Privacy Policy

Status: January 24, 2026

1. Data Protection at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website or use our services. Personal data is any data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.

Data Collection on This Website

Who is responsible for data collection on this website? Data processing on this website is carried out by the website operator. You can find their contact details in the "Information on the Responsible Party" section of this privacy policy.

How do we collect your data? On the one hand, your data is collected when you provide it to us. This can be, for example, data you enter when subscribing to the newsletter or purchasing a product via our checkout process. Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page view).

What do we use your data for? Part of the data is collected to ensure the error-free provision of the website (Hosting). Other data can be used to analyze your user behavior (Analytics) or to process your payments and orders (Stripe). We use email services to send you the purchased products (Download Links) and manage your subscription.

What rights do you have regarding your data? You have the right at any time to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future.

2. Hosting and Content Delivery

Vercel

We host this website with Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel is a platform for hosting and delivering web content. When you visit our website, Vercel collects various log files including your IP addresses. For details, please see Vercel's privacy policy: https://vercel.com/legal/privacy-policy

Legal Basis: The use of Vercel is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable, fast, and secure presentation of our website.

Data Transfer to the USA: Vercel processes data in the USA. We have concluded a Data Processing Agreement (DPA) with Vercel. Vercel relies on Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework.

3. General Notes and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

Information on the Responsible Party (Controller)

The responsible party for data processing on this website is:
Pawel Lebek
Leopoldstraße 2
32051 Herford
Germany
Email: contact@reviewstudios.io

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data.

4. Payment Processing (Stripe)

Stripe

We use the payment service provider Stripe to process payments on our website. The provider for customers within Europe is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The parent company is Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA.

Data Processing: When you make a purchase, your payment data (e.g., credit card number, purchase amount, time of transaction) is processed by Stripe via an interface on our website. We generally do not store your complete payment data (such as full credit card numbers) on our own servers; this is handled directly by Stripe's secure infrastructure. We only receive confirmation of the payment, the customer ID, and the email address to fulfill the contract.

Legal Basis: The transmission of your data to Stripe is based on Art. 6(1)(b) GDPR (processing for the performance of a contract). We cannot process your order without this payment information.

Data Transfer to the USA: Stripe may transfer data to the USA. Stripe complies with the EU-US Data Privacy Framework (DPF) and uses Standard Contractual Clauses (SCCs) to ensure a level of data protection comparable to that of the EU. For more information, please refer to Stripe's Privacy Policy: https://stripe.com/privacy

5. Data Collection on This Website

Cookies and Consent Management

Our website uses cookies. Cookies are small text files that are stored on your device.

CookieYes

We use CookieYes (CookieYes Limited, Winchester House, 11 Cranmer Road, Kennington, London SE11 4EJ, United Kingdom) for cookie consent management. The legal basis is Art. 6(1)(c) GDPR (legal obligation to obtain cookie consent).

Google Fonts (Local Hosting)

This site uses locally hosted Google Fonts. No connection is made to Google's servers. The integration is based on Art. 6(1)(f) GDPR.

6. Analytics and Marketing

Google Tag Manager & Google Analytics

We use Google Tag Manager and Google Analytics provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: Analysis of user behavior.

Processed Data: Anonymized IP address, pages accessed, technical information.

Legal Basis: Art. 6(1)(a) GDPR (Consent via cookie banner).

Data Transfer: Google may transfer data to the USA under the EU-US Data Privacy Framework.

Microsoft Clarity

We use Microsoft Clarity provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Purpose: Heatmaps and session recordings.

Legal Basis: Art. 6(1)(a) GDPR (Consent).

Rewardful Affiliate Tracking

We use Rewardful (Rewardful, Inc., 228 Park Ave S, New York, NY 10003, USA).

Purpose: Attribution of sales to affiliate partners.

Legal Basis: Art. 6(1)(a) GDPR (Consent).

7. Email Services (Download Links & Newsletter)

We use external service providers to send emails. This includes transactional emails (containing your download links after purchase) and newsletters (if you opted in).

Brevo (formerly Sendinblue)

We use Brevo to send newsletters and transactional emails. The provider is Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France.

Purpose: Sending the newsletter and purchase confirmations.

Processed Data: Email address, Name, IP address, interaction data (opens/clicks).

Server Location: Brevo stores data on servers within the European Union (EU).

Legal Basis:

  • Transactional Emails (Downloads): Art. 6(1)(b) GDPR (Performance of a contract).
  • Newsletter: Art. 6(1)(a) GDPR (Consent).

Data Processing Agreement: We have concluded a Data Processing Agreement (DPA) with Brevo.

Resend

We use Resend to deliver transactional emails (e.g., instant delivery of your download link). The provider is Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.

Purpose: Reliable delivery of system emails and download links.

Processed Data: Email address, email content.

Legal Basis: Art. 6(1)(b) GDPR (Performance of a contract - delivery of purchased goods).

Data Transfer to the USA: Resend processes data in the USA. We ensure compliance with GDPR through Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework (where applicable).

8. Your Rights as a Data Subject

You have the following rights under the GDPR:

  • Right to information (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

9. Security and Changes

SSL/TLS Encryption

This website uses SSL/TLS encryption for security reasons.

International Data Transfers

Some of our service providers (Vercel, Stripe, Google, Microsoft, Resend, Rewardful) are based in the USA or process data there. We ensure that these providers comply with the GDPR via the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs).

Changes to the Privacy Policy

We reserve the right to adapt this privacy policy to always comply with the current legal requirements. The new privacy policy will apply to your next visit.