Privacy Policy
1. Controller
The controller responsible for data processing is:
Malte Hoffmann
Am Salzstadel 13
83022 Rosenheim, Germany
Email: info@getpacefy.com
For the budget and campaign data you upload to the Service, we act as a processor on your behalf within the meaning of Art. 28 GDPR; you remain the controller for that data.
2. What data we process, and the legal basis
- Account data — when you register with your email address, we store that email address and a cryptographic hash of your password. Passwords are hashed with bcrypt (using a per-password salt) and are never stored in readable form. If you choose Sign in with Google, we receive your email address, name, and Google account identifier from Google (we never receive your Google password). Legal basis: Art. 6(1)(b) GDPR (performance of contract).
- Budget & campaign data you upload (via CSV files you export from your advertising platforms) — processed solely to provide the pacing service. This data is yours; we process it only on your instruction. Legal basis: Art. 6(1)(b) GDPR.
- Server logs & IP address — to operate and secure the Service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stability and security).
- Billing data — payments are handled by Stripe; we receive limited subscription/billing status. Legal basis: Art. 6(1)(b) and, for invoices, Art. 6(1)(c) GDPR (legal retention obligations).
- Transactional emails — currently only password-reset messages, sent when you request them. Legal basis: Art. 6(1)(b) GDPR.
How spend data reaches Pacefy: Today, spend data is imported via CSV files that you export from your advertising platform and upload to Pacefy. The supported exports are Google Ads and Meta.
Pacefy also includes a direct read-only connection to Google Ads and Meta. If, and only if, you connect an advertising account, we store the resulting OAuth access and refresh tokens encrypted at rest (Fernet, AES-128-CBC with HMAC) and use them once per day to read campaign-level spend figures — campaign ID, campaign name, date, and amount spent. The scopes we request are read-only (Google adwords, Meta ads_read); we cannot and do not create, modify, or pause campaigns. You can disconnect at any time in Settings → Integrations, which deletes the stored tokens. This connection is subject to approval by Google and Meta and is not yet generally available.
Both paths are separate from Sign in with Google, which we use only for authentication — see "Account data" above.
3. Cookies
We use two httpOnly cookies to maintain your authenticated session: a short-lived access token and a refresh token. Both are marked Secure and SameSite=Lax, and both are strictly necessary for the Service to function. We set no tracking or advertising cookies, so no consent banner is required (§ 25(2) TDDDG).
4. Hosting and third-party services
We use the following providers:
- Hetzner Online GmbH (Germany) — server hosting and data storage. Data is stored within the EU. (processor)
- Cloudflare, Inc. (USA) — DNS and domain services. (processor)
- Resend (USA) — transactional email delivery. (processor)
- Stripe — payment processing. (processor)
- Google (Google Ireland Limited / Google LLC, USA) — authentication when you choose Sign in with Google. Google acts as an independent controller for the sign-in. Privacy policy: policies.google.com/privacy
5. International data transfers
Hosting and primary data storage take place within the EU (Hetzner). Some providers (Cloudflare, Resend, Stripe, Google) may process data in the USA. Such transfers are safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses pursuant to Art. 46 GDPR.
6. Data retention
- Account & uploaded data — retained while your account is active. On account closure or request, deleted within 30 days. Nightly database backups are retained for 30 days and then deleted, so backup copies disappear within 30 days of the deletion.
- Advertising-platform OAuth tokens — retained only while the corresponding connection exists. Deleted immediately when you disconnect the account.
- Invoice / payment records — retained for the statutory period (up to 10 years, § 147 AO / § 257 HGB).
- Server logs — retained for 90 days.
7. Your rights (GDPR)
You have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing. To exercise any of these rights, contact info@getpacefy.com. Requests are handled manually and answered within 30 days; there is currently no self-service export or account-deletion button in the app. Step-by-step deletion instructions are available at getpacefy.com/data-deletion.
You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
8. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via email.
Last updated: June 2026