Legal
Privacy Policy
This privacy policy explains which personal data we collect through this website and the GemOrLemon service, and how we handle it. We comply with the GDPR (Regulation (EU) 2016/679).
1. Controller
codebeam GmbH
Maria-Theresia-Straße 41, 4600 Wels, Austria
E-mail: [email protected]
Full contact details: see Imprint.
2. Account data
When you create an account in the GemOrLemon app, we process the data you provide (e-mail address, name, organization name, hashed password) to operate your account and provide the service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Account data is deleted when you delete your account, unless statutory retention obligations require otherwise.
3. Uploaded CSV files
The Stripe CSV exports you upload can contain personal data of the seller's customers (such as names and e-mail addresses). These files are processed in memory to compute the report metrics and are not stored: once the analysis is computed, the raw files are discarded. Only the computed, aggregated metrics of your report are persisted – they contain no names or e-mail addresses of the seller's customers. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in providing the analysis you requested (Art. 6(1)(f) GDPR). It is your responsibility to ensure you may lawfully share the seller's exports with us for analysis.
4. AI-assisted report text
The written summary of a report is phrased by a large language model. Only the computed, aggregated metrics are transmitted to the AI provider for this purpose – never the raw CSV files and never personal data of the seller's customers. The numbers themselves are computed in our own code, not by the AI.
5. Hosting & server logs
When you visit this website or use the app, our servers automatically process technical connection data (IP address, date and time of the request, requested URL, browser user agent) in server logs. We use this data to deliver the service reliably and to detect and defend against abuse. Legal basis: our legitimate interest in the secure and stable operation of the service (Art. 6(1)(f) GDPR). Log data is deleted after a short rotation period.
6. Payment processing
Payments are processed by Stripe. When you purchase a report, you are redirected to Stripe Checkout, where Stripe collects the data required for the payment (name, e-mail address, payment details, and for business purchases the company name and VAT ID). Stripe acts as its own controller for the payment transaction; details are described in the Stripe Privacy Policy. We receive from Stripe a confirmation of the payment and the billing details, which we process to fulfil the contract (Art. 6(1)(b) GDPR) and to meet statutory bookkeeping obligations (Art. 6(1)(c) GDPR).
7. Cookies & analytics
This website sets no cookies. To measure reach, we use umami, a privacy-friendly analytics tool that we host ourselves on our own EU infrastructure (analytics.codebeam.com). No data is shared with third parties; all data stays on our servers.
umami works without cookies and without storing personal data. No IP addresses are stored and no cross-site or cross-device profile is built. We only collect anonymous, aggregated metrics such as pages viewed, approximate origin (country), browser used and the referring source. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in a privacy-friendly, anonymous reach measurement); as no personal data is processed, no consent is required.
The app stores the technically required session tokens needed to keep you logged in; these are not used for tracking.
8. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with a supervisory authority; in Austria this is the Datenschutzbehörde (dsb.gv.at).