Splister: Privacy Policy
- Effective date
- 13 August 2026
- Version
- 1.3
This Privacy Policy explains how we handle personal data when you visit our website, create an account, or use the Splister application (together, the "Services"). It is provided in accordance with the EU General Data Protection Regulation ("GDPR") and the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, "UAVG").
1. Who is responsible for your data
For the personal data described in this policy, the data controller is:
NWR Products Voordijk 500, 2993 BE Barendrecht, the Netherlands Email: support@splister.com
We have not appointed a Data Protection Officer, as we are not required to do so. Privacy questions can be sent to the address above and will be handled by our management.
2. What personal data means
Personal data is any information relating to an identified or identifiable natural person. Individual pieces of information that, taken together, allow someone to be identified also count as personal data.
3. Legal bases we rely on
We process personal data only where we have a legal basis to do so:
- Performance of a contract (Art. 6(1)(b) GDPR), to provide the Services you have signed up for, including your account, generation of output, store connections, and billing.
- Legal obligation (Art. 6(1)(c) GDPR), to comply with obligations such as tax and accounting retention requirements.
- Legitimate interests (Art. 6(1)(f) GDPR), to keep the Services secure, prevent abuse and fraud, understand and improve how the Services perform, and defend legal claims. We balance these interests against your rights before relying on this basis.
- Consent (Art. 6(1)(a) GDPR), for marketing communications and any other processing we specifically ask you to agree to. You may withdraw consent at any time, without affecting processing that already took place.
4. What we collect and why
4.1 Data you give us
Account data. Your name, email address, and a securely hashed password. Where applicable, your company name, address, and VAT number for invoicing. Basis: contract.
Communications. The content of emails and support requests you send us, and our replies. Basis: contract and legitimate interest in providing support.
Billing data. Records of your purchases, credit balance, and invoices. Card details are entered directly with our payment provider and are never received or stored by us. Basis: contract and legal obligation.
4.2 Data generated by your use of the Services
Service Data. The product URLs you submit, the product information retrieved from them, the settings and templates you configure, and the listings and images generated for you. In normal use this is commercial product information rather than personal data. Where it does contain personal data (for example, a person visible in a product photograph you supply, or names appearing in a source listing), we process it on your instructions as your processor, and you act as controller. Section 12 sets out what that means.
Store connection data. The domain of any store you connect and the access token issued by that platform. Access tokens are encrypted at rest. We access your store only to the extent needed for the features you use. Basis: contract.
Usage and technical data. IP address, browser and device information, pages viewed, actions performed in the application, timestamps, and error logs. We use this to operate and secure the Services, diagnose faults, detect abuse, and understand which features are used. These technical logs, including your IP address and user agent, are stored with our log provider and deleted after 30 days. Basis: legitimate interest.
4.3 Data collected automatically on our website
When you visit our website, our server automatically records technical information including your IP address, the pages you request, referring page, and browser details. This is used to deliver and secure the website. Basis: legitimate interest.
Cookies and similar technologies are described in our separate Cookie Policy. We use no analytics, advertising, or tracking cookies, and we set no third-party cookies. Should that change, non-essential cookies will be placed only after you consent.
4.4 Affiliate programme
If you join our affiliate programme, we process your partner code, records of the customers you referred, your commission and payout records, and — before your first payout — the invoicing details you provide (business name, address, VAT number, IBAN, and country). Basis: contract; legal obligation for financial records. The programme's own rules are set out in the Affiliate Terms.
If you sign up through a partner link, we record the link between your account and the referring partner, and we log the click itself with the landing page, the referring site, and a salted hash of your IP address — never the address itself. Click logs are deleted after 30 days. Basis: legitimate interest in operating the programme and preventing fraud.
Affiliates never see your name, email address, or any other personal detail: their dashboard shows referred customers only as anonymous entries with a date, a status, and a commission amount.
5. Service providers who process data for us
We use the following categories of processor. Each is bound by a data processing agreement requiring appropriate security and confidentiality, and each processes data only on our instructions.
| Purpose | Provider | Data involved |
|---|---|---|
| Application hosting | Vercel Inc. | All Service data, technical logs |
| Database | Neon Inc. | Account, billing, and service records |
| File storage | Vercel Inc. (Vercel Blob) | Generated and source images |
| AI text generation | Anthropic PBC | Product data and settings submitted for generation |
| AI image generation | Google LLC | Product images and prompts submitted for generation |
| Background processing | Inngest Inc. | Job metadata |
| Payments | Stripe, Inc. | Billing and transaction data (card data is entered directly with Stripe and never reaches us) |
| Transactional email | Resend (Plus Five Five, Inc.), delivering via Amazon Web Services | Name, email address, message content |
| Store integration | Shopify Inc. | Product data read from and written to the store you connect |
| Log management and fault analysis | Axiom, Inc. | Technical logs, including IP address, user agent, and requested paths |
We use no analytics, advertising, or tracking providers. Our log provider stores technical server logs only; it does not track you across websites or build a profile of you.
AI providers. Data sent to our AI providers is processed to produce your output. We have contracted with these providers on terms under which your content is not used to train their models. We do not send your account credentials, billing data, or store access tokens to AI providers.
We may also share data with our accountant, legal advisers, or authorities where we are legally required to do so, or where necessary to establish or defend legal claims.
We do not sell personal data, and we do not share it with advertising networks for their own purposes.
6. Where your data is processed, and international transfers
Our application, database, file storage, and technical logs are all hosted in Frankfurt, Germany (EU). Our transactional email provider processes in Ireland (EU).
Some of our providers process data outside the European Economic Area, including in the United States. This applies in particular to our AI text and image providers and to our payment provider. Where this happens, we ensure an appropriate safeguard is in place, normally the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures. Several of these providers are also certified under the EU-US Data Privacy Framework.
You may request further information about these safeguards at support@splister.com.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data | For as long as your account is open, then deleted or anonymised within 90 days of closure |
| Service Data (source data, generated output) | For as long as your account is open, or until you delete it. Deleted content is removed from live systems immediately and from backups within 35 days |
| Store access tokens | Until you disconnect the store or close your account, then deleted |
| Invoices and financial records | 7 years, as required by Dutch tax law |
| Support correspondence | 24 months after the matter is closed |
| Security and access logs, including IP address | 30 days |
| Affiliate click logs (hashed IP, landing page, referring site) | 30 days |
| Affiliate commission, payout, and invoicing records | 7 years, as required by Dutch tax law |
| Marketing consent records | Until consent is withdrawn, plus 12 months as proof of the withdrawal |
Where data must be retained for a legal reason, we restrict its use to that purpose until the period expires.
8. How we protect data
We apply technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS) for all connections;
- encryption at rest for store access tokens and other sensitive credentials;
- password hashing using a modern, salted algorithm, we never store passwords in readable form;
- role-based access, with access to production data limited to staff who need it;
- separation of development and production environments;
- automated backups and periodic restore testing;
- logging of administrative access;
- vetting of processors and contractual security commitments.
No system can be guaranteed completely secure, but we review these measures regularly. Our approach to preventing and responding to data loss is set out in our Data Loss Prevention Policy.
9. Personal data breaches
If a personal data breach occurs, we will:
- record and investigate the incident without delay;
- notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of it, where the breach is likely to result in a risk to individuals;
- notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, describing what happened, what data was involved, what we are doing about it, and what they can do;
- notify you promptly where the breach affects Service Data for which you are the controller, so that you can meet your own notification obligations.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data where one of the grounds in Art. 17 GDPR applies;
- restriction of processing in the circumstances set out in Art. 18 GDPR;
- data portability. To receive data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible;
- object to processing based on our legitimate interests, and to object at any time to direct marketing;
- withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email support@splister.com. We will respond within one month. Where a request is complex, we may extend this by up to two further months and will tell you why. We may ask you to verify your identity before acting.
You can access, correct, and delete much of your data yourself directly in your account settings.
Right to complain. You may lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority where you live or work. We would appreciate the opportunity to address your concerns first.
11. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of that kind.
Please note that the Services themselves use AI to generate content at your request. That is content generation, not a decision about you.
12. When we act as your processor
Where Service Data contains personal data, you are the controller and we are your processor. In that role we:
a) process such data only on your documented instructions, which include your use of the Services and these terms, unless required otherwise by law; b) ensure that personnel with access are bound by confidentiality; c) apply the security measures described in section 8; d) engage sub-processors only under the conditions in section 5, and inform you of intended changes so that you may object; e) assist you, so far as reasonably possible, in responding to requests from data subjects and in meeting your obligations under Articles 32 to 36 GDPR; f) notify you without undue delay after becoming aware of a personal data breach affecting your data; g) delete or return the data at the end of the Services, except where storage is required by law; h) make available the information necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality.
You warrant that you have a lawful basis for the data you submit, and that where required you have informed the individuals concerned.
13. Children
The Services are intended for business users aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Marketing
We will send you service messages relating to your account, such as security notices, billing confirmations, and important changes. These are necessary to the contract and cannot be unsubscribed from while you hold an account.
We will only send you marketing messages where you have consented, or where permitted by law in respect of our own similar services. Every marketing message includes an unsubscribe link, and you can withdraw consent at any time in your account settings or by contacting us.
15. Changes to this policy
We may update this policy to reflect changes in the Services or in the law. Where a change is material, we will notify you by email or in the application before it takes effect. The version and effective date at the top always indicate the current version.