⚠️ DRAFT — NOT LEGAL ADVICE. Prepared as a starting point for Spread; must be reviewed by a qualified Belgian/EU (GDPR) lawyer before use. Placeholders in
[brackets]need filling. Last drafted: 2026-06-02. Last updated: 2026-08-11.
Spread — Privacy Policy
This policy explains how Harold Taeter, a sole trader (entreprise personne physique) established in Belgium and trading as "Spread" ("Spread", "we") handles your personal data when you use Spread. We are the data controller. You can reach us at privacy@spreadmymessage.com, or by post at:
Avenue Prince Baudouin 19 4802 Heusy (Verviers) Belgium
[Reviewer note: the controller is the founder as a sole trader — registered 2026-08-06, so this is now the settled position rather than a pre-incorporation placeholder, and the address above is his own (there is no separate business premises). Two things still to come: the enterprise/VAT number, and a re-check if the controller becomes an SRL/BV — which is a change of controller identity and therefore a material change under §9, obliging direct notice to every data subject. See docs/legal/LEGAL-REVIEW.md §1 and docs/legal/ACCOUNTANT-REVIEW.md §1.1.]
1. What we collect
- You give us: your name, email address, the ad message and image you submit, and the location you target. Optionally, if you tick the marketing opt-in, we record that consent.
- Contact details we publish. Every ad must carry a way for people to reach you — at least one of a phone number, a WhatsApp number or a public email address, plus an optional website link. This is the whole point of the ad: it is shown publicly on your ad's page, on the board if you list it there, and it is where your Meta ad sends people. Please use details you are willing to make public. It is deliberately separate from the email address above, which we use only to reach you and never publish.
- How your ad was set up and how it did. Your ad's page also shows what you paid, the size of the area you targeted, how long the ad runs, and how many times it was shown and clicked, so that someone who sees your ad can understand what putting one out involves. Two The area shown is the one you targeted — the map on your page draws the same circle your ad is aimed at, so please choose a centre you are comfortable being seen. What the page never shows is your name or the email address you gave us to reach you.
- Payments: handled by Stripe, and by whichever payment method you choose to pay with — a card, or a service like PayPal, Apple Pay, Google Pay, Link or Amazon Pay. If you pick one of those, you sign in to them directly and they handle your details themselves; we never see your card number or your login for them. Whichever you use, we receive only limited payment metadata (e.g. the payer name and whether payment succeeded), not your full card details.
- If you join our waitlist: just your email address, and a record of the wording you agreed to and when. Spread is not open to everyone yet, so you can ask us to tell you when it is. We use that address for one email: the one that says we have opened. We do not use it for anything else, we do not add you to our marketing list, and we do not pass it on. Every message we send you carries a link that takes you off the list, and following it deletes your address rather than keeping a record of you.
- Automatically: basic technical/usage data (e.g. IP address, device/browser) when you use the site.
2. Why we use it, and our legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Create and run your ad on Meta; deliver results | Performance of our contract with you |
| Screen your ad against advertising policies (incl. via an AI provider) | Legitimate interests (compliance, account health) / contract |
| Take payment and prevent fraud | Contract / legitimate interests |
| Email you status and results | Contract |
| Meet legal, tax and platform obligations | Legal obligation |
| Send you marketing emails (updates, tips) — only if you opt in | Consent (withdraw anytime via the unsubscribe link) |
| Tell you when Spread opens — only if you asked us to, on the waitlist | Consent (withdraw anytime via the link in any email we send; it deletes your address) |
| Cookies / analytics, where used | Consent (see Section 6) |
3. Who we share it with (processors and recipients)
We share data only as needed to provide the service:
- Meta — to create, run and report on your ad. Your ad is published publicly, and the information you submit for it is processed under Meta's own terms. (For ads shown in the EU, Meta also requires the advertiser's name to appear with the ad — this applies when we expand to the EU.) Meta also receives consent-based measurement data about visitors to the hosted ad page (Pixel / Conversions API — see Section 6).
- Stripe — to process your payment. If you choose to pay with PayPal, Apple Pay, Google Pay, Link, Amazon Pay or Klarna rather than by card, that company also handles your payment, under its own privacy policy and the account you hold with it.
- Resend — to send you transactional emails (status, results).
- Anthropic — your ad text and image are sent to Anthropic's API to screen them against advertising policy. They process it to return a moderation result and do not use it to train models.
- Neon — the database your submission is stored in. Vercel — hosting; it processes every request to the site.
- Inngest — runs our background jobs (moderation, emails, scheduled clean-ups). Because it has to be able to resume a job after a failure, it holds the job's working state, which can include your email address.
- LocationIQ — turns the place you type into a map position, and a map position back into a place name. It receives what you type in the location box and the coordinates of the pin you set.
- Cloudflare — stores your ad image (R2), and runs the anti-bot check on the form (Turnstile), which receives your IP address.
- Sentry — collects error reports when something breaks, so we can fix it. It is configured not to collect personal data, and we strip email addresses and private links from reports before they are sent.
We do not sell your personal data.
4. International transfers
Some processors (e.g. Anthropic, Stripe, Resend, Meta) may process data outside the EEA, including in the United States. Where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy mechanism. [Confirm each processor's mechanism.]
5. How long we keep it
We keep your data only as long as we need it:
- Your ad and account data — the name (where collected), email, message, image, location and the screening record — is kept for up to 12 months, then anonymised: we clear the personal details and keep only a non-personal record of the transaction (see below). The 12 months run from the point we've finished doing anything with your ad — whichever is latest of: your most recent ad, the end of its run, the day your board listing comes down (including any renewals), and the settling of any payment or card dispute. So a listing you keep renewing stays up, and its data stays with us, for as long as you keep renewing it.
- Financial and transaction records — amounts, payment references and invoices — are kept for 7 years, because Belgian accounting and tax law requires it. These are kept in a minimised form that no longer needs your message or image.
- Marketing data — kept until you unsubscribe; after that we keep only a minimal record of your opt-out so we don't email you again.
- Waitlist data — your address is kept until you take yourself off the list, and in any case for no more than 12 months from the day you joined, after which we delete it whether we have opened or not. Leaving the list deletes your address outright; unlike the marketing list above, we keep no record that you were ever on it, because there is nothing left for such a record to protect you from.
- How long your ad's page stays public — separate from how long we keep the data. The page we host for your ad (the one your ad links to) is publicly reachable while your ad is running and for 7 days afterwards. If you also choose to list it on our public board, it stays reachable for 60 days from the day you list it; we email you before that runs out, and you can renew it or take it down at any time from your status page. After that the page stops being publicly reachable, whether or not we still hold the underlying data under the periods above.
[Reviewer note: these periods (12 months / 7 years) are our provisional best-guess defaults — confirm against Belgian accounting law + a GDPR proportionality view at legal review. See docs/legal/LEGAL-REVIEW.md.]
6. Cookies & measurement on hosted ad pages
We use only the cookies necessary to run the site by default. On the public ad pages we host (the page a Meta ad links to, and the page a board listing opens), we use the Meta Pixel and Meta's Conversions API to measure how the ad performs — for example, that the page was viewed and that someone tapped a contact button. These set advertising cookies and share the visitor's IP address, device/browser information and interaction with Meta (acting as an independent controller under its own terms).
This measurement loads only with the visitor's consent: nothing fires until you choose Accept on the banner shown on the page, and Decline leaves the page fully usable with no Pixel and no cookies set. Your choice is remembered on your device so we don't ask again. This processing is based on consent (GDPR Art. 6(1)(a) / ePrivacy). You can change your mind at any time: at the foot of the page there is a line showing your current choice with a Change link, which brings the banner back so you can accept or decline again. Withdrawing takes effect immediately and is as easy as giving it in the first place.
Separately from the Meta measurement above, we keep simple aggregate statistics for each hosted ad page — a running count of page views and of taps on the contact buttons — so the advertiser can see how their campaign is doing. These are plain totals: they set no cookies, store nothing on your device, and record nothing about you individually (your IP address is used transiently only to rate-limit abuse, and is not stored with the count).
To be explicit about what the banner's choices mean: Accept loads the Meta Pixel and shares the measurement data described above with Meta; Decline means no Pixel, no advertising cookies, and nothing shared with Meta. The anonymous page totals are kept in both cases — they are not affected by the banner, because nothing is placed on or read from your device and no personal data is retained. To the extent any processing is involved at all, it is based on our legitimate interest (GDPR Art. 6(1)(f)) in reporting campaign performance to the advertiser.
Note: this section concerns visitors to a hosted ad page, who may be different people from the advertiser who submitted the ad.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your data, and to withdraw consent where processing is based on consent. If you opted in to marketing, you can withdraw that consent at any time via the unsubscribe link in any marketing email (or by contacting us). To exercise any of these, contact privacy@spreadmymessage.com. You also have the right to lodge a complaint with your supervisory authority — in Belgium, the Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit).
8. Children
Spread is not directed to anyone under 18, and you must be 18+ to use it.
9. Changes to this policy
If we make a material change to this policy — for example a new purpose for using your data, a new recipient we share it with, a change to who the data controller is, or a change to how you exercise your rights — we will contact you directly, by email to the address you gave us, to tell you what has changed and what it means for you. That message will be about the change and nothing else. Where a change is a significant one, we will tell you before it takes effect, so you have time to consider it and to exercise your rights.
We will not rely on you checking this page. Minor edits — a typo, or rewording that doesn't change what we do — aren't treated as material changes; they're simply recorded below with a new Last updated date at the top of this page.
Every substantive change is listed here, so you can see what changed and when.
| Date | What changed |
|---|---|
| 2026-08-11 | Sections 1, 2 and 5: a new waitlist. Spread is not open to everyone yet, so you can now leave your email address to be told when it is. That address is used for one email and nothing else, it does not put you on our marketing list, and the link in any message we send takes you off the list and deletes your address. If you never leave it, nothing here affects you: this adds a place to give us an address, not a new use of one we already have. Written before launch, so it describes the service as it will first operate rather than a change to anything already running. |
| 2026-08-10 | Section 6: you can now change your cookie choice at any time. The foot of a hosted ad page shows the choice you made with a Change link that brings the banner back, so accepting and then declining (or the reverse) takes one click. This section used to tell you to clear your browser's storage, which was not a fair answer: withdrawing consent has to be as easy as giving it. Nothing about what we collect has changed. The banner's own wording was also rewritten to say plainly that it is about cookies, and that accepting tells Meta you visited. |
| 2026-08-09 | Section 1: your ad's page also shows how the ad was set up and how it did — what you paid, the area you targeted (as a map), how long it runs, and how many times it was shown and clicked — so that someone who sees your ad can understand what putting one out involves. The area shown is the one you chose, so pick a centre you're happy to have seen; the form says so where you set it. What the page does not show is your name, which we have also stopped putting in the page's title — the title is now the same on every page of the site. Written before launch, so this describes the service as it will first operate rather than a change to anything already running. |
| 2026-08-07 | Sections 1 and 3: you can now pay with PayPal, Apple Pay, Google Pay, Link or Amazon Pay as well as by card, so these sections name them. If you pick one, you sign in to that company directly and it handles your payment details itself, under its own privacy policy — we still never see your card number or your login. Nothing new is collected or stored about you, and nothing changed for paying by card; this names the companies that can now be involved. |
| 2026-08-06 | Who we are, at the top: we now give our full identity and a postal address — Spread is run by Harold Taeter as a sole trader established in Belgium, registered on this date. Nothing about how your data is handled has changed; this tells you exactly who the data controller is and gives you a second way to reach us. |
| 2026-08-06 | Section 6: removed the part added the day before about people who comment on an ad. We have postponed that feature until after launch, so we do not copy anyone's comments and hold nothing about a commenter. This takes data away rather than adding any: if it comes back, this section comes back with it and will be listed here again before it does. |
| 2026-08-05 | Section 6: a new part for people who comment on an ad — we now copy the comments left on an ad across to the private results page of the person who placed it, so replies actually reach them (our ads run from Spread's own Facebook and Instagram accounts, so the comments land with us). It sets out exactly what we hold about a commenter, why, who sees it, and how to have it removed. Nobody's data is published by this, and no comment is used to contact, profile or advertise to anyone. |
| 2026-08-04 | Sections 1 and 3, both describing what we already do rather than changing it. Section 1 now says that the contact details on your ad (phone / WhatsApp / public email, and any link or display name) are collected to be published — they are the ad's whole point — and are separate from the email we use to reach you, which is never published. Section 3 now names every company that handles your data, not just the main four: Neon (the database), Vercel (hosting), Inngest (background jobs, which can hold your email address while a job is running), LocationIQ (turning what you type into a map position), Cloudflare (image storage and the anti-bot check, which sees your IP) and Sentry (error reports, with personal data stripped). No new sharing began on this date; these were missing from the list. |
| 2026-08-01 | Section 5: spelled out when the 12-month retention clock starts — it runs from the point we've finished with your ad, so a board listing you keep renewing keeps its data with us. No change to how long we keep anything; this describes what already happens. |
| 2026-07-31 | No change to how we handle your data. Rewrote this section: we now commit to telling you directly about material changes rather than only posting them here, and added the Last updated date and this change history. |
| 2026-07-30 | Section 5: added how long the ad page we host for you stays publicly reachable (while your ad runs plus 7 days; 60 days from listing if you also put it on our public board), separately from how long we keep the data. |
| 2026-07-16 | Section 6: spelled out what the banner's Accept and Decline each do, and that the anonymous page totals are kept either way. |
| 2026-07-15 | Section 6: disclosed the consent-free aggregate counters on hosted ad pages (page views, contact taps) and the legitimate-interest basis for them. |
| 2026-06-23 | Section 6 rewritten: disclosed the Meta Pixel and Conversions API on hosted ad pages, what is shared with Meta, and that this loads only with the visitor's consent. Section 3 updated to match. |
| 2026-06-16 | Named the data controller and the privacy contact address (previously placeholders), and set concrete retention periods (12 months for ad and account data; 7 years for financial records). |
This history was reconstructed from our change records on 2026-07-31; changes before that date were not stamped in the policy at the time they were made.
10. Contact
Privacy questions or requests: privacy@spreadmymessage.com.