Privacy Policy
1. Information about the Collection of Personal Data and Contact Details of the Controller
We appreciate your interest in our website. The protection of your privacy is of great importance to us. Below we inform you about the handling of your personal data when using our website in accordance with the General Data Protection Regulation (GDPR) and other relevant data protection provisions. Personal data is any data with which you can be personally identified.
The controller responsible for data processing on this website within the meaning of the GDPR is Ultramarin GmbH, Schönhauser Allee 43a, 10435 Berlin.
Phone: +49 30 555 785 450
Email: contact@ultramarin.ai
This website uses the widely adopted SSL (Secure Socket Layer) or TLS (Transport Layer Security) method in conjunction with the highest level of encryption supported by your browser. These security measures protect the transmission of personal data. You can recognize an encrypted connection by the https:// prefix and the lock symbol in your browser's address bar.
Furthermore, Ultramarin GmbH employs appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse. These include, among others, the use of encryption technologies, regular security audits, and strict access controls.
2. Purpose and Legal Basis of Our Data Processing
Consent (Art. 6(1)(a) GDPR)
The basis for processing your data is your consent (Art. 6(1)(a) GDPR). You may revoke this at any time. Please note that revocation only applies for the future and does not affect the lawfulness of processing carried out prior to revocation. We will always inform you about the precise details of processing within the scope of the respective inquiry.
Performance of a Contract (Art. 6(1)(b) GDPR)
We use your personal data to fulfill our contractual obligations to you (Art. 6(1)(b) GDPR). This is necessary so that we can provide you with our services as agreed. Specifically, this relates to the use of Shyller.
Legitimate Interest (Art. 6(1)(f) GDPR)
We process your data to safeguard our legitimate interests pursuant to Art. 6(1)(f) GDPR. We ensure in advance through a balancing of interests that your data protection rights and expectations do not outweigh our purposes. This ensures a fair balance between our services and your protection.
3. What Data Is Processed?
We use the service Appwrite (www.appwrite.io) for managing user accounts and authentication on our website.
Unlike a purely informational visit to our website, data is only transmitted to Appwrite when you actively log into your user account or create a new account. Only at that point does your browser establish a connection to the provider's servers.
When creating a user account and during subsequent login, the following data is collected and forwarded to Appwrite for processing:
- Email address
- First and last name
- Password (in encrypted form)
This data processing is based on Art. 6(1)(b) GDPR, as the information is necessary for the fulfillment of the user agreement and the provision of Shyller's features.
4. Third-Party Providers
As a matter of principle, we do not share customer data with third parties. In exceptional cases and within the scope of data protection regulations, customer data may be shared with third parties for the stated purposes. These include external service providers such as IT service providers (e.g., Appwrite and PostHog), as well as product partners.
We ensure that third-party providers implement appropriate data protection measures and protect your data in accordance with applicable data protection regulations.
5. Our Data Protection Principles
When processing your personal data, Ultramarin GmbH strictly adheres to the requirements of the GDPR. We are guided by the following principles:
- Lawfulness, fairness, and transparency: We process your data only with your explicit consent. Before you give consent, we explain clearly and completely for what purpose we need the data.
- Data minimization: We only ask for information that is absolutely necessary for the respective purpose. Our principle is: as little as possible, as much as necessary.
- Storage limitation: We only retain your data for as long as is necessary for the agreed purpose. We inform you transparently about the exact retention periods.
- Integrity and confidentiality: Security is our top priority. Ultramarin GmbH implements comprehensive technical and organizational measures to protect your data from unauthorized access or misuse by third parties.
6. Duration of Storage of Personal Data
The duration of storage of personal data is determined by the respective legal basis, the purpose of processing, and, where applicable, additionally by the respective statutory retention period.
Personal data processed on the basis of explicit consent pursuant to Art. 6(1)(a) GDPR will be stored until the data subject revokes their consent.
Once the customer provides us with personal data and a contractual relationship is established and services are rendered on this basis, we are bound by commercial, tax, and regulatory archiving, documentation, and disclosure obligations. These obligations also cover customer data. Such retention periods range from two to ten years. The legal basis for this is Art. 6(1)(b) and (c) GDPR. After expiry of these periods, data is routinely deleted unless it is still required for contract fulfillment or contract initiation and/or there is no legitimate interest on our part in continued storage.
Personal data processed on the basis of Art. 6(1)(f) GDPR will be stored until the data subject exercises their right to object pursuant to Art. 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing serves the establishment, exercise, or defense of legal claims.
Unless otherwise stated in other sections of this declaration regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.
7. Your Data Subject Rights
As a data subject, you have the following rights vis-à-vis the controller:
- Right of access pursuant to Art. 15 GDPR
- Right to rectification pursuant to Art. 16 GDPR
- Right to erasure pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to notification pursuant to Art. 19 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to withdraw consent pursuant to Art. 7(3) GDPR
- Right to lodge a complaint pursuant to Art. 77 GDPR
Right to Object
If your personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21(1) GDPR. The objection must be substantiated and addressed in writing to the controller.
If you exercise your right to object, we will cease processing the data concerned. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for the processing which override your interests, fundamental rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims.
8. Cookies and Other Tracking Technologies
When you use our services (including our website and tools), we use cookies and similar tracking and storage technologies, such as local storage or small transparent image files (pixels). These are small text files or data packets placed locally on your device via your web browser.
The technologies we use fall into three categories:
1. Technically Necessary (Functional) Cookies and Local Storage
These technologies are strictly required to provide the core functions of our tool and website. They ensure that our services work correctly (e.g., storing your login status, session ID, language selection, security features, account management, and your cookie decision). Without them, our service could not be operated securely and reliably. Specifically, Shyller stores your cookie decision (us_cookie_consent, local storage, 12 months) and your language preference (us_locale, cookie, 12 months).
This use is based on Art. 6(1)(f) GDPR (our legitimate interest in a technically error-free and secure provision of our services). Session cookies are deleted automatically when you end your visit or close your browser. Other data in local storage remains permanently until you delete it manually in your browser or the browser cache is cleared.
2. Analytics Cookies
Analytics cookies allow us to collect information about how you use our website. They help us understand how visitors use our platform and how the website and services could be improved. We use PostHog exclusively for this purpose (see the overview under category 3). Analytics cookies are set only with your consent (Art. 6(1)(a) GDPR; Section 25(1) TDDDG).
3. Marketing Cookies and Third-Party Providers
We use marketing technologies solely to measure the performance of our advertising (conversion measurement): if you reached us through a Google ad, the ad click is linked to a later trial or subscription. No Google cookies or scripts are loaded on our website for this; the data is transmitted server side and only with your consent (Art. 6(1)(a) GDPR). Processing may also be carried out by providers located outside the European Union or the European Economic Area; the safeguards in place are listed per provider in the overview below.
We work with the following third-party providers in operating our services:
Appwrite Cloud (Appwrite Code Ltd., Israel): User accounts, authentication, and the application database (for example your watchlist and settings). Data processed: email address, name, password (in hashed form), session identifiers, IP address, content you store in the app. Legal basis: Art. 6(1)(b) GDPR. Account data is stored in the Frankfurt region (cookie a_session_* on fra.cloud.appwrite.io and cookieFallback in local storage, each up to 12 months); access from Israel is covered by the EU adequacy decision for Israel. Privacy policy: appwrite.io/privacy
Netlify (Netlify, Inc., USA): Hosting and worldwide delivery of the website, including image optimization. Data processed: IP address, browser and device information, requested pages (technical server logs, stored for a short period only). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable delivery of the website). Netlify does not set cookies on this website. Transfer to the USA; Netlify is certified under the EU-US Data Privacy Framework. Privacy policy: netlify.com/privacy
Stripe (Stripe Technology Europe, Ltd., Ireland; part of Stripe, LLC, USA): Payment processing and subscription management. Stripe is used only when you purchase a subscription or open the billing portal; you are then redirected to pages operated by Stripe, on which Stripe sets its own cookies. Data processed: name, email address, payment details, subscription and invoice data. Legal basis: Art. 6(1)(b) GDPR. Stored according to statutory commercial and tax retention periods. For processing in the USA, Stripe is certified under the EU-US Data Privacy Framework. Privacy policy: stripe.com/privacy
Resend (Plus Five Five, Inc., USA): Delivery of service emails such as onboarding information, watchlist alerts, and the market digest. Data processed: email address, name, email content, delivery metadata (stored for a short period only). Legal basis: Art. 6(1)(b) and (f) GDPR. Transfer to the USA; Resend is certified under the EU-US Data Privacy Framework, with EU standard contractual clauses additionally in place. Emails do not set cookies on this website. Privacy policy: resend.com/legal/privacy-policy
PostHog (PostHog, Inc., USA; EU cloud): Product analytics (category 2). Data processed: pseudonymous usage events such as pages viewed and features used, device and browser information, campaign parameters of your visit. Legal basis: your consent (Art. 6(1)(a) GDPR; Section 25(1) TDDDG). Cookies and local storage (ph_*) are set only after consent and are valid for 12 months. Event data is stored in the EU (Frankfurt); access by PostHog, Inc. is safeguarded by EU standard contractual clauses. Independently of your cookie consent, for paying customers we record individual contract events server side (for example the start of a trial or the payment of a subscription) based on Art. 6(1)(f) GDPR (legitimate interest in measuring our business performance); you may object to this at any time (see section 7). Privacy policy: posthog.com/privacy
Google Ads (Google Ireland Limited, Ireland; Google LLC, USA): Conversion measurement for our advertising (category 3). Data processed: ad click identifier (gclid) and conversion events with time and value; the identifier from the URL is stored by PostHog and transmitted to Google server side only if you have given marketing consent. Legal basis: Art. 6(1)(a) GDPR. Stored according to Google's retention periods for conversion data. Transfer to the USA; Google LLC is certified under the EU-US Data Privacy Framework. Privacy information: business.safety.google/privacy
Your Choices (Opt-Out and Browser Settings)
Whenever you visit our website, you can use our cookie banner to accept or decline the use of analytics and marketing cookies. You can change your selection or withdraw it with effect for the future at any time via the “Cookie settings” link in the footer of our website or in the user menu within the app. If your browser sends the Global Privacy Control signal, we treat it as a refusal of analytics and marketing cookies.
In addition, you can configure in the settings of most browsers which cookies you want to accept or decline in general. Please note, however: if you choose to disable technically necessary (functional) cookies, some components and core functions of our services may no longer be fully available.
9. Currency and Changes to This Privacy Policy
This privacy policy is currently valid as of September 2026.
Due to the further development of the website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version of the privacy policy can be accessed and printed at any time on the Shyller website (www.shyller.ai).