nandzz
Nandzz logonandzz

Where businesses and clients connect.

PlatformGet Started
LegalTerms & ConditionsPrivacy PolicyCookie PolicyAcceptable UseData Processing AgreementLegal notice
SupportContact UsReport content

© 2026 nandzz. All rights reserved.

Nandzz - Share what you create | Product Hunt
HomeSign in
TermsPrivacyCookiesAcceptable UseDPAReport contentLegal notice

Privacy Policy

How Nandzz collects and uses personal data, and the rights you have. This covers account holders, visitors and people who book through a Nandzz page.

Effective: 6 October 2026·Read in Italiano

This document is also available in Italian. For consumers resident in Italy, the Italian version prevails.

The short version

  • We collect only what we need to run Nandzz, take payments, keep the service secure and meet legal duties.
  • We do not sell your data, show ads or use tracking cookies. Visitor statistics are cookieless and anonymised.
  • If you book with a business through Nandzz, that business is in charge of your data. We process it on their behalf.
  • You can access, correct, export and delete your data. You can also write to us at [email protected].

Contents

  1. Who is responsible
  2. What we collect, why, and on what legal basis
  3. Your right to object to legitimate interests
  4. If you book through a Nandzz page
  5. Who we share data with
  6. International transfers
  7. Security
  8. Your rights
  9. Children
  10. Cookies
  11. Additional information for the UK and the United States
  12. Changes to this policy

1. Who is responsible

The data controller is [LEGAL NAME] S.r.l., [STREET, POSTCODE CITY (PROVINCE)], Italia, VAT [P.IVA — pending registration]. You can reach us at [email protected] or by PEC at [PEC ADDRESS].

We have not appointed a Data Protection Officer, because the law does not require it for our activities. Your requests are handled directly by the team responsible for privacy.

Bookings and AI chats on a business's page.Each business using Nandzz controls the personal data of its own customers. We act as that business's processor under Art. 28 GDPR (see our DPA). This applies to:

  • bookings you make on a business's page
  • messages you send to its AI agent

For requests about that data, contact the business directly. We will help them answer you. Section 4 explains this in more detail.

2. What we collect, why, and on what legal basis

The table below lists each processing activity under the GDPR (Regulation (EU) 2016/679), with the data used, the legal basis under Art. 6 GDPR, and how long we keep it.

ActivityDataLegal basisRetention
Account and sign-inEmail, password (hashed), username, display name, Google account name, email and avatar if you use Google sign-in, phone number if you verify itContract (Art. 6(1)(b))While your account exists. Deleted within 30 days of account deletion.
Your public page and contentProfile details, bio, avatar, branding, business address, published content, links, gallery, comments, likes and followsContract (Art. 6(1)(b))Until you delete it or your account
Payments and invoicingName, email, billing address, plan, transactions, credit history. Card data stays with Stripe.Contract; legal obligation (tax and accounting, Art. 6(1)(c))10 years, as required by Italian accounting law (Art. 2220 Civil Code)
Service emails and messagesEmail or phone number, message contentContract; legitimate interest in security noticesDelivery logs for 24 months
Cookieless visitor statisticsA one-way hash of IP address, browser user-agent and date, which rotates every day. Raw IP addresses are never stored. If you are signed in, your user ID is used instead.Legitimate interest (Art. 6(1)(f)): showing page owners how many people visit13 months
Security and abuse preventionIP address, request and authentication logs, rate-limit countersLegitimate interest: keeping the service secureUp to 90 days, unless needed for an investigation
AI features you useInstructions and content you submit to the AI editorContractNot stored by us beyond the job result. The provider keeps it for up to 30 days for abuse monitoring.
Support and contact formName, email, your messageLegitimate interest in answering you; contract where it relates to your accountUp to 24 months after the conversation ends
Content reports (DSA)URL reported, reason, your name and email if givenLegal obligation (DSA Art. 16)24 months
Terms acceptance recordsVersion accepted and timestampLegal obligation and legitimate interest in proving consent and acceptanceWhile your account exists

We do not use your data for advertising, profiling or automated decisions with legal or similarly significant effects (Art. 22 GDPR). We do not use your content or your customers' data to train AI models.

Providing account and payment data is necessary to use those features. Everything else is optional.

3. Your right to object to legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights. We keep the data minimal, for example by hashing visitor data daily. You can object at any time by writing to [email protected]. We will stop unless we have compelling legitimate grounds, or need the data for legal claims.

4. If you book through a Nandzz page

When you book an appointment or chat with an AI agent on a business's Nandzz page, the business collects the following data, and its own staff can see it:

  • your name and phone number
  • your email, if you give it
  • your address, if the business asks for it
  • your notes
  • the appointment details
  • your chat messages

The business is the controller, and Nandzz processes the data on its behalf. Its own privacy notice applies. Ask the business directly if you want to exercise your rights.

On the business's behalf, we:

  • store your booking
  • send confirmation, change and reminder emails
  • send a WhatsApp reminder via Twilio, only if you tick the box. To stop reminders later, ask the business.
  • generate AI chat answers via OpenAI. Chat messages are not kept by us after the answer is sent.

Booking customer details are anonymised automatically 24 months after the appointment, or earlier if the business deletes them or closes its account.

If you are signed in to your own Nandzz account when you book, we also link the booking to your account so you can manage it. For that link we are the controller, and the legal basis is contract.

5. Who we share data with

We do not sell or rent personal data. We share it only with:

  • Service providers (processors) that help us run Nandzz, under contracts that bind them to our instructions. They are listed below.
  • Businesses you book with, which receive the booking data you enter.
  • The public, for content you choose to publish on your page.
  • Authorities, when the law requires it, or to protect rights and safety.
  • A buyer or successor, if Nandzz is merged or sold. They will be bound by this policy, and we will tell you first.

Sub-processors

ProviderPurposeDataLocationTransfer safeguard
Supabase, Inc.Database, authentication, file storage, server functionsAll account, content, booking and billing recordsEU (AWS Ireland / Frankfurt)EU hosting; SCCs for support access from the US
Amazon Web Services EMEA SARL (Amplify, CloudFront, SES)Website hosting and delivery; transactional email (booking confirmations and reminders)IP address, request metadata, email address and message contentEU/EEANot required (EU/EEA)
Stripe Payments Europe, Ltd.Payments, subscriptions, invoices, fraud preventionName, email, billing address, payment method (we never see full card numbers)Ireland; Stripe, Inc. (US)EU–US Data Privacy Framework and/or Standard Contractual Clauses
Twilio Inc.WhatsApp booking reminders and replies; phone verification SMSPhone number, message contentUnited StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses
OpenAI, L.L.C.AI agent answers and document search (embeddings)Chat messages typed by visitors; documents uploaded by the businessUnited StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses
Anthropic, PBCAI-assisted editing of your contentContent and instructions you submit to the AI editorUnited StatesStandard Contractual Clauses
Google Ireland Ltd. / Google LLCSign in with Google; address autocomplete (Places) when you type an addressGoogle account name, email, avatar; typed address text and IP addressIreland; United StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses
Web3FormsDelivery of contact-form messagesName, email, messageUnited StatesStandard Contractual Clauses

6. International transfers

Our main database is hosted in the EU. Some providers in the table above are based in the United States or may access data from there. When data leaves the EU/EEA, we rely on safeguards:

  • the EU–US Data Privacy Framework, for certified recipients (Art. 45 GDPR adequacy decision)
  • the European Commission's Standard Contractual Clauses (Art. 46 GDPR), with additional measures where needed

You can ask us for a copy of these safeguards.

7. Security

We protect data with:

  • encryption in transit (TLS) and at rest
  • row-level access controls in the database
  • least-privilege access for staff
  • hashed passwords
  • isolated (sandboxed) rendering of user-uploaded web content

No system is perfectly secure. If a breach is likely to put you at risk, we will notify you and the competent authority as the law requires.

8. Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy
  • rectify inaccurate data. Most of it you can edit yourself in Settings.
  • erase your data. Delete your account in Settings, or ask us.
  • restrict processing in certain cases
  • data portability. Use "Download my data" in Settings to get a machine-readable JSON file.
  • object to processing based on legitimate interests (section 3)
  • withdraw consent at any time, without affecting earlier processing

Write to [email protected]. We answer within one month. In complex cases this can be extended by two more months, and we will tell you if so. We may ask you to confirm your identity.

You also have the right to complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali. You can also complain to the authority where you live or work.

9. Children

Nandzz is not intended for children under 14, and they may not create an account. If you believe a child under 14 has given us personal data, contact us and we will delete it.

10. Cookies

We use only technically necessary cookies and similar storage, so no consent banner is needed. See the Cookie Policy for the full list.

11. Additional information for the UK and the United States

United Kingdom.The UK GDPR gives you the same rights. You can complain to the Information Commissioner's Office (ico.org.uk). Transfers from the UK use the UK Addendum to the Standard Contractual Clauses, or the UK–US data bridge.

California and other US states. In the last 12 months we collected the categories described in section 2:

  • identifiers
  • commercial information
  • internet activity
  • user content

We used them for the business purposes described above. We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use sensitive personal information to infer characteristics.

You may request to know, correct or delete your personal information through the contacts above. We will not discriminate against you for exercising these rights. An authorised agent can make a request on your behalf, with proof of authorisation.

12. Changes to this policy

We update this policy when our processing changes. For significant changes, we will notify you in the app or by email before they apply. The date at the top shows the current version.