Privacy Policy
patchletter is built to be deliberately data-minimal: the only required datum is an email address. No tracking pixels in emails, no advertising cookies, no consent banner. Application, database and object storage run on our own server at netcup in Nuremberg, Germany; section 3 names the other providers involved and where they are based.
1. Controller
patchletter UG (haftungsbeschränkt), Meisterweg 16, 45896 Gelsenkirchen, Germany, represented by its Managing Director Kolja Sagorski — hello@patchletter.com
2. What data we process — and why
a) Account & sign-in (magic link)
To sign you in, we store your email address and the time of confirmation (double-opt-in record). There is no password. The sign-in link is valid for 30 minutes; the confirmation link for a new registration is valid for 24 hours. For the logged-in session we set one technically necessary cookie. Requesting a sign-in link adds a second, equally necessary one: it holds a random value with no personal reference and makes sure the code from the sign-in email only works in the browser where you started signing in; it expires after one hour. Both are set only once you sign in. On top of that there is a cookie for your chosen language — that one already on your first visit, and again on every language switch. There are no advertising or tracking cookies. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
b) Update & security emails
As a core service, patchletter sends product-related update and security notifications. We store your subscribed products and delivery settings as well as a log of the emails sent (subject, referenced releases where applicable, provider ID) for 12 months. If you tell us which version of a product you run, we store that entry together with the time and how it was made (dashboard, sign-up, or the one-click link in an update email); the record of those confirmations is deleted after 90 days. Our emails contain no open trackers. They do contain one link that performs an action and therefore identifies your account when you click it: the one that records your version, in the same way the unsubscribe link does. No other link in our emails is redirected or counted. Each of these notifications includes a one-click unsubscribe link. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for product notifications.
b.1) Five emails about patchletter Pro
For newly registered free accounts, we use the confirmed email address to introduce our own related paid service in a finite series of five emails. The first is due no earlier than 48 hours after registration; each subsequent email is due 21 days after the previous one was accepted by our mail provider. Older accounts are not enrolled afterwards. We explain this use when collecting your address. You can object there, in your dashboard, or through the link in every Pro email, without costs other than transmission costs at basic rates. This objection leaves your tool subscriptions unchanged. The series also stops when you gain Pro or MSP access, including through a team, and does not restart after a downgrade. We rely on our legitimate interest in informing existing customers about our own similar services (Art. 6(1)(f) GDPR), subject to the requirements of section 7(3) UWG. Account confirmation is not recorded as separate newsletter consent.
We store the registration-notice version, sequence progress, next due date and any stop reason with your account until account deletion. This prevents objections or completed series from being forgotten when older mail logs are deleted. Individual send logs are retained for 12 months. The Pro emails contain no open or click trackers.
c) Deliverability events
Our mail service reports non-delivery (bounce) and complaints to us. We store these events for 24 months and suppress affected addresses from sending. Legal basis: legitimate interest in deliverability and abuse prevention (Art. 6(1)(f) GDPR).
d) Server logs
When the website is accessed, technically necessary logs are created (IP address, time, requested URL, user agent). They serve operation and attack detection and are deleted after 14 days. Legal basis: Art. 6(1)(f) GDPR.
e) Bot protection (ALTCHA)
Registration and sign-in use a self-hosted proof-of-work check (ALTCHA) so automated requests are harder. The check runs only on our server in Nuremberg; no data is sent to a third party and no cookies are set for it. Legal basis: Art. 6(1)(f) GDPR (abuse prevention).
f) Analytics (Umami)
We use Umami for analytics. It runs on our own server at netcup in Nuremberg, Germany — the same machine as the application; no third party is involved. Umami sets no cookies and stores nothing on your device. Per page view we record: the page address (without query parameters), the referrer, browser, operating system, screen resolution, browser language and a location derived from your IP address down to city level. That lookup happens locally on our server; the IP address itself is not stored. From these details Umami forms a pseudonymous session identifier. In addition we count clicks on individual elements we have named ourselves and, for the Pro funnel, named steps on the pricing, sign-in, billing-details, checkout and thank-you pages. The thank-you page distinguishes four displayed states: paid, direct debit submitted, invoice or bank transfer, and still open. What is stored is the name we assigned, plus, in a few cases, one further detail we defined ourselves: the category chosen, the number of products selected, the billing period, the payment method and the identifier of the error message shown. All of these values come from a fixed list in our source code; none of them is anything you typed. Query and hash values are excluded from page addresses, so campaign parameters are not recorded. No text you see or enter. On public pages (everything under /de and /en except search) we additionally record, for a share of visits, how the page is used: click positions and scroll depth for aggregated click and scroll maps (heatmaps), and the course of the visit as a session recording. The recording reproduces the page layout, mouse movements, clicks and scrolling; visible text and all input are masked before they leave your device. We do not record sign-in, unsubscribe, checkout or any page behind sign-in, nor visits whose address contains parameters. We delete heatmap data and recordings after 90 days. Measurement also happens on pages behind sign-in. We still do not combine any of this with your account, do not link it across devices and do not pass it on. Legal basis: Art. 6(1)(f) GDPR (understanding how our service is used). We do not show a consent banner for it; we consider that justifiable because the measurement works without cookies, without third parties and without profiling, and is limited to the details listed above.
We also measure use of the public API on this same Umami instance, separately from website visits. We record the endpoint type, response status, response time, time of the request and whether a valid API key was used. Product identifiers, query parameters, email addresses and API keys are not sent to Umami. To estimate distinct clients, our application derives a pseudonymous identifier from the connection's IP address and User-Agent using a secret-keyed hash. This identifier changes each month; the original IP and User-Agent are not sent to Umami. No location is determined for API requests. This measurement has no account link. Health checks and our own monitoring are excluded. We delete API measurement events and their session data after 90 days. Separately, we use the last-used timestamps of personal API keys in our application database to count active API accounts; these account counts are not sent to Umami.
g) Tool suggestions
When you suggest a tool, we store the name/URL/note and, optionally, your email address (only to notify you if it is added).
h) Error monitoring
To find faults we run Bugsink, a self-hosted error monitor on our own server at netcup in Nuremberg, Germany — the same machine as the application. If an error occurs, technical context is recorded (URL, browser, error message and, where applicable, the ID of a logged-in account). No third party is involved. Legal basis: Art. 6(1)(f) GDPR.
i) Contacting us by email
Email you send to an @patchletter.com address is received and stored for us by our mail provider mailbox.org (Heinlein Hosting GmbH) in Berlin, Germany. We process the content solely to handle your request. Legal basis: Art. 6(1)(b) and (f) GDPR.
Two addresses are additionally processed by machine and are not read by a person. Reports that receiving mail servers send to dmarc@patchletter.com about our own domains (DMARC and SMTP-TLS reports) are forwarded to our mail server in Nuremberg and handed from there to our application on the same server, which evaluates them automatically. Until 29 August 2026 that detour ran via our machine in Germany. We store the reporting operator, the reporting period, the published policy and, per sending mail server, its IP address, the number of messages, how they were handled and the DKIM/SPF result. We do not store the report file itself, nor message content, recipient addresses, subject or sender of the report email. Purpose: to detect whether forged mail is being sent in our name and to decide on a stricter DMARC policy. Legal basis: Art. 6(1)(f) GDPR — the security of our email delivery. An IP address here identifies a sending mail server, not a visitor; we nevertheless treat it as personal data as a precaution.
The second such address is unsubscribe@patchletter.com. Every email we send carries it in its List-Unsubscribe header (RFC 8058), so that one click in your mail program is enough to unsubscribe. Mail arriving there takes the same path: it is handed to our application in Nuremberg, matched against the unsubscribe code it carries and processed automatically; nothing else is evaluated. Legal basis: Art. 6(1)(c) GDPR in conjunction with your right to object.
j) Webhooks (optional)
You can optionally set up delivery targets in the dashboard so update notifications reach your own endpoint or a chat channel instead of only your inbox. For each target we store the name you choose, the target URL, a secret for the signature, the format and the delivery status; for each delivery we store which release it concerned, whether it worked, the HTTP status code and, if applicable, the error message. The messages themselves contain only product data — product name, version, release channel, links and time of detection. No email address and no other account data is transmitted.
Where the data goes is your decision: the target is the address you enter. If you point it at a service run by someone else — a chat provider, for example — that provider receives the message and processes it under its own terms; where that provider is located and what it does with the data is outside our control. We do not use targets for any purpose of our own. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), since the delivery is the feature you asked for. Delete a target in the dashboard at any time; nothing is sent to it afterwards.
k) Wish list
Wishes you submit in the dashboard are stored with title, text, time and status against your account, and so are your votes on other people's wishes. Wishes we approve are shown to other signed-in users without your name or address. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
l) Billing and payment data (patchletter Pro, vendor presence)
If you purchase a paid offering, we store your organisation's billing details: company name, address, country, billing email address, VAT ID where given (with the time it was verified), the chosen payment method, and for each invoice the period, amounts, VAT rate, status and a copy of the invoice PDF. Payment itself is handled by our payment provider (section 3): it receives your company name, billing email address and an internal identifier of your organisation. Card details are entered only on its hosted payment page. For SEPA direct debit, the account holder and IBAN pass through our server once and are forwarded directly to the provider; we do not store them. We store only the provider's identifiers for customer, mandate and payment. We also keep an event log of billing (invoice created, payment succeeded or failed, dunning step). Legal basis: performance of a contract (Art. 6(1)(b) GDPR); for retaining invoices Art. 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code (AO) and § 14b of the German VAT Act (UStG).
m) Team, invitations and distribution addresses (patchletter Pro)
If you invite other people into your organisation, we store their email address, the intended role, who invited them and the time of the invitation, its acceptance or its revocation; the invitation email goes out over our transactional email path (section 3). For each member we store the role, the time of joining and that member's notification settings. Distribution addresses without an account of their own are stored with an optional label; they receive email only after they have confirmed it themselves, and every email to them carries the same one-click unsubscribe link as any other. For these data we are your processor; the agreement is linked in section 3. Legal basis in relation to you: performance of a contract (Art. 6(1)(b) GDPR).
n) Signing the data processing agreement
You sign the agreement under Art. 28 GDPR electronically on our own DocuSeal instance (sign.patchletter.com) in Nuremberg. This stores the name and email address of the person signing, the signature, the time and IP address of signing and the finished document; no signature provider is involved. We keep the signed version for the term of the contract and, after that, as evidence for as long as claims from it can still be raised; there is no automatic deletion for it. Legal basis: Art. 6(1)(b) and (c) GDPR.
o) Former live chat on the pricing page
From 29 to 30 September 2026 you could write to us in a chat on the pricing page; the chat is no longer offered. It ran on our own Chatwoot instance (chat.patchletter.com) on our server in Nuremberg; no chat provider was involved. From that period we store the messages, the time they were sent, an email address where one was given, and the technical details transmitted when the chat was opened (IP address, browser, operating system, referring page). These conversations are deleted 12 months after their last activity. Legal basis: Art. 6(1)(b) GDPR where the enquiry concerned a contract, otherwise Art. 6(1)(f) GDPR (answering enquiries).
3. Recipients & processors
The same providers, with categories of data, places of processing and safeguards each, are listed at our register of sub-processors.
- netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany (Amtsgericht Mannheim HRB 705547) — server hosting: one server we run ourselves in a data centre in Nuremberg, with the application, database, object storage, Umami, Bugsink and DocuSeal, and the mail server that hands our emails to the relay named below. Processing takes place in Germany. Data processing agreement under Art. 28 GDPR.
- Scaleway SAS, 8, rue de la Ville-l’Évêque, 75008 Paris, France — authoritative name servers and registration of our domain; that resolves domain names, and no account data or email content is transmitted in the process. Until 28 September 2026 Scaleway carried our hosting; the data remaining there (servers, database, backups in the Paris and Amsterdam regions) was deleted on 29 September 2026. Scaleway operates only within the EU. Data processing agreement under Art. 28 GDPR.
- Heinlein Hosting GmbH (mailbox.org), Schwedter Str. 8/9b, 10119 Berlin, Germany — mailbox and receipt of email sent to us, and storage of our off-site backups. From 25 to 29 August 2026 it also delivered our sign-in links. The backups are encrypted on our own server before they are transferred; mailbox.org holds ciphertext only. Processing takes place in Germany. Data processing agreement under Art. 28 GDPR.
- LOGIN SystemHaus GmbH, Hagenauer Str. 55, 65203 Wiesbaden, Germany (Amtsgericht Wiesbaden HRB 12713): delivery of all our emails via the mailbridge relay — update, security and Pro information emails as well as sign-in links and confirmation emails. Processing takes place exclusively in Germany. Data processing agreement under Art. 28 GDPR.
- Mailjet SAS (Sinch group), 13-13 bis rue de l’Aubrac, 75012 Paris, France — standby path for sending our emails; used only if the path above fails. Processing takes place in EU data centres (Frankfurt and Saint-Ghislain). Data processing agreement under Art. 28 GDPR.
- IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany — separate server for uptime monitoring of our services (status page) and a second, encrypted backup of our data, rotated after 30 days; the monitoring itself involves no personal data. Processing takes place in Germany. Data processing agreement under Art. 28 GDPR.
- Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands — payment provider for card and SEPA direct debit payments; it also issues and sends our invoices. For the payment itself Mollie is a supervised payment institution and a controller in its own right; for issuing the invoices it acts on our behalf (Art. 28 GDPR). It receives your company name, billing email address and an internal identifier of your organisation, plus the invoice data. Processing takes place in the EU.
- Qonto SA, 6 impasse Bonne Nouvelle, 75010 Paris, France; German branch c/o Beyond, Chausseestrasse 29, 10115 Berlin — regulated payment institution and provider of our receiving bank account. For invoice payments, Qonto processes the transfer data supplied by the sending bank, including sender, account, amount, reference and timestamps, as a controller in its own right. Our self-hosted reconciliation retrieves incoming transactions through Qonto's API and sends only transaction ID, amount, reference, status and booking time to our application. Processing takes place in the EU.
Analytics (Umami), error monitoring (Bugsink) and bot protection (ALTCHA) we run ourselves, all on our own server in Nuremberg — no third party is involved in any of them.
One more recipient exists only if you create it yourself: a webhook target you set up (see 2j). We do not choose it, and it is not a processor acting for us — you instruct us to deliver there. The messages contain product data only, no account data.
A transfer to a third country does not take place. All processors we use process exclusively within the EU; there is therefore no case in which we would have to rely on Standard Contractual Clauses. Email you send to us stays in Germany since 21 August 2026 — it is received and read at mailbox.org and no longer forwarded abroad.
If your organisation stores other people’s addresses with us — team members in patchletter Pro and MSP — we act as your processor for those. The agreement under Art. 28 GDPR, including the list of sub-processors and the technical and organisational measures, is at Data Processing Agreement. For the free service it is not needed: there we are the controller, not your processor.
4. Retention & deletion
- Live chat: conversations 12 months after their last activity, together with contacts that have no conversation left (enforced by a daily job).
- Account: until you delete it — in the dashboard with one click. The account, team and all data not subject to statutory retention are hard-deleted immediately; billing records are retained as described below.
- The record of version confirmations from update emails: 90 days. The entry itself stays on your subscription until you change it.
- Unconfirmed sign-ups are deleted automatically after 48 hours.
- An account counts as in use for as long as it receives our emails; there is no automatic deletion for inactivity. You can delete your account yourself at any time (see above).
- Notification log: 12 months · deliverability events: 24 months · server logs: 14 days.
- DMARC and SMTP-TLS reports (see 2i): 12 months · the log of received report emails: 90 days.
- Webhook targets and their delivery log: until you delete the target — and in any case together with your account.
- Billing details, invoices and the billing event log: ten years from the end of the calendar year in which the invoice was issued (§ 147 AO). Deleting your account removes the account, team, current billing profile and payment identifiers at once; the invoice PDF and pseudonymised accounting record remain for that period.
- Team memberships, invitations and distribution addresses: until you remove them — and at the latest together with the organisation.
- Signed data processing agreements: for the term of the contract and afterwards as evidence for as long as claims can still be raised (see 2n).
5. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). To exercise them, contact hello@patchletter.com. Right to complain: the competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Germany).
Last updated: 8 October 2026