Privacy Policy
Version 1.7 · Effective: 15 August 2026
Version 1.7 explains referral-link personalization, attribution, and rewards. It applies when a customer chooses to share a referral link or a recipient deliberately opens an eligible referral link. Customers who do not participate are unaffected.
The billing and tax correction introduced in Version 1.6 remains effective from 14 August 2026.
This notice is published with the Terms of Service (Version 1.1) and the Cookie Policy referral-attribution update.
| Data controller | Displaydev OÜ, Ankru 8-23, Tallinn, 11713, Estonia |
| Privacy contact | privacy@display.dev |
| Primary regulation | EU General Data Protection Regulation (GDPR) |
| Data collected | Account info, organisation info, referral attribution and reward data, account session and security data, usage events, lifecycle-marketing data, billing and tax information, page views, session replay recordings, guest access events, aggregate artifact view counts, security/audit logs, pseudonymous operational telemetry, signup attribution (self-reported source + first-party acquisition context) |
| Key sub-processors | Neon (US + SCC), PostHog (EU), Stripe (US + SCC), Cloudflare (global + SCC), Fly.io (US + SCC), Postmark (US + SCC), Loops (US + SCC), Better Stack (EU) |
| Key user rights | Access, rectification, erasure, restriction, portability, objection, supervisory authority complaint |
| Retention (overview) | Account data: until deletion + 30 days; Active session records: until expiry, revocation, or account deletion; Transactional email content: 45 days; Lifecycle-marketing contact and workflow data: until account deletion; Billing: 7 years; Usage events: account lifetime; Session replay: 30 days; View counts: account lifetime; Guest events: account lifetime; Audit logs: account lifetime; Operational telemetry: 90 days |
| Data selling | We do not sell personal data |
Introduction
This Privacy Policy explains how Displaydev OÜ ("Displaydev", "we", "us", "our"), a company registered in Estonia (EU), collects, uses, stores, and shares personal data when you use display.dev and its associated services (collectively, the "Service").
Displaydev OÜ is the data controller for personal data processed under this policy.
We are subject to the EU General Data Protection Regulation (GDPR) and, where applicable, other national data protection laws. If you have questions or wish to exercise your rights, contact us at privacy@display.dev.
1. What Personal Data We Collect and Why
We collect only the data necessary to provide and improve the Service.
| Data category | What we collect | Purpose | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|---|
| Account data | Full name, email address, account creation timestamp | Create and manage your account; authenticate you | Contract — Art. 6(1)(b) | Until account deleted, then purged within 30 days |
| Account session and security data | Opaque session identifier and token, IP address, browser user agent, derived device label, sign-in method, and session creation and expiry timestamps | Authenticate and secure your account; let you review and end active sessions; notify you of new sign-ins | Contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) | Until the session expires, is ended, or the account is deleted; security-email content is retained by Postmark for 45 days |
| Organisation data | Organisation name, URL slug, email domain | Provision your organisation; associate members | Contract — Art. 6(1)(b) | Until organisation deleted, then purged within 30 days |
| Referral data | Opaque personal or organisation referral code; inviting organisation ID; the sharing member's first name and organisation name shown to a referral-link visitor; the referred organisation ID; reward eligibility, availability, and use | Personalise a referral invitation; preserve first-touch attribution; determine and apply organisation-owned referral rewards | Contract – Art. 6(1)(b) when you participate; legitimate interest – Art. 6(1)(f) to prevent duplicate or fraudulent rewards | Referral cookie: 30 days unless consumed earlier; personal code: while the membership is active; organisation code and attribution: until the organisation is deleted; unused reward authority: until use or organisation deletion; used reward and invoice evidence: 7 years after use |
| Usage events | Actions taken in the product: artifact publish, update, delete, rollback; organisation creation; API key creation; onboarding completion; branding changes | Understand how the product is used; improve features; detect abuse | Legitimate interest — Art. 6(1)(f) | Account lifetime |
| Billing data | Subscription plan, billing tier, payment status and, when you supply them through Stripe Checkout or Billing Portal, billing address, billing name, and tax ID. Payment card details and these billing details are handled exclusively by Stripe and never stored on our servers | Process payments; calculate and collect applicable taxes; enforce plan limits | Contract — Art. 6(1)(b) | 7 years (Estonian Accounting Act obligation) |
| Page views and navigation (in-app, signed-in users) | URLs visited inside the authenticated product; page-leave events | Measure engagement; improve UX | Legitimate interest — Art. 6(1)(f) | Account lifetime |
| Page views and navigation (display.dev marketing site) | URLs visited on display.dev; page-leave events | Measure engagement; improve UX | Consent — Art. 6(1)(a), collected only if you accept the cookie banner | 2 years (only for visitors who accepted) |
| Session replay (in-app, signed-in users) | Recordings of authenticated app sessions: mouse movements, clicks, scroll position, page structure, and DOM state via PostHog's rrweb-based session replay. Form input values are masked in-browser before transmission. Browser console logs are captured alongside the recording | Diagnose user-facing issues; understand product friction | Legitimate interest — Art. 6(1)(f) | 30 days |
| Session replay (display.dev marketing site) | As above, recorded only when you accept the cookie banner | Diagnose marketing-site UX issues | Consent — Art. 6(1)(a), collected only if you accept the cookie banner | 30 days |
| Guest access events | Email address of guest viewers who authenticate via one-time code; identifier of the artifact accessed | Gate access to private artifacts | Contract — Art. 6(1)(b) | Account lifetime |
| Artifact view counts | Aggregate view count per artifact per day — no viewer identity is stored | Show publishers how their content is performing | Contract — Art. 6(1)(b) | Account lifetime |
| Security and audit logs | Administrative actions: member invites, permission changes, SSO configuration | Security monitoring; compliance | Legitimate interest — Art. 6(1)(f) | Account lifetime |
| Operational telemetry | Request identifiers; service, release, route template, response status, and duration; redacted error details and stack traces; HMAC-derived structured identity/resource correlation. Opaque internal UUIDs may appear in diagnostic error context, but resolving them to a person or organisation requires authorised database access. We exclude names, email addresses, credentials, customer hostnames, artifact names, and artifact content | Operate, diagnose, secure, and improve the reliability of the Service | Legitimate interest — Art. 6(1)(f) | 90 days |
| Signup attribution | Your answer to the optional post-signup question "How did you find display.dev?" (a choice from a fixed list, plus optional free text), and best-effort first-visit context captured by the first-party dsp_acq cookie: utm_* campaign parameters, the referring site's hostname, the landing page path, and the first-visit timestamp. No full URLs, query strings, or ad click IDs | Understand which channels bring new customers; decide where to focus launch and distribution work | Legitimate interest — Art. 6(1)(f); the question itself is optional and skippable | Until organisation deleted, then purged within 30 days |
| Lifecycle-marketing data | User ID, email address, derived first name, organisation name for member onboarding, onboarding and artifact-publication events, workflow state, and delivery, bounce, complaint, and unsubscribe status | Send and operate product activation emails after eligible onboarding and person-attributed artifact-publication actions | Legitimate interest — Art. 6(1)(f); you may unsubscribe from every activation email | Until account deletion. An unsubscribed contact remains present only to preserve suppression until deletion |
Where we rely on legitimate interest (Art. 6(1)(f)), the processing is proportionate and limited to what is necessary. Data is aggregated where possible. You retain the right to object at any time (see Section 4).
2. How We Collect Personal Data
Directly from you — when you create an account, set up an organisation, configure billing, contact support, or otherwise interact with the Service.
Automatically inside the authenticated product — when you use the signed-in Service, we collect the session and security data needed to authenticate and protect your account. We also collect usage events, page views, and device/session information through our analytics tooling (PostHog) on a legitimate-interest basis.
On the display.dev marketing site — only with your consent — PostHog is not loaded until you click Accept in our cookie banner. If you decline, we do not initialise PostHog and do not send any analytics events from the marketing site. You can change your choice at any time from the Cookie settings link in the footer.
Via the first-party dsp_acq attribution cookie — on your first visit to display.dev or app.display.dev, if the visit carries an acquisition signal (campaign parameters, an external referrer, or a non-homepage landing page), we set a first-party cookie holding that context. It is not an analytics tracker: it contains no identifiers, is not sold or used for advertising, and is deleted when you answer or skip the post-signup "How did you find display.dev?" question (or after 30 days, whichever comes first). If you submit or skip that question, the sanitized context (referrer hostname, landing path, campaign parameters) is recorded against your organisation and sent to our analytics sub-processor (PostHog — see Section 5); it is not shared beyond that. If you decline analytics consent in the cookie banner, we stop setting the cookie and delete any existing copy on your next page load. See the Cookie Policy §5 for the full description.
Via social login — if you sign in with Google or Microsoft, those providers share your name and email address with us to create or authenticate your account. Google and Microsoft act as independent data controllers for their own authentication services and are not sub-processors of display.dev.
Via referral links — when you open an eligible referral link, we resolve its
opaque code and may show the sharing member's first name and organisation name.
We set the strictly necessary dsp_ref cookie on api.display.dev to preserve the
first eligible inviting organisation for up to 30 days. The cookie contains no
member identifier, display name, or raw referral code. If you create a genuinely
new organisation during that period, we store the inviting organisation on the
new organisation so both organisations can receive and use any qualifying
reward. Later referral links do not replace that first-touch attribution.
Via direct lifecycle events – when an account completes an eligible onboarding or person-attributed publication action, our API sends Loops the limited account, onboarding, and publication facts described in Section 1. We do not replay historical actions. Loops uses these facts only to run the activation-email workflows. We do not send artifact content, artifact names, artifact URLs, comments, credentials, or per-contact tracking links.
From third parties — Stripe provides payment-related status signals (e.g. subscription renewal success or failure). We do not purchase or receive personal data from data brokers.
3. Cookies and Tracking
| Cookie / tracker | Purpose | Type | Consent required? |
|---|---|---|---|
| Session cookie (HTTP-only) | Maintains your authenticated session after login | Strictly necessary | No |
| PostHog analytics (in-app, identified users) | Tracks product usage for identified (logged-in) users | Analytics | No (legitimate interest; opt-out available) |
| PostHog analytics (display.dev marketing site) | Tracks page views and navigation on the marketing site | Analytics | Yes — opt-in via cookie banner |
| PostHog session replay (in-app, identified users) | Records in-app sessions (inputs masked) for diagnostics and UX research | Analytics | No (legitimate interest; opt-out available) |
| PostHog session replay (display.dev marketing site) | Records marketing-site sessions (inputs masked) | Analytics | Yes — opt-in via cookie banner |
dsp_acq (display.dev + app.display.dev) | Remembers first-visit acquisition context (campaign parameters, referrer hostname, landing path) until the post-signup attribution question is answered or skipped; 30-day maximum | First-party attribution | No — but declining analytics consent prevents it and deletes any existing copy |
dsp_ref (api.display.dev) | Preserves the first eligible inviting organisation while a referred visitor creates a genuinely new organisation; contains only a signed organisation identifier and expiry, never a member ID, name, or raw referral code | Strictly necessary referral attribution | No — set only after an eligible referral link is opened; 30-day maximum and cleared after successful organisation creation |
dsp_consent (display.dev + app.display.dev) | Mirrors your cookie-banner Accept / Decline choice so our servers can honor it | Strictly necessary | No |
Google Analytics 4 — _ga, _ga_<streamId> (display.dev + app.display.dev) | Distinguishes visitors and sessions for aggregate traffic reporting | Advertising and measurement | Yes — opt-in via cookie banner |
Google Ads — _gcl_au (display.dev + app.display.dev) | Links an account signup back to the Google ad click that led to it | Advertising and measurement | Yes — opt-in via cookie banner |
Reddit Ads pixel — _rdt_uuid (display.dev + app.display.dev) | Links an account signup back to the Reddit ad that led to it | Advertising and measurement | Yes — opt-in via cookie banner |
Analytics on display.dev (PostHog) is loaded only after you accept via our cookie banner. If you decline, we do not initialize PostHog and do not send any analytics events. You can change your choice at any time from the Cookie settings link in the footer.
Advertising measurement. We buy ads on Google and Reddit, and we use the tags above to see which ads led to an account being created. They are loaded through a single Google Tag Manager container on display.dev and app.display.dev, and only after you accept the cookie banner — Google Consent Mode v2 is set to denied by default before any tag loads. The signal these tags send carries no name, email address, or artifact content: only that a signup happened and which login method was used. We do not upload customer lists or hashed email addresses to any ad platform, and we run no ad measurement on dsp.so. Google and Reddit act as independent controllers for the attribution they perform on their own platforms.
Apart from the tags listed above, we set no advertising or cross-site tracking cookies. You can manage cookies through your browser settings. Disabling the session cookie will prevent you from logging in.
The full inventory of cookies and browser-storage keys across display.dev and dsp.so is listed in our Cookie Policy.
3a. Aggregate analytics on dsp.so
We operate a separate public-artifact origin, dsp.so, where published artifacts are served to viewers. On that origin we run no third-party client-side analytics. We do record three streams of server-side telemetry, without setting cookies on your browser:
- Aggregate view counts — per-artifact, daily view buckets, so publishers can see how many people read their content. No viewer identity is stored.
- Publish-to-claim funnel — for publicly-claimable artifacts we record the first and second distinct IP (hashed with a server-side secret before persistence) to measure whether viewers actually claim the URL. Exactly two events per artifact, then no further tracking.
- Operational telemetry — bounded request, status, timing, release, and redacted error context used to diagnose and secure the delivery service. Structured identity/resource correlation is pseudonymous; the telemetry excludes names, email addresses, credentials, customer hostnames, artifact names, and artifact content and is retained for 90 days.
All three are processed on a legitimate interest basis under GDPR Art. 6(1)(f): pseudonymised inputs, capped scope, no behavioural profiling. You have the right to object (see Section 4). For the full enumeration of cookies and storage keys on dsp.so, see the Cookie Policy.
4. Your Rights Under GDPR
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data, subject to our retention obligations (e.g. billing records retained for 7 years by law).
- Right to restriction of processing — request that we limit how we use your data while a dispute is resolved.
- Right to data portability — receive your personal data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest (Art. 6(1)(f)). We will stop processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or the supervisory authority in your EU member state of residence.
To exercise any right, contact us at privacy@display.dev. We will respond within 30 days.
4a. Rights for US State Residents
If you are a resident of California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), Virginia (CDPA), or Utah (UCPA), you have rights under your state's privacy statute that parallel the GDPR rights in §4:
- Right to know — request the categories of personal data we collect, the sources, purposes, and the sub-processors we share it with (see §5).
- Right to delete — request deletion of your personal data, subject to the retention obligations in §10.
- Right to correct — request correction of inaccurate data.
- Right to opt out of sale or sharing — we do not sell personal data. We do use the Google and Reddit advertising tags described in §3, which some of these statutes treat as "sharing" for cross-context behavioural advertising. Those tags run only if you accept our cookie banner, and declining (or switching to Decline later from Cookie settings in the footer) is your opt-out. You can also email privacy@display.dev to opt out.
- Right to limit use of sensitive personal information — we do not process sensitive categories as defined by these statutes.
- Right to non-discrimination — exercising any of these rights will not change your service or pricing.
To exercise any right, email privacy@display.dev. We respond within 45 days as required by CCPA; for complex requests we may extend by a further 45 days and will notify you.
5. Sub-processors and Data Sharing
We share personal data only with the sub-processors listed below, each bound by a Data Processing Agreement. We do not sell personal data to third parties.
| Processor | Data shared | Purpose | Location | Transfer mechanism |
|---|---|---|---|---|
| Neon | User accounts, org data, viewer access events, billing records, audit logs | Primary database | United States | Standard Contractual Clauses (SCCs) |
| PostHog | User ID, email, usage events, page views | Product analytics | EU (eu.posthog.com) | — (EU region; no third-country transfer) |
| Stripe | Billing contact details, including billing address, billing name, and tax ID; subscription status | Payment and tax processing | United States | Standard Contractual Clauses (SCCs) |
| Cloudflare | Artifact bodies, normalized recipient emails, creator IDs, derived search indexes, aggregate artifact view counts, and CDN cache | Customer-content storage, derived search indexing, CDN, and artifact delivery | Global (EU primary where available) | Standard Contractual Clauses (SCCs) |
| Fly.io | All data processed by the API | Application hosting | United States (Ashburn, VA) | Standard Contractual Clauses (SCCs) |
| Postmark | Recipient email addresses and transactional email content, including one-time codes, invitation details, and account-security notification details (sign-in method, derived device, masked IP address, and sign-in time) | Transactional email (sign-in OTPs, guest invites, account notifications) | United States | Standard Contractual Clauses (SCCs) |
| Loops (Loops Labs, Inc.) | User ID, email address, derived first name, organisation name for member onboarding, lifecycle events, workflow state, and delivery/unsubscribe data | Product activation and lifecycle-marketing emails | United States | Standard Contractual Clauses (SCCs) |
| Better Stack | Pseudonymous operational logs and error reports described in §1, including bounded diagnostic context and opaque internal UUIDs where present | Service monitoring, incident diagnosis, and security operations | European Union (Germany) | — (EU region; no third-country transfer) |
Advertising platforms. Google and Reddit are not sub-processors. When you accept our cookie banner, the tags described in §3 let each platform set its own cookie in your browser and attribute a signup to an ad click. Each acts as an independent controller for that processing under its own privacy policy (Google, Reddit); we send them no name, email address, customer list, or artifact content. If you decline the banner, no data reaches either platform.
We may also disclose personal data to legal authorities if required by applicable law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights or the safety of others.
6. International Data Transfers
Displaydev OÜ is based in Estonia (EU/EEA). Some sub-processors are located in or process data in the United States or other third countries outside the EU/EEA. Where we transfer personal data to third countries, we rely on EU Standard Contractual Clauses (SCCs) as the transfer mechanism. You may request a copy of the applicable SCCs by contacting privacy@display.dev.
7. Data Security
We apply industry-standard technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. This includes encryption of data in transit and at rest, access controls on production systems, and security monitoring of administrative actions.
No system is completely secure. If you believe your account has been compromised, contact us immediately at privacy@display.dev.
8. Children's Privacy
The Service is not directed at children under the age of 16 and we do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it promptly. Contact us at privacy@display.dev if you believe we have inadvertently collected such data.
9. Third-Party Links
The Service may contain links to third-party websites or services. This Privacy Policy applies only to display.dev. We are not responsible for the privacy practices of third-party sites and encourage you to review their policies.
10. Data Retention
| Data category | Retention period |
|---|---|
| Account and organisation data | Duration of account/organisation, then purged within 30 days of deletion |
| Active session records | Until the session expires, is ended, or the account is deleted |
| Transactional email content held by Postmark | 45 days |
| Lifecycle-marketing contact, workflow, delivery, and unsubscribe data held by Loops | Until account deletion; an unsubscribed contact is retained in suppressed form until deletion |
| Usage events and in-app page views | Account lifetime |
| Session replay recordings | 30 days |
| Billing records | 7 years (Estonian Accounting Act obligation) |
| Referral data | Personal code while the membership is active; organisation code and attribution until organisation deletion; unused reward authority until use or organisation deletion; used reward and invoice evidence for 7 years after use |
| Guest access events | Account lifetime |
| Artifact view counts (aggregate) | Account lifetime |
| Security and audit logs | Account lifetime |
| Operational telemetry held by Better Stack | 90 days |
Data subject to a fixed retention period is deleted or anonymised once that period elapses. Data retained for the lifetime of your account is deleted within 30 days of account closure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will provide a prominent notice within the Service 14 days before the change takes effect. Disclosures for a new optional program may instead take effect when you deliberately participate, provided no referral information is disclosed externally and no attribution begins before participation, and the notice remains available for 14 days. If an immediate change is required to stop unlawful or incorrect processing, it may take effect on publication and the notice will remain available for 14 days afterward. Continued use of the Service after the effective date constitutes acceptance of other updated policy terms.
12. Contact
Displaydev OÜ Ankru 8-23, Tallinn, 11713, Estonia
We aim to respond to all requests within 30 days. For complex requests, we may extend this period by a further two months and will notify you accordingly.