Pedrablanca Digital Group LLC · Effective Date: March 23, 2026 · Last updated: March 23, 2026
Data requests: privacy@restackd.com
When visitors view your public profile page at yourname.restackd.com, we collect aggregate visit counts and click metrics. We do not track individual visitors beyond their session.
| Purpose | Legal Basis (GDPR) |
|---|---|
| Delivering the platform and features | Contract performance |
| Personalizing AI content to your voice profile | Contract performance |
| Processing payments and subscriptions | Contract performance |
| Sending account, billing, and product notifications | Contract performance / Legitimate interest |
| Improving the platform and debugging | Legitimate interest |
| Fraud prevention and security | Legitimate interest / Legal obligation |
| Responding to data requests and legal compliance | Legal obligation |
| Marketing communications (optional, opt-in) | Consent |
We do not sell your personal information to third parties.
We share data with the following service providers to operate Restackd:
We do not use advertising networks or sell data to data brokers.
We use session cookies for authentication (to keep you logged in) and local storage for preferences. We do not use third-party advertising or analytics cookies. You can clear cookies via your browser settings; this will log you out of Restackd.
We retain different types of data for different periods based on legal requirements, business necessity, and your privacy rights. Details are below:
| Data Category | Retention Period | Reason |
|---|---|---|
| Personal Profile (name, email, avatar) | Duration of account + 1 year after last login | Contract performance; deleted upon account closure |
| Financial Records & Tax Forms | 7 years from transaction | IRS Code §6001 (tax recordkeeping requirement); preserved even upon deletion |
| Payment & Payout Records | 7 years from transaction | Tax reporting, chargeback defense, payment processor requirements |
| Seller Agreements & Signatures | 7 years from acceptance | Legal protection and tax compliance |
| Product Licenses & Sales History | Until expiration + 7 years | Tax records and revenue reconciliation |
| User-Generated Content (posts, pages, products) | Duration of account use | Deleted within 30 days of account closure; 30-day grace for exports |
| AI Chat History & Interaction Logs | 1 year of inactivity | Service improvement; deleted upon account closure |
| Traffic & Analytics (IP addresses) | 90 days (then hashed) | GDPR compliance; IP/user-agent anonymized after 90 days |
| Anonymized Analytics & Metrics | Indefinite | No PII; used for service improvement |
| OAuth & Integration Tokens | Duration of active integration | Security best practice; deleted on revocation or account closure |
| Affiliate & Referral Data | 7 years | IRS 1099-NEC reporting requirement |
| Compliance & Audit Logs | 7 years from event | Legal protection and regulatory compliance |
When you request account deletion:
We use automated processes to enforce data retention:
You have the right to request access, correction, or deletion of your personal data. Submit requests to privacy@restackd.com. We will respond within 30 days (45 days for CCPA requests). Note: We cannot delete data required by law (e.g., financial records for tax purposes).
We protect your data using industry-standard practices: HTTPS encryption for all data in transit, hashed and salted authentication tokens, restricted database access controls, and regular security reviews. No system is 100% secure. If you believe your account has been compromised, contact security@restackd.com immediately.
Under the California Consumer Privacy Act (CCPA), California residents have additional rights: the right to know what personal information we collect and how it is used; the right to deletion; the right to opt-out of the sale of personal information; and the right to non-discrimination for exercising these rights.
We do not sell your personal information. We share data only with service providers (Stripe, Google, Anthropic) as described in Section 3, solely to operate the platform. To submit a CCPA request — including requests to know, delete, or confirm opt-out — email privacy@restackd.com with the subject "CCPA Request". We will respond within 45 days as required by law.
If you are in the European Economic Area or United Kingdom, you have rights under the GDPR including the right of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and to object to processing based on legitimate interests. You also have the right to lodge a complaint with your local supervisory authority. To exercise your GDPR rights, contact privacy@restackd.com.
We respond to all verified rights requests within 30 days.
Restackd is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact privacy@restackd.com and we will promptly delete it.
Your data may be processed in the United States and other countries where our service providers operate. By using Restackd, you consent to this transfer. Where required, we implement appropriate safeguards such as Standard Contractual Clauses for transfers from the EEA.
We may update this policy from time to time. Significant changes will be communicated via email or an in-app notice at least 14 days before taking effect. The "Last updated" date at the top reflects when this policy was last changed.
Pedrablanca Digital Group LLC
Privacy: privacy@restackd.com
Security: security@restackd.com
General: hello@restackd.com
We aim to respond to all privacy inquiries within 5 business days.
© 2026 Pedrablanca Digital Group LLC. All rights reserved.