Privacy Policy.
How Snippli handles personal data, for our paying customers and for the visitors of the websites that embed our widgets. Swiss-hosted, FADP and GDPR compliant.
Contents
- Who is responsible
- Two roles: customer data vs. visitor data
- What we collect from customers
- What we collect from visitors
- Why we process data (legal bases)
- Where data is hosted
- Sub-processors
- How long we keep data
- Cookies and tracking
- Your rights
- Security
- International transfers
- Changes to this policy
- Contact and complaints
1. Who is responsible
The controller responsible for personal data processing under this Privacy Policy is:
Foldercrate (operator of Snippli)
Switzerland
Email: info@snippli.com
Snippli is a product of Foldercrate, an independent Swiss software studio. For questions specifically about data protection, contact info@snippli.com.
2. Two roles: customer data vs. visitor data
Snippli processes personal data in two distinct capacities:
- As a controller for our paying customers (e.g. when you sign up for an account, pay an invoice or contact support). This Privacy Policy describes that processing.
- As a processor on behalf of our customers, for personal data of their website visitors that flows through our widgets. In that case, our customer is the controller and decides what data to collect and why. We process such "Visitor Data" only on documented instructions from our customer.
3. What we collect from customers
When you sign up, use the dashboard or contact us, we may collect:
- Account data: name, email address, password (hashed), preferred language, account preferences;
- Billing data: billing name and address, VAT number, payment method (card data is handled directly by Stripe. We never see or store full card numbers);
- Usage data: dashboard activity logs, IP addresses, timestamps, browser and device metadata used for security and abuse prevention;
- Support data: messages, screenshots and any information you voluntarily provide in support tickets or emails.
4. What we collect from visitors (on our customers' behalf)
When a visitor lands on a website that embeds Snippli widgets, we may process:
- Pseudonymous identifiers used to deduplicate impressions and prevent abuse;
- Aggregate signals such as page URL, referrer, country (derived from IP and immediately discarded), device type and approximate timestamp;
- Form input that the visitor voluntarily submits via lead-capture widgets (e.g. email address, message content). Only where the customer has configured such a widget.
By default, our analytics layer (powered by Logiwolf) is cookieless and avoids storing any personal identifiers in the browser.
5. Why we process data (legal bases)
Under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR), we rely on the following legal bases:
- Performance of a contract , to deliver the Service you have subscribed to;
- Legitimate interests , to keep the Service secure, prevent fraud and abuse, and improve the product (Art. 6(1)(f) GDPR);
- Legal obligation , to comply with tax, accounting and other applicable laws;
- Consent , for any processing where consent is required, which you can withdraw at any time.
6. Where data is hosted
All Snippli production data, including customer accounts, widget configurations and visitor data. Is hosted exclusively on infrastructure operated by Hostpoint AG in Switzerland. Backups are also retained in Switzerland.
This means your data does not, by default, leave Swiss data centres for routine processing.
7. Sub-processors
To run the Service we use a small number of carefully chosen third-party providers ("sub-processors"). Where any of these are based outside Switzerland, transfers are protected by appropriate safeguards (such as Standard Contractual Clauses).
- Hostpoint AG (Switzerland), core hosting and storage;
- Stripe Payments Europe (Ireland / United States), payment processing and billing;
- Logiwolf (Switzerland), privacy-first analytics for the Snippli dashboard;
- Email delivery provider , transactional emails (signup, receipts, password reset);
- Customer support tooling , where used, to manage support requests.
An up-to-date list is available on request at info@snippli.com.
8. How long we keep data
- Active accounts: for as long as the account is active, plus a reasonable period afterwards to handle billing and support follow-ups.
- Closed accounts: personal data is deleted or anonymised within 90 days of closure, unless we are legally required to retain it longer (e.g. invoicing records under Swiss accounting law are kept for 10 years).
- Visitor data: aggregated event data is retained for analytics purposes for up to 13 months by default and can be configured shorter by the customer; raw IP addresses are processed transiently and not stored long-term.
- Backups: rolled out of backup snapshots within 35 days.
9. Cookies and tracking
The Snippli marketing website (snippli.com) uses only strictly necessary cookies for security and session management. We do not use third-party advertising or behavioural tracking cookies on our marketing site.
The Snippli embed script and the Logiwolf analytics layer are designed to operate without cookies wherever possible. If a customer chooses to enable a feature that relies on cookies on their own website, the customer is responsible for obtaining any required consent from their visitors.
10. Your rights
Depending on your location, you may have the following rights with respect to your personal data:
- Access , request a copy of the personal data we hold about you;
- Rectification , ask us to correct inaccurate or incomplete data;
- Erasure , ask us to delete your data, subject to legal retention obligations;
- Restriction , ask us to pause processing in certain circumstances;
- Portability , receive your data in a machine-readable format;
- Objection , object to processing based on legitimate interests;
- Withdrawal of consent , at any time, where processing is based on consent.
To exercise any of these rights, email info@snippli.com. We will respond within the timeframes required by applicable law (typically within 30 days under GDPR / FADP).
If you are a website visitor and want to exercise rights regarding data collected through a widget on a third-party website, you should contact that website's operator first, since they are the controller for that data.
11. Security
We protect personal data with industry-standard technical and organisational measures, including encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, audit logs, regular backups, and staff training. No system is perfectly secure, but we treat security as a first-class engineering priority.
If we ever detect a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the competent supervisory authority within the timeframes required by applicable law.
12. International transfers
Personal data is processed primarily in Switzerland. Where any sub-processor processes data outside Switzerland or the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and the Swiss-EU adequacy mechanism.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the latest version. For material changes, we will notify you by email or through the dashboard at least 30 days before they take effect.
14. Contact and complaints
For any privacy question, write to info@snippli.com.
If you believe we have not handled your personal data lawfully, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch , or, if you are based in the EU, with your local data protection authority.