1. Introduction and scope
This privacy policy explains how personal data is processed when you use the newsletter features and the demo shop on this website. It applies only to those areas; other parts of the site (for example the blog, landing pages, or admin area) are not covered in detail here, except where the demo shop incidentally uses an existing login session.
This website is not officially affiliated with TanStack or TanStack Start. It is operated as a demonstration and template project.
2. Controller
The controller under the GDPR is:
Michael Hrenkac/o IP-Management #9796Ludwig-Erhard-Straße 1820459 HamburgGermanyContact for privacy-related requests: michael.hrenka@protonmail.com
Email correspondence you initiate is processed on the basis of Art. 6(1)(f) GDPR in order to handle your request, and is deleted once it is no longer needed, subject to any statutory retention obligations.
Data protection officer: A data protection officer has not been appointed.
3. Hosting
The website is delivered from a Hetzner virtual private server located in Germany. A Docker container runs the TanStack Start application behind a Caddy reverse proxy with automatic TLS. Cloudflare is used for DNS. Each visit generates technically necessary access and security logs (including IP address, timestamp, requested URL, and technical metadata). These logs are unavoidable for the secure and stable operation of any publicly reachable website.
The hosting infrastructure processes this data on the operator’s behalf to provide the service. Log retention depends on server configuration and is limited to operational needs.
The current deployment does not include web analytics, advertising trackers, or similar profiling tools.
4. Newsletter
You can subscribe to the newsletter by providing your email address and, optionally, your name. When you sign up, we also record where you gave consent (for example a dedicated signup page or a newsletter block on the landing page).
Subscription uses double opt-in: after signup you receive a confirmation email with a one-time link. Only after you confirm does your subscription become active. Confirmation and unsubscribe links contain random tokens; only cryptographic hashes of those tokens are stored in the database, not the raw tokens themselves.
We process and store the following newsletter-related data:
- email address
- optional name
- consent source (where you signed up)
- subscription status (pending, confirmed, or unsubscribed)
- hashed confirmation and unsubscribe tokens
- timestamps such as confirmation or unsubscribe time
- an internal audit trail of email-related events (for example confirmation sent, subscription confirmed, or unsubscribe)
Confirmation and newsletter emails are sent through Resend. When an issue is broadcast to confirmed subscribers, contacts may be synchronised to a Resend segment so delivery can be managed there. Issue broadcasts use Resend-managed unsubscribe links; confirmation emails use our own unsubscribe links.
You can unsubscribe at any time using the link in newsletter emails. Unsubscribing updates the local subscription record when you use our confirmation-flow unsubscribe link, or is handled through Resend when you use the unsubscribe link in a broadcast. A contact previously synced to Resend may remain there until the next segment synchronisation.
5. Demo shop
The shop on this website is a demonstration only. It offers demo products and is not intended to sell real goods or services. Checkout is wired for technical demonstration using payment providers in test or sandbox mode only. No real payments are accepted or settled through this shop.
When you browse the shop or use the cart, we assign or reuse an anonymous cart session identifier. Cart contents (product variants and quantities) are stored in our database and linked to that session or, if you are logged in, to your user account.
If you proceed to demo checkout, you may be redirected to hosted checkout pages operated by Stripe (test mode) and/or CoinGate (sandbox). Card numbers, crypto wallet details, and similar payment credentials are entered only on those provider pages; this application does not store them.
If you are logged in, your account email may be used to pre-fill checkout or to associate the cart and order with your account. For anonymous checkout, an email address may be taken from the payment session when the demo flow completes.
When a demo checkout completes, we may store:
- customer email address
- order amounts, currency, and status
- payment provider references (for example Stripe session, customer, or payment intent IDs, or CoinGate order metadata)
- line-item snapshots (product name, SKU, unit price, quantity)
- trimmed payment event records for webhook auditing (not full provider webhook payloads)
A demo order confirmation email may be sent through Resend when the checkout flow succeeds. Shipping or billing addresses are not collected by this application.
6. Cookies
This website uses the following cookies in connection with the newsletter and demo shop:
- cart_session_id — identifies an anonymous shopping cart for up to 30 days; httpOnly, SameSite=Lax, path /
- Supabase authentication session cookies — only if you are logged in while using the shop; managed by Supabase Auth for session handling
The cart cookie is technically necessary to maintain your cart between visits. Authentication cookies are necessary if you choose to use the shop while logged in. No separate marketing or analytics cookies are set for these features.
7. Legal bases (Art. 6 GDPR)
Where personal data is processed, the operator relies on the following legal bases:
- Newsletter signup, confirmation, delivery, and unsubscribe handling: Art. 6(1)(a) GDPR (consent). You can withdraw consent for future newsletters at any time by unsubscribing.
- Hosting and security logs, cart session cookie, and operation of the demo shop (including test checkout orchestration): Art. 6(1)(f) GDPR (legitimate interests in providing a functional, secure demonstration environment), and where applicable Art. 6(1)(b) GDPR (steps prior to a contract at your request when you initiate demo checkout).
- Email correspondence with the controller (for example privacy requests): Art. 6(1)(f) GDPR (legitimate interests in handling your request).
8. Recipients and categories of recipients
Beyond the operator as controller, personal data may be processed by the following categories of recipients, depending on how you use the newsletter and demo shop:
- Hosting infrastructure: Hetzner (virtual private server in Germany) and the reverse-proxy layer (Caddy) on the operator’s server
- Database and authentication: Supabase (managed Postgres and, when used, Auth)
- Email delivery: Resend (newsletter and order confirmation emails)
- Demo card checkout: Stripe (test mode hosted checkout and webhooks)
- Demo crypto checkout: CoinGate (sandbox hosted checkout and callbacks)
- Email service provider of the controller (currently Proton AG, Switzerland), for correspondence you initiate
The operator does not sell personal data and does not pass it on beyond what is necessary for the purposes described above.
9. Data categories and storage periods
Categories of data may include in particular:
- technical connection and access data from hosting
- newsletter contact and consent data, token hashes, and email event logs
- cart session identifiers, cart contents, orders, order items, and payment event summaries
- data visible to or processed by Resend, Stripe, or CoinGate in connection with emails or demo checkout you initiate
- contact data in email correspondence with the controller
Storage periods: hosting logs are retained only as long as operationally necessary. The cart_session_id cookie expires after 30 days; database cart and order records are not automatically deleted by the application. Newsletter and order records are kept until manual deletion by an administrator or until you successfully exercise your erasure rights, subject to statutory retention duties. There is currently no automated purge job for subscribers, carts, or orders.
10. International transfers
Hosting on the operator’s Hetzner server in Germany keeps primary website delivery within the EU/EEA. However, newsletter and demo-shop features rely on processors that may store or process personal data outside the EEA, in particular in the United States. The following summaries reflect each provider’s published position as of June 2026; please refer to their current documents for authoritative details.
Overview of the EU-US Data Privacy Framework (DPF) program and the official DPF participant list maintained by the U.S. Department of Commerce.
- Resend (email delivery; United States): privacy policy, Data Processing Agreement. Resend states certification under the EU-US DPF and the UK Extension to the EU-US DPF; see its DPF certification announcement and verify active status on the official DPF participant list.
- Stripe (demo checkout in test mode; United States): privacy policy, Data Processing Agreement, Data Privacy Framework policy. Stripe states compliance with the EU-US DPF, the UK Extension, and the Swiss-US DPF; certification can be verified on the official DPF participant list.
- Supabase (database and authentication; United States and possibly other regions such as Singapore): privacy policy and Data Processing Addendum. Supabase’s privacy notice describes transfers to the United States and Singapore as safeguarded by the European Commission’s Standard Contractual Clauses (SCCs). Supabase is not listed as a DPF participant; SCCs under its DPA are the relevant transfer mechanism.
Where a provider participates in the DPF, that framework may serve as an adequacy-based transfer mechanism in addition to, or instead of, SCCs, depending on the circumstances and the provider’s contractual terms. The operator does not sell personal data and selects processors only as needed to operate the newsletter and demo shop.
11. No automated decision-making
The operator does not carry out automated decision-making, including profiling, with legal effect or similarly significant effect on you within the meaning of Art. 22 GDPR.
12. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. In Germany, the state data protection authority responsible for your federal state is one example.
13. Your rights
Where personal data is processed, you generally have the following rights under the GDPR:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (“right to be forgotten”, Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- objection to processing (Art. 21 GDPR)
- data portability (Art. 20 GDPR)
- withdrawal of consent at any time, with effect for the future, where processing is based on your consent (Art. 7(3) GDPR); the lawfulness of processing carried out before withdrawal is not affected
To exercise your rights, please contact michael.hrenka@protonmail.com. For newsletter data, unsubscribing via the link in our emails is the quickest way to stop future mailings.
14. Version and changes to this privacy policy
Version: June 2026.
The operator may update this privacy policy when technical or legal requirements change. The current version is always available at /privacy/en and /privacy/de on this website. Where changes are material, the operator will try to inform users appropriately, for example via this website.