Privacy English only

Privacy Notice

How Shuuka handles account data, public profile analytics, verification records, app disclosures, and safety reports.

Updated

13 March 2026

Built from the current Shuuka web, API, verification, analytics, and app privacy flows in this codebase.

Controller

Edward Vasquez, Zurich, Switzerland

Applies to

Marketing pages, registered users, public profiles, verification requests, fake-link reports, marketplace apps, and profile app interactions

Legal framework

Swiss nDSG and, where applicable, GDPR / DSGVO

1. Scope

What this notice covers

This notice explains how Shuuka processes personal data when you visit the website, create or use a Shuuka account, browse a public Shuuka profile, submit a verification request, report a fake link, contact support, submit or install marketplace apps, or interact with apps embedded on a public profile.

Shuuka acts as the controller for its own service operations, including account creation, login, verification workflows, platform security, first-party profile analytics, fake-link reporting, and marketplace governance. When a profile owner installs apps or forms that collect visitor data for their own purposes, the profile owner and, in some cases, the app provider may be separate controllers for that collection.

  • Registered users who create and manage profiles, routes, apps, settings, and verification requests.
  • Visitors to public profiles, including visitors who click links, view apps, or interact with profile-level analytics and consent controls.
  • People who submit support requests, fake-link reports, or verification materials.
  • Developers and operators who submit apps, manifests, screenshots, and privacy disclosures to the Shuuka marketplace.

2. Data

Data we collect

Account, profile, and preference data

  • Email address, nickname, hashed password, public profile identifiers, avatar, profile text, social links, route destinations, and account preferences such as language, theme, timezone, and privacy mode.
  • Profile configuration data used to publish your official identity, including link ordering, profile settings, app installations, and theme selections.

Verification and trust data

  • Verification request type, company name, company email, website or profile URLs, generated verification codes, network verification status, reviewer actions, and audit history needed to confirm account control.
  • Signals used to protect identity integrity, such as fake-link reports, reporter email address when provided, reported platform or URL, and moderation outcomes.

Profile visitor analytics and security data

  • For public profiles, Shuuka derives a short-lived pseudonymous visitor identifier ("visitor_hash") from a truncated IP address (the last octet of IPv4 addresses and the last 80 bits of IPv6 addresses are discarded before processing), the browser's User-Agent, and the first tag of the Accept-Language header, combined with a server-side salt that rotates every 24 hours. The inputs themselves are not retained; only the resulting hash is stored.
  • The daily salt rotation means the same visitor produces a different hash on a different day — Shuuka can count unique visitors within a day but cannot re-identify the same visitor across days. No persistent identifier is stored in the visitor's browser (no cookie, no localStorage, no browser fingerprinting of canvas, WebGL, fonts, or audio).
  • Alongside visitor_hash, Shuuka processes session identifiers, browser and device type, referrer, approximate geolocation (country / city), click events, and app interaction events to give the profile owner audience and security insight. Raw IP addresses used internally by security checks are encrypted at rest on profile-session rows and never retained beyond the retention window.
  • Raw event rows are retained for up to 365 days and will move to 90 days once aggregate rollups are in place. Aggregated counters (monthly profile visits, daily signups) are retained indefinitely because they contain no per-visitor identifier.
  • If a profile owner enables privacy mode, Shuuka suppresses analytics collection for that profile at the platform level — no visitor_hash is derived, no events are recorded, and no presence signal is emitted.

Communications, support, and marketplace data

  • Messages sent through contact or support flows, operational emails, marketplace app manifests, screenshots, privacy manifest declarations, installation settings, and related moderation records.
  • When a profile app collects visitor input through Shuuka-managed storage, the submitted values are stored in encrypted form and made available to the profile owner through the product.

4. Sharing

Who receives data

  • Infomaniak Network AG in Switzerland hosts core Shuuka infrastructure and related service operations.
  • Profile owners receive the data that is intentionally submitted to them through their own profile, including app submissions and moderation workflows they control.
  • App-specific third parties chosen by a profile owner may receive visitor data or set their own identifiers when an embedded app connects to them. Shuuka requires privacy declarations in app manifests and can gate certain apps behind consent before they load.
  • OpenAI may receive prompt content if you intentionally use an AI feature that routes through the Shuuka API.
  • Stripe, Inc. (stripe.com, USA) processes payment and billing data if you subscribe to a paid Shuuka plan. Stripe acts as a data processor for the transaction. The data Stripe receives includes your name, email address, payment method details, and billing address at checkout. Stripe processes this data under its own Privacy Policy. Shuuka does not store full card numbers — Stripe tokenises payment credentials before they reach Shuuka systems.
  • We may disclose data to professional advisers, regulators, law enforcement, or a buyer in a corporate transaction where legally required or reasonably necessary to protect rights, safety, or the integrity of the platform.

5. Apps

App-first privacy on public profiles

Shuuka supports marketplace and billboard-style apps on public profiles. Those apps can embed third-party services, collect visitor input, or forward visitors to external destinations. For that reason, privacy on profiles is not one generic banner. It is app-specific.

Each approved app can declare a privacy manifest that describes what the app collects, whether it transfers data to a third party, which privacy policy applies, and whether visitor consent is required before the app loads. Where an app declares a third-party transfer or other consent-sensitive behavior, Shuuka can show a platform-level consent gate before the iframe is activated.

  • A profile owner remains responsible for their own legal notices and for the purpose behind the app they install.
  • An app developer remains responsible for accurately declaring data flows in the app manifest.
  • A third-party provider such as a media embed, map, or marketing tool remains responsible for its own downstream processing once a visitor connects to it.

6. Transfers

International transfers

Shuuka is operated from Switzerland. Core hosting is designed to stay under Swiss control where possible. Some optional features, especially AI services or profile apps that connect to third-party providers, may involve recipients outside Switzerland or the EEA, including the United States.

Where Shuuka initiates such transfers for its own features, we rely on the provider's contractual safeguards and service terms. Where a profile owner installs an app that connects to a third party, the transfer details are driven by that app and are expected to be declared in the app's privacy manifest and policy link.

7. Retention

How long we keep data

  • Account and profile data are kept while the account is active and for a limited operational period after deletion or scheduled removal, where needed for recovery, fraud prevention, or legal handling.
  • Verification records, trust logs, and fake-link reports are kept for as long as needed to resolve the request, defend the decision, and preserve platform integrity.
  • Encrypted app submissions and app storage are kept according to the profile owner's use of the feature, unless law or platform safety requires earlier restriction or removal.
  • Analytics, security logs, and operational records are kept only as long as reasonably necessary for insight, fraud prevention, debugging, and compliance, and may be anonymized or deleted on different schedules depending on the record type.

8. Security

How we protect data

  • Passwords are stored as hashes, not in plain text.
  • Shuuka uses HTTPS in transit for website and API traffic.
  • App user inputs handled by Shuuka-managed storage are encrypted at rest.
  • Visitor identifiers used for analytics are pseudonymous by construction: IP addresses are truncated before the hash is computed, the per-day salt rotates automatically, and raw IP addresses stored for security checks on profile sessions are encrypted at rest.
  • Access is limited to people and systems that need it for service, security, or moderation work.
No internet service can guarantee absolute security. If you believe a profile, route, or account is being abused, contact [email protected] or [email protected].

9. Rights

Your rights

Depending on where you are located, you may have the right to access, correct, delete, restrict, object to, or export your data, and to withdraw consent where consent is the legal basis. You may also ask us to review a moderation or verification handling decision.

Because Shuuka processes profile analytics on the basis of legitimate interests (Art. 6(1)(f) GDPR / DSGVO), you have a specific right under Art. 21 GDPR to object to that processing. Logged-in profile owners can enable Privacy Mode at any time on the Settings page — this immediately stops Shuuka from deriving visitor_hash values, recording events, or emitting presence signals for that profile, and it does so platform-wide (no banner required).

To make any other privacy request, email [email protected]. If you are in Switzerland and are not satisfied with our response, you can contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch. If you are in the EEA, you can contact your local supervisory authority.

10. Age

Children

Shuuka accounts are intended for people who are at least 18 years old. If you believe a child has provided data to Shuuka inappropriately, contact [email protected] so we can review and remove it where required.