Privacy Policy
1. Controller & contact
Data controller: Riddle OÜ (registry code 17254064), Estonia. Privacy contact: info@riddle.ee.
2. What we collect and why
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Email, name, avatar, Google account id | Account & authentication | Contract (Art. 6(1)(b)) | Until account deletion |
| Stripe customer id, purchase & credit-ledger history | Billing, fraud prevention, accounting | Contract + Legal obligation | Ledger retained for accounting (tax law) even after account close |
| Uploaded images, generated images, prompts | Providing the core generation service | Contract | Until you delete them / account deletion |
| Discovered ASINs, blacklist, preferences | Amazon product discovery & personalization | Contract | Until account deletion |
| Amazon Associates tracking ID (affiliate tag) | Building your affiliate links on generated pins | Contract | Until you change/remove it or delete your account |
| Referral code & attributed purchases | Running the referral program | Legitimate interest (Art. 6(1)(f)) | Up to 24 months after the referral, for reconciliation |
| IP address, request counters | Rate limiting, abuse prevention, security | Legitimate interest | Short-lived (≈24h cache TTL) |
3. Sub-processors
We share data with the following processors, each under a data-processing agreement:
- Hosting/CDN: Vercel Inc.
- Database: Neon (PostgreSQL)
- Cache/queue: Redis (managed Redis provider)
- Object storage: Amazon Web Services (S3), currently in the AWS
us-east-1region (see §4 on our planned move to an EU region) - Payments: Stripe
- AI image/text generation: OpenAI
- Amazon product data (bestseller discovery): Rainforest API (TrajectData)
- Authentication: Google
3a. Amazon product discovery
When you discover products, we query a third-party Amazon data provider (Rainforest API) to retrieve publicly available Amazon catalog data — product titles, images, ASINs, and ranking. This is Amazon's product data, not your personal data, and we store the products you keep against your account so you can generate pins from them. The affiliate links on your generated pins are built from the Amazon Associates tracking ID you provide; we do not track clicks, sales, or commissions on your links — that happens in your own Amazon Associates account.
4. International transfers
Several of our processors are based in the United States (OpenAI, Stripe, Google), and our object storage and database are currently hosted in a US AWS region (us-east-1). Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses and/or the processor's EU–US Data Privacy Framework certification as the transfer safeguard. We are working to migrate our database and object storage to an EU region to minimise such transfers; this policy will be updated when that migration completes. You can request details of the safeguards for a specific processor by emailing info@riddle.ee.
5. Your rights
Under the GDPR you can access, rectify, erase, restrict, port, and object to processing of your data, and lodge a complaint with your supervisory authority. Use Account → Privacy & data to export or delete your data, or email info@riddle.ee. We respond within 30 days.
6. Cookies
See our Cookie Policy. We use only essential cookies plus a functional first-party referral store; we do not use advertising cookies.
7. Security & breaches
We take appropriate technical and organisational measures to protect your data. In particular: data is transmitted over encrypted (HTTPS/TLS) connections; your uploaded and generated images are stored in a private object-storage bucket with public access blocked, and are served only through short-lived, ownership-checked links; every request for your data is scoped to your own account, so one user cannot access another user's products, images, or billing records; we never see or store your full payment-card details (card data is handled entirely by Stripe); and access keys and secrets are held server-side only and are never shipped to the browser.
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and will inform affected users without undue delay when the breach is likely to result in a high risk to them.
8. Children
The Service is not directed to children under 16.
9. Changes
We will post updates here and, for material changes, notify you in-app.