Privacy Policy
How we handle personal data on martechsentinel.com, and how we collect vendor information from public websites.
Not yet finalised — no effective date.
Draft — pending legal review. This document has not been reviewed by an attorney and is not yet in force. Any remaining values shown in square brackets are still to be confirmed.
1. Who we are
MarTech Sentinel (“we”, “us”) is operated by Raiden Gate Design Kft., 1048 Budapest, Bőröndös 18., Hungary, company registration 01-09-432430, e-mail: sayhi@raidengatedesign.com. We are the data controller for the processing described in this policy.
2. What this policy covers
Two distinct kinds of processing:
- Account and usage data — information about you when you use martechsentinel.com.
- Publicly sourced vendor data — information we collect from software vendors’ public websites to build our product database (see Section 8, our Article 14 notice).
3. Account and usage data we process
| Data | Purpose | Legal basis |
|---|---|---|
| E-mail, name, profile image (via sign-up) | Account creation, authentication | Contract (Art. 6(1)(b)) |
| Audit history, app activity | Providing the service | Contract |
| Payment data (when paid plans are active: handled by Stripe via Clerk Billing; we never store card numbers) | Billing | Contract |
| Aggregated page analytics (cookieless, no cross-site tracking) | Service improvement | Legitimate interest (Art. 6(1)(f)) |
| Rate-limit counters, security logs | Abuse prevention | Legitimate interest |
We do not sell personal data and do not use it for third-party advertising.
4. Processors and sub-processors
We use the following processors, each under the data processing terms that the provider offers its customers (Article 28 GDPR):
| Processor | Role | Location / transfer mechanism |
|---|---|---|
| Clerk, Inc. | Authentication; subscription management (Clerk Billing) | United States — EU-U.S. Data Privacy Framework (Clerk’s certification) and Clerk’s data processing addendum |
| Neon | Database hosting | European Union — AWS eu-central-1 (Frankfurt) for our production database; the provider’s data processing terms apply |
| Vercel, Inc. | Application hosting; cookieless web analytics and performance monitoring | United States — Standard Contractual Clauses and the UK addendum under Vercel’s data processing addendum |
| Modal Labs, Inc. | Health-check and background compute | United States — the provider’s data processing terms apply |
| Firecrawl (Mendable, Inc.) | Web content acquisition | United States — the provider’s data processing terms apply |
| Google LLC (Gemini API) | AI-based analysis of public vendor page content | United States and other Google locations — Google’s data processing terms apply |
| Functional Software, Inc. (Sentry) | Error monitoring | United States — the provider’s data processing terms apply |
| Stripe, Inc. | Payment processing via Clerk Billing (only when paid plans are active) | United States — safeguards under Stripe’s and Clerk’s data processing terms |
The current sub-processor list, including the personal data each one handles, is maintained at /legal/subprocessors.
5. Retention
- Account data: while your account is active, then deleted within 90 days of a deletion request.
- Audit history: 24 months, then aggregated or deleted.
- Security and rate-limit logs: 12 months.
6. Your rights
Access, rectification, erasure, restriction, portability, objection (Arts. 15–21 GDPR). Contact: sayhi@raidengatedesign.com. You may lodge a complaint with the Hungarian NAIH (naih.hu) or your local supervisory authority.
7. Cookies
We use only strictly necessary cookies, set by our authentication provider Clerk on martechsentinel.com: __client_uat (also under a suffixed name) records whether you are signed in, and __session holds your signed-in session. Clerk also keeps an authentication cookie on its own subdomain, clerk.martechsentinel.com. Our analytics is cookieless, and we set no advertising or tracking cookies. If we later add non-essential cookies or tracking, we will ask for consent first.
8. Publicly sourced vendor data (Article 14 notice)
Our product contains a database of marketing-technology vendors built from vendors’ own public websites (product pages, documentation, trust centers, legal pages).
- What we collect: company-level facts — product names, features, security and compliance statements, hosting and legal information — with the source URL and collection timestamp.
- What we avoid by design: we filter out personal data (names, e-mail addresses, team-page content) during extraction. Where incidental personal data of vendor representatives appears, for example a named signatory in a public document, the legal basis is legitimate interest (Art. 6(1)(f)); a documented balancing assessment is available on request.
- How we collect: an identified crawler that respects robots.txt and machine-readable text-and-data-mining opt-outs, applies rate limits, and accesses only publicly available pages — never content behind logins or paywalls.
- Your rights as a vendor or individual: request correction or removal at sayhi@raidengatedesign.com — see also our correction process in the Terms of Service. We respond within 14 days.
9. Changes
We will post changes here with a new “last updated” date; material changes will be announced to registered users by e-mail.