Privacy policy
Last updated: 22 September 2026
Protecting your data matters to us. This policy explains which personal data we process when operating redeemoid, why, on which legal basis and for how long – under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Controller
redeemoid is a service provided by:
Daniel Kurdoghlian – Pushing PixelsMalmögasse 16
1100 Wien
Österreich
E-Mail: office@redeemoid.com
Web: pushingpixels.at
For questions about data protection or to exercise your rights, please write to the email address above.
2. Overview
- We use no advertising cookies, no profiling and no social media plugins. How often the pages are opened is counted by our own cookieless statistics on our own server (see section 3).
- We only process data as far as necessary to run the platform, fulfil contracts, meet legal obligations or keep the service secure.
- We do not sell data.
3. Visiting the website and the widget
When you open redeemoid – including through the redeem widget embedded on other websites – our server processes technically necessary data: IP address, date and time, requested address, referrer, browser and operating system. This is needed to deliver pages, keep the service stable and fend off attacks. Server logs are kept with limited size on a rotating basis and overwritten automatically.
To prevent guessing of codes and abuse of login and sign-up, we briefly store the IP address (for IPv6 the /64 network) together with a counter in a cache. Expired entries are deleted automatically, at the latest after one day.
Legal basis: legitimate interest in a secure and working service (Art 6(1)(f) GDPR).
If the widget is embedded on another website, that website's operator is responsible for their own site; the widget itself is loaded from our server and does not set cookies.
Card designer
In the free card designer you can upload an image and paste your own codes. Your browser only sends them when you download a PDF; our server uses them solely to build that PDF and discards them right afterwards. Image and codes are neither stored nor logged and are not passed to third parties. The preview is created in your browser only. To prevent abuse, we count the PDFs created per IP address as described above. Legal basis: carrying out your request (Art 6(1)(b) GDPR).
Reach measurement
We count page views with Umami. The software runs on our own server, in the same data centre as the website. There is no service provider involved, nothing is passed to third parties, and nothing leaves the EU.
We set no cookies for this. Nothing is stored on your device, and we do not reach into anything kept there. Your browser sends a few details along with every request, among them language and screen size, and those are counted. Because nothing is stored on or retrieved from your device, no consent is required (§ 165(3) Austrian Telecommunications Act 2021).
For every page view we store: the address opened, the page title, the referrer, country, browser, operating system, device type, screen size, language and time. Redeem codes, keys from links (for confirming, unsubscribing or downloading, for example) and identifiers of packages and orders are removed from the address before it is counted.
Besides page views we count certain actions: that a price was calculated, one of the sign-up buttons clicked (and which one), an account created, a package created, a file uploaded, an order started or paid, codes generated, an export downloaded, a card scanned, a code entered, redeemed or rejected, a download started, a launch notification requested, or a PDF created in the card designer. Only the fact that it happened is counted, with at most a rough class (the order of magnitude of a code count, for example) – never a code, a name, an amount or any content.
Some of these actions are reported to the counter by our server rather than by your browser. So that they belong to the same visit, the server passes your IP address and browser identification on to the counter – to our own software on our own server, not to third parties. Until the action has been counted, usually a few seconds, both wait in a queue on our server; after that they are deleted there, within one hour at the latest.
We do not store your IP address. It is used at the moment of the request for two things: the country is derived from it, and an identifier is calculated that holds the page views of one visit together. That identifier is built with a secret that changes every month; your IP address cannot be derived back from it, and in the next month the same visit is no longer recognisable. We build no profiles and do not follow you across other websites.
Legal basis is our legitimate interest in knowing which pages are read and where visitors come from (Art 6(1)(f) GDPR). You can object at any time (Art 21 GDPR); a message to office@redeemoid.com is enough. A content blocker stops the counting as well.
4. Cookies
We only set technically necessary cookies:
sessionid– keeps you signed in (up to 2 weeks).csrftoken– protects forms against forgery (1 year).django_language– remembers the selected language (browser session).
Legal basis: § 165(3) Austrian Telecommunications Act 2021 and Art 6(1)(b) and (f) GDPR. No consent is required for these cookies.
5. User account (creators)
For sign-up and use we process: email address, password (only as a secure hash), optionally name and company, language, currency, email preferences, a personal referral code and, where applicable, whose referral link you signed up with. We send you a link to confirm your email address.
Legal basis: performance of the contract (Art 6(1)(b) GDPR). The data is kept until your account is deleted, unless statutory retention obligations apply (see section 11).
To protect against automated sign-ups and abusive password resets, these two forms use Cloudflare Turnstile (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). When the form loads, Cloudflare processes technical data such as IP address, browser and device information to tell humans from bots; according to Cloudflare this data is not used for advertising. We only receive the result of the check and send your IP address to Cloudflare for it. The legal basis is our legitimate interest in the security of the platform and in preventing abuse (Art 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework (Art 45 GDPR).
6. Packages, files and download codes
For your packages we store settings, description, the uploaded file, the generated codes, exports and card designs. Files, exports and card images are kept with our storage provider (see section 10). Exports are deleted automatically after 14 days.
Legal basis: performance of the contract (Art 6(1)(b) GDPR).
7. Redeeming codes (fans)
No account is needed to redeem a code. We process the code you enter, the time of its first redemption and, for each download, an entry with the time, browser identification (user agent), whether the widget was used, and a shortened IP address (last 8 bits zeroed for IPv4, last 80 bits for IPv6) that cannot be traced back to an individual. These entries enforce download limits, help detect abuse and feed the creators' statistics, who only see aggregated numbers.
Legal basis: performance of the contract with you or the creator and legitimate interest in preventing abuse (Art 6(1)(b) and (f) GDPR). The entries are deleted together with the package.
8. Payments
Payments are processed by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). You enter your payment details directly with Stripe; we do not receive them. We send Stripe your email address, the amount and an order number and receive the payment status and references. Stripe also issues the invoice. Stripe may transfer data to the USA based on the EU-US Data Privacy Framework or standard contractual clauses. Details: stripe.com/privacy.
For each order we store amount, currency, price breakdown, coupon, payment references and the time you accepted the terms. Legal basis: performance of the contract and legal obligations (Art 6(1)(b) and (c) GDPR).
9. Emails
We send you contract-related emails (email confirmation, password reset, order and delivery confirmations) and – depending on your settings – low-code alerts and regular status reports. You only receive our newsletter if you enabled it in your settings. Every optional email contains an unsubscribe link, and you can change your settings at any time.
Legal basis: performance of the contract (Art 6(1)(b) GDPR), our legitimate interest for status reports and alerts (point (f)), and your consent for the newsletter (point (a)), which you can withdraw at any time.
Launch notification
Before redeemoid opened, visitors could leave an email address on the home page to hear about the launch. Since the launch this function is switched off. The addresses stored for it are no longer needed and are therefore deleted: automatically by the next daily clean-up, within one day of the launch at the latest. Clicking an old confirmation link now only deletes the address it belongs to.
10. Recipients and processors
We use the following service providers, who process data on our behalf and on our instructions (Art 28 GDPR):
- Server and database hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland
- Storage of files, exports and card images: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland (Object Storage, Rechenzentren in Deutschland)
- Email delivery: Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, Frankreich
- Protecting sign-up and password reset against bots: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (see section 5)
Stripe acts as an independent controller for payment processing (see section 8). Beyond that we only disclose data where legally required.
The reach measurement (section 3) is absent from this list on purpose: it runs on our own server, with no further recipient involved.
11. Retention
- Account data: until the account is deleted.
- Order and invoice data: 7 years under § 132 Austrian Federal Fiscal Code (BAO).
- Exports: 14 days.
- Database backups: overwritten on a rotating basis (by default after 14 days).
- Abuse-protection cache: deleted after expiry, at the latest after one day.
- Reach measurement: the figures are kept without a fixed deadline. They describe page views, not people, and contain neither your IP address nor an identifier that stays recognisable beyond one month.
12. Your rights
You have the right of access (Art 15 GDPR), rectification (Art 16), erasure (Art 17), restriction of processing (Art 18), data portability (Art 20) and to object to processing based on legitimate interests (Art 21). You can withdraw consent at any time with effect for the future. Please contact us at the email address above.
If you believe that the processing of your data violates data protection law, you can lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
13. Security
All connections are encrypted (HTTPS). Passwords are only stored as hashes, download links are signed and valid for a few minutes only, and access to packages is restricted to their owners.
14. Changes
We update this policy when the platform or the legal situation changes. The version published here applies.
This is a convenience translation. In case of discrepancies, the German version prevails.