Privacy Policy
1. Controller and Contact
Controller under the GDPR is Gabriel Sgroi, Charlottenstr. 47, 73230 Kirchheim unter Teck, Germany. Email: support@mail.bookmer.com.
2. Scope of This Policy
This Privacy Policy explains how personal data is collected and processed when you use Bookmer, LoginSign, Bookmer ID, public pages, account functions, authentication, browser extensions, custom domains, developer tools, support, emails, payments and related services.
The Services are not intended for children under 16. We do not knowingly collect personal data from children where parental consent or another legal basis would be required.
3. Categories of Personal Data
Depending on how you use the Services, we may process the following categories:
- Account data: name, username, email address, profile image, account ID, language and settings.
- Authentication data: sessions, passkeys, OAuth providers, magic links, verification codes, login timestamps and security events.
- Bookmer content: bookmarks, folders, labels, icons, thumbnails, titles, descriptions, notes, wallpapers, domains and publishing settings.
- Public page data: published URLs, landing targets, social-preview metadata, public thumbnails, public titles and public descriptions.
- Technical data: IP address, device, browser, operating system, referrer, timestamps, logs, crash data and error events.
- Payment data: plan, subscription status, invoices, payment provider references and billing events.
- Communication data: support requests, newsletter data, abuse reports, legal notices and related correspondence.
- Developer data: application names, client IDs, redirect URLs, app icons, consent settings, API usage and integration metadata.
3. Local Data, Browser Storage and Synchronization
Some Bookmer data may be stored locally in your browser or device. If you use Bookmer without an account, certain information can remain local and may not be recoverable by us. If you use account-based synchronization, bookmarks, folders, settings and public-page data may be transmitted to and stored on our servers so that they are available across devices.
Browser storage, cache, cookies and extension storage can be deleted through your browser or device settings. Deleting local data can remove unsynchronized information.
3. Purposes of Processing
We process personal data to:
- create, secure and manage user accounts, sessions and profiles,
- provide bookmark management, synchronization, customization, search and publishing,
- operate LoginSign / Bookmer ID authentication, passkeys, OAuth and verification,
- send transactional emails, verification codes, security notices and support messages,
- process payments, subscriptions, invoices, cancellations and refunds,
- detect abuse, phishing, spam, malware, fraud, attacks and unauthorized access,
- maintain backups, troubleshoot issues and improve reliability,
- generate previews, thumbnails, metadata and public-page rendering,
- provide customer support and respond to legal or rights-holder requests,
- comply with legal, tax, accounting and regulatory obligations.
3. Legal Bases
- Contract performance, Art. 6(1)(b) GDPR: providing accounts, synchronization, subscriptions and requested features.
- Legitimate interests, Art. 6(1)(f) GDPR: security, abuse prevention, service reliability, troubleshooting and product improvement.
- Legal obligations, Art. 6(1)(c) GDPR: tax, accounting, consumer law, legal claims and regulatory duties.
- Consent, Art. 6(1)(a) GDPR: optional newsletters, optional analytics, optional cookies or other consent-based features.
3. LoginSign / Bookmer ID and Authentication
LoginSign / Bookmer ID processes account and authentication data to let you sign in, manage your profile and authorize connected applications. This can include OAuth provider data, email verification, passkeys, sessions, consent decisions, account switching, security events and device-related information.
When you authorize a connected application, that application may receive the information shown in the consent or integration flow. Developers are responsible for their own services, terms and privacy practices.
3. Email, Alias Addresses and Forwarding
Transactional emails may be sent through infrastructure such as Amazon SES. Alias or relay addresses may be used to forward messages to the real email address connected to your account. We may process headers, delivery events, bounce events and complaint events to provide forwarding, prevent spam and protect deliverability.
3. Public Pages, Search Engines and Social Previews
If you publish or share Bookmer pages, selected content can be visible to visitors. Search engines may index public pages if visibility is enabled. Messengers, social networks and crawlers may read public metadata such as title, description, thumbnail and URL.
Public data can be copied, cached or archived by third parties outside our control. If you remove a public page, external caches or search results may take time to update.
3. Thumbnails, Icons and External Metadata
To display bookmarks and public pages, the Services may fetch or process icons, thumbnails, screenshots, metadata and preview information from URLs you add. This may reveal to the target website or infrastructure provider that a URL was requested.
3. Cookies and Similar Technologies
We use cookies, local storage and similar technologies for sessions, login, security, preferences, synchronization and core functionality. Optional analytics or marketing technologies are used only where legally permitted or where consent is obtained.
3. Analytics, Logs and Error Reporting
We may process aggregated usage data, technical logs, performance data, crash reports and error information to operate, secure and improve the Services. Logs are also used to investigate outages, fraud, abuse, security incidents and support requests.
3. Payments and Billing
When you purchase paid services, payment data is processed by payment providers. We receive information needed to manage the subscription, verify payment status, issue invoices, process cancellations and handle refunds. We do not store full payment card numbers unless a payment provider explicitly provides tokenized references required for recurring billing.
3. Service Providers and Recipients
We may use providers for hosting, databases, storage, email delivery, DNS, payments, analytics, crash reporting, push notifications, support, security, monitoring and content delivery. Depending on the feature, providers may include infrastructure, identity, payment and email providers such as hosting providers, Amazon SES, Stripe, PayPal, Apple, Google or similar services.
We may disclose data to authorities, courts, advisors, rights holders or third parties where required by law, necessary to defend rights, or necessary to investigate abuse, security incidents or unlawful content.
3. International Transfers
Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions, Standard Contractual Clauses or other safeguards required by GDPR. Some third-party providers may process data in countries with different data-protection standards.
3. Security Measures
We use technical and organizational measures to protect personal data, including transport encryption, access controls, monitoring, backups, logging, separation of roles and security-focused development practices. No online service can guarantee absolute security. You must protect your own devices, sessions and credentials.
3. Retention
We keep personal data only as long as necessary for account operation, service delivery, security, legal claims, backups, tax, accounting and regulatory obligations. Some logs may be retained for a limited period for abuse prevention and security. Backup deletion can take additional time.
3. Account Deletion and Data Export
You can request account deletion through the product where available or by contacting support. Deletion removes account-related data from active systems where possible. Before deletion, export any content you want to keep. Limited backup, legal or security retention may continue for a restricted period.
3. Your Rights
You may request access, rectification, deletion, restriction, portability, objection and withdrawal of consent where applicable. You also have the right to complain to a competent data-protection supervisory authority. To exercise rights, contact support@mail.bookmer.com.
3. Changes to This Policy
We may update this Privacy Policy when the Services, legal requirements, providers, security practices or processing activities change. The latest version is published centrally under bookmer.com/legal/privacy.