, contact robinekrenn@gmail.com.

2. Personal Data We Process

  • Account and contact data such as name, email address, username, phone number where provided, login events and account settings.
  • Usage, device and security data such as IP address, browser, timestamps, pages viewed, consent records and abuse-prevention signals.
  • Creator, brand, campaign, listing, waitlist and communication data submitted through the platform.
  • Payment and invoice metadata processed through payment and accounting providers. We do not store full card numbers.
  • Social-platform data only where a user connects an account or otherwise authorizes access through the relevant platform flow.

3. Purposes And Legal Bases

  • To provide the platform, waitlist, marketplace, creator and campaign functions.
  • To perform contracts and pre-contractual steps requested by users.
  • To comply with tax, accounting, fraud-prevention and legal-retention duties.
  • To protect platform security, prevent abuse and enforce terms.
  • To send transactional messages and, where permitted, product or launch updates.
  • To improve product performance based on legitimate interests or consent where required.

4. Processors And Recipients

We may use hosting, database, analytics, email, payment, accounting, customer-support and infrastructure providers where required to operate the service. These providers process data only under appropriate contractual and security obligations.

Payment services are handled by Stripe or another named payment provider when enabled. Accounting data may be processed in sevdesk or equivalent bookkeeping systems. Official tax and authority records may be shared where legally required.

5. International Transfers

Some providers may process data outside Austria or the European Economic Area. Where this happens, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses or another lawful transfer mechanism.

6. Retention

We keep personal data only as long as needed for the stated purposes. Accounting, invoice and transaction records may be retained for at least seven years where Austrian law requires it. Security logs, support messages and platform records are retained as long as needed for abuse prevention, legal defense and product operation.

7. Your Rights

Subject to the GDPR and applicable law, you may request access, rectification, deletion, restriction, portability or objection. Where processing is based on consent, you may withdraw consent for the future. You may also lodge a complaint with the Austrian Data Protection Authority.

8. Cookies And Tracking

We use essential cookies and similar technologies for login, security, preferences and service operation. Analytics or marketing technologies are used only where configured lawfully and, where required, after consent.

9. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse and alteration. No system can be guaranteed perfectly secure, but security issues are reviewed and handled with priority.

10. Email And Notification Choices

ThemePages sends account-security and service messages that are necessary to verify accounts, protect users, process bookings, report payment or payout status, handle delivery, refunds and disputes, and provide requested platform functions. These required service messages cannot be disabled while the relevant account or transaction remains active.

Direct-message alerts, chat digests, draft reminders, campaign announcements and promotions are separate optional categories. Users can control them in Notification Settings. Marketing categories are disabled by default unless the user makes an affirmative choice or another lawful basis clearly applies.

Notification choices are stored server-side so they apply across devices. Delivery providers may retain technical delivery, bounce and complaint metadata for security, abuse prevention and reliable delivery.