Last updated October 4, 2026
Privacy policy
This policy explains what personal data SubmitStorm collects, why, who else touches it, how long we keep it, and what you can do about it. It is written to be read. The short version: we collect what we need to run your account and your order, we share your brief with the directories because that is the service, we use a few well-known providers to run the site, and you can download or delete your data yourself in Settings.
1. Who is responsible
The data controller is GrubGuru, a company registered in British Columbia, Canada, email [email protected]. We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for customers in the EU, the EEA and the UK, under the General Data Protection Regulation (GDPR) and the UK GDPR. Our servers are in the EU. We have not appointed a data protection officer; the scale of what we do does not require one. Write to the address above with anything about your data.
2. What we collect
- Account data: your name, email address and a hash of your password; if you sign in with Google, the name, email address and profile picture Google sends us.
- Order data: the package, price, currency, dates and status of each order, and the Stripe identifiers of the payment. Card numbers never reach us.
- Your brief: everything you enter for a submission: product name, website, descriptions, category, tags, logo, screenshot, social links, a contact name for listings and a contact email for us, phone, city and country if you give them, and your notes to us. "Fill with AI" reads your public website to draft these.
- Campaign records: which directories we submitted your product to, when, the result, the listing URL, and a proof screenshot of each submission (which shows the listing data from your brief). Your site's Domain Rating at the start and end of an order.
- Badge check: when you press "Check my site", we fetch your homepage once and record which of our badge directories it links to.
- Emails you send us and our replies.
- Google Analytics 4, only with your consent: page views, the pages and lists you read, your rough location from a shortened IP address, browser and device type, and a random client id in a cookie. Nothing from Google loads before you choose "Accept analytics" in the cookie banner, wherever you are, and it stops when you choose "Only necessary". The data is not joined to your account.
- Technical data: the IP address, browser and time of sign-ins and of security-relevant actions, and ordinary server logs (IP address, requested page, time, user agent) kept for security and debugging.
We do not collect special categories of data and we have no reason to; please do not put any in your brief.
3. Why we use it, and on what legal basis
- To provide the service you bought (contract, Art. 6(1)(b) GDPR): run your account, process the order, create and submit your listings, send the final report, answer your questions.
- To meet legal obligations (Art. 6(1)(c)): keep accounting and tax records of payments, answer lawful requests.
- For our legitimate interests (Art. 6(1)(f)): keep the site secure and prevent abuse, debug problems, keep an anonymised record of which directories accept listings, and improve the service. You can object to this (Section 8).
- With your consent (Art. 6(1)(a)): Google Analytics cookies, given or refused in the cookie banner and changeable any time under "Cookie settings" in the footer. Marketing email would also need your consent; we send none today.
We send only the emails the service needs: order confirmation, campaign start, the final report when it finishes, password and security notices, and answers to your questions. There is no newsletter.
4. Who else receives it
Directories. The service is the publication of your brief on third-party directories, so the content of your brief, including the contact name you chose for it, goes to each directory we submit to. Directories write to a mailbox we set up for your campaign, not to your own email address. From then on each directory is its own controller under its own privacy policy. We cannot delete a listing from a directory; most directories let you claim and edit or remove a listing yourself, and we help where we can.
Providers that process data for us, under contracts that bind them to our instructions:
- Stripe (Stripe Payments Europe, Ltd., Ireland; Stripe, Inc., USA): payment processing and receipts. Stripe is also an independent controller for its own fraud prevention.
- Resend (Plus Five Five, Inc., USA): sending our emails.
- Google (Google Ireland Ltd.; Google LLC, USA): Google sign-in if you choose it, and Google Analytics 4 if you consent to analytics cookies (Google is a processor for the measurement and keeps the data for 14 months).
- Our hosting provider (Germany): runs the website and stores the database and uploaded images.
- Our network and security provider (USA): carries every connection to the website and decrypts it on the way, so it handles everything sent to and from the site, including what you type into forms; it protects the site against attacks and runs the human check on the sign-up form.
- Providers that host or operate our own tooling (in the European Union, the United States and China): they receive only the product information from your brief, which is meant to be public, never your account or payment data, and may not use it for their own purposes.
- Ahrefs (Ahrefs Pte. Ltd., Singapore): receives your domain name to return its Domain Rating.
Badge images. The badge component preview on your order page shows each badge image from its directory's own server, so those directories see your IP address and browser, as any website you load does.
We may also disclose data where the law requires it, and to a successor if SubmitStorm is sold, under this policy. We do not sell personal data and we do not share it for advertising.
5. Where the data is
The website and database run in Germany. Some providers above are in the United States (Stripe, Resend, Google, the network and security provider and some tooling providers), Singapore (Ahrefs) or China (some tooling providers). Transfers to the US rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses; transfers to other countries rely on standard contractual clauses. Only the product information from your brief, which is meant to be public, goes to the tooling providers for fulfilment; your account and payment data stay with the website in the EU and with the providers named above for what they do.
6. How long we keep it
- Account and brief: while your account exists. When you close it, personal fields and uploaded files are removed at once (Section 8).
- Orders and payments: 6 years from the end of the tax year of the payment, as Canadian tax law requires, kept without your personal details once the account is closed.
- Campaign records and proof screenshots: 12 months after the order is completed, then deleted; the anonymised fact that a directory accepted or rejected a listing is kept.
- Security and server logs: 90 days.
- Emails: 2 years after the last exchange.
7. Cookies
One strictly necessary cookie keeps you signed in; our network and security provider may add strictly necessary security cookies; Google Analytics cookies are set only after you accept them in the cookie banner, and "Cookie settings" in the footer changes the answer any time. The cookie policy lists every cookie, what it does and how long it lasts.
8. Your rights
Under the GDPR you can:
- access your data and get a copy: Settings has a "Download my data" button that gives you everything as a JSON file;
- correct it: your name and password in Settings, your brief in the order, anything else by email;
- delete it: Settings has "Delete my account"; what stays and why is in Section 6;
- restrict or object to processing based on our legitimate interests, and withdraw consent where processing is based on it (analytics: "Cookie settings" in the footer);
- take your data with you in a structured, machine-readable format (the same JSON file);
- complain to a supervisory authority: in Canada, the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada, www.priv.gc.ca; in the EU, the EEA or the UK, the data protection authority of the country where you live.
For anything you cannot do yourself, email [email protected] from the address on your account; we answer within 30 days. We do not make decisions about you by automated means that have legal or similarly significant effects.
9. Security
Connections are encrypted (HTTPS), passwords are stored hashed, access to the database and the servers is restricted to us, payment data never touches our systems, and the credentials for directory accounts are kept on our fulfilment machines, not in the website. If a breach ever affects your data, we tell you and the authority as the GDPR requires.
10. Children
The service is for adults. We do not knowingly collect data from anyone under 18; if you think we have, tell us and we will delete it.
11. If you are in the United States
We do not sell personal information or share it for cross-context behavioural advertising, and we do not use sensitive personal information beyond what the service needs. Where a state privacy law (such as the California Consumer Privacy Act) applies to you, you have the rights to know, access, correct and delete your information, to data portability, and not to be discriminated against for using them. Use the Settings page or email [email protected]; we verify requests through the email on your account, and an authorised agent may act for you with your written permission. We do not respond to browser "Do Not Track" signals because we do no tracking to switch off.
12. If we emailed you about SubmitStorm
We sometimes write to the makers of products that are listed on public launch directories, once, to tell them about the service. If you received such an email and are not a customer, this is all we hold about you: the name and website of your product, the directory it is listed on, the contact address published for it (and your name, when the directory shows it), the fact that we wrote and when, and what came back: a bounce, a reply or an opt-out. We took the first four from the public listing and the product's public website. We use them for that one email and to make sure there is no second one. The legal basis is our legitimate interest in telling a business about a service made for it (GDPR Art. 6(1)(f)).
You can object at any time: reply "no" to the email, use its unsubscribe link, or write to [email protected]. We then keep only your address, on a do-not-contact list, so that your objection holds. Products we never wrote to are deleted from our records 120 days after their launch. The emails are sent from mailboxes hosted by Google, and before we write, a verification service checks that the address exists; it receives nothing but the address. We do not pass these details to anyone else, and the rights in Section 8 apply here too.
13. Changes
When this policy changes, the date at the top changes with it, and if the change matters to you we tell you by email before it takes effect.