Privacy policy
Your agency's data and the data of its clients that you enter into Raportly: why we collect it, how long we keep it and how to delete it.
This is an English translation provided for convenience. The binding version of this policy is the Polish one, published at raportly.com/polityka-prywatnosci. If the two differ, the Polish version prevails.
This policy covers the raportly.com website and the Raportly application, which you log in to with your account.
1. Who the controller is
- The controller of personal data is Rafał Wójciak, correspondence address: ul. Kościelna 18, 24-173 Markuszów, Poland.
- For anything concerning personal data, write to: kontakt@raportly.com.
- We have not appointed a data protection officer. All requests go to the address given in section 2 above.
- The legal basis is Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the "GDPR").
2. The two roles in which we process data
- We are the controller of the data of people who create an account in Raportly, contact us, or signed up for the early access list. These are the data described in § 3 below.
- We are a processor of the data that an agency enters into the Application about its clients and retrieves from their analytics and advertising accounts. The controller of these data is the agency or its client, and we process them only on the agency's instructions. The terms of this processing are described in § 8 below.
3. What data we collect and why
Account in the Application
- Scope: e-mail address, password in encrypted form, agency name, the date the account was created and the date of the last login.
- Purpose: creating and running the account, authentication, contact about the service.
- Basis: Article 6(1)(b) GDPR, that is, the performance of the service agreement.
- How long: for as long as the agreement lasts, and for 30 days after it ends. After that, the account and the data linked to it are deleted. If the account is suspended because the subscription expired, or the free period from a code or the free Starter plan ended, we keep the data for 90 days from the suspension and then delete them together with the account. Paying for a plan during that time stops the deletion.
Payments
- Scope: the e-mail address given at payment, the identifiers of your customer record and subscription in Stripe, the payment history and the history of plan changes (plan, dates, source of the change). If you ask for an invoice, also the data needed to issue it: name, address and tax identification number (NIP), if you have one. You give your card number directly to Stripe. We do not receive it.
- Purpose: billing the subscription, issuing invoices and applying the discounts described in § 6 of the Terms.
- Basis: Article 6(1)(b) GDPR, Article 6(1)(c) GDPR, that is, our tax obligations, and Article 6(1)(f) GDPR, that is, our legitimate interest in defending against claims.
- How long: accounting documents for 5 years, counted from the end of the calendar year in which the tax payment deadline passed. We keep the history of plan changes after the account is deleted as well, for 6 years from the end of the year in which the change took place, and then delete it.
Referral codes and partner codes
- Scope: which account referred your account, or which partner's code was entered on your account, the date the code was entered, and for a partner code also the amounts of your payments for 12 months from the first payment.
- Purpose: granting a free month to the agency that referred you, and calculating the partner's remuneration.
- Basis: Article 6(1)(b) GDPR, that is, the performance of the agreement whose terms are described in § 6 of the Terms, and after the account is deleted Article 6(1)(c) and (f) GDPR, that is, tax obligations and defence against claims.
- How long: the referral information until the account is deleted. We keep the amounts on which the partner's remuneration was calculated after the account is deleted, no longer linked to it, for 6 years from the end of the year in which the payment was made, and then delete them.
Access to Google and Meta accounts
- Scope: access tokens issued by Google and Meta, and the identifiers of the connected GA4 properties, pages, Instagram accounts and ad accounts.
- Purpose: retrieving the data needed to prepare the report.
- Basis: Article 6(1)(b) GDPR.
- How long: until the integration is disconnected or the account is deleted.
- We ask for read-only permissions. Raportly will not change settings, publish content or start campaigns on a connected account. How the tokens are stored is described in § 9 below.
Early access list and contact
- Scope: your e-mail address and the content of the message you send us.
- Purpose: replying to your message, letting you know when the service launches.
- Basis: Article 6(1)(a) GDPR (consent) and Article 6(1)(f) GDPR, that is, our legitimate interest in corresponding with you.
- How long: until you withdraw consent or the correspondence ends, and then for one year in case of questions about it. You can withdraw consent at any time by writing to kontakt@raportly.com. Withdrawing consent does not affect what we did before it was withdrawn.
Templates from the blog
- Scope: your e-mail address, the consent sentence you tick in the form, the date of consent, the blog post you sign up from, and whether you confirm the address.
- Purpose: sending the report templates and e-mails with material about reporting and information about the product.
- Basis: Article 6(1)(a) GDPR, that is, your consent.
- How long: until you withdraw consent. You unsubscribe through the link in every message or by writing to kontakt@raportly.com, and we then delete your address. Withdrawing consent does not affect what we did before it was withdrawn.
Consent to marketing e-mails when creating an account
- Scope: your e-mail address, whether you gave consent, the date of consent and the consent sentence in force at the time.
- Purpose: sending e-mails with information about the product and offers from Raportly.
- Basis: Article 6(1)(a) GDPR, that is, your consent. Consent is optional: it does not affect creating or running the account.
- How long: until you withdraw consent. You withdraw it in the Application's settings or through the link in every marketing message. Withdrawing consent does not affect what we did before it was withdrawn.
Analytics on how the Application is used
- Scope: your account's identifier, the names of actions taken in the Application (for example signing up, connecting a Google or Meta account, downloading a report, choosing a plan), the addresses of the pages visited, browser information and the IP address. We also record the course of a visit: cursor movements, clicks, scrolling and the page layout. In the recording, all text, form fields, images and charts are masked, so it shows no figures and no names. We do not send your e-mail address, your name, the statistics of the agency's clients, the addresses of report recipients or access tokens. We collect nothing from public report links.
- Purpose: finding out which features agencies use and at which step of the setup they give up, so we know what to improve.
- Basis: Article 6(1)(a) GDPR, that is, the consent you give in the cookie banner.
- How long: 24 months from collection, and visit recordings 30 days. After you withdraw consent, we stop collecting new data, and we will delete the data collected earlier at your request sent to kontakt@raportly.com.
Ads on Facebook and Instagram
-
Scope:
- the addresses of the public raportly.com pages visited (listed in § 7(2)), browser and device information, the IP address and the identifiers stored in Meta's cookies,
- if you create an account or buy a plan: the fact that you created the account, went to payment and made the purchase, and for a payment also the plan's name, the amount and the currency,
- with the same events, your e-mail address and your Raportly account identifier, turned into a digest (a hash). The address cannot be read back from the digest, but Meta can compare it with the digests of the addresses of people who have a Facebook or Instagram account.
If you are logged in to Facebook or Instagram, Meta may link these data to your account there. We do not pass Meta any data of the agency's clients or anything you enter into the Application.
-
Purpose: finding out which ads on Facebook and Instagram bring visitors and customers, showing our ads to people who visited the site, and choosing who sees our ads based on who creates an account and buys a plan.
-
Basis: Article 6(1)(a) GDPR, that is, your consent to marketing cookies given in the cookie banner. We send the fact that you created an account, went to payment or made a purchase only if this consent is on at that moment.
-
How long: we collect the data until you withdraw consent. We do not store them ourselves. Meta stores them under its own rules, described in § 4(6) below.
Security and server logs
- Scope: IP address, browser information, the time and type of the request.
- Purpose: keeping the service secure, detecting abuse, limiting the number of requests and diagnosing failures.
- Basis: Article 6(1)(f) GDPR, that is, our legitimate interest in keeping the service working and secure.
- How long: up to 30 days.
4. Who we share data with
-
We use providers that process data on our behalf. Each of them has signed a data processing agreement with us and processes data only on our instructions:
- Supabase - database and authentication. The data are stored in the European Union, in Frankfurt.
- Vercel - hosting of the application and the website.
- Tally - early access list sign-ups collected before we closed that form.
- Resend - sending e-mails from Raportly, for example the templates from the blog.
- Google Ireland Limited (Google Analytics) - counts visits to the public raportly.com pages listed in § 7(2). This is a separate service from the Google Analytics 4 accounts of the agency's clients referred to in section 2 below: there, Google is a source of data; here, it is a processor. We turn it on only once you agree to analytics cookies in the banner (rules in § 7).
- PostHog, Inc. (PostHog) - analytics on how the Application is used. The data are stored in the European Union, in Frankfurt. We turn it on only once you agree to analytics cookies in the banner (rules in § 7).
-
The connected Google Analytics 4, Meta Ads, Facebook and Instagram accounts are not our subcontractors. They are sources from which we retrieve data on the agency's instructions. The rules for processing data on their side are set by Google and Meta.
-
We may also share data with entities authorised by law, if they request it in the manner provided for by law.
-
We do not sell personal data. For marketing purposes we pass them on only to Meta, to the extent described in point 6 below and only with your consent.
-
Payments are handled by Stripe Payments Europe, Limited, with its registered office in Dublin (Ireland). You give your card number and the other data needed for payment directly to Stripe. From us, Stripe receives the account's e-mail address, the agency's identifier in Raportly and the plan chosen. When carrying out payments and managing subscriptions, Stripe acts on our instructions, as a processor. Separately, Stripe is the controller of the data it processes for its own purposes: fraud prevention, obligations related to anti-money laundering, and developing its services. These rules are described in Stripe's privacy policy, available at stripe.com/privacy.
-
On the public pages (§ 7(2)), we use the Meta pixel, and from our server we pass on the fact that you created an account, went to payment and bought a plan through the Conversions API. These are tools of Meta Platforms Ireland Limited, with its registered office in Dublin (Ireland). We turn them on only once you agree to marketing cookies in the banner (rules in § 7). For collecting these data and transmitting them to Meta, we are responsible together with Meta, as joint controllers within the meaning of Article 26 GDPR. The terms of this arrangement are set out in the Controller Addendum, available at facebook.com/legal/controller_addendum. You may exercise the rights described in § 6 with us or with Meta. Once Meta receives the data, it processes them as a separate controller, for its own purposes, including showing ads. These rules are described in Meta's privacy policy, available at facebook.com/privacy/policy.
5. Transfers of data outside the European Economic Area
We store data in the European Union. Some of our providers, however, are based in the United States and may access data in order to maintain the service. In that case, the transfer takes place on the basis of standard contractual clauses approved by the European Commission or of an adequacy decision. Stripe may transfer data to the United States, to Stripe, LLC and Stripe, Inc., on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses. Meta may transfer data to the United States, to Meta Platforms, Inc., on the same basis. We will provide a copy of the safeguards used on request sent to kontakt@raportly.com.
6. Your rights
-
You have the right to:
- access your data and receive a copy of them,
- have data that are inaccurate or incomplete rectified,
- have your data erased,
- restrict processing,
- transfer your data to another service provider,
- object to processing based on our legitimate interest,
- withdraw consent at any time, where processing is based on it.
-
Send your request to kontakt@raportly.com. We reply within one month of receiving the request. If the matter is complex, we may extend this period by a further two months, and we will then tell you so within the first month.
-
You can delete your account yourself in the Application's settings. The deletion cannot be undone.
-
If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
7. Cookies
-
On the raportly.com website and in the Application, we use three kinds of cookies: those necessary for it to work, and analytics and marketing cookies, which we turn on only after you consent.
-
Public pages, in this policy, are: the home page, the blog, the feature pages, the legal documents, the sign-up page and the plan choice page. They do not include the Application, that is everything from
/dashboarddown, the login and password change pages, signing up through an invitation to an agency's team, or the report opened from the link an agency sends to its client. -
Necessary cookies
- The session cookie, set by Supabase after you log in to the Application. It keeps the session between requests and expires when you log out or when the session's validity period ends.
- The cookie that remembers your choice in the cookie banner, so that we do not ask for consent on every visit.
- The basis is Article 399(3) of the Polish Act of 12 July 2024 Electronic Communications Law, under which cookies necessary to provide the service do not require consent.
-
Analytics cookies
- On the public pages, we measure visits in Google Analytics 4, to know which content is read and at which step of signing up visitors give up. Google then stores its own cookies.
- In the Application and on the public pages, we measure in PostHog which features agencies use, and we record the course of a visit with text, form fields and images masked (details in § 3). PostHog then stores its own cookies and data in the browser's storage. On public report links, PostHog collects nothing. Google Analytics does not run in the Application.
- We turn them on only once you tick consent in the cookie banner. The basis is Article 399(1) of the Electronic Communications Law in conjunction with Article 6(1)(a) GDPR, that is, your consent.
- You can withdraw consent at any time by clicking "Ustawienia cookies" (Cookie settings) in the page footer or in the account menu in the Application. Withdrawing consent does not affect what we measured before.
-
Marketing cookies
- On the public pages, the Meta pixel runs. Meta then stores its own cookies, which tell us whether a visit came from an ad on Facebook or Instagram and let us show our ads to people who visited the site. Details are in § 3 and § 4(6).
- Marketing cookies do not run in the Application.
- We turn them on only once you tick consent to marketing cookies in the cookie banner. Consent to analytics cookies does not turn them on. The basis is Article 399(1) of the Electronic Communications Law in conjunction with Article 6(1)(a) GDPR, that is, your consent.
- You can withdraw consent at any time, in the same way as consent to analytics cookies. Withdrawing consent does not affect the data Meta received before.
-
You can delete cookies at any time in your browser's settings. Deleting the session cookie logs you out, and after the cookie banner's cookie is deleted, the banner appears again.
8. Processing of the agency's clients' data on the agency's behalf
This section is a data processing agreement within the meaning of Article 28 GDPR. You conclude it with us together with the Terms, by creating an account in Raportly. You are the controller or act on behalf of the controller, and we are the processor.
- Subject matter and purpose: we process the data entrusted to us only to supply you with the service described in the Terms, that is, to retrieve data from the connected accounts, prepare a report from them and send it to the recipients you indicate, including on a schedule.
- Duration: for the term of the agreement, and for 30 days after it ends, during which you can download a copy of the data. If the account is suspended, we process the data until it is deleted, at most for 90 days from the suspension, and during that time we retrieve and send nothing new.
- Type of data: names and contact details of the agency's clients, e-mail addresses of report recipients, identifiers of the clients' analytics and advertising accounts, statistics retrieved from those accounts, and branding materials entered into the report.
- Categories of data subjects: the agency's clients, the contact persons they designate, and report recipients.
- Our obligations: we process the data only on your documented instructions, give access to them only to persons bound by confidentiality, apply the security measures described in § 9 below, help you respond to requests from data subjects, and notify you of a personal data breach without undue delay, and no later than 24 hours after becoming aware of it.
- Sub-processing: we use the subcontractors listed in § 4(1) above. We will inform you by e-mail of an intended addition or replacement of a subcontractor no later than 30 days before the change. Within that period you may object, and you then have the right to terminate the agreement.
- Audit: at your request, we will make available the information needed to demonstrate that we meet our obligations under Article 28 GDPR, and allow an audit agreed in advance.
- After the end: after the agreement ends, we delete the data entrusted to us within the period set out in section 2 above. At your request, we will delete them earlier.
- We do not use the data entrusted to us for our own purposes or to build summaries or comparisons, and we do not make them available to other agencies.
9. How we protect data
- We encrypt connections to the Application.
- We separate each agency's data at the database level. A query from one agency's account cannot reach another agency's data.
- We encrypt the access tokens to Google and Meta accounts and keep them on the server only. We never return them to the browser or write them to logs.
- We do not store passwords in plain text, only as a hash. We do not know your password.
- Only people who need it to maintain the service have access to the production infrastructure.
10. Changes to this policy
- We may change this policy if the way the Application works, the list of providers or the law changes.
- We will inform you of a change by e-mail no later than 14 days before it takes effect, and publish the new version on this page.
- The policy applies from 2 November 2026.