Qomvia

Privacy policy

Last updated 7 September 2026. Controller: BitSpark GmbH, Oberfeldstrasse 61, 3067 Boll, Switzerland, reachable at [email protected].

What we store

  • Account data: your email address, sign-in link tokens and session records. Basis: contract.
  • Project data: domains you track, packs you enable, imported catalogue data and the results of scans and visibility runs. Basis: contract.
  • Scan data: public HTTP responses from scanned websites and the scores derived from them. This is business data about websites, not personal data about visitors. Basis: legitimate interest in operating a public measurement index.
  • Billing data: subscription and credit records, plus a Stripe customer reference. Card data never reaches our servers. Basis: contract and legal retention duties.

We do not run advertising trackers or third-party analytics profiling, and we do not sell personal data.

Processors

  • Vercel: hosting and request logs.
  • Neon: the PostgreSQL database.
  • Stripe: payments and subscription state.
  • Resend: transactional email (sign-in links, alerts).
  • Model providers (OpenAI, Anthropic, Google, xAI): only for visibility runs, and only the generated buying questions are sent; account identifiers are not.

Retention

Sessions expire automatically. Scan history is kept while a site is in the public index. Account and project data are deleted within 30 days of account deletion; invoices are kept as long as accounting law requires.

Your rights

You can request access, correction, deletion, restriction, portability or object to processing based on legitimate interest; write to [email protected]. You may also complain to your data protection authority. Website owners who want their site removed from the public index should use opt-out, which is immediate and needs no account.

Cookies

One first-party cookie (qv_session) keeps you signed in. It is strictly necessary, and there are no marketing or analytics cookies to consent to.