Last update: 21st of September 2026
This document describes how we collect and process users’ data through https://stape.io/, https://community.stape.io/, https://comments.stape.io, and https://help.stape.io/ webpages, hereinafter simply referred to as the “Website”. The terms “we”, “us”, “our” refer to Stape, Inc., a legal person registered under the laws of the State of Delaware, USA.
WE ARE COMMITTED TO SAFEGUARDING PRIVACY AND NOT GOING TO MISUSE OUR USERS’ DATA.
The below information will help you better understand how your data is handled and how you can manage all the matters related to your privacy.
Controller details:
Name: Stape, Inc.
Registration number: 5987286
Registered address: 901 N Market St., Suite 100, Wilmington, DE, 19801, USA
Contact email address: privacy@stape.io
1.1. Account and profile set up
If you want to use the Website functionality, you will have to register an account on a particular webpage. For this purpose, we will ask only for your email address, since this is enough to set up an account. Further information such as first and last name, photo, company name and other information, in particular geolocation, you provide on a voluntary basis so as to be able to act as a full-fledged Website user.
We use your account information to:
We will store your account data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.
1.2. Website functionality
Via the Website, you will be able to perform different actions to organize and manage Server-side tagging in a dedicated server-side environment or communicate with the other users on Service-related topics. We will store and process the following categories of information:
The applied legal basis for this is the performance of the contract (Terms of Use) between you and us (GDPR Art. 6.1.b). We will store this data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.
1.3. Payments
We do not collect your financial information. For the purpose of ordering the upgraded version of Service you will be automatically redirected to Stripe, 2Checkout or to another duly authorized contractor. They will collect and store your financial data directly and according to their respective policies.
We shall retain only payment confirmation provided by the relevant payment service provider in order to comply with applicable accounting and financial laws (GDPR Art. 6.1.c and in our legitimate interests to comply with foreign laws as per Art. 6.1.f). We will store this data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.
1.4. Communications
You may leave a request with your inquiries including request for support: (1) via https://help.stape.io/; (2) in our live chat; (3) or by email. The provided information used to help you with your request, fix and improve the Website, and analyse our efficiency, including by creating statistics of inquiries related to support issues.
The applied legal basis for this is the performance of the contract (Terms of Use) between you and us (GDPR Art. 6.1.b) and our legitimate interest to improve the Website (GDPR Art. 6.1.f). We will store this data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.
1.5. Demo access
You can receive free access to our Service to know how the Website works. In order to perform this, you have to submit your email and setup password upon first visit.
We will use this information to provide you with the free plan of Service. The applied legal basis for these activities is our legitimate interest (GDPR Art. 6.1.f). We will store your email for as long as the demo account is active. If it becomes inactive, we will delete or anonymize your email within 12 months after your last user session.
The following data collection activities are present on the Website:
We store marketing data for 12 months of the last communication with you. For the activities that are based on consent, you can withdraw your consent at any time by contacting us directly. The withdrawal will not affect the lawfulness of processing based on consent before. You can also opt-out of the e-mail subscription by clicking the appropriate button our emails to you.
Our Website may use social media features, such as the “Tweet” button, “Share on Facebook” button or other sharing instruments (“SMF”). SMF can let you post information about your activities on the Website to third-parties platforms and social networks. SMF may also allow you to like or highlight information we have posted on our Website. SMF are either hosted by each respective platform or hosted directly on our Website. To the extent the SMF are hosted by the platforms themselves, and you click through to these from our Website, the platform may receive information showing that you have visited our Website. If you are logged in to your social media account, it is possible that the respective social media network can link your visit to our Website with your social media profile.
We also allow you to log in to certain pages of our Website using sign-in services. These services authenticate your identity and provide you the option to share certain personal data from these services. Your possible information exchanges with SMF are covered by the privacy policies of the companies providing them.
We disclose personal information to third parties only as described in this Privacy Notice and only for the purposes stated below. We use the following types of third-party providers:
| Type of third party | Identity / examples | Personal information disclosed | Purpose of disclosure |
|---|---|---|---|
| Cloud and infrastructure providers | Companies which provide cloud server computing services | Account, usage, communications, and technical data | Host, store, and operate the Website and Service |
| Communications, email, and CRM providers | Companies which provide communication, e-mail server, and client relationship management services | Contact details and message content | Send transactional and support communications and manage customer relationships. Message exchanges may include personal data. |
| Analytics, advertising, and marketing providers | Companies which help to monitor the behaviour of the Website’s visitors or provide advertising or marketing services, including Google Analytics (see Section 2.1) | Usage, device, and marketing data | Measure Website performance, improve usability, and (where permitted) conduct marketing |
| Payment and financial service providers | Stripe, 2Checkout, and other duly authorized payment contractors; companies which provide financial services and process accounting documents | Payment confirmation and related billing data (financial card data is collected by the payment provider, not by us) | Process payments and comply with accounting and financial laws |
| Survey providers | Companies which provide survey services | Contact details and survey responses | Collect feedback and improve the Service |
| Work management providers | Companies which help with work management with further personal data processing | Support, account, and operational data | Manage internal operations, tickets, and Service delivery |
| Account registration and authorization providers | Companies which help with your account registration or authorization | Identifiers and authentication data | Create, authenticate, and maintain user accounts |
| Website security providers | Cloudflare, Inc. (Cloudflare Turnstile) (see Section 2.2) | Technical signals such as IP address, TLS fingerprint, and User-Agent | Detect bots and protect the Website |
The providers listed above process personal data based on our instructions only, except where a provider acts as an independent controller as expressly described in this Notice (for example, Cloudflare’s independent processing described in Section 2.2, payment providers that collect financial data directly, and social media platforms described in Section 1.7).
We apply appropriate safeguards required by the GDPR such as signing data processing agreements for the protection of personal data with contractors and partners, including the Standard Contractual Clauses (SCC) adopted by the European Commission and compliant with the EU data protection laws when transferring your personal data outside of EEA. Please contact us if you would like to receive a copy of the SCCs.
Where we receive personal data from the European Union, the United Kingdom, or Switzerland in reliance on the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), we also apply the DPF Principles, including the Accountability for Onward Transfer Principle, as described in Sections 2.4 and 4.
2.1. Analytics
When using the analytics services, we collect details of the use of the Website, including, but not limited to traffic data and location data. Non-personally identifiable information is collected and processed by Google Analytics in an anonymised and aggregated way to improve our Website usability and for marketing purposes. Google Analytics is a web analytics service that tracks and reports user traffic on apps and websites. Google Analytics uses the data collected to track and monitor the use of the Website. This data may also be shared with other Google services. For more information on the privacy practices of Google, you can check its Policies at www.google.com/analytics/policies/.
We will store this type of information while it is relevant for our analysis and research or as long as your account is active whichever comes faster. We will delete analytics data within 24 months of your last Website visit.
2.2. Website security — Cloudflare Turnstile
To protect our Website against malicious automated traffic (bots), we use Cloudflare Turnstile, a pro-privacy bot-detection service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile operates invisibly in the background — it does not display a visual challenge (such as a CAPTCHA) to you and does not require any action on your part.
What data Turnstile processes. When you visit our Website, Turnstile collects and processes certain technical signals ("Signals"), including your IP address, TLS fingerprint, User-Agent header, and the site key associated with our Website. Cloudflare does not use these Signals to directly identify you as an individual; they are used solely to distinguish human visitors from automated bots.
Cloudflare's dual role.
Further information. This processing is governed, in addition to this Privacy Notice, by Cloudflare's Turnstile Privacy Addendum, which supplements Cloudflare's main Privacy Policy. For information on any cookies set by Cloudflare in connection with Turnstile, please refer to our Cookie Notice and Cloudflare's Cookie Policy.
2.3. Other disclosures
In addition to the disclosures for the purposes identified before, we may disclose information about you:
Except as provided in this Privacy Notice, we will not sell, share or rent your information to third parties.
2.4. Accountability for onward transfers
Stape, Inc. remains responsible for personal data that it receives under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF and subsequently transfers to a third party acting as an agent on its behalf.
In particular, Stape, Inc. remains liable under the DPF Principles if its third-party agent processes such personal data in a manner inconsistent with the DPF Principles, unless Stape, Inc. proves that it is not responsible for the event giving rise to the damage.
Before we transfer personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, or the Swiss-U.S. DPF to a third party acting as an agent, we will:
EU, UK, and Swiss individuals, and other individuals where applicable law so provides, have the rights described below. These rights apply to personal data we process, including personal data received from the European Union, the United Kingdom, and Switzerland in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
You can formulate such requests or channel further questions on data protection by contacting us at privacy@stape.io. We will respond to access and other rights requests within a reasonable time.
3.1. Access to personal data
You have the right to access the personal data we hold about you. You may obtain confirmation of whether we process your personal data, disclosure of the data involved in the processing, and a copy of the information undergoing processing.
Upon request, we will provide you with access to the personal data that we hold about you, except where the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question, or where the rights of persons other than you would be violated. We may also limit or deny access where permitted or required by law.
To request access, contact us at privacy@stape.io. Further information about the DPF Access Principle is available at https://www.dataprivacyframework.gov/framework-article/6–ACCESS and https://www.dataprivacyframework.gov/framework-article/8–Access.
3.2. Choice and means to limit use and disclosure
We offer the following choices and means for limiting the use and disclosure of your personal data:
Further information about the DPF Choice Principle is available at https://www.dataprivacyframework.gov/framework-article/2–CHOICE and https://www.dataprivacyframework.gov/framework-article/12–Choice--Timing-of-Opt-Out.
3.3. Other GDPR rights
You may also exercise the following rights regarding your personal data, where applicable:
If you believe that our use of personal information violates your rights, or if you are dissatisfied with a response you received to a request you formulated to us, you have the right to lodge a complaint with the competent data protection authority of your choice. Additional DPF-specific recourse options for EU, UK, and Swiss individuals are described in Section 4.
This Section describes Stape, Inc.’s commitments under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). These commitments apply to personal data received from the European Union, the United Kingdom, and Switzerland in reliance on the applicable framework. The rights described in this Section are available to EU, UK, and Swiss individuals.
4.1. Affirmative DPF commitment
Stape, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Stape, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Stape, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Stape, Inc. is committed to applying the DPF Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability to personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
4.2. How to contact us with DPF inquiries or complaints
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Stape, Inc. commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Stape, Inc. at:
Stape, Inc.
Attn: Privacy / Data Protection
901 N Market St., Suite 100, Wilmington, DE, 19801, USA
United States
Email: privacy@stape.io
Please include “DPF Inquiry” or “DPF Complaint” in the subject line and describe your request or concern in reasonable detail so that we can investigate and respond.
4.3. Independent dispute resolution and European data protection authorities
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, EU, UK, and Swiss individuals may also bring a complaint free of charge to the relevant European data protection authority.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Stape, Inc. commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), the UK Information Commissioner’s Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
This independent recourse mechanism is available to affected individuals free of charge.
4.4. Binding arbitration
Under certain conditions, more fully described in Annex I of the DPF Principles, EU, UK, and Swiss individuals may invoke binding arbitration as a last-resort residual rights mechanism for some residual claims concerning compliance with the DPF Principles that have not been resolved by other available independent recourse mechanisms.
Stape, Inc. is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to Stape, Inc. and following the procedures and subject to conditions set forth in Annex I of the Principles.
Further information is available on the Data Privacy Framework website at https://www.dataprivacyframework.gov/.
4.5. Oversight by the U.S. Federal Trade Commission
Stape, Inc. is subject to the investigatory and enforcement powers of the United States Federal Trade Commission (FTC) with regard to Stape, Inc.’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
4.6. Disclosures to public authorities
Stape, Inc. may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Further information about access requests by public authorities under the DPF is available at https://www.dataprivacyframework.gov/framework-article/16–Access-Requests-by-Public-Authorities.
We will take all necessary measures to protect your information from unauthorised or accidental access, destruction, modification, blocking, copying, distribution, as well as from other illegal actions of third parties. As we use the services of third-party software providers across several countries outside of the European Union, we may transfer the collected data to those countries for further processing. In such cases, we will make sure that relevant safeguards are in place. More information on international safeguards can be provided upon request.
Immediate access to the data is only allowed to our authorised employees involved in maintaining the application. Such employees keep strict confidentiality and prevent unauthorised third-party access to personal information.
We may update this Privacy Notice from time to time by posting a new version on our Website. We advise you to check this page occasionally to ensure you are happy with any changes. However, we will endeavour to provide you with an announcement about any significant changes.