Legal
Privacy
This policy describes what the website processes based on how it is actually built: a read-only intelligence site with no visitor accounts and a browser-only analysis tool.
Last updated
Scope
This policy covers the public website. It is an informational service: it publishes source-linked payments-industry intelligence and offers a merchant payment diagnostics tool that runs entirely in your browser. There are no user accounts, no login, no newsletter and no payment processing.
“Personal data” and the rights referred to below are used in the sense of the EU General Data Protection Regulation (GDPR) and the German Bundesdatenschutzgesetz (BDSG).
Who operates this website
Hosting and infrastructure
The frontend is deployed on Vercel, which serves the pages through its content delivery network and runs the server-side rendering. Dynamic pages are rendered on the server and query a Supabase managed PostgreSQL database; that query runs server-side, not from your browser.
When your browser requests a page it necessarily transmits your IP address and the request headers (such as the user agent) to the hosting platform, as with any website. The identity of the platform operators as processors, the data-processing agreements with them, and the regions in which content and the database are hosted are operator-confirmed details recorded in the launch checklist.
Server and log data
The infrastructure providers process standard request logs — IP address, timestamp, requested URL, referrer and user agent — on a transient basis to deliver the site, keep it secure and diagnose faults. The legal basis is the legitimate interest in operating a functional, secure website (Art. 6(1)(f) GDPR).
Beyond those platform-level logs, the application keeps no record of your visit. It sets no logging cookie and loads no logging or analytics script. When a database query fails, a technical error message is written to the server log; it does not contain visitor data.
Public intelligence data
The intelligence feed, briefs, company list, weekly reports, market pulse and system metrics are rendered from a read-only public dataset held in Supabase. The site reads it with a publishable (anonymous) key that is constrained by row-level security to published, evidence-passed records only.
That dataset is about payments-industry developments, organisations and public sources. It is not built from, and does not contain, personal data about visitors to this site. Named individuals may appear where they are the subject of industry coverage; see Your rights.
Cookies, storage and tracking
This website sets no cookies. It writes nothing to localStorage, sessionStorage or IndexedDB. It uses no analytics, advertising, A/B-testing or tracking services, and embeds no third-party scripts or pixels.
Because nothing non-essential is stored on your device, there is currently no cookie or consent banner — there is nothing to consent to. If a future feature introduces analytics or another consent-relevant technology, a compliant consent mechanism will be added before it ships.
Fonts
The two typefaces (Geist and Geist Mono) are self-hosted: they are bundled with the site at build time and served from this domain. Your browser makes no request to Google Fonts or any other third-party font host.
Merchant Analyzer
The Merchant Analyzer runs entirely in your browser. A CSV you select is read locally with the browser’s file.text() API and analysed by deterministic code on your device.
No file, no transaction row and no figure derived from your data is uploaded, sent to this site’s server, written to Supabase, sent to any AI model, or stored anywhere. Exported summaries are generated in your browser and never leave it unless you save them. Reloading or leaving the page discards everything. Files whose column headers look like card numbers, security codes, cardholder names or other personal data are rejected before any analysis runs.
External source links
Briefs and reports link to third-party source URLs — regulators, company sites, trade press. Only http and https links are rendered. Following a link takes you to a site this project does not operate and which has its own privacy practices.
Outbound links are marked rel="noopener noreferrer", and the site’s referrer policy (strict-origin-when-cross-origin) limits the referrer information sent to the destination to the origin only.
AI and automated processing
Language models (Anthropic’s Claude) and a search API are used only inside the backend research pipeline that retrieves sources and drafts briefs. That pipeline runs on a schedule and on operator demand. It never runs in response to a page you request, and it never receives anything you enter or upload — the public website makes no AI calls at all.
Contact and email
The site has no contact form, no newsletter and no sign-up. It does not collect email addresses. Any contact channel is the one published in the Legal notice; if you email that address, your message and address are processed only to handle your enquiry (Art. 6(1)(b) or (f) GDPR) and not for any other purpose.
Data retention
The website itself stores no visitor data, so there is nothing visitor-related for it to retain or delete. Platform request logs are retained by the hosting providers according to their own retention schedules, recorded in the launch checklist for the operator to confirm.
Your rights
Where a controller processes personal data about you, the GDPR gives you the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw consent where processing is based on it.
Because this website collects no personal data from visitors, there is normally nothing to exercise these rights against here. If you believe the published intelligence dataset contains personal data about you as a named individual, contact the operator via the Legal notice and the request will be assessed.
Supervisory authority
Changes to this policy
This policy may change as the site develops. The current version is always the one published here, dated at the top. Material changes will be reflected in that date.
Methodology explains how the intelligence pipeline works.