Effective 1 October 2026.
1. who we are
Spookat is run by Jakub Merta, a sole trader registered in Poland (jednoosobowa działalność gospodarcza), NIP 5833455773, REGON 522668870 (“Spookat”, “we”). Write to us at hi@spookat.com. We have not appointed a data protection officer; we are not required to.
2. two roles
- Controller. For data about our customers, people on our waitlist and visitors of spookat.com, we decide what happens to it. This policy covers that.
- Processor. When a visitor chats through a Spookat widget on one of our customers’ sites, that customer is the controller and we process the chat on their behalf, under our data processing agreement. If you chatted with a site that uses Spookat, the site owner is your first contact. If you write to us instead, we pass your request on to them. With each message a visitor sends, we keep the page it was sent from and the page before it (both without query strings), the browser and operating system, the browser’s language, time zone and local time, the widget’s language, and the country, looked up from the IP address, which is never stored (section 7). If the site has no paid plan (its trial or subscription ended), the widget says the team can’t answer right now: the site owner can read your message, and it’s deleted with the rest of the site’s history.
3. what we collect, why, and for how long
| what | why | legal basis | how long |
|---|---|---|---|
| visits to spookat.com, counted by our self-hosted Umami: page, referrer, browser, device type, country | to see which pages work | legitimate interest, Art. 6(1)(f) GDPR | aggregated statistics, no profile of you |
waitlist: your email, the language of the page you signed up on and, if the link had one, the utm_source you came from |
to send you an invite, in your language | consent, Art. 6(1)(a) | until you sign up or ask us to delete it, and at most 12 months |
| account: email, name, the language our emails to you use (from your waitlist entry or your browser at sign-up), and, if you sign in with GitHub, Google or Discord, your account id there and its sign-in tokens, encrypted | to run your account and email you in your language | contract, Art. 6(1)(b) | while the account exists, then deleted within 30 days; backups age out 30 days after that |
| billing: plan, country, invoice data we get back from Paddle, or from Shopify or Wix if you pay through their app store | to know what you paid for and keep tax records | contract and legal obligation, Art. 6(1)(b) and (c) | as long as Polish tax and accounting law requires (generally 5 years after the end of the year) |
| support: what you send to hi@spookat.com | to help you | contract or legitimate interest | as long as the conversation needs, and at most 24 months |
Umami on spookat.com sets no cookies and stores no IP address. It counts visits with a salted hash that rotates, so it can’t recognise you over time. It runs on our own server under spookat.com/u/, so no third party sees your visit.
We use IP addresses only in memory, to deliver pages and messages, to rate-limit abuse and, for chat messages, to look up the country (section 7). We never write them to a database, a log or an error report. Cloudflare (below) carries all traffic to our sites, the widget’s included, as our network proxy and CDN, so it sees IP addresses in transit.
Card and payment details never reach us. On spookat.com, Paddle (see below) sells the subscription as merchant of record and handles payment as an independent controller, under Paddle’s privacy policy. If you install Spookat from the Shopify App Store or the Wix App Market, that platform bills the plan with your store’s other charges, as an independent controller under its own privacy policy.
4. who else gets data
We share data only with the services we need to run Spookat, each under a contract that binds them to protect it:
| who | what for | where |
|---|---|---|
| Paddle.com Market Limited | billing, merchant of record | United Kingdom |
| Postmark (ActiveCampaign, LLC) | transactional email: sign-in links, notices, reply follow-ups | United States |
| Backblaze, Inc. | database backups; provider-side encryption at rest required | EU region |
| OVH Sp. z o.o. | hosting | Warsaw, Poland, EU |
| Cloudflare, Inc. | network proxy and CDN in front of our sites, IP addresses in transit | United States, global network |
| OpenRouter, Inc. | intent tags and live translation, both coming soon and off for every site until then; afterwards only for sites whose customer turns them on | United States |
OpenRouter passes the text to the AI model provider it routes the request to, which processes it only to answer that request. For live translation that is the text of a chat’s messages and the target language, never a name, an email address or any other detail of the chat, and only for sites that turned translation on.
Slack and Discord get chat messages only when a customer connects their own workspace or server to Spookat. That is the customer’s choice, and Slack’s or Discord’s terms and retention settings apply there.
Signing in with GitHub, Google or Discord is optional; an emailed link always works. If you choose one, that provider sends us your account email, whether it verified it, your name and your profile picture link, and sees that you signed in to Spookat. Its own privacy policy applies on its side. Discord is also the one a customer connects their server with, above.
Transfers outside the EEA rely on an adequacy decision (United Kingdom) or on the European Commission’s Standard Contractual Clauses (United States).
5. cookies
spookat.com sets no cookies. The Spookat widget on our customers’ sites sets no cookies, ever: after a visitor sends a first message, it keeps one chat token in that browser’s localStorage, under spookat: followed by the site key, so the conversation survives a reload.
Only the dashboard at app.spookat.com uses cookies, and only strictly necessary ones: the session that keeps you signed in, and short-lived ones while you accept a team invite, open a claim link, sign in with GitHub, Google or Discord (to check that the sign-in comes back to the browser that started it) or link a Shopify or Wix store. Website visitors who chat never get any of them.
6. your rights
You can ask us for access to your data, a copy of it (portability), to correct it, to delete it, to restrict or object to how we use it, and you can withdraw consent at any time without affecting what happened before. Write to hi@spookat.com; we answer within one month.
You can also complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
7. country lookup
We turn an IP address into a country with an offline database that runs on our own server. The IP address is never sent anywhere and never stored. IP to country data by DB-IP.com, licensed under CC BY 4.0.
8. changes
If this policy changes in a way that matters, we update this page and email customers before the change applies.