Privacy policy
Last updated: 17 September 2026
Protecting your data matters to us. This policy explains which personal data we process when operating redeemoid, why, on which legal basis and for how long – under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Controller
redeemoid is a service provided by:
Daniel Kurdoghlian – Pushing PixelsMalmögasse 16
1100 Wien
Österreich
E-Mail: office@redeemoid.com
Web: pushingpixels.at
For questions about data protection or to exercise your rights, please write to the email address above.
2. Overview
- We use no tracking or analytics tools, no advertising cookies and no social media plugins.
- We only process data as far as necessary to run the platform, fulfil contracts, meet legal obligations or keep the service secure.
- We do not sell data.
3. Visiting the website and the widget
When you open redeemoid – including through the redeem widget embedded on other websites – our server processes technically necessary data: IP address, date and time, requested address, referrer, browser and operating system. This is needed to deliver pages, keep the service stable and fend off attacks. Server logs are kept with limited size on a rotating basis and overwritten automatically.
To prevent guessing of codes and abuse of login and sign-up, we briefly store the IP address (for IPv6 the /64 network) together with a counter in a cache. Expired entries are deleted automatically, at the latest after one day.
Legal basis: legitimate interest in a secure and working service (Art 6(1)(f) GDPR).
If the widget is embedded on another website, that website's operator is responsible for their own site; the widget itself is loaded from our server and does not set cookies.
4. Cookies
We only set technically necessary cookies:
sessionid– keeps you signed in (up to 2 weeks).csrftoken– protects forms against forgery (1 year).django_language– remembers the selected language (browser session).
Legal basis: § 165(3) Austrian Telecommunications Act 2021 and Art 6(1)(b) and (f) GDPR. No consent is required for these cookies.
5. User account (creators)
For sign-up and use we process: email address, password (only as a secure hash), optionally name and company, language, currency, email preferences, a personal referral code and, where applicable, whose referral link you signed up with. We send you a link to confirm your email address.
Legal basis: performance of the contract (Art 6(1)(b) GDPR). The data is kept until your account is deleted, unless statutory retention obligations apply (see section 11).
To protect against automated sign-ups and abusive password resets, these two forms use Cloudflare Turnstile (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). When the form loads, Cloudflare processes technical data such as IP address, browser and device information to tell humans from bots; according to Cloudflare this data is not used for advertising. We only receive the result of the check and send your IP address to Cloudflare for it. The legal basis is our legitimate interest in the security of the platform and in preventing abuse (Art 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework (Art 45 GDPR).
6. Packages, files and download codes
For your packages we store settings, description, the uploaded file, the generated codes, exports and card designs. Files, exports and card images are kept with our storage provider (see section 10). Exports are deleted automatically after 14 days.
Legal basis: performance of the contract (Art 6(1)(b) GDPR).
7. Redeeming codes (fans)
No account is needed to redeem a code. We process the code you enter, the time of its first redemption and, for each download, an entry with the time, browser identification (user agent), whether the widget was used, and a shortened IP address (last 8 bits zeroed for IPv4, last 80 bits for IPv6) that cannot be traced back to an individual. These entries enforce download limits, help detect abuse and feed the creators' statistics, who only see aggregated numbers.
Legal basis: performance of the contract with you or the creator and legitimate interest in preventing abuse (Art 6(1)(b) and (f) GDPR). The entries are deleted together with the package.
8. Payments
Payments are processed by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). You enter your payment details directly with Stripe; we do not receive them. We send Stripe your email address, the amount and an order number and receive the payment status and references. Stripe also issues the invoice. Stripe may transfer data to the USA based on the EU-US Data Privacy Framework or standard contractual clauses. Details: stripe.com/privacy.
For each order we store amount, currency, price breakdown, coupon, payment references and the time you accepted the terms. Legal basis: performance of the contract and legal obligations (Art 6(1)(b) and (c) GDPR).
9. Emails
We send you contract-related emails (email confirmation, password reset, order and delivery confirmations) and – depending on your settings – low-code alerts and regular status reports. You only receive our newsletter if you enabled it in your settings. Every optional email contains an unsubscribe link, and you can change your settings at any time.
Legal basis: performance of the contract (Art 6(1)(b) GDPR), our legitimate interest for status reports and alerts (point (f)), and your consent for the newsletter (point (a)), which you can withdraw at any time.
10. Recipients and processors
We use the following service providers, who process data on our behalf and on our instructions (Art 28 GDPR):
- Server and database hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland
- Storage of files, exports and card images: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland (Object Storage, Rechenzentren in Deutschland)
- Email delivery: Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, Frankreich
- Protecting sign-up and password reset against bots: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (see section 5)
Stripe acts as an independent controller for payment processing (see section 8). Beyond that we only disclose data where legally required.
11. Retention
- Account data: until the account is deleted.
- Order and invoice data: 7 years under § 132 Austrian Federal Fiscal Code (BAO).
- Exports: 14 days.
- Database backups: overwritten on a rotating basis (by default after 14 days).
- Abuse-protection cache: deleted after expiry, at the latest after one day.
12. Your rights
You have the right of access (Art 15 GDPR), rectification (Art 16), erasure (Art 17), restriction of processing (Art 18), data portability (Art 20) and to object to processing based on legitimate interests (Art 21). You can withdraw consent at any time with effect for the future. Please contact us at the email address above.
If you believe that the processing of your data violates data protection law, you can lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
13. Security
All connections are encrypted (HTTPS). Passwords are only stored as hashes, download links are signed and valid for a few minutes only, and access to packages is restricted to their owners.
14. Changes
We update this policy when the platform or the legal situation changes. The version published here applies.
This is a convenience translation. In case of discrepancies, the German version prevails.