This policy explains how we collect and use personal data, the purposes and legal bases for processing, and your rights under the GDPR.
Download as PDF
Download nowActive versions
Version datedArchived versions
No archived versions are available.
1. Who we are
Wendung is a web and funnel analytics service operated by Alexander Alekseenko, Einzelunternehmer, Virgilstraße 9, 81673 Munich, Germany. This policy explains what personal data we collect, why we process it, and how we handle it under the EU General Data Protection Regulation, or GDPR.
2. Our roles under GDPR
Wendung has two different roles depending on the data involved.
- Controller
- For our website analytics, dashboard product analytics, account, workspace, billing, security, and communication data, Wendung decides why and how the data is processed.
- Processor
- For analytics events sent by a customer application through the Wendung SDK, the customer is the controller and Wendung processes the data on the customer's instructions.
3. Account and product data
We collect the following data to create and operate your Wendung account, secure the service, provide support, and manage billing.
- Account profile
- Name, email address, email verification status, password hash, onboarding state, and account preferences.
- Workspace and project data
- Workspace names, member and invitation details, project settings, allowed origins, API keys, funnel definitions, usage counters, and plan information.
- Authentication and security metadata
- Session token records, session expiry, IP address, user agent, verification tokens, password reset requests, and similar security records.
- Error and performance diagnostics
- When you allow analytics and diagnostics, Sentry receives dashboard error reports and sampled performance traces to help us find and fix problems. Reports can include stack traces, navigation and request details, and browser and device metadata. You can withdraw this choice under Account. API error reporting and performance diagnostics operate separately and can include endpoint details, IP addresses, and account identifiers, including your user ID and email.
- Billing data
- Stripe customer and subscription identifiers, plan, subscription status, invoice metadata, and payment status. Full card details are handled by Stripe and are not stored by Wendung.
- Support and transactional communication
- Messages you send us and transactional email metadata needed for account confirmations, password resets, workspace invitations, billing, and service notices.
We process account, workspace, subscription, and related support data to provide the service or take steps you request before a contract, under GDPR Article 6(1)(b). Billing records needed to meet tax and accounting obligations fall under Article 6(1)(c). We rely on Article 6(1)(f) for protecting accounts, preventing abuse, maintaining service availability, and investigating server faults. These interests do not replace consent for optional browser analytics and diagnostics, described below.
The account and billing details requested as required are needed to create your account or provide a paid subscription. Without them, we cannot provide the corresponding service. Optional analytics is not a condition of using the website or dashboard.
4. Analytics event data
When a customer application sends events through the Wendung SDK, Wendung processes that data as a processor for the customer. The customer decides what events, properties, traits, and user IDs to send, and is responsible for having a lawful basis and providing its own privacy notice to end users.
- Event name, event ID, timestamp, batch ID, request ID, project ID, and origin.
- Session ID and the user ID that the customer provides through the SDK, if any.
- Event properties and user traits that the customer includes in the payload.
- SDK version, page URL, and referrer when included in the SDK context.
- Country and city derived from Cloudflare request metadata, plus browser, operating system, and device type parsed from the User-Agent header.
- Ingest request status and delivery diagnostics used to debug event delivery.
Customers can enable automatic pageviews or send them manually. Sites must be registered in the project for web analytics reporting. Full pageviews can include the following data in addition to the event data above.
- Page URL and title. In full collection mode, the SDK sends the current URL, including its query string and fragment. Ingest removes the fragment and retains only allow-listed query parameters and the UTM campaign parameters listed below. The original pathname remains in the event alongside a normalized path used for reports.
- Referrer, referrer domain and channel type, and UTM source, medium, campaign, term, and content parameters.
- Browser, operating system, device type, and screen size, plus country and city derived from Cloudflare request metadata.
- A random visitor identifier and a session identifier generated by the SDK. The visitor identifier is kept in the browser storage of the customer site so repeat visits can be counted as one visitor. It is not derived from the IP address. These identifiers are pseudonymous, not proof that the data is anonymous. If a customer supplies a user ID, the service can associate session activity with that user.
- Session aggregates derived from pageviews, such as entry and exit page, session duration, and bounce state, and hourly totals used for reporting.
- A bot flag derived from the User-Agent header. Requests classified as bots are excluded from reports.
Wendung does not add request IP addresses to analytics event rows. Cloudflare receives the request IP address and User-Agent header when delivering the website and SDK, and when receiving analytics requests. The absence of IP addresses from analytics rows does not mean that infrastructure providers never process or log them. Customers should not send special category data, payment card data, government ID numbers, health data, or other sensitive data through the SDK unless we have explicitly agreed to that in writing.
The SDK also offers an aggregate mode for pageviews while a customer's consent choice is pending. This mode sends the page origin and pathname, the referrer's origin, event timestamps, and event and batch identifiers. Ingest adds country, browser, operating system, device type, and a bot flag. Accepted aggregate events omit visitor and session identifiers, user traits, custom properties, query strings, fragments, titles, screen dimensions, and city. Individual event records feed the pageview totals. They do not contribute to visitor or session counts.
An aggregate collection mode does not establish a consent exemption. A pathname can still contain personal information. Customers must assess their configuration and applicable law before collecting without consent. Our own website uses the consent-based setup below.
6. AI features
Wendung may offer optional AI chat and AI-generated funnel insights. When you use these features, prompts, selected workspace/project context, funnel configuration, aggregated analytics results, and generated responses may be processed by Anthropic so the feature can respond. We do not use AI features for decisions that produce legal or similarly significant effects about individuals.
7. Service providers
We use the following providers to operate Wendung. They process data for the services described below. Their role depends on the service and processing involved. Payment providers may also process data under their own legal obligations.
- Cloudflare
- Infrastructure, DNS, CDN, Workers, Queues, KV, rate limiting, security, and edge routing. Privacy policy
- Neon
- Application Postgres database for account, workspace, project, billing, and product configuration data. Privacy policy
- Tinybird
- Analytics event store, query engine, pageview and session aggregates, ingest request logs, and event delivery diagnostics. Privacy policy
- Stripe
- Subscription billing, checkout, invoices, payment processing, and billing portal operations. Privacy policy
- Resend
- Transactional email delivery for account confirmation, password reset, email change, account deletion, workspace invitations, and service messages. Privacy policy
- Inngest
- Background job orchestration for scheduled usage syncs and asynchronous insight generation workflows. Privacy policy
- Sentry
- Error monitoring and performance tracing for the dashboard and API, including stack traces, request metadata, browser and device metadata, IP address, and the signed-in user ID and email address, processed in the Sentry EU data region. Privacy policy
- Anthropic
- AI model provider for optional AI chat and AI-generated funnel insights when those features are enabled or used. Privacy policy
8. Retention and deletion
Account, workspace, and project data are retained for as long as needed to provide the service, maintain security, resolve disputes, and comply with legal obligations. Billing and tax records may be retained longer where required by law or by Stripe under its own retention rules.
Customer analytics has separate reporting and deletion periods. Reporting windows are 7 days for Free, 30 days for Starter, 90 days for Growth, and 365 days for Scale. Scheduled deletion uses 60 days for Free, 30 days for Starter, 90 days for Growth, and 365 days for Scale. Some underlying stores expire sooner. Deletion runs in background jobs, so the reporting cutoff is not an instant deletion of every stored copy.
Project owners can request deletion of analytics events, associated delivery logs, and derived pageview and session reports from project settings. Project-level usage totals used for quotas remain separate from this deletion and do not contain visitor or session identifiers.
You can request account deletion from account settings. The self-service action may be blocked while you are the only owner of a workspace with an active or trialing subscription, so that billing and ownership issues can be resolved first. You can still contact us to exercise your statutory erasure rights.
9. Your GDPR rights
Where GDPR applies, you may have the right to request access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent.
You can object to processing based on legitimate interests for reasons relating to your particular situation. Contact us using the address below so we can assess your objection.
Contact us at hello@wendung.app to exercise your rights. We will respond without undue delay and within one month where GDPR applies. For complex or numerous requests, GDPR permits an extension of up to two further months; we will explain the extension within the first month. If your request concerns analytics data that we process for one of our customers, we may need to refer the request to that customer as the controller.
You can lodge a complaint with a supervisory authority, including one in the EU country where you live or work, or where you believe an infringement occurred. Our local authority is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
10. International transfers
Wendung is operated from Germany. Some providers may process data outside the EU/EEA. Where this happens, we rely on adequacy decisions, Standard Contractual Clauses, or other transfer mechanisms recognized under GDPR.
Contact us at hello@wendung.app for information about the safeguards applicable to your data and how to obtain a copy.
11. Security
We use technical and organizational safeguards appropriate to the service, including access controls, transport encryption where applicable, password hashing, rate limiting, and infrastructure protections. No internet service can be guaranteed completely secure, but we work to reduce risk and respond to issues promptly.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the date above and may notify you by email or in-app notice where appropriate.