GDPR Compliance
Last updated: July 5, 2026
Streakfox is committed to processing personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page outlines our key practices.
1. Data Controller & Processor
Depending on context, Streakfox acts as:
- Data Controller – for account-related data.
- Data Processor – for end-user widget interactions on behalf of our customers.
2. Lawful Bases
We rely on contractual necessity to provide the Service and legitimate interests for analytics that improve product performance.
3. Sub-Processors
Our primary infrastructure providers:
- Cloudflare – Worker, queue, cache, routing, and static asset infrastructure.
- PlanetScale – managed PostgreSQL database hosting.
- Resend – transactional email delivery when email features are enabled.
- Stripe – billing and subscription processing when paid plans are enabled.
We maintain signed Data Processing Agreements (DPAs) with each sub-processor.
4. Data Subject Rights
Data subjects can request access, rectification, deletion, or export of their data by emailing dpo@streakfox.com. We respond within 30 days.
5. Security Measures
- Encryption in transit (TLS 1.3) & at rest.
- Role-based access controls & audit logging.
- Regular penetration testing & vulnerability scans.
6. Data Retention & Deletion
Widget event data is retained for 90 days by default. Customers can request shorter or longer retention during beta.
7. Contact
For GDPR inquiries, email our Data Protection Officer at dpo@streakfox.com.