Privacy Policy

1. Overview

This privacy policy explains how Ad Analyzer (“we”, “us”, “the service”) collects, processes, and protects your data. Ad Analyzer is a web-based analytics tool for Amazon Advertising performance data. We are committed to protecting your privacy and being transparent about our data practices.

2. Data Controller (Art. 4(7) GDPR)

Christoph Weil

Enzianstr. 2, 82515 Wolfratshausen, Germany

Email: analyzer@christophweil.de

Phone: +49 (0) 151 40463650

3. Personal Data We Collect

Depending on how you use Ad Analyzer, we may collect the following personal data:

a) Account registration

  • Email address (required)
  • Name (optional)
  • Password (stored as a hash, never in plain text)
  • Preferred language
  • Referral code (optional)

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) — this data is necessary to create and manage your account.

b) Guest access

If you choose “Continue as Guest”, a temporary anonymous session is created. No personal data (name, email) is collected, but a session cookie is set in your browser (see Section 7).

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) — you explicitly request access to the service.

c) Payment data

If you purchase a subscription, payment processing is handled entirely by Stripe. We store your Stripe customer ID and subscription ID to manage your subscription status. We do not store credit card numbers, bank account details, or other payment credentials.

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).

4. Browser-Based File Processing

When you upload an Amazon Advertising bulk file, the data is parsed and analyzed locally on your device using JavaScript. Your advertising file data is not transmitted to our servers and is discarded when you close the browser tab.

5. AI Analysis Feature (Optional)

Ad Analyzer offers an optional AI-powered analysis feature. When you explicitly activate this feature, aggregated campaign performance metrics (spend, sales, impressions, clicks, ACoS, etc.) are sent to our server and forwarded to the Anthropic API (Claude) for analysis.

This data is processed in real time and is not stored permanently by us or by Anthropic beyond the duration of the request. No personal identifiers are included in the API request.

If you do not use the AI analysis feature, no campaign data is sent to any external service.

Legal basis: Consent (Art. 6(1)(a) GDPR) — you actively choose to trigger the analysis.

6. Hosting & Server Logs

This website is hosted on Vercel. When you visit the site, Vercel's servers automatically collect standard server log information, including:

  • Your IP address
  • Date and time of access
  • Browser type and version (user agent)
  • Referring URL

This data is collected for operational purposes and is subject to Vercel's Privacy Policy.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — ensuring the security and availability of the website.

7. Cookies

We use the following cookies:

CookiePurposeDuration
sb-*-auth-tokenAuthentication session (keeps you logged in)Session / refresh

These cookies are strictly necessary for the authentication service you explicitly request when logging in or continuing as a guest. They do not track you across websites and are not used for analytics or advertising.

We also use sessionStorage (not a cookie) to remember your theme preference (light/dark mode). This data stays in your browser tab and is cleared when you close it.

Legal basis: TTDSG § 25(2) Nr. 2 — strictly necessary for the service explicitly requested by the user. No consent required.

8. Web Analytics

We use Vercel Analytics and Vercel Speed Insights to understand general usage patterns and website performance. These tools:

  • Do not set cookies
  • Do not use browser fingerprinting
  • Do not track users across websites
  • Collect anonymized page view data (URL, referrer, country, device type, browser)
  • Process IP addresses server-side for geolocation but do not store them

For details, see Vercel Analytics Privacy.

Legal basis: Consent (Art. 6(1)(a) GDPR). Analytics are only loaded after you explicitly accept them via our cookie banner. You can withdraw your consent at any time by clearing your browser's local storage or using your browser's privacy settings.

9. Third-Party Services & Data Processors

We use the following third-party services to operate Ad Analyzer:

Vercel Inc. (USA)

Website hosting, deployment, analytics, and speed insights. Privacy Policy

Supabase Inc. (USA)

Database hosting, user authentication, and account management. Your account data (email, name, subscription status) is stored in Supabase. Privacy Policy

Stripe Inc. (USA)

Payment processing for subscriptions. When you purchase a subscription, you are redirected to Stripe's hosted checkout page. Stripe processes your payment details directly. Privacy Policy

Anthropic PBC (USA)

AI-powered campaign analysis (only when explicitly triggered by you). Aggregated, non-personal campaign metrics are sent for analysis. Privacy Policy

10. Data Transfers Outside the EU

Some of our service providers are based in the United States (Vercel, Supabase, Stripe, Anthropic). Data transfers to the USA are covered by the EU-U.S. Data Privacy Framework (adequacy decision by the European Commission, July 2023) and/or Standard Contractual Clauses (SCCs) where applicable.

11. Data Retention

  • Account data: Retained for as long as your account exists. You can delete your account at any time from your settings page.
  • Guest session data: Temporary and discarded when the session ends.
  • Payment data: Retained by Stripe according to their retention policy and legal requirements. We retain Stripe customer and subscription IDs for as long as the subscription relationship exists.
  • Server logs: Managed by Vercel according to their retention policy.
  • Uploaded file data: Never stored — processed in your browser only and discarded when you close the tab.

12. Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

  • Right of access (Art. 15) — request information about data we hold about you
  • Right to rectification (Art. 16) — request correction of inaccurate data
  • Right to erasure (Art. 17) — request deletion of your data
  • Right to restrict processing (Art. 18) — request limitation of data processing
  • Right to data portability (Art. 20) — receive your data in a machine-readable format
  • Right to object (Art. 21) — object to the processing of your data

You can exercise your right to data portability and erasure directly from your settings page (export data / delete account). For all other requests, please contact us using the details below.

You also have the right to lodge a complaint with a supervisory authority. The competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

13. Contact

For any privacy-related questions or to exercise your rights under GDPR, please contact:

Christoph Weil

Email:

Enzianstr. 2, 82515 Wolfratshausen, Germany

14. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or for legal reasons. Any changes will be posted on this page. We encourage you to review this page periodically for the latest information.

Last updated: February 2026