Privacy policy

Last updated: 18 July 2026

This notice explains what personal data we process when you use Lutendo at lutendo.app, why we process it, and what rights you have. Lutendo connects sellers who run product campaigns with testers who buy, test, and review products. We keep this notice as plain as we can.

Who is responsible

The controller responsible for the processing described here is:

Lutendotech OÜ (registry code 16734112)
Tornimäe tn 5, 10145 Tallinn, Estonia
info@dodotech.io

We have not appointed a data protection officer; at our scale the thresholds of Art. 37 GDPR are not met. Please send privacy inquiries to info@dodotech.io.

What we process and why

For each purpose we name the data involved and the legal basis under Art. 6 GDPR. We do not make automated decisions about you within the meaning of Art. 22 GDPR, and we do not sell your data.

You are not legally required to provide any data. Some data is contractually necessary: without your email address, for example, we cannot create your account or provide the service.

Account and profile

When you create an account we process your email address, your chosen role (seller or tester), your password (stored only as a hash by our authentication provider), and the profile details you add later, such as your name, country, and reviewer profile link. If you sign in with Google, we receive your email address from your Google account. We use this data to operate your account and provide the service you signed up for.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract with you).

Campaigns, applications, and orders

When you take part in the marketplace we process the data that makes it work: campaigns you create or apply to, application status and milestones, order IDs you submit, reviews you report, and cashback and points balances. To verify a reported review we may check the public reviewer profile you linked. Sellers see the application data of testers who applied to their campaigns; testers see the campaign and seller details needed to take part.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract with you).

Payments and payouts

To settle campaign payments and tester payouts we process the data each transaction needs: amounts, currency, timestamps, and the payment or payout details you provide (for example an IBAN for a bank transfer). Card data is collected and processed directly by our payment provider; we never store full card numbers. Bank details you enter for payouts are stored with your account and shared only with the provider that executes the payout.

We keep transaction records for as long as tax and commercial law require.

Legal basis: Art. 6(1)(b) GDPR (payment processing as part of the contract) and Art. 6(1)(c) GDPR (statutory bookkeeping and tax obligations).

Product analytics (only with your consent)

If you consent, we use PostHog, hosted in the EU, to understand how the product is used: the pages you visit, the features you use, and the actions you take in the app, linked to your account. This shows us what works and what needs fixing.

Without your consent nothing is captured and no analytics identifiers are stored on your device. You can withdraw your consent at any time in your account settings; withdrawal stops future collection and does not affect the lawfulness of what happened before.

Legal basis: Art. 6(1)(a) GDPR (consent).

Operational events

Our servers record a small set of operational events when key actions complete, for example that a signup or a payout went through. These events carry internal IDs, the event type, and coarse categories (for example which sign-in method was used); never names, bank details, or free text. We evaluate them in aggregate to keep the service reliable and to count how often key flows succeed or fail; we do not build person profiles from them.

You can object to this processing at any time (see Your rights below).

Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in operating and improving a reliable service).

Campaign view measurement

When you are signed in as a tester and a campaign card is actually visible on your screen, we record that you saw that campaign on that day. The record contains only the campaign, your tester account, the date, and the technical timestamp the record was written: no IP address, no device details, no browsing history. Signed-out visitors are not counted.

We use these records solely to show sellers aggregate view counts for their own campaigns (a lifetime total and a total for the last 7 days). Sellers never see who viewed a campaign.

Records linked to your account are kept for 90 days. After that they are folded into anonymous daily totals per campaign and the account-linked records are deleted. You can object to this measurement at any time; we then delete the view records linked to your account (see Your rights below).

Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in giving sellers accurate aggregate performance figures for campaigns they pay to run).

Cookies and device storage

We use session cookies to keep you signed in and a cookie that remembers your language choice. They are strictly necessary to provide the service you request and do not require consent.

Analytics storage (a PostHog identifier in a cookie or local storage) is only set after you consent. If you decline or withdraw, no analytics identifiers are stored. We do not use advertising or tracking cookies.

Who receives your data

We share personal data only with the service providers below, and only as far as each purpose requires. Providers that process data on our behalf are bound by data processing agreements under Art. 28 GDPR.

  • Supabase: database, authentication, and file storage for the application.
  • Stripe: card payment processing for sellers.
  • ConnectPay: holding and transferring seller campaign funds.
  • Tremendous: tester payouts (for example PayPal rewards).
  • Wise: tester bank payouts.
  • PostHog (EU hosting): product analytics, only after your consent, and server-side operational events.
  • Hetzner: hosting of the application servers in the EU.

Our data is hosted in the EEA where available: the database and authentication run on an EU Supabase project, product analytics on PostHog's EU cloud, our servers at Hetzner in Germany, and ConnectPay is established in Lithuania. Where a provider is established outside the EEA, we rely on the safeguards of Chapter V GDPR: for Stripe and Tremendous (United States) on their EU-US Data Privacy Framework certification and/or standard contractual clauses, and for Wise (United Kingdom) on the EU adequacy decision for the UK.

How long we keep data

Account and marketplace data is kept while your account exists. If you delete your account, personal data is deleted unless a law requires us to keep it longer.

Transaction and billing records are kept for the statutory retention periods of commercial and tax law.

Campaign view records linked to your account are kept for 90 days and then reduced to anonymous totals. Consent decisions are kept as an audit trail for as long as your account exists.

Analytics and operational events linked to your account are deleted when your account is erased.

Your rights

You have the following rights regarding your personal data. To exercise any of them, contact us at the address above.

  • Access (Art. 15 GDPR): learn which data we hold about you and receive a copy.
  • Rectification (Art. 16 GDPR): have incorrect data corrected.
  • Erasure (Art. 17 GDPR): have your data deleted.
  • Restriction (Art. 18 GDPR): have the processing of your data restricted.
  • Data portability (Art. 20 GDPR): receive the data you provided in a machine-readable format.
  • Objection (Art. 21 GDPR): object to processing based on legitimate interest, including the operational events and the campaign view measurement described above. If you object to the view measurement, we delete the view records linked to your account.

Where processing is based on your consent, you can withdraw it at any time with effect for the future, for product analytics directly in your account settings.

You also have the right to complain to a data protection supervisory authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, www.aki.ee). You can also complain to the supervisory authority of the EU member state where you usually live or work.

Contact

For any privacy question or to exercise your rights, contact us at info@dodotech.io.