Privacy Policy
Last updated: August 2, 2026
1. Controller
The controller responsible for data processing is:
Holger Sadek, BSc, Berggasse 20, 1090 Vienna, Austria
Email: hello@yul.io
2. Processed data
When using yul.io, the following personal data may be processed:
- Account data: name, email address, password, profile picture
- Gift data: recipient name, occasion, date, images
- Participant data: name and email address (required), optional videos, images and comments
- Technical data: IP address, browser information and access data (server logs)
- Token-based access data for share and surprise links
- Advertising attribution data: pseudonymous click identifiers (GCLID, GBRAID or WBRAID), conversion type and time and, for purchases, transaction ID, value and currency
- Internal campaign-progress data: a random identifier for the currently open wizard, wizard steps reached, Google UTM campaign parameters and the coarse country segment Germany, Austria, other or unknown
3. Purposes of processing
Personal data is processed for the following purposes:
- Providing and operating the platform
- Creating and managing video gifts
- Technical processing and rendering of content
- Communicating with users, for example by email
- Ensuring system security and preventing misuse
- Measuring the effectiveness of paid advertising and allocating the advertising budget efficiently
4. Legal bases
Personal data is processed on the basis of the following legal grounds:
- Art. 6(1)(b) GDPR for the performance of a contract
- Art. 6(1)(f) GDPR for legitimate interests in security, reliable operation and measuring advertising effectiveness
- Art. 6(1)(a) GDPR based on consent, including the limited transfer of Google Ads conversion data described below
5. Hosting and infrastructure
yul.io uses the following technical service providers:
- Cloudflare (Pages, Workers, D1, R2 - EU region)
- Amazon Web Services (S3 and EC2 in Ireland, CloudFront)
- Mailgun (EU) for email delivery
- Stripe for payment processing
- Cloudflare Turnstile for bot protection
These providers process data only to the extent necessary to provide their services.
Processing generally takes place within the EU or EEA. Where providers are based outside the EU/EEA or data transfers cannot be fully excluded, transfers may be based on appropriate safeguards such as standard contractual clauses.
6. User content
Users may upload content such as videos, images and text.
Such content may contain personal data.
Processing takes place solely for the purpose of providing the platform and creating the final video compilation.
7. Email communication
yul.io sends transactional emails only, for example:
- verification emails
- comment notifications
- upload confirmations
- render status updates
- payment confirmations
- support communication
No newsletters or marketing emails are sent.
8. Payment processing
Payments are processed through Stripe Checkout.
In this context, personal data such as payment-related information may be processed.
The exact scope of processing depends on Stripeβs standard checkout process and the data provided there.
Payment processing is carried out directly by the payment service provider.
10. Google Ads conversion measurement
If a landing-page URL contains a pseudonymous Google Ads click identifier, such as the Google Click ID (GCLID), GBRAID or WBRAID, we show a separate choice for Google Ads conversion measurement on larger screens. This choice is not shown on mobile. The choice is temporarily remembered in session storage for the current browser tab. If a project is created from the visit, we record the click identifier server-side, associate it with that project and document any choice already made.
Only if the organizer actively consents may we transmit the click identifier together with the event type and time when a relevant action occurs, such as creating an active project, receiving a first external contribution or making a purchase. For a purchase, the transmitted data may also include the transaction ID, value and currency. An explicit refusal on the landing page is respected. If no choice is made, including on mobile, no conversion data is sent to Google.
For this measurement, we do not use marketing or tracking cookies, browser-side Google tags, Google Tag Manager or Google Analytics. The permission is limited to conversion measurement and does not include personalized advertising. In particular, we do not transmit names, email addresses or telephone numbers. However, Google can associate the pseudonymous click identifier with the original ad click.
Separately from any transfer to Google, for visits labelled with the fixed Google CPC source we record aggregate landing-page traffic. This includes the UTC day, landing-page path, referrer hostname, visit count, visible-active thresholds after 10, 30 and 60 seconds, and total visible active time. The traffic beacon sends no Google click identifier, UTM campaign parameter, visitor identifier or browser identifier, and uses no cookie or browser storage. These aggregate traffic statistics are not transferred to Google.
Separately from any transfer to Google, for visits labelled as Google CPC traffic we record internally which creation-wizard steps are reached. A random identifier is created when the wizard opens and exists in memory only while that wizard remains open. We store that identifier, the step reached, UTM campaign parameters, the page path and a coarse segment derived from Cloudflare's country code (Germany, Austria, other or unknown). This dataset does not store a Google click identifier, IP address, browser identifier, name or contact details and is not transferred to Google. Processing is based on Art. 6(1)(f) GDPR to evaluate the onboarding flow and campaign effectiveness.
The internal recording and assignment of the click identifier is based on Art. 6(1)(f) GDPR. Our legitimate interest is to understand the effectiveness of our advertising and to allocate our advertising budget efficiently. The transmission of conversion data to Google is based exclusively on consent under Art. 6(1)(a) GDPR.
Raw click identifiers and internal campaign-progress data are stored for no longer than 90 days and are then deleted. The consent decision itself may be retained for as long as necessary to document the choice and comply with legal obligations.
The choice applies to later projects started through our Google ads as well. Consent can be withdrawn at any time with effect for the future by emailing hello@yul.io. After withdrawal, no further conversion events are sent to Google.
If consent is given, the limited transfer is made to the Google contracting entity responsible for our Google Ads account and is performed server-side through the Google Data Manager API. Further information about Google's processing of data and possible transfers to third countries is available at https://policies.google.com/privacy.
11. Server logs
When accessing the platform, technical access data may be processed, such as IP address, timestamp, browser information and request data.
These logs are provided through Cloudflare as part of the infrastructure.
Storage is based on Cloudflareβs default logging configuration and any applicable legal retention obligations.
12. Retention period
Source media for video gifts with a paid final video is stored for 3 months after the first paid final video was rendered. The paid final video is stored for 6 months after rendering.
Source media for video gifts with only unpaid final videos is stored for 1 month after the first final video was rendered. Unpaid final videos are stored for 2 months after rendering.
If no final video has been rendered, uploaded source media is stored for 3 months after the first upload, provided the last upload is at least 1 month old.
When an automatic retention period expires, affected files are moved to trash and permanently deleted after 14 days. Users may extend storage once by 1 month; further extensions require contacting support.
Users may delete content, video gifts and accounts themselves at any time.
Statutory retention obligations remain unaffected.
13. Rights of data subjects
Users have the following rights under the GDPR:
- access to stored personal data
- rectification of inaccurate data
- erasure
- restriction of processing
- data portability
- objection to processing
- withdrawal of consent at any time with effect for the future
14. Right to lodge a complaint
Data subjects have the right to lodge a complaint with a supervisory authority.
In Austria, the competent authority is the Austrian Data Protection Authority.
15. Sources of data
Data is collected either directly from users, for example when creating an account or uploading content, or automatically when using the platform.
Data may also be provided by other users within the context of a video gift, for example where an owner enters recipient details or participants contribute content.
16. Data relating to third parties
Users may upload content that contains personal data of other persons.
Users are responsible for ensuring that they are authorized to share and submit such data for processing.
17. Changes
This Privacy Policy may be updated if necessary.