Privacy Policy
Pedrablanca Digital Group LLC · Last updated: April 28, 2026
Data requests: privacy@restackd.com
1. Information We Collect
1.1 Account Information
- ·Email address and display name (from sign-up or Google OAuth)
- ·Profile photo (if provided via Google)
- ·Account creation date and login history
1.2 Content You Create
- ·Onboarding answers and voice profile (niche, tone, style preferences)
- ·AI-generated posts and content kits
- ·Landing page content (bio, offer, story, CTA)
- ·Affiliate programs and links you add
- ·Digital products you list in your store
1.3 Usage & Technical Data
- ·Pages visited, features used, clicks, and session duration
- ·IP address, browser type, device type, and operating system
- ·Referring URL and general geographic region (country/state)
- ·Crash reports and error logs
1.4 Transaction Data
- ·Subscription plan, billing cycle, and status
- ·Credit pack purchase history
- ·Affiliate commission tracking and payout records (if you participate in our affiliate program)
- ·Payment receipts and refund history
- ·Note: we never store raw card numbers — all payment data is handled by FanBasis (our Merchant of Record payment processor)
1.5 Public Page Data
When visitors view your public profile page at yourname.restackd.com, we collect aggregate visit counts and click metrics. We do not track individual visitors beyond their session.
1.6 Restackd Affiliate Program Data
If you participate in the Restackd Affiliate Program (where you earn commissions for referring customers to Restackd), we collect and process:
- ·Affiliate ID and unique referral links
- ·Customer attribution data (which customers signed up via your link)
- ·Subscription details for referred customers (for commission calculation)
- ·Commission balance and payout history
- ·Payment information you provide (PayPal email, Wise account, or ACH details)
- ·W-9 form for US affiliates (required for IRS 1099-NEC reporting if commission earnings exceed $600 in a calendar year)
- ·Affiliate Agreement acceptance and signature records
This data is processed solely to track and pay your affiliate commissions and is retained for 7 years for tax reporting purposes.
2. How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Delivering the platform and features | Contract performance |
| Personalizing AI content to your voice profile | Contract performance |
| Processing payments and subscriptions | Contract performance |
| Sending account, billing, and product notifications | Contract performance / Legitimate interest |
| Improving the platform and debugging | Legitimate interest |
| Fraud prevention and security | Legitimate interest / Legal obligation |
| Responding to data requests and legal compliance | Legal obligation |
| Marketing communications (optional, opt-in) | Consent |
We do not sell your personal information to third parties.
3. Third-Party Services
We share data with the following service providers to operate Restackd:
- ·FanBasis (Merchant of Record) — We use FanBasis (fanbasis.com) as our third-party Merchant of Record payment processor to handle credit pack purchases, founder licenses, and Lifetime sales. FanBasis processes all card data, fraud prevention, and global tax compliance on our behalf. See FanBasis's privacy policy at fanbasis.com/privacy for their data practices.
- ·Affiliate payouts — When paying affiliate commissions, we use PayPal, Wise, or direct ACH. We share affiliate names, payment amounts, and payment account details (email or account info you provide) with these providers to complete payouts.
- ·Google — OAuth sign-in only. Google may receive your email for identity verification.
- ·Anthropic — AI content generation. Your voice profile answers and generation prompts are sent to Anthropic's API for AI processing.
- ·Hosting infrastructure — VPS hosting in the EU/US. Your data is processed on servers we control.
We do not use advertising networks or sell data to data brokers.
4. Cookies & Tracking
We use session cookies for authentication (to keep you logged in) and local storage for preferences. We do not use third-party advertising or analytics cookies. You can clear cookies via your browser settings; this will log you out of Restackd.
5. Data Retention
We retain different types of data for different periods based on legal requirements, business necessity, and your privacy rights. Details are below:
5.1 Retention Schedule by Data Category
| Data Category | Retention Period | Reason |
|---|---|---|
| Personal Profile (name, email, avatar) | Duration of account + 1 year after last login | Contract performance; deleted upon account closure |
| Financial Records & Tax Forms | 7 years from transaction | IRS Code §6001 (tax recordkeeping requirement); preserved even upon deletion |
| Payment & Payout Records | 7 years from transaction | Tax reporting, chargeback defense, payment processor requirements |
| Seller Agreements & Signatures | 7 years from acceptance | Legal protection and tax compliance |
| Product Licenses & Sales History | Until expiration + 7 years | Tax records and revenue reconciliation |
| User-Generated Content (posts, pages, products) | Duration of account use | Deleted within 30 days of account closure; 30-day grace for exports |
| AI Chat History & Interaction Logs | 1 year of inactivity | Service improvement; deleted upon account closure |
| Traffic & Analytics (IP addresses) | 90 days (then hashed) | GDPR compliance; IP/user-agent anonymized after 90 days |
| Anonymized Analytics & Metrics | Indefinite | No PII; used for service improvement |
| OAuth & Integration Tokens | Duration of active integration | Security best practice; deleted on revocation or account closure |
| Affiliate & Referral Data | 7 years | IRS 1099-NEC reporting requirement |
| Compliance & Audit Logs | 7 years from event | Legal protection and regulatory compliance |
5.2 Data Deletion Upon Account Closure
When you request account deletion:
- ·Personal data (name, email, avatar) is anonymized within 30 days
- ·Your generated content (posts, pages, products) is retained for 30 days (allows export), then deleted
- ·Transaction records are preserved for 7 years per IRS requirements
- ·Tax form data and seller agreements are preserved for 7 years (legal requirement)
- ·Email address is hashed to prevent account recovery
- ·AI chat history is deleted immediately
- ·OAuth tokens are revoked and deleted immediately
5.3 Automated Data Cleanup
We use automated processes to enforce data retention:
- ·Daily: Anonymize IP addresses in traffic logs (>90 days old), delete personal data from closed accounts (>30 days)
- ·Weekly: Delete AI chat history older than 1 year
- ·Monthly: Archive compliance logs and anonymize audit trails (>90 days)
- ·Quarterly: Review affiliate and referral data (retained for tax purposes)
5.4 Right to Data Access & Deletion
You have the right to request access, correction, or deletion of your personal data. Submit requests to privacy@restackd.com. We will respond within 30 days (45 days for CCPA requests). Note: We cannot delete data required by law (e.g., financial records for tax purposes).
6. Security
We protect your data using industry-standard practices: HTTPS encryption for all data in transit, hashed and salted authentication tokens, restricted database access controls, and regular security reviews. No system is 100% secure. If you believe your account has been compromised, contact security@restackd.com immediately.
7. Your Rights
7.1 All Users
- ·Access — request a copy of your personal data
- ·Correction — update inaccurate information via account settings
- ·Deletion — request deletion of your account and data
- ·Export — download your generated content from your dashboard
- ·Opt-out — unsubscribe from marketing emails via the unsubscribe link
7.2 California Residents (CCPA)
Under the California Consumer Privacy Act (CCPA), California residents have additional rights: the right to know what personal information we collect and how it is used; the right to deletion; the right to opt-out of the sale of personal information; and the right to non-discrimination for exercising these rights.
We do not sell your personal information. We share data only with service providers as described in Section 3, solely to operate the platform. To submit a CCPA request — including requests to know, delete, or confirm opt-out — email privacy@restackd.com with the subject "CCPA Request". We will respond within 45 days as required by law.
7.3 EEA/UK Residents (GDPR)
If you are in the European Economic Area or United Kingdom, you have rights under the GDPR including the right of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and to object to processing based on legitimate interests. You also have the right to lodge a complaint with your local supervisory authority. To exercise your GDPR rights, contact privacy@restackd.com.
We respond to all verified rights requests within 30 days.
8. Children's Privacy
Restackd is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact privacy@restackd.com and we will promptly delete it.
9. International Transfers
Your data may be processed in the United States and other countries where our service providers operate. By using Restackd, you consent to this transfer. Where required, we implement appropriate safeguards such as Standard Contractual Clauses for transfers from the EEA.
10. AI Training Data
What we train on: We do not use your personal data, user content, or store data to train our internal AI models or LLMs. Any AI processing that helps you generate content (like product descriptions or emails) happens via third-party APIs (OpenAI, Anthropic) and is governed by their privacy policies.
What we don't train on: Your customer lists, email addresses, sales data, product files, and affiliate earnings are never included in any training dataset. These remain yours alone.
11. Data Residency
Where your data is stored: All Restackd user data is stored in a PostgreSQL database hosted on Hostinger infrastructure located in Europe. You retain full ownership of your data at all times.
Data backups: We maintain encrypted daily backups in the same region to ensure business continuity and disaster recovery.
12. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email or an in-app notice at least 14 days before taking effect. The "Last updated" date at the top reflects when this policy was last changed.
13. Contact & Data Requests
Pedrablanca Digital Group LLC
Privacy: privacy@restackd.com
Security: security@restackd.com
General: hello@restackd.com
We aim to respond to all privacy inquiries within 5 business days.
© 2026 Pedrablanca Digital Group LLC. All rights reserved.