Spread — Privacy Policy
Last updated: 2026-08-30.
This policy explains how Harold Taeter, a sole trader (entreprise personne physique) established in Belgium and trading as "Spread" ("Spread", "we") handles your personal data when you use Spread. We are the data controller — enterprise number 1041.047.352, VAT number BE 1041.047.352. You can reach us at privacy@spreadmymessage.com, or by post at:
Avenue Prince Baudouin 19 4802 Heusy (Verviers) Belgium
1. What we collect
- You give us: your name, email address, the ad message and image you submit, and the location you target. Optionally, if you tick the marketing opt-in, we record that consent.
- Contact details we publish. Every ad must carry a way for people to reach you — at least one of a phone number, a WhatsApp number or a public email address, plus an optional website link. This is the whole point of the ad: it is shown publicly on your ad's page, on the board if you list it there, and it is where your Meta ad sends people. Please use details you are willing to make public. It is deliberately separate from the email address above, which we use only to reach you and never publish.
- How your ad was set up and how it did. Your ad's page also shows what you paid, the size of the area you targeted, how long the ad runs, and how many times it was shown and clicked, so that someone who sees your ad can understand what putting one out involves. The area shown is the one you targeted — the map on your page draws the same circle your ad is aimed at, so please choose a centre you are comfortable being seen. What the page never shows is your name or the email address you gave us to reach you.
- Payments: handled by Stripe, and by whichever payment method you choose to pay with — a card, or a service like PayPal, Apple Pay, Google Pay, Link or Amazon Pay. If you pick one of those, you sign in to them directly and they handle your details themselves; we never see your card number or your login for them. Whichever you use, we receive only limited payment metadata (e.g. the payer name and whether payment succeeded), not your full card details.
- If you contact us: whatever you choose to tell us. By email, that is your address and your message. By telephone, our line goes to voicemail, so it is the number you call from and a recording of the message you leave. We keep it only until we have dealt with it, and we do not record calls in any other way.
- Automatically: basic technical/usage data (e.g. IP address, device/browser) when you use the site.
If you appear in someone else's ad. An ad can mention or show a person who didn't submit it — a name in the message, a face in the photo. We have no way to reach such a person (we hold no contact details for them), so we say it here instead: what we hold is only what the ad itself contains, we use it only to screen and run that ad, and the person who submitted it promised us they had the right to include you. If you find yourself in an ad on Spread and want it changed or removed, contact privacy@spreadmymessage.com — you don't need an account or to have used Spread, and the same rights in Section 7 apply to you.
2. Why we use it, and our legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Create and run your ad on Meta; deliver results | Performance of our contract with you |
| Screen your ad against advertising policies (incl. via an AI provider) | Legitimate interests (compliance, account health) / contract |
| Take payment and prevent fraud | Contract / legitimate interests |
| Email you status and results | Contract |
| Meet legal, tax and platform obligations | Legal obligation |
| Send you marketing emails (updates, tips) — only if you opt in | Consent (withdraw anytime via the unsubscribe link) |
| Cookies / analytics, where used | Consent (see Section 6) |
How your ad is screened — an automated decision. When you submit an ad, it is checked automatically before anything is published: software, including an AI model, reads your message and image and compares them against Meta's advertising policies and our own acceptance rules — the categories we don't accept, the languages we support, and claims or content that could be misleading, unlawful or unsafe. This screening can decline your ad automatically, without a person having looked at it first. If that happens, we tell you the reason, you are not charged (the hold on your payment method is released), and you can ask for a human review: a real person with the authority to overturn the automated decision looks at your ad and decides afresh. We use this screening only to decide whether we can run the ad you asked us to run — never to profile you or for any other purpose.
3. Who we share it with (processors and recipients)
We share data only as needed to provide the service:
- Meta — to create, run and report on your ad. Your ad is published publicly, and the information you submit for it is processed under Meta's own terms. (For ads shown in the EU, Meta also requires the advertiser's name to appear with the ad — this applies when we expand to the EU.) Meta also receives consent-based measurement data about visitors to the hosted ad page (Pixel / Conversions API — see Section 6).
- Stripe — to process your payment. If you choose to pay with PayPal, Apple Pay, Google Pay, Link, Amazon Pay, Klarna or Satispay rather than by card, that company also handles your payment, under its own privacy policy and the account you hold with it.
- Resend — to send you transactional emails (status, results).
- Anthropic — your ad text and image are sent to Anthropic's API to screen them against advertising policy. They process it to return a moderation result and do not use it to train models.
- Neon — the database your submission is stored in. Vercel — hosting; it processes every request to the site.
- Inngest — runs our background jobs (moderation, emails, scheduled clean-ups). Because it has to be able to resume a job after a failure, it holds the job's working state, which can include your email address.
- LocationIQ — turns the place you type into a map position, and a map position back into a place name. It receives what you type in the location box and the coordinates of the pin you set.
- Zadarma — runs our telephone line. If you call and leave a message, Zadarma records it and sends the recording to us by email. It only ever holds what you say and the number you call from.
- Cloudflare — stores your ad image (R2), and runs the anti-bot check on the form (Turnstile), which receives your IP address.
- Google — if you give a link as your public contact, we send that link (and nothing else) to Google's Web Risk service, which tells us whether it is a known malware or phishing address. This runs before your ad goes anywhere public. We never open the link ourselves.
- Sentry — collects error reports when something breaks, so we can fix it. It is configured not to collect personal data, and we strip email addresses and private links from reports before they are sent.
We do not sell your personal data.
4. International transfers
Some of the companies in Section 3 process data outside the EEA — mostly in the United States; our geocoding provider (LocationIQ) is based in India. Where they do, the transfer is covered by an appropriate safeguard: several (including Stripe, Cloudflare, Vercel, Sentry, Anthropic and Meta) are certified under the EU–U.S. Data Privacy Framework (Google too), which the European Commission recognises as providing adequate protection, and for the others we rely on the EU Standard Contractual Clauses incorporated in their data-processing agreements. You can ask us at privacy@spreadmymessage.com which safeguard covers a given provider and how to obtain a copy of it.
5. How long we keep it
We keep your data only as long as we need it:
- Your ad and account data — the name (where collected), email, message, image, location and the screening record — is kept for up to 12 months, then anonymised: we clear the personal details and keep only a non-personal record of the transaction (see below). The 12 months run from the point we've finished doing anything with your ad — whichever is latest of: your most recent ad, the end of its run, the day your board listing comes down (including any renewals), and the settling of any payment or card dispute. So a listing you keep renewing stays up, and its data stays with us, for as long as you keep renewing it.
- Financial and transaction records — amounts, payment references and invoices — are kept for 7 years, because Belgian accounting and tax law requires it. As that law counts it, the period runs from 1 January of the year after the financial year the transaction belongs to. These records are kept in a minimised form that no longer needs your message or image.
- Marketing data — kept until you unsubscribe; after that we keep only a minimal record of your opt-out so we don't email you again.
- How long your ad's page stays public — separate from how long we keep the data. The page we host for your ad (the one your ad links to) is publicly reachable while your ad is running and for 7 days afterwards. If you also choose to list it on our public board, it stays reachable for 60 days from the day you list it; we email you before that runs out, and you can renew it or take it down at any time from your status page. After that the page stops being publicly reachable, whether or not we still hold the underlying data under the periods above.
6. Cookies & measurement on hosted ad pages
We use only the cookies necessary to run the site by default. On the public ad pages we host (the page a Meta ad links to, and the page a board listing opens), we use the Meta Pixel and Meta's Conversions API to measure how the ad performs — for example, that the page was viewed and that someone tapped a contact button. These set advertising cookies and share the visitor's IP address, device/browser information and interaction with Meta (acting as an independent controller under its own terms).
This measurement loads only with the visitor's consent: nothing fires until you choose Accept on the banner shown on the page, and Decline leaves the page fully usable with no Pixel and no cookies set. Your choice is remembered on your device so we don't ask again. This processing is based on consent (GDPR Art. 6(1)(a) / ePrivacy). You can change your mind at any time: at the foot of the page there is a line showing your current choice with a Change link, which brings the banner back so you can accept or decline again. Withdrawing takes effect immediately and is as easy as giving it in the first place.
Separately from the Meta measurement above, we keep simple aggregate statistics for each hosted ad page — a running count of page views and of taps on the contact buttons — so the advertiser can see how their campaign is doing. These are plain totals: they set no cookies, store nothing on your device, and record nothing about you individually (your IP address is used transiently only to rate-limit abuse, and is not stored with the count).
To be explicit about what the banner's choices mean: Accept loads the Meta Pixel and shares the measurement data described above with Meta; Decline means no Pixel, no advertising cookies, and nothing shared with Meta. The anonymous page totals are kept in both cases — they are not affected by the banner, because nothing is placed on or read from your device and no personal data is retained. To the extent any processing is involved at all, it is based on our legitimate interest (GDPR Art. 6(1)(f)) in reporting campaign performance to the advertiser.
Note: this section concerns visitors to a hosted ad page, who may be different people from the advertiser who submitted the ad.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your data, and to withdraw consent where processing is based on consent. If you opted in to marketing, you can withdraw that consent at any time via the unsubscribe link in any marketing email (or by contacting us). To exercise any of these, contact privacy@spreadmymessage.com. You also have the right to lodge a complaint with your supervisory authority — in Belgium, the Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit).
If you are in Mexico: your ARCO rights
This document is also our aviso de privacidad for the purposes of Mexican data-protection law.
The rights above have their own names in Mexico, where they are known together as the ARCO rights: acceso (access — knowing what data we hold about you and what we do with it), rectificación (correcting it if it is wrong or incomplete), cancelación (asking us to delete it) and oposición (asking us to stop using it for a particular purpose). You can also revoke your consent wherever we rely on consent, and limit the use or disclosure of your data. These are the same rights as in the paragraph above, under the names Mexican law gives them.
To exercise any of them, write to privacy@spreadmymessage.com telling us who you are, which right you want to exercise, and which data it concerns. We answer by the same route. If our answer does not satisfy you, you can go to the Mexican data-protection authority, which since 20 March 2025 is the Secretaría Anticorrupción y Buen Gobierno (it took over from INAI, which was dissolved).
We do not ask you for sensitive personal data, and we do not need any to run the service. If your message or your image happens to contain some, we process it only to screen and run that ad, as Section 2 describes.
8. Children
Spread is not directed to anyone under 18, and you must be 18+ to use it.
9. Changes to this policy
If we make a material change to this policy — for example a new purpose for using your data, a new recipient we share it with, a change to who the data controller is, or a change to how you exercise your rights — we will contact you directly, by email to the address you gave us, to tell you what has changed and what it means for you. That message will be about the change and nothing else. Where a change is a significant one, we will tell you before it takes effect, so you have time to consider it and to exercise your rights.
We will not rely on you checking this page. Minor edits — a typo, or rewording that doesn't change what we do — aren't treated as material changes; they're simply recorded below with a new Last updated date at the top of this page.
Every substantive change is listed here, so you can see what changed and when.
| Date | What changed |
|---|---|
| 2026-08-30 | Sections 1, 2 and 5: the waitlist is gone. Spread opened on 2026-08-29, so the "tell me when you open" list has no purpose left and we removed it: the form, the emails and the stored addresses (the list was empty: every address had already been deleted or was never given). This takes away a way of giving us data; nothing else changes, and if you never joined it, nothing here ever affected you. |
| 2026-08-29 | Section 3 now also names Satispay among the payment services you can pick instead of a card (it appears only when you pay in euros). Like the others, if you pick it you sign in to that company directly and it handles your payment under its own privacy policy — we never see your login, and nothing new is collected or stored about you. The option was already offered; this names it. |
| 2026-08-23 | Sections 1 and 3: we now publish a telephone number, and it goes straight to voicemail. If you call and leave a message, Zadarma, the company that runs the line, records it and sends the recording to us by email. We keep a message only until we have dealt with it. Nobody listens in and calls are not recorded in any other way: the line exists so that you have a second way to reach us alongside email, which is still the fastest. Section 1 also now says plainly what we hold when you contact us by either route, which it had never covered. |
| 2026-08-23 | Section 3 now names Google, which was missing. If you give a link as your public contact, we check it against Google's list of known malware and phishing addresses before your ad goes anywhere public — we send the link and nothing else, and we never open it ourselves. This check was already running; it was simply not listed here, and this corrects that. Nothing new is collected, and nothing about your ad or your email address is sent to Google. |
| 2026-08-22 | This policy is now published in Spanish as well as English, and Section 7 gains a part for readers in Mexico: it names the ARCO rights (acceso, rectificación, cancelación, oposición) and the authority you can turn to if our answer doesn't satisfy you, the Secretaría Anticorrupción y Buen Gobierno. Nothing about what we collect, why, or who we share it with has changed — these are the same rights you already had, under the names Mexican law gives them, in a language more of our readers can read. A stray word left over from an earlier edit was also removed from Section 1. |
| 2026-08-20 | Who we are, at the top: we now also give our enterprise number and VAT number. Our VAT registration came through on this date, and a business that is registered for VAT has to show that number where you can easily find it. This is the same data controller as before, identified more fully — nothing about what we collect, why, or who we share it with has changed. |
| 2026-08-18 | Four additions, all describing what already happens rather than changing it, made during a legal review pass. Section 2 now explains in full that your ad is screened automatically when you submit it, that this can decline an ad without a person looking at it first, and that you can always ask for a human review with the power to overturn it — the screening itself has been disclosed here since the start, but not the automated decision or your route past it. Section 1 now speaks to people who appear in someone else's ad (a name or a face): what we hold, why, and that they can contact us without ever having used Spread. Section 4 names the actual safeguards covering data sent outside the EEA (the EU–U.S. Data Privacy Framework for the certified providers, Standard Contractual Clauses for the rest) instead of describing them loosely. Section 5 states how the 7-year clock on financial records is counted (from 1 January of the following year), as Belgian law requires. The draft banner at the top of this page was also removed. |
| 2026-08-11 | Sections 1, 2 and 5: a new waitlist. Spread is not open to everyone yet, so you can now leave your email address to be told when it is. That address is used for one email and nothing else, it does not put you on our marketing list, and the link in any message we send takes you off the list and deletes your address. If you never leave it, nothing here affects you: this adds a place to give us an address, not a new use of one we already have. Written before launch, so it describes the service as it will first operate rather than a change to anything already running. |
| 2026-08-10 | Section 6: you can now change your cookie choice at any time. The foot of a hosted ad page shows the choice you made with a Change link that brings the banner back, so accepting and then declining (or the reverse) takes one click. This section used to tell you to clear your browser's storage, which was not a fair answer: withdrawing consent has to be as easy as giving it. Nothing about what we collect has changed. The banner's own wording was also rewritten to say plainly that it is about cookies, and that accepting tells Meta you visited. |
| 2026-08-09 | Section 1: your ad's page also shows how the ad was set up and how it did — what you paid, the area you targeted (as a map), how long it runs, and how many times it was shown and clicked — so that someone who sees your ad can understand what putting one out involves. The area shown is the one you chose, so pick a centre you're happy to have seen; the form says so where you set it. What the page does not show is your name, which we have also stopped putting in the page's title — the title is now the same on every page of the site. Written before launch, so this describes the service as it will first operate rather than a change to anything already running. |
| 2026-08-07 | Sections 1 and 3: you can now pay with PayPal, Apple Pay, Google Pay, Link or Amazon Pay as well as by card, so these sections name them. If you pick one, you sign in to that company directly and it handles your payment details itself, under its own privacy policy — we still never see your card number or your login. Nothing new is collected or stored about you, and nothing changed for paying by card; this names the companies that can now be involved. |
| 2026-08-06 | Who we are, at the top: we now give our full identity and a postal address — Spread is run by Harold Taeter as a sole trader established in Belgium, registered on this date. Nothing about how your data is handled has changed; this tells you exactly who the data controller is and gives you a second way to reach us. |
| 2026-08-06 | Section 6: removed the part added the day before about people who comment on an ad. We have postponed that feature until after launch, so we do not copy anyone's comments and hold nothing about a commenter. This takes data away rather than adding any: if it comes back, this section comes back with it and will be listed here again before it does. |
| 2026-08-05 | Section 6: a new part for people who comment on an ad — we now copy the comments left on an ad across to the private results page of the person who placed it, so replies actually reach them (our ads run from Spread's own Facebook and Instagram accounts, so the comments land with us). It sets out exactly what we hold about a commenter, why, who sees it, and how to have it removed. Nobody's data is published by this, and no comment is used to contact, profile or advertise to anyone. |
| 2026-08-04 | Sections 1 and 3, both describing what we already do rather than changing it. Section 1 now says that the contact details on your ad (phone / WhatsApp / public email, and any link or display name) are collected to be published — they are the ad's whole point — and are separate from the email we use to reach you, which is never published. Section 3 now names every company that handles your data, not just the main four: Neon (the database), Vercel (hosting), Inngest (background jobs, which can hold your email address while a job is running), LocationIQ (turning what you type into a map position), Cloudflare (image storage and the anti-bot check, which sees your IP) and Sentry (error reports, with personal data stripped). No new sharing began on this date; these were missing from the list. |
| 2026-08-01 | Section 5: spelled out when the 12-month retention clock starts — it runs from the point we've finished with your ad, so a board listing you keep renewing keeps its data with us. No change to how long we keep anything; this describes what already happens. |
| 2026-07-31 | No change to how we handle your data. Rewrote this section: we now commit to telling you directly about material changes rather than only posting them here, and added the Last updated date and this change history. |
| 2026-07-30 | Section 5: added how long the ad page we host for you stays publicly reachable (while your ad runs plus 7 days; 60 days from listing if you also put it on our public board), separately from how long we keep the data. |
| 2026-07-16 | Section 6: spelled out what the banner's Accept and Decline each do, and that the anonymous page totals are kept either way. |
| 2026-07-15 | Section 6: disclosed the consent-free aggregate counters on hosted ad pages (page views, contact taps) and the legitimate-interest basis for them. |
| 2026-06-23 | Section 6 rewritten: disclosed the Meta Pixel and Conversions API on hosted ad pages, what is shared with Meta, and that this loads only with the visitor's consent. Section 3 updated to match. |
| 2026-06-16 | Named the data controller and the privacy contact address (previously placeholders), and set concrete retention periods (12 months for ad and account data; 7 years for financial records). |
This history was reconstructed from our change records on 2026-07-31; changes before that date were not stamped in the policy at the time they were made.
10. Contact
Privacy questions or requests: privacy@spreadmymessage.com.