Legal

Privacy Policy

Last updated: 13 August 2026

The short version.

We collect an email if you ask us to keep you posted. Payment details go straight to Stripe and never touch our servers. Analytics only run if you accept cookies, and you can change your mind. We do not sell personal data to anyone.

The full policy below is the part that governs, because “trust us” is not a legal basis.

1.Who we are

Knockplum (“Knockplum”, “we”, “us”) is an independent team based in Portugal that operates the website knockplum.com and the Knockplum App Store Optimization data API.

For the personal data described in this policy, we act as the data controller under Regulation (EU) 2016/679 (the “GDPR”) and Portuguese Law no. 58/2019. You can reach us about any privacy matter at [email protected]. We have not appointed a Data Protection Officer, as we are not required to.

2.Scope

This policy covers knockplum.com, including our documentation, blog, waitlist, contact channels, and purchases made through our checkout. It also covers the Knockplum API once it is available to customers.

It does not cover third-party websites we link to, or the App Store and Google Play themselves, which are operated by Apple Inc. and Google LLC respectively.

3.Personal data we process

We keep this deliberately narrow. We process:

  • Waitlist and contact data — the email address you submit, plus anything you choose to write to us in an email.
  • Purchase data — name, email address, billing country, and transaction details, together with card metadata such as brand, last four digits, and expiry. Full card numbers are entered on Stripe’s systems and are never received or stored by us.
  • Technical and usage data — IP address (from which an approximate location is derived), browser and device type, referring page, pages viewed, and interaction events, collected via server logs of our hosting provider and, subject to your consent, Google Analytics.
  • API account data — once the API is live, an account identifier, API key, and request metering records (endpoint, timestamp, credits consumed).

We do not knowingly process special categories of personal data under Article 9 GDPR, and we ask you not to send any to us.

4.Why we process it, and on what legal basis

Each activity below relies on a specific legal basis under Article 6(1) GDPR:

PurposeDataLegal basis
Adding you to the waitlist and telling you when the API opensEmail addressConsent — Art. 6(1)(a). Withdrawable at any time.
Selling credits, delivering them, invoicing, and handling refundsPurchase data, account dataPerformance of a contract — Art. 6(1)(b)
Answering your emails and providing supportContact dataContract, or legitimate interests where no contract exists — Art. 6(1)(b) / (f)
Operating the service securely, metering credits, preventing abuse and fraudTechnical data, API metering recordsLegitimate interests in a secure, functioning, fairly metered service — Art. 6(1)(f)
Measuring site traffic to improve content and performanceAnalytics data via cookiesConsent — Art. 6(1)(a), together with Art. 5(3) ePrivacy Directive
Keeping accounting, tax, and invoice recordsPurchase dataLegal obligation — Art. 6(1)(c)

We do not use your personal data for automated decision-making or profiling that produces legal effects for you, and we do not use it to train machine-learning models.

5.Cookies and similar technologies

We use two kinds of browser storage, and no more:

  • Strictly necessary storage — a single entry that records your cookie choice, so we do not ask again on every page. This is exempt from consent because it exists only to honour your decision.
  • Analytics cookies — Google Analytics 4 cookies that measure visits, pages, and referrers in aggregate. These are set only after you accept. If you continue without analytics, no Google Analytics script is loaded at all.

You can withdraw consent at any time using the Cookie settings link in the footer, which clears your stored choice and lets you decide again. Clearing your browser storage has the same effect. We do not use advertising cookies, cross-site tracking pixels, or third-party ad networks.

6.Who we share data with

We do not sell personal data, and we do not share it for anyone else’s marketing. We use a short list of processors who act on our instructions under Article 28 GDPR:

ProcessorWhat it doesData involved
Stripe Payments Europe, Ltd. (Ireland) and affiliatesPayment processing and checkoutPurchase and card data
Google Ireland Ltd. / Google LLC — Cloud StorageWebsite hosting and deliveryTechnical data, server logs
Google Ireland Ltd. / Google LLC — Analytics 4Aggregate traffic measurement, after consentAnalytics and device data
Our waitlist form provider, where configuredReceiving and storing waitlist submissionsEmail address

We may also disclose data where we are legally required to, or where it is necessary to establish or defend legal claims. If we ever restructure or transfer the business, personal data may transfer with it, and this policy continues to apply until we tell you otherwise.

7.International transfers

Some of our processors are based in, or have parent companies in, the United States, so your personal data may be transferred outside the European Economic Area. Where that happens we rely on the safeguards in Chapter V GDPR: the European Commission’s Standard Contractual Clauses in the relevant processor’s data processing terms and, where the recipient is certified, the EU-US Data Privacy Framework adequacy decision.

You may request a copy of the relevant transfer safeguards by emailing us.

8.How long we keep it

DataRetention
Waitlist emailUntil we contact you at launch and you either become a customer or ask to be removed, and in any case no longer than 24 months from collection
Support correspondenceUp to 24 months after the conversation ends
Purchase, invoice, and accounting recordsFor the retention period required by Portuguese tax law, currently 10 years
Analytics dataPer the retention setting in Google Analytics, a maximum of 14 months
Server logs and API metering recordsUp to 12 months, then deleted or aggregated

9.Your rights

Under Articles 15 to 22 GDPR you have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, portability of data you provided to us, and to object to processing based on our legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

Email [email protected] to exercise any of these. We will respond within one month, extendable by two further months for complex requests, as permitted by Article 12(3). We do not charge for this unless a request is manifestly excessive.

If you are unhappy with how we handled your data, you can complain to the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt, or to the supervisory authority where you live or work. We would appreciate the chance to fix it first.

10.Security

The site is served over HTTPS. Payments are handled by a PCI-DSS compliant provider. We limit access to personal data to the people who need it, keep the data we collect to a minimum, and use reputable infrastructure providers.

No service can promise absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify the CNPD within 72 hours and inform you where the GDPR requires it.

11.Children

Knockplum is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email us and we will delete it.

12.Changes to this policy

As the product develops, this policy will change. The date at the top always shows the current version. If a change materially affects how we use your personal data, we will make it obvious on the site and, where we hold your email for that purpose, tell you directly.

13.Contact

Knockplum, Portugal. [email protected]. A real person reads it.