SwissTrustWidget

Privacy Policy

Last updated: March 2026

1. Data Controller

GEWE GmbH Postfach 583 CH-3000 Bern Email for data protection requests: info@swisstrustwidget.ch UID: CHE-440.568.800VAT Managing Director: Andri Werren

2. Scope

This privacy policy applies to swisstrustwidget.ch and app.swisstrustwidget.ch. It explains which personal data we collect, for what purpose and on what legal basis — in accordance with the Swiss Federal Act on Data Protection (nFADP).

3. What data do we collect?

Website visits: IP address (anonymized), date/time, page visited, referrer, browser type. Hosted on Vercel (USA). Analytics: Umami Analytics (privacy-friendly, no cookies), Google Analytics and Microsoft Clarity (consent only). Account creation: email address, encrypted password, plan status, connected Google locations. Widget embedding: No tracking cookies, no personal data of website visitors is stored.

4. Third parties

Vercel (hosting), Supabase (backend), Stripe (payment), Resend (emails), Google Places API (reviews), Google Analytics, Microsoft Clarity, Umami Analytics, Google reCAPTCHA, Google Ads, Google Fonts, CookieYes. For data transfers to the USA, we rely on EU Standard Contractual Clauses.

5. Cookies

Technically necessary: session cookies, CookieYes consent. Analytics (consent only): Google Analytics, Microsoft Clarity. Marketing (consent only): Google Ads conversion tracking. You can revoke consent at any time via the CookieYes banner.

6. Purpose of data processing

Service provision, payment processing, communication (transactional emails), security (spam protection, rate limiting), improvement (anonymized analytics), marketing (consent only).

7. Data storage and deletion

Account data: stored while active, deleted within 30 days of account deletion. Server logs: deleted after 30 days. Rate limiting: IPs deleted after 15 minutes. Payment data: stored by Stripe per their retention policies.

8. Data security

HTTPS/TLS, bcrypt password hashing, PCI-DSS certified payment processing, restricted access, regular security updates.

9. Your rights (nFADP)

Right of access (Art. 25), right of rectification (Art. 32), right to erasure, right to data portability (Art. 28), right to object. Contact: info@swisstrustwidget.ch — processed within 30 days.

10. Changes

We may update this privacy policy at any time. In case of substantial changes, registered users are informed by email.

11. Supervisory authority

Federal Data Protection and Information Commissioner (FDPIC) Feldeggweg 1 CH-3003 Bern www.fdpic.admin.ch

12. Contact

GEWE GmbH Postfach 583 CH-3000 Bern Email: info@swisstrustwidget.ch