SubmitStorm

Last updated October 4, 2026

Privacy policy

This policy explains what personal data SubmitStorm collects, why, who else touches it, how long we keep it, and what you can do about it. It is written to be read. The short version: we collect what we need to run your account and your order, we share your brief with the directories because that is the service, we use a few well-known providers to run the site, and you can download or delete your data yourself in Settings.

1. Who is responsible

The data controller is GrubGuru, a company registered in British Columbia, Canada, email [email protected]. We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for customers in the EU, the EEA and the UK, under the General Data Protection Regulation (GDPR) and the UK GDPR. Our servers are in the EU. We have not appointed a data protection officer; the scale of what we do does not require one. Write to the address above with anything about your data.

2. What we collect

We do not collect special categories of data and we have no reason to; please do not put any in your brief.

3. Why we use it, and on what legal basis

We send only the emails the service needs: order confirmation, campaign start, the final report when it finishes, password and security notices, and answers to your questions. There is no newsletter.

4. Who else receives it

Directories. The service is the publication of your brief on third-party directories, so the content of your brief, including the contact name you chose for it, goes to each directory we submit to. Directories write to a mailbox we set up for your campaign, not to your own email address. From then on each directory is its own controller under its own privacy policy. We cannot delete a listing from a directory; most directories let you claim and edit or remove a listing yourself, and we help where we can.

Providers that process data for us, under contracts that bind them to our instructions:

Badge images. The badge component preview on your order page shows each badge image from its directory's own server, so those directories see your IP address and browser, as any website you load does.

We may also disclose data where the law requires it, and to a successor if SubmitStorm is sold, under this policy. We do not sell personal data and we do not share it for advertising.

5. Where the data is

The website and database run in Germany. Some providers above are in the United States (Stripe, Resend, Google, the network and security provider and some tooling providers), Singapore (Ahrefs) or China (some tooling providers). Transfers to the US rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses; transfers to other countries rely on standard contractual clauses. Only the product information from your brief, which is meant to be public, goes to the tooling providers for fulfilment; your account and payment data stay with the website in the EU and with the providers named above for what they do.

6. How long we keep it

7. Cookies

One strictly necessary cookie keeps you signed in; our network and security provider may add strictly necessary security cookies; Google Analytics cookies are set only after you accept them in the cookie banner, and "Cookie settings" in the footer changes the answer any time. The cookie policy lists every cookie, what it does and how long it lasts.

8. Your rights

Under the GDPR you can:

For anything you cannot do yourself, email [email protected] from the address on your account; we answer within 30 days. We do not make decisions about you by automated means that have legal or similarly significant effects.

9. Security

Connections are encrypted (HTTPS), passwords are stored hashed, access to the database and the servers is restricted to us, payment data never touches our systems, and the credentials for directory accounts are kept on our fulfilment machines, not in the website. If a breach ever affects your data, we tell you and the authority as the GDPR requires.

10. Children

The service is for adults. We do not knowingly collect data from anyone under 18; if you think we have, tell us and we will delete it.

11. If you are in the United States

We do not sell personal information or share it for cross-context behavioural advertising, and we do not use sensitive personal information beyond what the service needs. Where a state privacy law (such as the California Consumer Privacy Act) applies to you, you have the rights to know, access, correct and delete your information, to data portability, and not to be discriminated against for using them. Use the Settings page or email [email protected]; we verify requests through the email on your account, and an authorised agent may act for you with your written permission. We do not respond to browser "Do Not Track" signals because we do no tracking to switch off.

12. If we emailed you about SubmitStorm

We sometimes write to the makers of products that are listed on public launch directories, once, to tell them about the service. If you received such an email and are not a customer, this is all we hold about you: the name and website of your product, the directory it is listed on, the contact address published for it (and your name, when the directory shows it), the fact that we wrote and when, and what came back: a bounce, a reply or an opt-out. We took the first four from the public listing and the product's public website. We use them for that one email and to make sure there is no second one. The legal basis is our legitimate interest in telling a business about a service made for it (GDPR Art. 6(1)(f)).

You can object at any time: reply "no" to the email, use its unsubscribe link, or write to [email protected]. We then keep only your address, on a do-not-contact list, so that your objection holds. Products we never wrote to are deleted from our records 120 days after their launch. The emails are sent from mailboxes hosted by Google, and before we write, a verification service checks that the address exists; it receives nothing but the address. We do not pass these details to anyone else, and the rights in Section 8 apply here too.

13. Changes

When this policy changes, the date at the top changes with it, and if the change matters to you we tell you by email before it takes effect.