Legal

Privacy Policy

Last updated:

Privacy Policy

The effective date is when this version takes effect. The last updated date is when we last made substantive changes.

1. Introduction

PeekTag ApS ("PeekTag", "we", "our", or "us") provides a digital platform that allows users to create, publish, share, monetize, and interact with smart tags and interactive experiences ("Tags"). Tags may contain interactive content, forms, media, payments, storefronts, automations, integrations, and AI-powered components.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use our websites, applications, APIs, integrations, creator tools, AI-powered features, and related services (collectively, the "Services").

This Policy applies to business customers, creators, account holders, visitors, end users who interact with Tags, and people who communicate with us. For individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, references to "personal information" should be understood as references to "personal data" under applicable data protection law.

PeekTag ApS is the controller for the personal data described in this Privacy Policy, unless a separate data processing agreement or customer agreement states otherwise.

2. Information We Collect

2.1. Information you provide directly

We collect personal information you voluntarily provide, including:

  • Account and profile information: such as name, email address, username, profile photo, password or authentication credentials, phone number, date of birth where needed, country, language, role, organization, and account settings.

  • Billing and transaction information: such as plan, purchase history, invoices, tax information, payout status, refund history, and limited billing details. Payment card data is processed by Stripe, Apple, Google, or another payment provider and is not stored by PeekTag.

  • User content: such as text, images, videos, files, product information, storefront content, forms, survey responses, templates, prompts, instructions, generated outputs, and other content you upload, submit, embed, publish, or process through Tags or AI features.

  • Communications: such as support requests, messages, feedback, survey answers, event registrations, reviews, and other exchanges with us.

  • Verification and compliance information: such as information needed to verify your identity, age, business status, seller eligibility, tax status, payout account, or compliance with legal, payment, security, or platform requirements.

  • Contact and invitee information: if you use features that invite another person, send a Tag to a contact, or share content with others. Please do not provide another person's contact details unless you have permission to do so.

2.2. Information from connected accounts and third parties

We may receive personal information from third parties, including:

  • Sign-in providers: such as Google, Apple, or Microsoft, when you use them to create or access your account. This may include your name, email address, profile image, account identifier, and authentication status.

  • Connected apps and integrations: such as Google Drive, YouTube, Slack, Shopify, OpenAI, Stripe, Zapier, Canva, LinkedIn, or other tools you choose to connect. We process the data needed to provide the integration you authorize.

  • Payment, fraud prevention, analytics, security, hosting, customer support, and infrastructure providers.

  • Public sources and business databases: limited to information such as company name, role, public business profile, or professional contact details where permitted by law, including for B2B outreach based on legitimate interests.

If you connect a Google service, our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.

2.3. Information collected automatically

When you use the Services, we and our service providers may automatically collect:

  • Log data: such as IP address, browser type and settings, operating system, referring and exit pages, timestamps, session identifiers, error logs, and interactions with our platform.

  • Usage data: such as features used, clicks, searches, pages viewed, Tags opened, templates used, session duration, engagement metrics, generation history, and workflow activity.

  • Device data: such as device type, device name, identifiers, language settings, country, screen size, network information, carrier, connection type, browser version, and approximate location derived from IP address.

  • Location data: such as approximate location for localization, analytics, fraud prevention, and security. We collect precise location only if you grant permission for a feature that needs it.

  • Communication interaction data: such as whether you open emails or click links in service or marketing communications. We may use pixels or similar technologies for this purpose where permitted.

  • Cookies and similar technologies: used to sign you in securely, remember preferences, analyze usage, improve the Services, prevent fraud, and support optional marketing or measurement features. See our Cookie Policy for more information.

3. Biometric, Face, Voice, and Likeness Information

Some PeekTag features, such as virtual try-on, image generation, video generation, avatar features, voice features, or other AI-assisted media tools, may involve photographs, images, video, audio, body measurements, facial geometry, voice characteristics, or other information that can identify or relate to a person.

Where applicable law treats this information as biometric data, biometric identifiers, special category data, or sensitive personal information, we process it only as needed to provide the feature you request, with any required consent or authorization.

Providing this information is voluntary. If you choose not to provide it, you may be unable to use the specific feature that depends on it, but you may still use other parts of the Services.

Unless we clearly tell you otherwise for a specific feature, PeekTag does not store biometric templates, faceprints, or voiceprints after the requested processing is complete. Any transient biometric measurements used to provide a requested feature are deleted or made non-identifying when no longer needed for that feature.

We do not sell, lease, trade, or disclose biometric information for profit. We may disclose it only to limited service providers who help us provide the requested feature, where required by law, or with your consent.

If you upload or process media containing another person, you are responsible for having all required rights, permissions, disclosures, and consents from that person.

4. Sensitive Information

Other than media or information you choose to provide for a feature that specifically requires it, do not submit sensitive personal information through the Services. This includes government identifiers, payment card numbers, account credentials, health information, criminal history, political opinions, religious beliefs, trade union membership, precise geolocation, genetic data, biometric templates, or information about children unless the feature expressly supports it and applicable law permits it.

Do not include personal information about yourself or others in prompts, instructions, or AI inputs unless it is necessary for the feature you are using and you have the right to provide it.

5. How We Use Personal Data

We use personal information for the following purposes and lawful bases:

  • Service delivery and account operations. We use account, profile, content, technical, usage, and connected-account data to provide the Services, create and maintain accounts, publish and display Tags, process forms and submissions, sync integrations, generate outputs, manage workspaces, provide support, and communicate service notices. Legal basis: contract performance and legitimate interests.

  • Payments, subscriptions, billing, and payouts. We use billing, transaction, tax, account, and verification data to process payments, manage subscriptions, issue invoices, administer refunds, verify sellers, process payouts, prevent payment abuse, and comply with tax and accounting rules. Legal basis: contract performance, legal obligation, and legitimate interests.

  • AI processing and generation. If you use AI features, we process prompts, files, images, videos, metadata, settings, and related inputs to generate or edit outputs, run automations, provide recommendations, moderate content, and secure the Services. Legal basis: contract performance, legitimate interests, and consent where required.

  • AI training preferences. We do not use your non-public content to train AI models unless you explicitly opt in or as otherwise described in your settings or a separate agreement. Public content, feedback, aggregated data, de-identified data, and operational data may be used to improve the Services as described in this Policy and your settings.

  • Personalization. We use account, usage, preference, content, device, and cookie data to remember settings, personalize experiences, recommend templates or features, localize the Services, and improve usability. Legal basis: legitimate interests and consent where required for optional cookies or personalization.

  • Analytics and service improvement. We use usage, device, log, feedback, content, and interaction data to understand how the Services are used, troubleshoot issues, measure performance, improve reliability, develop new features, and improve security. Legal basis: legitimate interests and consent where required.

  • Safety, moderation, fraud prevention, and enforcement. We use account, content, usage, device, log, transaction, and security data to detect abuse, enforce our Terms, prevent fraud, protect users, investigate suspicious activity, and secure the Services. Legal basis: legitimate interests, legal obligation, and contract performance.

  • Marketing and communications. We use contact, account, marketing preference, usage, event, and communication interaction data to send product updates, newsletters, offers, event invitations, and other marketing communications where permitted. Legal basis: consent where required and legitimate interests where permitted. You can opt out of marketing at any time.

  • Legal compliance and protection. We use information as necessary to comply with applicable law, court orders, regulatory requests, tax obligations, sanctions screening, recordkeeping duties, and to establish, exercise, or defend legal claims. Legal basis: legal obligation and legitimate interests.

  • Aggregated, de-identified, and anonymized data. We may create aggregated, de-identified, or anonymized data that cannot reasonably identify you. We may use and share such data for analytics, research, reporting, product improvement, benchmarking, and business purposes.

6. How We Share Personal Data

PeekTag does not sell personal data for money. We also do not share personal data for cross-context behavioral advertising unless we clearly disclose that practice and provide any opt-out required by law.

We may disclose personal information to the following categories of recipients:

  • Service providers and sub-processors: such as hosting, cloud infrastructure, storage, authentication, analytics, email delivery, customer support, logging, monitoring, security, fraud prevention, content moderation, AI model, compute, and payment service providers. These providers are required to process personal data under confidentiality and data protection obligations.

  • AI model and infrastructure providers: where needed to provide AI-powered features, generate outputs, moderate content, or run workflows. We limit the data shared to what is needed for the requested feature or operational purpose.

  • Payment processors and app stores: such as Stripe, Apple, Google, or other payment providers. They process payment information under their own terms and privacy policies.

  • Connected apps and integrations: when you choose to connect a third-party service or authorize a workflow. The third party's use of information is governed by its own terms, settings, and privacy policy.

  • Organization, workspace, or business administrators: if you use PeekTag through an organization, team, workspace, school, agency, or enterprise account. Administrators may access, monitor, manage, export, delete, or control account activity, content, billing, roles, and settings for that workspace.

  • Other users and the public: when you publish or share Tags, profiles, templates, storefronts, forms, comments, reviews, media, outputs, or other content publicly or with selected recipients. Your visibility settings and sharing choices determine who can view or interact with that content.

  • Affiliates: if PeekTag operates with affiliated entities that support the Services.

  • Professional advisors: such as lawyers, auditors, accountants, banks, insurers, and consultants, where necessary for the services they provide to us.

  • Business partners: such as event partners, promotion partners, marketplace partners, or integration partners, where you participate in an event, promotion, marketplace feature, or co-branded offering.

  • Authorities, regulators, courts, payment networks, law enforcement, or private parties: where we believe disclosure is necessary or appropriate to comply with law, protect rights and safety, prevent fraud or abuse, enforce our Terms, or respond to legal process.

  • Business transferees: in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transfer of all or part of our business.

7. Your Choices

  • Access or update your information. If you have an account, you may review and update certain account information through your account settings.

  • Marketing communications. You may opt out of marketing emails by using the unsubscribe link in the message or by contacting us. You may still receive service, security, legal, billing, and transactional messages.

  • Cookies and similar technologies. You can manage cookies through our Cookie Policy, Cookie Settings, browser settings, or device settings. If you disable cookies, some Services may not work properly.

  • Opt-out preference signals. Where required by applicable law, we recognize Global Privacy Control ("GPC") signals as requests to opt out of sale, sharing, or targeted advertising for the browser or device sending the signal. We do not currently respond to "Do Not Track" signals because there is no uniform standard for them.

  • Connected accounts. You may disconnect supported integrations through your PeekTag settings or the third-party service's settings. Revoking access may not affect information already processed before revocation.

  • Delete content or close your account. You may delete certain content or request account deletion through available account controls or by contacting us. Deleted content may remain in backups, logs, or legal records for a limited period as described in this Policy.

  • Declining to provide information. You do not have to provide personal information, but if information is required to provide a feature, comply with law, process payment, verify identity, or secure the Services, we may not be able to provide that feature without it.

8. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, account management, security, fraud prevention, legal compliance, tax and accounting, dispute resolution, backup, and legitimate business purposes.

To determine retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes of processing, whether those purposes can be achieved through other means, your choices, and applicable legal requirements.

Typical retention periods include:

  • Active account data: retained while your account remains active.

  • Account deletion restore period: for up to 30 days after account deletion, account content may remain restorable upon request.

  • Logs, analytics, security, and abuse-prevention records: typically retained for up to 90 days, unless a longer period is needed for security, legal, tax, fraud-prevention, or dispute purposes.

  • Temporary AI sessions, previews, and generated assets: typically retained for up to 30 days for delivery, debugging, safety, and security, unless saved by you, published, required for a paid feature, or retained for legal or operational reasons.

  • Backups: retained for a limited backup cycle and then overwritten or deleted according to our backup processes.

  • Legal, tax, accounting, billing, payout, and compliance records: retained for the period required or permitted by applicable law.

  • Biometric templates, faceprints, or voiceprints: unless we clearly state otherwise for a specific feature, not stored after the requested feature is complete.

When we no longer need personal information, we delete it, anonymize it, aggregate it, or securely isolate it from further processing until deletion is possible.

9. International Data Transfers

PeekTag is based in Denmark and primarily operates from the EEA. We may use service providers, infrastructure, model providers, payment providers, support tools, or other recipients located in the EEA, UK, United States, and other countries.

Where personal data is transferred outside the EEA, UK, or Switzerland, we use appropriate safeguards where required, such as adequacy decisions, the EU Standard Contractual Clauses ("SCCs"), the UK International Data Transfer Addendum or International Data Transfer Agreement, the EU-U.S. Data Privacy Framework or UK Extension where applicable, or another transfer mechanism permitted by law.

In limited situations, we may rely on a lawful derogation, such as your explicit consent, performance of a contract, or the establishment, exercise, or defense of legal claims.

10. Data Security and Breach Response

We use commercially reasonable technical and organizational measures designed to protect personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction.

These measures may include encryption in transit and at rest, access controls, multi-factor authentication, least-privilege access, logging and monitoring, backups, security reviews, vendor assessments, and incident response procedures.

No online service can be guaranteed to be completely secure. You are responsible for keeping your password, devices, credentials, and connected accounts secure.

If we become aware of a personal data breach that requires notification, we will work with applicable regulators and notify affected individuals where required by law.

11. Your Privacy Rights

Depending on where you live and the lawful basis for processing, you may have rights to:

  • Access. Access personal data we hold about you.

  • Correction. Correct inaccurate or incomplete personal data.

  • Deletion. Delete personal data where there is no valid reason for us to continue processing it.

  • Restriction. Restrict processing in certain circumstances.

  • Portability. Receive a portable copy of personal data you provided to us.

  • Objection. Object to processing based on legitimate interests.

  • Marketing objection. Object to direct marketing at any time.

  • Withdraw consent. Withdraw consent where processing is based on consent. Withdrawal does not affect processing that occurred before withdrawal.

  • Complaint. Lodge a complaint with a data protection authority.

We may need to verify your identity before responding to a request. We try to respond to valid privacy requests within one month for EEA/UK requests, or within the period required by applicable law. If a request is complex or repeated, we may extend the response period where permitted and will notify you.

We may decline a request where permitted by law, for example if we cannot verify your identity, the request is manifestly unfounded or excessive, or we need to retain information for legal, security, tax, fraud-prevention, or dispute purposes.

To exercise your rights, contact [email protected].

12. Notice to European Users

This section applies to individuals located in the EEA, UK, or Switzerland.

  • Controller. PeekTag ApS is the controller for the personal data covered by this Privacy Policy, unless we process data on behalf of a business customer under a separate data processing agreement.

  • Legal bases. Our legal bases include contract performance, legitimate interests, legal obligation, consent, and, where applicable, vital interests. We identify the relevant purposes and bases in the "How We Use Personal Data" section above.

  • Legitimate interests. Where we rely on legitimate interests, those interests may include operating and improving the Services, protecting the security and integrity of the Services, preventing fraud and abuse, supporting users, developing new features, understanding usage, and communicating about relevant products or services. You may object to processing based on legitimate interests as described in this Policy.

  • Special category data. We do not intentionally collect special category data unless you choose to provide it for a feature that requires it, such as a media or AI feature, or where required by law. Where required, we obtain consent or rely on another lawful condition.

  • Automated decision-making. We do not use personal data for solely automated decisions that produce legal or similarly significant effects unless we disclose that processing separately and provide rights required by law.

  • Complaints. We encourage you to contact us first so we can try to resolve your concern. You may also lodge a complaint with your local supervisory authority. In Denmark, the supervisory authority is Datatilsynet, the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, Denmark, email: [email protected].

13. Notice to U.S. State Residents

This section applies to residents of U.S. states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Texas, and similar laws where applicable.

  • Categories collected. The categories of personal information we collect are described in the "Information We Collect" section. They may include identifiers, account information, commercial information, internet or network activity, approximate location, audio/visual content you provide, inferences, sensitive information where you choose to provide it, and professional or business information.

  • Sources, purposes, and recipients. The sources of personal information, purposes of processing, and categories of recipients are described in the "Information We Collect", "How We Use Personal Data", and "How We Share Personal Data" sections.

  • Sale, sharing, and targeted advertising. PeekTag does not sell personal information for money. If we use cookies or similar technologies in a way that applicable U.S. law treats as "sale", "sharing", or targeted advertising, we will provide an opt-out mechanism, such as Cookie Settings, a "Your Privacy Choices" control, or recognition of GPC where required.

  • Sensitive personal information. We do not use or disclose sensitive personal information for purposes that require a right to limit, unless we provide the required notice and choice.

  • Rights. Subject to applicable law and verification, you may request to know or access personal information, delete it, correct it, obtain a portable copy, opt out of sale/sharing/targeted advertising, limit certain uses of sensitive personal information, and appeal a denied request where the law provides that right. We will not discriminate against you for exercising privacy rights.

  • Authorized agents. Where allowed by law, an authorized agent may submit a request on your behalf. We may require proof of authorization and may ask you to verify your identity directly.

  • California Shine the Light. California residents may request information once per year about certain disclosures of personal information to third parties for their own direct marketing purposes, where applicable.

To exercise U.S. privacy rights, contact [email protected].

14. Children

The Services are not directed to children under 13. We do not knowingly collect personal data from children under 13 without required consent. If we learn that a child under 13 has provided personal data without required consent, we will delete it as required by law.

Where local law requires parental consent for users under a higher age, that consent is required. Educational or supervised versions of PeekTag, if offered, will follow applicable parental-consent, school-authority, and child privacy requirements.

15. Other Sites and Third-Party Services

The Services may contain links to third-party websites, apps, APIs, services, stores, payment pages, integrations, or content. PeekTag is not responsible for the privacy practices, security, content, or policies of those third parties. When you use a third-party service, that third party's terms and privacy policy apply.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will provide notice through the Services, by email, in-app notice, or another appropriate method before the changes take effect where required by law. Other changes are effective when posted.

Where law requires consent for a change, we will request consent. Your continued use of the Services after an updated Policy takes effect means you acknowledge the updated Policy.

17. Contact Information

If you have questions, requests, or complaints about this Privacy Policy or our privacy practices, contact us at:

PeekTag ApS

CVR: 45849651

Copenhagen, Denmark

Email: [email protected]

Legal contact: [email protected]

If you are contacting us about an intellectual property issue, please use [email protected] unless another reporting channel is provided.

Legal

Privacy Policy

Last updated:

Privacy Policy

The effective date is when this version takes effect. The last updated date is when we last made substantive changes.

1. Introduction

PeekTag ApS ("PeekTag", "we", "our", or "us") provides a digital platform that allows users to create, publish, share, monetize, and interact with smart tags and interactive experiences ("Tags"). Tags may contain interactive content, forms, media, payments, storefronts, automations, integrations, and AI-powered components.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use our websites, applications, APIs, integrations, creator tools, AI-powered features, and related services (collectively, the "Services").

This Policy applies to business customers, creators, account holders, visitors, end users who interact with Tags, and people who communicate with us. For individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, references to "personal information" should be understood as references to "personal data" under applicable data protection law.

PeekTag ApS is the controller for the personal data described in this Privacy Policy, unless a separate data processing agreement or customer agreement states otherwise.

2. Information We Collect

2.1. Information you provide directly

We collect personal information you voluntarily provide, including:

  • Account and profile information: such as name, email address, username, profile photo, password or authentication credentials, phone number, date of birth where needed, country, language, role, organization, and account settings.

  • Billing and transaction information: such as plan, purchase history, invoices, tax information, payout status, refund history, and limited billing details. Payment card data is processed by Stripe, Apple, Google, or another payment provider and is not stored by PeekTag.

  • User content: such as text, images, videos, files, product information, storefront content, forms, survey responses, templates, prompts, instructions, generated outputs, and other content you upload, submit, embed, publish, or process through Tags or AI features.

  • Communications: such as support requests, messages, feedback, survey answers, event registrations, reviews, and other exchanges with us.

  • Verification and compliance information: such as information needed to verify your identity, age, business status, seller eligibility, tax status, payout account, or compliance with legal, payment, security, or platform requirements.

  • Contact and invitee information: if you use features that invite another person, send a Tag to a contact, or share content with others. Please do not provide another person's contact details unless you have permission to do so.

2.2. Information from connected accounts and third parties

We may receive personal information from third parties, including:

  • Sign-in providers: such as Google, Apple, or Microsoft, when you use them to create or access your account. This may include your name, email address, profile image, account identifier, and authentication status.

  • Connected apps and integrations: such as Google Drive, YouTube, Slack, Shopify, OpenAI, Stripe, Zapier, Canva, LinkedIn, or other tools you choose to connect. We process the data needed to provide the integration you authorize.

  • Payment, fraud prevention, analytics, security, hosting, customer support, and infrastructure providers.

  • Public sources and business databases: limited to information such as company name, role, public business profile, or professional contact details where permitted by law, including for B2B outreach based on legitimate interests.

If you connect a Google service, our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.

2.3. Information collected automatically

When you use the Services, we and our service providers may automatically collect:

  • Log data: such as IP address, browser type and settings, operating system, referring and exit pages, timestamps, session identifiers, error logs, and interactions with our platform.

  • Usage data: such as features used, clicks, searches, pages viewed, Tags opened, templates used, session duration, engagement metrics, generation history, and workflow activity.

  • Device data: such as device type, device name, identifiers, language settings, country, screen size, network information, carrier, connection type, browser version, and approximate location derived from IP address.

  • Location data: such as approximate location for localization, analytics, fraud prevention, and security. We collect precise location only if you grant permission for a feature that needs it.

  • Communication interaction data: such as whether you open emails or click links in service or marketing communications. We may use pixels or similar technologies for this purpose where permitted.

  • Cookies and similar technologies: used to sign you in securely, remember preferences, analyze usage, improve the Services, prevent fraud, and support optional marketing or measurement features. See our Cookie Policy for more information.

3. Biometric, Face, Voice, and Likeness Information

Some PeekTag features, such as virtual try-on, image generation, video generation, avatar features, voice features, or other AI-assisted media tools, may involve photographs, images, video, audio, body measurements, facial geometry, voice characteristics, or other information that can identify or relate to a person.

Where applicable law treats this information as biometric data, biometric identifiers, special category data, or sensitive personal information, we process it only as needed to provide the feature you request, with any required consent or authorization.

Providing this information is voluntary. If you choose not to provide it, you may be unable to use the specific feature that depends on it, but you may still use other parts of the Services.

Unless we clearly tell you otherwise for a specific feature, PeekTag does not store biometric templates, faceprints, or voiceprints after the requested processing is complete. Any transient biometric measurements used to provide a requested feature are deleted or made non-identifying when no longer needed for that feature.

We do not sell, lease, trade, or disclose biometric information for profit. We may disclose it only to limited service providers who help us provide the requested feature, where required by law, or with your consent.

If you upload or process media containing another person, you are responsible for having all required rights, permissions, disclosures, and consents from that person.

4. Sensitive Information

Other than media or information you choose to provide for a feature that specifically requires it, do not submit sensitive personal information through the Services. This includes government identifiers, payment card numbers, account credentials, health information, criminal history, political opinions, religious beliefs, trade union membership, precise geolocation, genetic data, biometric templates, or information about children unless the feature expressly supports it and applicable law permits it.

Do not include personal information about yourself or others in prompts, instructions, or AI inputs unless it is necessary for the feature you are using and you have the right to provide it.

5. How We Use Personal Data

We use personal information for the following purposes and lawful bases:

  • Service delivery and account operations. We use account, profile, content, technical, usage, and connected-account data to provide the Services, create and maintain accounts, publish and display Tags, process forms and submissions, sync integrations, generate outputs, manage workspaces, provide support, and communicate service notices. Legal basis: contract performance and legitimate interests.

  • Payments, subscriptions, billing, and payouts. We use billing, transaction, tax, account, and verification data to process payments, manage subscriptions, issue invoices, administer refunds, verify sellers, process payouts, prevent payment abuse, and comply with tax and accounting rules. Legal basis: contract performance, legal obligation, and legitimate interests.

  • AI processing and generation. If you use AI features, we process prompts, files, images, videos, metadata, settings, and related inputs to generate or edit outputs, run automations, provide recommendations, moderate content, and secure the Services. Legal basis: contract performance, legitimate interests, and consent where required.

  • AI training preferences. We do not use your non-public content to train AI models unless you explicitly opt in or as otherwise described in your settings or a separate agreement. Public content, feedback, aggregated data, de-identified data, and operational data may be used to improve the Services as described in this Policy and your settings.

  • Personalization. We use account, usage, preference, content, device, and cookie data to remember settings, personalize experiences, recommend templates or features, localize the Services, and improve usability. Legal basis: legitimate interests and consent where required for optional cookies or personalization.

  • Analytics and service improvement. We use usage, device, log, feedback, content, and interaction data to understand how the Services are used, troubleshoot issues, measure performance, improve reliability, develop new features, and improve security. Legal basis: legitimate interests and consent where required.

  • Safety, moderation, fraud prevention, and enforcement. We use account, content, usage, device, log, transaction, and security data to detect abuse, enforce our Terms, prevent fraud, protect users, investigate suspicious activity, and secure the Services. Legal basis: legitimate interests, legal obligation, and contract performance.

  • Marketing and communications. We use contact, account, marketing preference, usage, event, and communication interaction data to send product updates, newsletters, offers, event invitations, and other marketing communications where permitted. Legal basis: consent where required and legitimate interests where permitted. You can opt out of marketing at any time.

  • Legal compliance and protection. We use information as necessary to comply with applicable law, court orders, regulatory requests, tax obligations, sanctions screening, recordkeeping duties, and to establish, exercise, or defend legal claims. Legal basis: legal obligation and legitimate interests.

  • Aggregated, de-identified, and anonymized data. We may create aggregated, de-identified, or anonymized data that cannot reasonably identify you. We may use and share such data for analytics, research, reporting, product improvement, benchmarking, and business purposes.

6. How We Share Personal Data

PeekTag does not sell personal data for money. We also do not share personal data for cross-context behavioral advertising unless we clearly disclose that practice and provide any opt-out required by law.

We may disclose personal information to the following categories of recipients:

  • Service providers and sub-processors: such as hosting, cloud infrastructure, storage, authentication, analytics, email delivery, customer support, logging, monitoring, security, fraud prevention, content moderation, AI model, compute, and payment service providers. These providers are required to process personal data under confidentiality and data protection obligations.

  • AI model and infrastructure providers: where needed to provide AI-powered features, generate outputs, moderate content, or run workflows. We limit the data shared to what is needed for the requested feature or operational purpose.

  • Payment processors and app stores: such as Stripe, Apple, Google, or other payment providers. They process payment information under their own terms and privacy policies.

  • Connected apps and integrations: when you choose to connect a third-party service or authorize a workflow. The third party's use of information is governed by its own terms, settings, and privacy policy.

  • Organization, workspace, or business administrators: if you use PeekTag through an organization, team, workspace, school, agency, or enterprise account. Administrators may access, monitor, manage, export, delete, or control account activity, content, billing, roles, and settings for that workspace.

  • Other users and the public: when you publish or share Tags, profiles, templates, storefronts, forms, comments, reviews, media, outputs, or other content publicly or with selected recipients. Your visibility settings and sharing choices determine who can view or interact with that content.

  • Affiliates: if PeekTag operates with affiliated entities that support the Services.

  • Professional advisors: such as lawyers, auditors, accountants, banks, insurers, and consultants, where necessary for the services they provide to us.

  • Business partners: such as event partners, promotion partners, marketplace partners, or integration partners, where you participate in an event, promotion, marketplace feature, or co-branded offering.

  • Authorities, regulators, courts, payment networks, law enforcement, or private parties: where we believe disclosure is necessary or appropriate to comply with law, protect rights and safety, prevent fraud or abuse, enforce our Terms, or respond to legal process.

  • Business transferees: in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transfer of all or part of our business.

7. Your Choices

  • Access or update your information. If you have an account, you may review and update certain account information through your account settings.

  • Marketing communications. You may opt out of marketing emails by using the unsubscribe link in the message or by contacting us. You may still receive service, security, legal, billing, and transactional messages.

  • Cookies and similar technologies. You can manage cookies through our Cookie Policy, Cookie Settings, browser settings, or device settings. If you disable cookies, some Services may not work properly.

  • Opt-out preference signals. Where required by applicable law, we recognize Global Privacy Control ("GPC") signals as requests to opt out of sale, sharing, or targeted advertising for the browser or device sending the signal. We do not currently respond to "Do Not Track" signals because there is no uniform standard for them.

  • Connected accounts. You may disconnect supported integrations through your PeekTag settings or the third-party service's settings. Revoking access may not affect information already processed before revocation.

  • Delete content or close your account. You may delete certain content or request account deletion through available account controls or by contacting us. Deleted content may remain in backups, logs, or legal records for a limited period as described in this Policy.

  • Declining to provide information. You do not have to provide personal information, but if information is required to provide a feature, comply with law, process payment, verify identity, or secure the Services, we may not be able to provide that feature without it.

8. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, account management, security, fraud prevention, legal compliance, tax and accounting, dispute resolution, backup, and legitimate business purposes.

To determine retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes of processing, whether those purposes can be achieved through other means, your choices, and applicable legal requirements.

Typical retention periods include:

  • Active account data: retained while your account remains active.

  • Account deletion restore period: for up to 30 days after account deletion, account content may remain restorable upon request.

  • Logs, analytics, security, and abuse-prevention records: typically retained for up to 90 days, unless a longer period is needed for security, legal, tax, fraud-prevention, or dispute purposes.

  • Temporary AI sessions, previews, and generated assets: typically retained for up to 30 days for delivery, debugging, safety, and security, unless saved by you, published, required for a paid feature, or retained for legal or operational reasons.

  • Backups: retained for a limited backup cycle and then overwritten or deleted according to our backup processes.

  • Legal, tax, accounting, billing, payout, and compliance records: retained for the period required or permitted by applicable law.

  • Biometric templates, faceprints, or voiceprints: unless we clearly state otherwise for a specific feature, not stored after the requested feature is complete.

When we no longer need personal information, we delete it, anonymize it, aggregate it, or securely isolate it from further processing until deletion is possible.

9. International Data Transfers

PeekTag is based in Denmark and primarily operates from the EEA. We may use service providers, infrastructure, model providers, payment providers, support tools, or other recipients located in the EEA, UK, United States, and other countries.

Where personal data is transferred outside the EEA, UK, or Switzerland, we use appropriate safeguards where required, such as adequacy decisions, the EU Standard Contractual Clauses ("SCCs"), the UK International Data Transfer Addendum or International Data Transfer Agreement, the EU-U.S. Data Privacy Framework or UK Extension where applicable, or another transfer mechanism permitted by law.

In limited situations, we may rely on a lawful derogation, such as your explicit consent, performance of a contract, or the establishment, exercise, or defense of legal claims.

10. Data Security and Breach Response

We use commercially reasonable technical and organizational measures designed to protect personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction.

These measures may include encryption in transit and at rest, access controls, multi-factor authentication, least-privilege access, logging and monitoring, backups, security reviews, vendor assessments, and incident response procedures.

No online service can be guaranteed to be completely secure. You are responsible for keeping your password, devices, credentials, and connected accounts secure.

If we become aware of a personal data breach that requires notification, we will work with applicable regulators and notify affected individuals where required by law.

11. Your Privacy Rights

Depending on where you live and the lawful basis for processing, you may have rights to:

  • Access. Access personal data we hold about you.

  • Correction. Correct inaccurate or incomplete personal data.

  • Deletion. Delete personal data where there is no valid reason for us to continue processing it.

  • Restriction. Restrict processing in certain circumstances.

  • Portability. Receive a portable copy of personal data you provided to us.

  • Objection. Object to processing based on legitimate interests.

  • Marketing objection. Object to direct marketing at any time.

  • Withdraw consent. Withdraw consent where processing is based on consent. Withdrawal does not affect processing that occurred before withdrawal.

  • Complaint. Lodge a complaint with a data protection authority.

We may need to verify your identity before responding to a request. We try to respond to valid privacy requests within one month for EEA/UK requests, or within the period required by applicable law. If a request is complex or repeated, we may extend the response period where permitted and will notify you.

We may decline a request where permitted by law, for example if we cannot verify your identity, the request is manifestly unfounded or excessive, or we need to retain information for legal, security, tax, fraud-prevention, or dispute purposes.

To exercise your rights, contact [email protected].

12. Notice to European Users

This section applies to individuals located in the EEA, UK, or Switzerland.

  • Controller. PeekTag ApS is the controller for the personal data covered by this Privacy Policy, unless we process data on behalf of a business customer under a separate data processing agreement.

  • Legal bases. Our legal bases include contract performance, legitimate interests, legal obligation, consent, and, where applicable, vital interests. We identify the relevant purposes and bases in the "How We Use Personal Data" section above.

  • Legitimate interests. Where we rely on legitimate interests, those interests may include operating and improving the Services, protecting the security and integrity of the Services, preventing fraud and abuse, supporting users, developing new features, understanding usage, and communicating about relevant products or services. You may object to processing based on legitimate interests as described in this Policy.

  • Special category data. We do not intentionally collect special category data unless you choose to provide it for a feature that requires it, such as a media or AI feature, or where required by law. Where required, we obtain consent or rely on another lawful condition.

  • Automated decision-making. We do not use personal data for solely automated decisions that produce legal or similarly significant effects unless we disclose that processing separately and provide rights required by law.

  • Complaints. We encourage you to contact us first so we can try to resolve your concern. You may also lodge a complaint with your local supervisory authority. In Denmark, the supervisory authority is Datatilsynet, the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, Denmark, email: [email protected].

13. Notice to U.S. State Residents

This section applies to residents of U.S. states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Texas, and similar laws where applicable.

  • Categories collected. The categories of personal information we collect are described in the "Information We Collect" section. They may include identifiers, account information, commercial information, internet or network activity, approximate location, audio/visual content you provide, inferences, sensitive information where you choose to provide it, and professional or business information.

  • Sources, purposes, and recipients. The sources of personal information, purposes of processing, and categories of recipients are described in the "Information We Collect", "How We Use Personal Data", and "How We Share Personal Data" sections.

  • Sale, sharing, and targeted advertising. PeekTag does not sell personal information for money. If we use cookies or similar technologies in a way that applicable U.S. law treats as "sale", "sharing", or targeted advertising, we will provide an opt-out mechanism, such as Cookie Settings, a "Your Privacy Choices" control, or recognition of GPC where required.

  • Sensitive personal information. We do not use or disclose sensitive personal information for purposes that require a right to limit, unless we provide the required notice and choice.

  • Rights. Subject to applicable law and verification, you may request to know or access personal information, delete it, correct it, obtain a portable copy, opt out of sale/sharing/targeted advertising, limit certain uses of sensitive personal information, and appeal a denied request where the law provides that right. We will not discriminate against you for exercising privacy rights.

  • Authorized agents. Where allowed by law, an authorized agent may submit a request on your behalf. We may require proof of authorization and may ask you to verify your identity directly.

  • California Shine the Light. California residents may request information once per year about certain disclosures of personal information to third parties for their own direct marketing purposes, where applicable.

To exercise U.S. privacy rights, contact [email protected].

14. Children

The Services are not directed to children under 13. We do not knowingly collect personal data from children under 13 without required consent. If we learn that a child under 13 has provided personal data without required consent, we will delete it as required by law.

Where local law requires parental consent for users under a higher age, that consent is required. Educational or supervised versions of PeekTag, if offered, will follow applicable parental-consent, school-authority, and child privacy requirements.

15. Other Sites and Third-Party Services

The Services may contain links to third-party websites, apps, APIs, services, stores, payment pages, integrations, or content. PeekTag is not responsible for the privacy practices, security, content, or policies of those third parties. When you use a third-party service, that third party's terms and privacy policy apply.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will provide notice through the Services, by email, in-app notice, or another appropriate method before the changes take effect where required by law. Other changes are effective when posted.

Where law requires consent for a change, we will request consent. Your continued use of the Services after an updated Policy takes effect means you acknowledge the updated Policy.

17. Contact Information

If you have questions, requests, or complaints about this Privacy Policy or our privacy practices, contact us at:

PeekTag ApS

CVR: 45849651

Copenhagen, Denmark

Email: [email protected]

Legal contact: [email protected]

If you are contacting us about an intellectual property issue, please use [email protected] unless another reporting channel is provided.