Privacy Policy
This policy explains what personal data Offerli collects, why, who we share it with, and the rights you have. It applies to offerli.app, the backoffice at my.offerli.app, and sites published through Offerli on offerli.link or on custom domains.
1. Who is responsible
The controller of your personal data is OD "Rimad Consulting", Kolodvorska 12b, 71000 Sarajevo, Bosnia and Herzegovina, ID number (JIB) 4304410870006. For anything about privacy, write to support@offerli.app.
The businesses that publish sites with Offerli decide what their sites say. If a business site shows personal data, such as an owner's name, that business is responsible for it.
2. What we collect
Waitlist sign-up
- Your email address, the page you signed up from, and the time.
- A one-way hash of your IP address and your browser's user agent, to stop spam.
Your account
- Your email address and whether it is verified.
- Your password, stored only as a secure hash by Google Firebase Authentication. We never see it.
- The version of the Terms of Service you accepted, and when.
Your business and site
- Business name, legal business name, address, working hours, menu content, prices, languages and currency.
- Your subdomain, custom domain, and every published version of your site.
- This information is public once you publish, because that is the purpose of the site.
Billing
- From Paddle, we receive your subscription id, plan, status, billing period dates and payment events.
- Paddle collects your card details, billing name, address and tax details. We do not receive or store card numbers.
Support and abuse reports
- The emails you send us and what they contain.
- If you report abuse, your email address and the details of your report.
Technical data
- Our servers and Cloudflare record requests, including IP address, time, requested address and user agent. This covers visitors to offerli.app, the backoffice, and published sites.
- Short-lived counters that limit how often an account or IP address can repeat an action.
- Error and activity logs from our backend.
3. Why we use it
| Purpose | Legal basis |
|---|---|
| Create and run your account, build and publish your site | Performing our contract with you |
| Take payments and manage your subscription | Performing our contract with you |
| Send service notices, such as payment problems or a takedown | Performing our contract with you |
| Send the one launch email to the waitlist | Your consent, which you can withdraw at any time |
| Keep the service secure, stop spam, fraud and abuse, and enforce our terms | Our legitimate interest in a safe service |
| Report illegal activity and answer lawful requests from authorities | Legal obligation, and our legitimate interest in preventing crime |
| Keep accounting and tax records | Legal obligation |
We do not sell personal data, show ads, or use your data for profiling or automated decisions that affect you.
6. Where your data is stored
Our main database and backend run on Google Cloud in the United States (us-central1). Published sites are served from Hetzner servers in the European Union and through Cloudflare's global network. Data sent to the United States or other countries is protected by the EU-U.S. Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses.
7. How long we keep it
- Account, business and site data: while your account exists. We delete it within 30 days after the account is deleted.
- Waitlist: until we send the launch email and you have had the chance to sign up, or until you ask us to remove you.
- Payment events we receive from Paddle: 90 days. Subscription status is kept while your account exists. Paddle keeps invoices and tax records for as long as the law requires.
- Rate limit counters: deleted automatically within about 2 hours.
- Server, Cloudflare and backend logs: up to 30 days.
- Support emails and abuse reports: as long as needed to handle them, and no longer than 2 years.
- Data held for an investigation or legal claim: until the matter is closed.
9. Your rights
Depending on the law that applies to you, including the EU and UK GDPR and the data protection law of Bosnia and Herzegovina, you have the right to:
- get a copy of your personal data;
- correct data that is wrong;
- have your data deleted;
- restrict or object to how we use it;
- receive your data in a portable format;
- withdraw consent at any time, without affecting earlier use.
To use these rights, including deleting your account, write to support@offerli.app from the email address on your account. We answer within 30 days. We may need to confirm your identity. Some data may be kept where the law requires it, or as described in section 5.
You also have the right to complain to a data protection authority, for example in the country where you live or work. In Bosnia and Herzegovina, this is the Personal Data Protection Agency.
10. Security
Data is encrypted in transit and at rest by our providers. Access to production data is limited to the people who run Offerli. Published sites are separate from the backoffice and cannot read your account. No system is perfectly secure. If a breach puts your rights at risk, we will tell you and the authorities as the law requires.
11. Changes
We may update this policy. For important changes, we tell account holders by email or in the backoffice before they apply. The version date at the top always shows the current version.