1. Who we are
TempoWeb Studio is the controller responsible for the personal data described in this policy. We are based at Van Ostadestraat 19 b, 3141 JN Maassluis, Netherlands. Privacy questions and rights requests can be sent to privacy@tempowebstudio.nl.
2. Data we collect
- Account and identity data: name, email address, business name, account identifier, authentication status, and profile details you provide.
- Project and customer data: briefs, messages, files, brand assets, website requirements, feedback, appointments, and support history.
- Contact and lead data: name, email, phone number, company, enquiry details, domain requests, and newsletter or blueprint requests.
- Transaction data: order, invoice, payment status, amount, and Stripe transaction references. We do not store full payment-card numbers.
- Technical and usage data: IP address, device and browser information, timestamps, security logs, referring pages, and consent choices.
- Advertising measurement data: only after you accept marketing cookies — page views, ad-click identifiers, and conversion events processed by the advertising tools described in section 4.
- Connected-platform data: data a provider sends after you deliberately choose to connect or sign in with that provider, as explained below.
3. Google and TikTok data
Google Sign-In
When you choose “Continue with Google,” we request only the basic authentication scopes presented on Google’s consent screen. We receive an account identifier and basic profile information such as your name, email address, and profile image, where available. We use this data only to authenticate you, create or link your TempoWeb account, secure the service, and display your account profile.
We do not use Google user data for advertising, sell it, or allow humans to read it except when necessary for security, support requested by you, legal compliance, or with your explicit consent. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
TikTok integrations
If a TikTok connection is offered and you choose to authorize it, the authorization screen will identify the exact scopes requested. Depending on the feature you select, this may include basic profile information or content you expressly choose to access, display, or publish. We use TikTok data only to provide the user-facing feature you requested. We do not sell TikTok data or use it for unrelated profiling or advertising.
You can revoke provider access from your Google or TikTok account settings. Revocation stops future access but does not automatically remove data already stored by TempoWeb; use our Data Deletion page to request removal.
4. Advertising and measurement tools (Google Ads, Meta Pixel)
With your consent, we use third-party advertising tools to measure how well our ads work and to reach people who may be interested in our services. None of these tools set cookies or send data before you accept the “Marketing” category in our cookie banner, and you can withdraw that consent at any time on the Cookie Policy page. Withdrawing consent stops all further sending immediately.
Google Ads
We use the Google Ads tag (Google Ireland Ltd.) to measure conversions from our advertising, governed by Google Consent Mode: advertising storage stays denied until you consent. Details are in Google’s privacy policy.
Meta (Facebook) Pixel
We use the Meta Pixel (Meta Platforms Ireland Ltd.) to measure ad performance and conversions (such as a page view, a submitted contact form, or a click on our WhatsApp button), to build advertising audiences, and to show more relevant Meta ads (retargeting). For the collection and transmission of this data, we and Meta Platforms Ireland are joint controllers under Art. 26 GDPR; for Meta’s subsequent processing, Meta is an independent controller. The relevant terms are Meta’s Controller Addendum, and Meta explains its processing in its privacy policy.
Where Meta’s “advanced matching” feature is enabled, contact details you enter on our site (such as email address or phone number) may additionally be shared with Meta in hashed (pseudonymised) form to improve conversion matching. Hashed data remains personal data under the GDPR, which is why this, too, happens only with your marketing consent.
Legal basis and transfers
The legal basis for all advertising tools is your consent (Art. 6(1)(a) GDPR), given via the cookie banner and withdrawable at any time. These providers may transfer data to the United States; Google LLC and Meta Platforms, Inc. are certified under the EU–U.S. Data Privacy Framework, and we additionally rely on Standard Contractual Clauses where required. You can also object to personalised advertising directly in your Meta ad preferences and Google ad settings.
5. Why we use data and our legal bases
- Contract: to create accounts, provide quotes, build and host projects, process orders, take payments, and provide support.
- Consent: for non-essential cookies, advertising and measurement tools, direct marketing, and optional third-party connections. You may withdraw consent at any time.
- Legitimate interests: to secure and improve our service, prevent abuse, communicate about active enquiries, and run our business, where those interests do not override your rights.
- Legal obligation: for tax, accounting, fraud prevention, lawful requests, and dispute handling.
6. Sharing and international transfers
We share data only with service providers needed to operate TempoWeb Studio, professional advisers, authorities when legally required, or a successor in a business transaction. Categories include hosting and database, authentication, payments, email, communications, scheduling, analytics, advertising measurement, file delivery, and domain registration. Our current provider list is on the Service Providers page.
Some providers process data outside the European Economic Area. Where required, we rely on an adequacy decision (including the EU–U.S. Data Privacy Framework), approved Standard Contractual Clauses, or another lawful transfer safeguard.
7. Retention and security
We keep account and project data while your account or contract is active and then only as long as reasonably needed for support, disputes, security, and legal obligations. Financial records are generally retained for seven years under Dutch tax rules. Leads that do not become customers are reviewed and deleted or anonymised when no longer needed. Provider tokens are retained only while the connection is active or needed for the requested feature.
We use access controls, encrypted transport, managed infrastructure, authentication controls, logging, and backups designed to protect data. No online service can guarantee absolute security; please contact us immediately if you suspect unauthorized account access.
8. Your rights
Subject to the GDPR and applicable exceptions, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). We may verify your identity before acting. See Data Deletion for the request process.
9. Children, changes, and contact
Our services are intended for business users aged 18 or older and are not directed to children. We may update this policy when our services or legal duties change. Material changes will be communicated through the site, account, or email where appropriate.
Contact: privacy@tempowebstudio.nl.