Privacy Policy
Most recent update: February 28, 2026
1. General information
We do not want to collect your data. We therefore want to be fully transparent about how we use it, and are always open to viable suggestions on how to reduce your data footprint on our servers. We try to use privacy-friendly open source software and not rely on third parties as much as possible.
This document outlines our responsibilities and duties regarding the processing of your personal data, as defined by Article 13 of the European Union’s General Data Protection Regulation (GDPR), and provides information on the rights that you have as a data subject.
2. Contact
Data protection officer: security@share.page
To report a privacy violation, please contact us at security@share.page
Should you wish to report a complaint or if you feel that share.page has not addressed your concern in a satisfactory manner, you may contact the responsible Information Commissioner’s Office.
3. Data processing reasons & legal basis
share.page differentiates between registered users and non-registered visitors. Anyone can view the public pages hosted on https://share.page, whether they are registered or not. A registered user is a person who signed up for an account on share.page (usually through https://share.page/auth/sign-up). We process and store as little information as possible.
3.1 Data processing for non-registered visitors
When accessing share.page and its services, the following information is processed by share.page for the reasons outlined below:
- The visitor’s IP, geographical location, language preferrence, previously-visited website (referrer URL), and device information such as operating system and browser brand.
- This data is used for analytics and maintenance of the platform’s services. For example, this helps us identify and fix problems that appear on certain devices.
- The visitor’s language preferences are used to display content in their preferred language. These preferences may be stored as a strictly-necessary cookie.
We’ve chosen Fathom Analytics for our website analytics because it doesn’t use cookies and complies with the GDPR, ePrivacy (including PECR), COPPA and CCPA. Our visitors’ IP addresses are only briefly processed and we have no way of identifying them. As per the CCPA, personal information is de-identified. Read more about this on the Fathom Analytics website.
The purpose of using this software is to understand our website traffic in the most privacy-friendly way possible so that we can continually improve our website and business. The lawful basis as per the GDPR is “Article 6(1)(f); where our legitimate interests are to improve our website and business continually.” As per the explanation, no personal data is stored over time.
3.2 Data processing for registered users
When a person creates an account on share.page, the following information is processed by share.page for the reasons outlined below:
- Account details (e-mail address, name), for the purpose of providing you with an account on our platform.
- Data is recorded during account registration on share.page at share.page (under “Sign up”).
- Data can be managed on the dashboard page at share.page/app.
- Legal basis for processing this data is the user’s consent to either share the data on our platform or to receive notifications (Art. 6.1.a GDPR).
- Payment information (IBAN, legal name, e-mail address), for the purpose of processing payments.
- Payment information is recorded upon payment through the selected third-party payment processor.
- share.page records identifiers provided by the third-party payment processor. Such identifiers can include an IBAN, legal name, e-mail address or other data.
- Legal basis for processing this data is to fulfill legal obligations for processing payments (Art. 6.1.c GDPR).
- Technical metadata for the purpose of providing the platform services and avoiding misuse of our resources.
- Data is processed during regular use of our website, and includes the IP address of the requesting computer, the browser and operating system you are using, the date and time of access, the Uniform Resource Locators (URL) requested on our website, as well as the previously visited website (referrer URL). When stored in logs, the IP address is truncated so that this data is not associated with your personal data.
- Further metadata includes technically necessary cookies to identify the session of a logged-in user or to protect users from so-called CSRF attacks. share.page does not use cookies or any other techniques for user-targeted analytics or advertisements.
- Legal basis for processing this data is a legitimate interest of the platform operator (Art. 6.1.f GDPR).
- When pages hosted on share.page process personal data using share.page’s resources (e.g. through a web page hosted on share.page), the project’s owner is primarily responsible for the data processing and must make sure to adhere to the GDPR as well as their local legislature independently from these terms.
4. Data handling by third parties
Personal data may only be processed by the association bodies which are responsible for their respective tasks. This specifically means that:
- Cash auditors can access bank statements and other financial details. Such data may only be used for fulfilling the task of auditing the company’s finances.
- share.page’s employees can access the database records & additional metadata required to investigate potential violations of our terms.
- Infrastructure administrators can access all resources and personal information stored on our servers. This is required for maintaining the infrastructure necessary for providing share.page’s services.
- Tasks involving processing personal data may be delegated to other people within the company by the responsible person.
The website is hosted on Scalingo’s servers, which are based in Paris, France.
Third parties may be involved with processing personal data under a specific data processing agreement. A full list of third-parties can be provided upon request.
5. Data retention
- Account details are stored until the deletion of the account.
- Membership details & payment records are stored for up to 10 years after the membership has ended due to legal obligations.
- Technical metadata like IP addresses are not stored for more than 7 days or as required by German legislature.
- Personal data may exist in encrypted backups for up to 1 year. If the data retention period is exceeded at the time of restoration of a backup, affected personal data will be purged.
- Personal data is stored in accordance with the statutory archiving obligations in Germany.
6. Data subject rights
As a subject of personal data processing, you have the following rights:
- Right to access: You can request copies of your personal data, as defined in Art. 15 GDPR.
- Right to rectification: you can request that share.page corrects any information you believe is inaccurate, or completes any information you believe is incomplete, as defined in Art. 16 GDPR.
- Right to erasure: you can request that share.page erases your personal data, under the condition that the retention and processing of the information is not required by law and is not neccessary due to the reasons outlined in Art. 17 (3) GDPR.
- Right to restrict processing: you can request that share.page restricts the processing of your personal data, as defined in Art. 18 GDPR.
- Right to object to processing: you can object to and withdraw consent to share.page processing your personal data, as defined in Art. 21 GDPR.
- Right to data portability: you can request that share.page transfers the data that we have collected to another organization, or directly to you, as defined in Art. 20 GDPR.
- If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please use the contact information listed in Art. 2 of this privacy policy.