← Back

Privacy Policy

1. Controller

The controller responsible for data processing on this website is:

[Malte Hoffmann]
[Am Salzstadel 13]
[83022 Rosenheim]
Email: [malte@scarb.de]

2. Data we collect

When you create an account, we collect your email address and a password (stored as a bcrypt hash). We do not collect payment information directly — payments are processed by Stripe.

When you connect a Google Ads or Meta Ads account, we store OAuth access tokens encrypted at rest. These tokens are used solely to fetch campaign spend data on your behalf.

3. How we use your data

We use your data exclusively to provide the Burnrate service: syncing ad spend, calculating budget pacing, and sending alerts. We do not sell or share your data with third parties for marketing purposes.

4. Cookies

We use a single httpOnly cookie to maintain your authenticated session. No tracking or advertising cookies are set.

5. Data retention

Your data is retained for as long as your account is active. You can request deletion of your account and all associated data at any time by contacting us at [malte@scarb.de].

6. Your rights (GDPR)

Under the GDPR you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing and to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at [malte@scarb.de].

7. Third-party services

We use the following third-party services which may process personal data:

  • Stripe — payment processing (privacy policy: stripe.com/privacy)
  • Google Ads API — ad spend data (privacy policy: policies.google.com/privacy)
  • Meta Ads API — ad spend data (privacy policy: facebook.com/privacy/policy)
  • Resend — transactional email delivery

8. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated via email.

Last updated: April 2026