Privacy Policy

Last updated: October 9, 2026

1. Introduction

Stack Enhance AB ("we," "our," or "us"), a Swedish company (Org.nr: 559427-8375), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email marketing intelligence platform, StackEnhance.

By using StackEnhance, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and organization details. Authentication is handled securely through Clerk.

Email Data

When you forward marketing emails to your StackEnhance inbox, we process and store:

  • Email content (subject, body, HTML)
  • Sender information
  • Timestamps and metadata
  • Images and links contained in emails

Important: We only process emails you explicitly forward to us. We do not access your personal email inbox.

Lawful Basis for Forwarded Email Content

When you forward a marketing email, it may contain personal data of third parties — most commonly the recipient's first name in the salutation, sometimes loyalty-program account numbers or balances. Our processing of this third-party data relies on the legitimate interest basis under Article 6(1)(f) GDPR: enabling the customer who forwarded the email to analyze competitor marketing. As a balancing safeguard, the inbound pipeline runs a multi-language privacy sanitizer (Swedish, Norwegian, Danish, Finnish, German, English; 80+ regex patterns) that removes recipient names, points balances, and account identifiers before the email is analyzed by AI or surfaced in the UI. Sanitization is documented in our internal PRIVACY_SANITIZATION.md reference.

A third-party data subject who believes their data should not be processed can email support@stackenhance.com with the subject "GDPR object" — we will identify the matching emails by recipient address and remove the unsanitized residue from R2 backup storage.

Usage Data

We collect information about how you interact with our platform, including pages visited, features used, and actions taken.

Visit Counting (No Cookies)

We count visits to our website ourselves, without cookies and without storing anything on your device. While a page is open and visible, your browser sends a small signal every 30 seconds containing the page path, the type of device (desktop, tablet or mobile) and, for the first page of a visit, the address of the page that linked to us and any campaign tags in the link. Our hosting provider, Vercel, adds an approximate location (country, region and city) derived from your IP address; we never receive or store the IP address itself. Each visit gets a random identifier that exists only while the page is open, so visits are not linked to one another. If you are signed in, the visit is linked to your account. We use these counts to see how many people are on the site and where they come from; they are deleted after 13 months.

3. How We Use Your Information

We use the collected information to:

  • Provide and maintain our service
  • Analyze email marketing patterns and generate insights
  • Process payments and manage subscriptions
  • Send transactional emails (receipts, notifications)
  • Improve our platform and develop new features
  • Respond to your requests and support inquiries

4. AI Processing

We use AI services (Google Gemini, OpenAI) to analyze email content and provide insights. Email content is sent to these services for processing. These providers have their own privacy policies and data handling practices.

AI-generated analysis includes health scores, content summaries, and marketing strategy insights. This data is stored with your account.

5. Data Storage and Security

Your data is stored securely using industry-standard practices:

  • Database hosted on Neon (PostgreSQL) with encryption at rest
  • Files stored on Cloudflare R2 with encryption
  • All data transmitted over HTTPS/TLS
  • Authentication handled by Clerk with SOC 2 compliance
  • Payments processed by Stripe (PCI-DSS compliant)

6. Data Sharing

We do not sell your personal information. We share data only with:

  • Service Providers: Clerk (authentication), Stripe (payments), Neon (database), Cloudflare (storage), Mailgun (email delivery)
  • AI Providers: Google Gemini (primary), OpenRouter (fallback), OpenAI (fallback) for content analysis
  • Analytics: Mixpanel for product analytics (only with your consent via cookie preferences)
  • Error Monitoring: Sentry for error tracking and performance monitoring to improve service reliability
  • Legal Requirements: When required by law or to protect our rights

7. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access: Request a copy of your data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Export your data in a standard format
  • Objection: Object to certain processing

To exercise these rights, use the data export feature in Settings or contact us at support@stackenhance.com.

8. Your Rights (CCPA - California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request information about the categories and specific pieces of personal information we collect about you
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To exercise these rights, use the data management features in Settings or contact us at support@stackenhance.com. We will respond to verifiable requests within 45 days.

9. Data Retention

While your account is active, your account data, forwarded emails, AI-generated analysis, screenshots, brand records, and campaign data are retained indefinitely so that your historical analysis remains available to you.

On account deletion we erase your personal identity: your user profile, preferences and settings, your brand-tracking subscriptions, your Clerk login, your uploaded avatar, and — when you are the last member of your organization — your Stripe customer record. Security and email-delivery logs are anonymized rather than deleted: the rows are kept for legal and fraud-prevention compliance with all personal identifiers stripped. By default a deletion is a soft delete with a 30-day grace period — your account is immediately deactivated, then permanently erased by an automated daily job once 30 days have elapsed, so an accidental deletion can be recovered within that window. You can request immediate permanent erasure (skipping the grace period) by emailing support@stackenhance.com.

The forwarded marketing emails — and the brand analysis built from them — are community data, not your personal data, and are retained. The emails you forward are marketing messages sent by brands; once ingested they are de-identified and pooled across every organization that tracks the same brand (send cadence, health scores, send-time patterns, subject lines). They are not tied to your account, and deleting your account does not remove them — other organizations rely on the same shared record. No part of it stays identifiable to your organization once your account is erased.

Internal observability tables (request logs, webhook delivery logs, audit logs, usage records) follow a rolling 30-to-180-day retention policy enforced by a weekly automated job. These tables never contain user-facing content — only operational metadata used for debugging and rate-limit enforcement.

10. Cookies

We use essential cookies for authentication (Clerk session) and session management. These are set on page load and cannot be disabled without breaking the product.

We also use the following third-party cookies, all of which are gated behind explicit consent in our cookie banner and never set before you opt in:

  • Mixpanel (mp_* cookies, EU host) — product analytics: feature usage, funnel events, retention cohorts. No advertising.
  • Microsoft Clarity (_clck, _clsk cookies) — session replay and heatmaps used for UX research. Inputs, email content, and Stripe form fields are automatically masked.

Our own visit counter (see "Visit Counting" in section 2) uses no cookies and stores nothing on your device.

We do not use cookies for advertising or cross-site tracking. You can withdraw consent at any time via the "Cookie preferences" link in the footer.

11. Children's Privacy

StackEnhance is not intended for users under 16 years of age. We do not knowingly collect information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the platform. Continued use after changes constitutes acceptance.

13. Signal in ChatGPT and Claude

Signal by StackEnhance can be added to AI assistants such as ChatGPT and Claude as a read-only connector (an MCP server at https://stackenhance.com/api/mcp and https://mcp.stackenhance.com/mcp). It answers questions about brands' marketing email activity from public, aggregate facts. Using it requires no StackEnhance account and no sign-in.

When an assistant uses the connector, we receive only:

  • The tool request: the brand, market, category, date range or number of results the assistant asks about
  • Technical request data: including the IP address of the system that connects to us. When ChatGPT or Claude calls the connector from its own servers, this is normally the AI provider's address rather than your device's

We do not receive your conversation or your identity from the AI assistant, and nothing the connector receives is linked to a StackEnhance account. If an assistant attaches other metadata to a request, the connector does not read or store it.

We use the IP address only for rate limiting and abuse prevention. For operations and troubleshooting we log each request: the tool called, its arguments, the outcome and how long it took. The IP address is written to these logs only when a request is refused, for example for exceeding the rate limit. The logs are held by our hosting providers (Vercel and Railway) for a limited period. Answers are cached for up to an hour; the cache holds only the public facts, never who asked.

The conversation itself is handled by the AI assistant's provider — OpenAI for ChatGPT, Anthropic for Claude — under that provider's own privacy policy.

14. Contact Us

For privacy-related questions or to exercise your rights, contact us at:

Company: Stack Enhance AB

Org.nr: 559427-8375

Email: support@stackenhance.com