Privacy at Swiftfunnel
Privacy policy
1. Controller
SINISTAR MEDIA, owner Phil Sievers
Zum Morgenland 2, 21376 Eyendorf, Germany
Email: info@swiftfunnel.ai
Swiftfunnel is a SINISTAR MEDIA SaaS offering and not a separate legal entity. No data protection officer has been appointed; send privacy enquiries to the address above.
2. Scope and roles
This policy covers swiftfunnel.ai, app.swiftfunnel.ai, pages.swiftfunnel.ai and related services. We are controller for accounts, billing, operations and our website. Where customers process their own prospects through funnels, the customer normally determines purpose and means and Swiftfunnel acts as processor under instructions. Customers must provide appropriate privacy information to funnel visitors.
3. Legal bases
- Art. 6(1)(b) GDPR for pre-contractual steps and contract performance.
- Art. 6(1)(c) for legal duties, including commercial and tax retention.
- Art. 6(1)(f) for secure, stable and economic operation.
- Art. 6(1)(a) for optional features requiring consent.
4. Website access and server logs
We process IP address, timestamp, target URL, referrer, HTTP status, transferred volume, browser and device data to deliver content, prevent attacks and diagnose errors under Art. 6(1)(f). Logs are deleted or anonymised when no longer required unless a security incident requires longer retention.
5. Essential storage
Essential cookies or local storage support sign-in, sessions, workspace selection, abuse prevention and your privacy choice under Art. 6(1)(b)/(f) GDPR and Section 25(2)(2) TDDDG. Sessions expire after at most 14 days or on logout. Privacy choices remain for up to twelve months and can be changed through Cookie settings.
6. Self-hosted analytics (Umami)
We self-host cookieless Umami at privacy.swiftfunnel.de to understand reach, performance, error paths and key product flows. It receives pages, shortened referrer/campaign data, browser/device class, approximate region, timestamps and pseudonymous session/event data, but no names, email, form content or lead data. IP addresses are only used technically to form a rotating, non-reversible identifier. The basis is Art. 6(1)(f).
Optional session recording
With consent, up to 10% of marketing-site visits may be recorded with text and input masking; the customer dashboard is excluded. The basis is Art. 6(1)(a), and consent can be withdrawn through Cookie settings.
7. Registration, workspace and contract use
We process names, email, password hashes, memberships, roles, funnel and asset content, configuration, activity, session data and support communication for account provision, permissions, security and support under Art. 6(1)(b)/(f). Passwords and tokens are not stored in plain text.
8. Funnels, forms and contacts
Customer funnels may collect name, email, phone and customer-defined fields. The customer is normally controller; we store and provide data on its instructions. Funnel analytics excludes form content.
9. Stripe payments
Stripe Payments Europe, Limited, Dublin, processes contact, invoice, payment, device and transaction data. Card details are entered only on Stripe pages. Bases are Art. 6(1)(b), (c) and (f) for fraud prevention. See Stripe’s privacy policy.
10. Email delivery
Transactional, security, invitation and support emails use our external server at mail.swiftfunnel.de and process recipient, sender, subject, content and delivery data under Art. 6(1)(b)/(f).
10a. Contact form and live chat
The contact form processes name, email, optional company, topic and message under Art. 6(1)(b) or (f). On app.swiftfunnel.ai, tawk.to Inc., USA, provides live chat and may process IP, browser/device data, page, timestamps, identifiers, chat messages and supplied contact data. US processing cannot be excluded. See tawk.to’s policy.
11. Security and error analysis
Cloudflare Turnstile protects forms and may process IP, browser, device and interaction data under Art. 6(1)(f). Sentry processes technical request and error data for diagnosis under Art. 6(1)(f); configuration limits form content and credentials.
12. Optional integrations
Only after a workspace owner configures them, required data may go to Anthropic for AI requests, Meta/WhatsApp for selected messaging or event functions, or customer-selected webhook and MCP/API targets. The basis depends on use and may be contract, consent or the customer’s chosen legal basis. Owners are responsible for targets and permissions.
12a. Protection measures for sensitive connection data (e.g. Google Ads, Meta Ads, WhatsApp)
Credentials for third-party accounts connected by customers (such as OAuth refresh tokens for Google Ads or Meta Ads, and WhatsApp Business API tokens) are stored exclusively in encrypted form (symmetric Fernet/AES-128 encryption with a server-held key) and are never returned to the dashboard in plaintext. Transmission uses TLS-encrypted connections only. Decryption is accessible only to automated system processes required for the function the customer explicitly requested (e.g. syncing ad campaign data); manual access by staff is not technically provided for. If a customer disconnects an integration, the associated credentials are deleted immediately. Data retrieved from the connected platform (e.g. campaign names, metrics) is stored only within the respective workspace and is not shared with third parties beyond the processors listed in section 13. Any action that actually modifies such a connection on the third-party platform (e.g. pausing a campaign) always requires the customer’s explicit confirmation in the dashboard.
13. Recipients and international transfers
Access is limited to authorised personnel and required hosting, infrastructure, payment, communication and security providers. Processor agreements are concluded where required. Transfers outside the EEA use an adequacy decision, standard contractual clauses or another Chapter V GDPR safeguard.
14. Retention
Data is kept only for its purpose, contract, security interests or legal duties. Commercial and tax records are generally retained for six or ten years. Data is then deleted or anonymised unless continued retention is required. Workspace customers can export or delete contacts and content through product features.
15. Data subject rights
Subject to legal conditions, rights include access, rectification, erasure, restriction, portability, objection to Art. 6(1)(f) processing and withdrawal of consent. Contact info@swiftfunnel.ai. For a customer’s funnel or contact, approach that customer as controller first.
16. Complaints
You may complain to a supervisory authority. Our competent authority is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hannover, www.lfd.niedersachsen.de.
17. Automated decisions and updates
We do not make solely automated decisions producing legal or similarly significant effects. We update this policy when features, providers or the law change.
Last updated: August 2026