Privacy Notice

STAPE, INC

Last update: 21st of September 2026

This document describes how we collect and process users’ data through https://stape.io/, https://community.stape.io/, https://comments.stape.io, and https://help.stape.io/ webpages, hereinafter simply referred to as the “Website”. The terms “we”, “us”, “our” refer to Stape, Inc., a legal person registered under the laws of the State of Delaware, USA. 

WE ARE COMMITTED TO SAFEGUARDING PRIVACY AND NOT GOING TO MISUSE OUR USERS’ DATA.

The below information will help you better understand how your data is handled and how you can manage all the matters related to your privacy.

Controller details:

Name: Stape, Inc.

Registration number: 5987286

Registered address: 901 N Market St., Suite 100, Wilmington, DE, 19801, USA

Contact email address: privacy@stape.io

1. Information we collect

1.1. Account and profile set up

If you want to use the Website functionality, you will have to register an account on a particular webpage. For this purpose, we will ask only for your email address, since this is enough to set up an account. Further information such as first and last name, photo, company name and other information, in particular geolocation, you provide on a voluntary basis so as to be able to act as a full-fledged Website user.

We use your account information to:

  • create and maintain your user account. The applied legal basis for this is the performance of the contract (Terms of Use) between you and us (GDPR Art. 6.1.b);
  • provide you with the hosting, backend infrastructure and data collection management systems (hereinafter “Service”) via the Website (GDPR Art. 6.1.b);
  • provide you with access to our community network along with the possibility to leave comments (GDPR Art. 6.1.b);
  • provide customer support and any pre-contractual communication for the purpose of providing the Service (GDPR Art. 6.1.b);
  • alerting of new updates regarding software implemented or general updates regarding the Website functionality (GDPR Art. 6.1.b), and analyse the efficiency of the Website in our legitimate interests (GDPR Art. 6.1.f);
  •  upon receiving the consent from you, to send you other relevant aspects of the Service and the Website, e.g. personal marketing or promotional materials such as newsletters, etc. (GDPR Art. 6.1.a).

We will store your account data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.

1.2. Website functionality

Via the Website, you will be able to perform different actions to organize and manage Server-side tagging in a dedicated server-side environment or communicate with the other users on Service-related topics. We will store and process the following categories of information:

  • internal communications made via the Website;
  • derived information created while using the Website (e.g., user logs, support requests, using stats, comments, responding to surveys, etc);

The applied legal basis for this is the performance of the contract (Terms of Use) between you and us (GDPR Art. 6.1.b). We will store this data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.

1.3. Payments

We do not collect your financial information. For the purpose of ordering the upgraded version of Service you will be automatically redirected to Stripe, 2Checkout or to another duly authorized contractor. They will collect and store your financial data directly and according to their respective policies. 

We shall retain only payment confirmation provided by the relevant payment service provider in order to comply with applicable accounting and financial laws (GDPR Art. 6.1.c and in our legitimate interests to comply with foreign laws as per Art. 6.1.f). We will store this data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.

1.4. Communications

You may leave a request with your inquiries including request for support: (1) via https://help.stape.io/; (2) in our live chat; (3) or by email. The provided information used to help you with your request, fix and improve the Website, and analyse our efficiency, including by creating statistics of inquiries related to support issues. 

The applied legal basis for this is the performance of the contract (Terms of Use) between you and us (GDPR Art. 6.1.b) and our legitimate interest to improve the Website (GDPR Art. 6.1.f). We will store this data for as long as you have the account with us. If you become inactive, we will delete or anonymize your information within 12 months after your last user session.

1.5. Demo access

You can receive free access to our Service to know how the Website works. In order to perform this, you have to submit your email and setup password upon first visit.

We will use this information to provide you with the free plan of Service. The applied legal basis for these activities is our legitimate interest (GDPR Art. 6.1.f). We will store your email for as long as the demo account is active. If it becomes inactive, we will delete or anonymize your email within 12 months after your last user session. 

1.6. Website, sales, and marketing activities

The following data collection activities are present on the Website:

  • collection of log files (IP address, device ID, etc.) to ensure correct Website functionality and manage user sessions, stored maximum for 12 months from your last visit. The applied legal basis is our legitimate interests (GDPR Art. 6.1.f);
  • cookies – for more information please visit our Cookie Notice;
  • web analytics (web pages interactions, source through which you accessed the Website, other user actions). This activity, depending on the method used, is performed based either on your consent (cookie tracking) or our legitimate interests (GDPR Art. 6.1.f).

We store marketing data for 12 months of the last communication with you. For the activities that are based on consent, you can withdraw your consent at any time by contacting us directly. The withdrawal will not affect the lawfulness of processing based on consent before. You can also opt-out of the e-mail subscription by clicking the appropriate button our emails to you.

1.7. Social media features

Our Website may use social media features, such as the “Tweet” button, “Share on Facebook” button or other sharing instruments (“SMF”). SMF can let you post information about your activities on the Website to third-parties platforms and social networks. SMF may also allow you to like or highlight information we have posted on our Website. SMF are either hosted by each respective platform or hosted directly on our Website. To the extent the SMF are hosted by the platforms themselves, and you click through to these from our Website, the platform may receive information showing that you have visited our Website. If you are logged in to your social media account, it is possible that the respective social media network can link your visit to our Website with your social media profile.

We also allow you to log in to certain pages of our Website using sign-in services. These services authenticate your identity and provide you the option to share certain personal data from these services. Your possible information exchanges with SMF are covered by the privacy policies of the companies providing them.

2. Third-party access to information

We disclose personal information to third parties only as described in this Privacy Notice and only for the purposes stated below. We use the following types of third-party providers:

Type of third partyIdentity / examplesPersonal information disclosedPurpose of disclosure
Cloud and infrastructure providersCompanies which provide cloud server computing servicesAccount, usage, communications, and technical dataHost, store, and operate the Website and Service
Communications, email, and CRM providersCompanies which provide communication, e-mail server, and client relationship management servicesContact details and message contentSend transactional and support communications and manage customer relationships. Message exchanges may include personal data.
Analytics, advertising, and marketing providersCompanies which help to monitor the behaviour of the Website’s visitors or provide advertising or marketing services, including Google Analytics (see Section 2.1)Usage, device, and marketing dataMeasure Website performance, improve usability, and (where permitted) conduct marketing
Payment and financial service providersStripe, 2Checkout, and other duly authorized payment contractors; companies which provide financial services and process accounting documentsPayment confirmation and related billing data (financial card data is collected by the payment provider, not by us)Process payments and comply with accounting and financial laws
Survey providersCompanies which provide survey servicesContact details and survey responsesCollect feedback and improve the Service
Work management providersCompanies which help with work management with further personal data processingSupport, account, and operational dataManage internal operations, tickets, and Service delivery
Account registration and authorization providersCompanies which help with your account registration or authorizationIdentifiers and authentication dataCreate, authenticate, and maintain user accounts
Website security providersCloudflare, Inc. (Cloudflare Turnstile) (see Section 2.2)Technical signals such as IP address, TLS fingerprint, and User-AgentDetect bots and protect the Website

The providers listed above process personal data based on our instructions only, except where a provider acts as an independent controller as expressly described in this Notice (for example, Cloudflare’s independent processing described in Section 2.2, payment providers that collect financial data directly, and social media platforms described in Section 1.7).

We apply appropriate safeguards required by the GDPR such as signing data processing agreements for the protection of personal data with contractors and partners, including the Standard Contractual Clauses (SCC) adopted by the European Commission and compliant with the EU data protection laws when transferring your personal data outside of EEA. Please contact us if you would like to receive a copy of the SCCs.

Where we receive personal data from the European Union, the United Kingdom, or Switzerland in reliance on the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), we also apply the DPF Principles, including the Accountability for Onward Transfer Principle, as described in Sections 2.4 and 4.

2.1. Analytics

When using the analytics services, we collect details of the use of the Website, including, but not limited to traffic data and location data. Non-personally identifiable information is collected and processed by Google Analytics in an anonymised and aggregated way to improve our Website usability and for marketing purposes. Google Analytics is a web analytics service that tracks and reports user traffic on apps and websites. Google Analytics uses the data collected to track and monitor the use of the Website. This data may also be shared with other Google services.  For more information on the privacy practices of Google, you can check its Policies at www.google.com/analytics/policies/.

We will store this type of information while it is relevant for our analysis and research or as long  as your account is active whichever comes faster. We will delete analytics data within 24 months of your last Website visit.

2.2. Website security — Cloudflare Turnstile

To protect our Website against malicious automated traffic (bots), we use Cloudflare Turnstile, a pro-privacy bot-detection service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile operates invisibly in the background — it does not display a visual challenge (such as a CAPTCHA) to you and does not require any action on your part.

What data Turnstile processes. When you visit our Website, Turnstile collects and processes certain technical signals ("Signals"), including your IP address, TLS fingerprint, User-Agent header, and the site key associated with our Website. Cloudflare does not use these Signals to directly identify you as an individual; they are used solely to distinguish human visitors from automated bots.

Cloudflare's dual role.

  • As our data processor: Cloudflare processes your Signals on our behalf and under our instructions for the purpose of securing our Website. As the data controller for this processing, we rely on our legitimate interests in maintaining a safe and secure Website (GDPR Art. 6.1.f). If you have questions or wish to exercise data protection rights relating to this processing, please contact us at privacy@stape.io.
  • As an independent data controller: Cloudflare also processes Signals as an independent controller for the purpose of improving Turnstile's bot-detection capabilities. For this purpose, Cloudflare relies on its own legitimate interests. If you have questions or wish to exercise data protection rights relating to Cloudflare's independent processing, please contact Cloudflare's Data Protection Officer at dpo@cloudflare.com.

Further information. This processing is governed, in addition to this Privacy Notice, by Cloudflare's Turnstile Privacy Addendum, which supplements Cloudflare's main Privacy Policy. For information on any cookies set by Cloudflare in connection with Turnstile, please refer to our Cookie Notice and Cloudflare's Cookie Policy.

2.3. Other disclosures

In addition to the disclosures for the purposes identified before, we may disclose information about you:

  • if we are required to do so by law, in connection with any legal proceedings or to establish, exercise or defend our legal rights; and
  • in case we sell, license or otherwise assign our company, corporate rights, the Website or its separate parts or features to third parties.

Except as provided in this Privacy Notice, we will not sell, share or rent your information to third parties.

2.4. Accountability for onward transfers

Stape, Inc. remains responsible for personal data that it receives under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF and subsequently transfers to a third party acting as an agent on its behalf.

In particular, Stape, Inc. remains liable under the DPF Principles if its third-party agent processes such personal data in a manner inconsistent with the DPF Principles, unless Stape, Inc. proves that it is not responsible for the event giving rise to the damage.

Before we transfer personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, or the Swiss-U.S. DPF to a third party acting as an agent, we will:

  • transfer such data only for limited and specified purposes;
  • ascertain that the agent is obligated to provide at least the same level of privacy protection as is required by the DPF Principles;
  • take reasonable and appropriate steps to ensure that the agent effectively processes the personal information transferred in a manner consistent with our obligations under the DPF Principles;
  • require the agent to notify us if it determines that it can no longer meet its obligation to provide the same level of protection as is required by the DPF Principles;
  • take reasonable and appropriate steps to stop and remediate unauthorized processing upon notice; and
  • provide a summary or representative copy of the relevant privacy provisions of our contract with that agent to the U.S. Department of Commerce upon request.

3. Your rights

EU, UK, and Swiss individuals, and other individuals where applicable law so provides, have the rights described below. These rights apply to personal data we process, including personal data received from the European Union, the United Kingdom, and Switzerland in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

You can formulate such requests or channel further questions on data protection by contacting us at privacy@stape.io. We will respond to access and other rights requests within a reasonable time.

3.1. Access to personal data

You have the right to access the personal data we hold about you. You may obtain confirmation of whether we process your personal data, disclosure of the data involved in the processing, and a copy of the information undergoing processing.

Upon request, we will provide you with access to the personal data that we hold about you, except where the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question, or where the rights of persons other than you would be violated. We may also limit or deny access where permitted or required by law.

To request access, contact us at privacy@stape.io. Further information about the DPF Access Principle is available at https://www.dataprivacyframework.gov/framework-article/6–ACCESS and https://www.dataprivacyframework.gov/framework-article/8–Access.

3.2. Choice and means to limit use and disclosure

We offer the following choices and means for limiting the use and disclosure of your personal data:

  • Marketing communications. You may opt out of receiving marketing emails at any time by clicking the unsubscribe link in those emails or by contacting us at privacy@stape.io. Transactional or Service-related communications may still be sent as needed to provide the Service.
  • Consent-based processing. Where we process personal data based on your consent (including certain cookies and marketing activities), you may withdraw that consent at any time by contacting us or, for cookies, through the Cookie Notice / cookie settings. Withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.
  • Objection to legitimate-interest processing. If we process your information for our legitimate interests (for example, certain marketing or research), you may object. If there are no compelling interests for us to refuse your request, we will stop the processing for such purposes.
  • Disclosure to a third party or materially different purpose. You have the right to opt out of having your personal information disclosed to a third party (other than our agents performing tasks on our behalf and pursuant to our instructions) or used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by you. To exercise this choice, contact us at privacy@stape.io.
  • Sensitive personal data. We will obtain your affirmative express consent (opt-in) before we disclose sensitive personal information to a third party or use it for a purpose other than those for which it was originally collected or subsequently authorized by you.
  • Account closure and deletion. You may request deletion of your account and related personal data as described below, subject to legal retention obligations.

3.3. Other GDPR rights

You may also exercise the following rights regarding your personal data, where applicable:

  • The right to object against the processing of your information. If we process your information for our legitimate interests (e.g., for direct marketing emails or for our marketing research purposes), you can object to it. Let us know what you object against and we will consider your request. If there are no compelling interests for us to refuse to perform your request, we will stop the processing for such purposes. If we believe our compelling interests outweigh your right to privacy, we will clarify this to you. You can also unsubscribe from all our emails in the body thereof.
  • The right to verify your information and seek its rectification. If you find that we process inaccurate or out-of-date information, you can verify the accuracy of your information and/or ask for it to be updated or corrected.
  • Restrict the processing of your information. When you contest the accuracy of your information, believe we process it unlawfully or want to object against the processing, you have the right to temporarily stop the processing of your information to check if the processing was consistent. In this case, we will stop processing your data (other than storing it) until we are able to provide you with evidence of its lawful processing.
  • The right to have your personal data deleted. If we are not under the obligation to keep the data for legal compliance and your data is not needed in the scope of an active contract or claim, we will remove your information upon your request.
  • The right to have your personal data transferred to another organisation. Where we process your personal data on the legal basis of consent you provided us or on the necessity to perform a contract, we can make, at your request, your data available to you or to an organisation of your choosing.

If you believe that our use of personal information violates your rights, or if you are dissatisfied with a response you received to a request you formulated to us, you have the right to lodge a complaint with the competent data protection authority of your choice. Additional DPF-specific recourse options for EU, UK, and Swiss individuals are described in Section 4.

4. Data Privacy Framework

This Section describes Stape, Inc.’s commitments under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). These commitments apply to personal data received from the European Union, the United Kingdom, and Switzerland in reliance on the applicable framework. The rights described in this Section are available to EU, UK, and Swiss individuals.

4.1. Affirmative DPF commitment

Stape, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Stape, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Stape, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

Stape, Inc. is committed to applying the DPF Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability to personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

4.2. How to contact us with DPF inquiries or complaints

In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Stape, Inc. commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Stape, Inc. at:

Stape, Inc.

Attn: Privacy / Data Protection

901 N Market St., Suite 100, Wilmington, DE, 19801, USA

United States

Please include “DPF Inquiry” or “DPF Complaint” in the subject line and describe your request or concern in reasonable detail so that we can investigate and respond.

4.3. Independent dispute resolution and European data protection authorities

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, EU, UK, and Swiss individuals may also bring a complaint free of charge to the relevant European data protection authority.

In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Stape, Inc. commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), the UK Information Commissioner’s Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

This independent recourse mechanism is available to affected individuals free of charge.

4.4. Binding arbitration

Under certain conditions, more fully described in Annex I of the DPF Principles, EU, UK, and Swiss individuals may invoke binding arbitration as a last-resort residual rights mechanism for some residual claims concerning compliance with the DPF Principles that have not been resolved by other available independent recourse mechanisms.

Stape, Inc. is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to Stape, Inc. and following the procedures and subject to conditions set forth in Annex I of the Principles.

Further information is available on the Data Privacy Framework website at https://www.dataprivacyframework.gov/.

4.5. Oversight by the U.S. Federal Trade Commission

Stape, Inc. is subject to the investigatory and enforcement powers of the United States Federal Trade Commission (FTC) with regard to Stape, Inc.’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

4.6. Disclosures to public authorities

Stape, Inc. may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Further information about access requests by public authorities under the DPF is available at https://www.dataprivacyframework.gov/framework-article/16–Access-Requests-by-Public-Authorities.

5. Security of information

We will take all necessary measures to protect your information from unauthorised or accidental access, destruction, modification, blocking, copying, distribution, as well as from other illegal actions of third parties. As we use the services of third-party software providers across several countries outside of the European Union, we may transfer the collected data to those countries for further processing. In such cases, we will make sure that relevant safeguards are in place. More information on international safeguards can be provided upon request.

Immediate access to the data is only allowed to our authorised employees involved in maintaining the application. Such employees keep strict confidentiality and prevent unauthorised third-party access to personal information.

6. Changes to this notice

We may update this Privacy Notice from time to time by posting a new version on our Website. We advise you to check this page occasionally to ensure you are happy with any changes. However, we will endeavour to provide you with an announcement about any significant changes.

Try Stape for all things server-side