Privacy policy
What Vessa collects, why and what you can do about it. Last updated 3 August 2026.
Controller
Good Fella Studio GmbH, Wolferding 6, 84137 Vilsbiburg, Germany. HRB 307957, Amtsgericht München. VAT ID DE459966102. Write to hello@vessa.design about anything on this page.
What we collect
- Account data: your email address. Vessa has no passwords, so your email is how you sign in.
- Content you create: guidelines, sections, uploaded images and fonts, stored so we can render and host your pages.
- Email subscription data: your email, when you subscribed and confirmed, which form or setting you used, the exact wording you agreed to, plus the IP address and browser string from those moments. We store the last few because they are the proof that you opted in, and we would have nothing else to show if someone disputed it.
- Referral data: your invite code, and which signups came through it.
- Payment data: a record of what you bought and when. Stripe handles the card itself. We never see or store card numbers.
- Product analytics: which pages get opened and which steps get finished. Anonymous until you sign in, then tied to your account id. Never your email.
- Server logs needed to run and secure the service.
Why we are allowed to
Running your account and hosting what you publish is performance of our contract with you (Art. 6(1)(b) GDPR). Email about the product is your consent (Art. 6(1)(a)), which you can withdraw at any time. Keeping the service secure and understanding how it is used is our legitimate interest (Art. 6(1)(f)). Invoices are a legal obligation (Art. 6(1)(c)).
Analytics
We use PostHog, hosted in the EU. It runs cookieless: nothing is stored on your device, session recording is off and we do not auto-capture what you click. Because we store nothing on your device, there is no cookie banner to click away. Once you sign in, events are tied to your account id so we can see whether the product works. Never to your email.
Who else processes it
Each of these acts as a processor for us, under a data processing agreement:
- Supabase: authentication and database, hosted in the EU.
- Vercel: hosting and delivery of the site.
- Cloudflare R2: the images and fonts you upload.
- Resend: sending email.
- Stripe: payments and invoices.
- PostHog: product analytics, hosted in the EU.
- Slack: internal notifications about signups and purchases.
Some of these are US companies. Where data reaches them outside the EU, it travels under the European Commission's standard contractual clauses.
How long we keep it
- An email subscription that is never confirmed is deleted after 90 days. We do not keep addresses nobody agreed to.
- Account data and your content: while your account exists. Delete your account and it goes.
- Invoices and payment records: ten years, because German tax law says so.
Your rights
You can ask for a copy of your data, have it corrected or deleted, ask us to restrict what we do with it, object to processing based on legitimate interest, and receive what you gave us in a portable format (Art. 15 to 21 GDPR). Where we rely on consent, you can withdraw it at any time without affecting what came before. Every marketing email has an unsubscribe link, and it works from one click.
You can also complain to a supervisory authority. Ours is the Bayerisches Landesamt für Datenschutzaufsicht in Ansbach, and you may equally go to the authority where you live.