1. Data Controller
NicheScope is the controller of your personal data. For any questions about your data, contact us at nichescope.app.
2. Data Collected
We only collect data necessary to operate the service:
- Account data: email address, account creation date.
- Payment data: handled exclusively by Stripe. NicheScope does not directly store or process your banking information.
- Usage data: niches analyzed, searches performed, search history, credits consumed.
- Technical data: IP address, browser type, pages visited — collected automatically for security and service improvement purposes.
3. Purposes of Processing
Your data is used to:
- Provide and improve the NicheScope service;
- Manage your account and subscription;
- Process your payments via Stripe;
- Send you service-related communications (confirmations, account alerts, weekly digest if enabled);
- Detect and prevent abuse and fraud;
- Comply with our legal obligations.
4. Legal Basis for Processing
Processing of your data is based on the following legal grounds:
- Contract performance: to provide the service you subscribe to.
- Legitimate interest: to improve the service, prevent fraud, and ensure security.
- Consent: for marketing communications (if you have consented).
- Legal obligation: to comply with applicable regulations.
5. Sub-processors and Data Transfers
NicheScope uses the following sub-processors to operate the service:
- Supabase — Database hosting and authentication. Data stored in Europe.
- Stripe — Payment processing. Payment data handled under Stripe's privacy policy.
- Vercel — Application hosting.
- YouTube Data API (Google) — Retrieval of public YouTube data for analyses. No personal data is transmitted to Google.
- OpenAI — SEO content generation. Only search keywords are transmitted, with no personally identifiable data.
- Resend — Transactional email delivery.
These sub-processors are bound by contractual data protection obligations compliant with GDPR.
6. Data Retention
Your data is retained for the duration of your active account and for 3 years after account termination, unless a longer legal retention period applies. Payment data is retained by Stripe under their own retention policy.
7. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: obtain a copy of your personal data.
- Right of rectification: correct inaccurate data.
- Right to erasure: request deletion of your account and data.
- Right to portability: receive your data in a structured format.
- Right to object: object to the processing of your data.
- Right to restriction: request restriction of processing.
To exercise these rights, contact us at nichescope.app. You also have the right to lodge a complaint with your local data protection authority.
8. Cookies
NicheScope only uses strictly necessary cookies for service operation (authentication session, language preference). No advertising or third-party tracking cookies are used.
9. Security
NicheScope implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, or destruction. Connections are secured by HTTPS and passwords are hashed.
10. Changes
This policy may be updated at any time. We will notify you by email of any substantial changes. The last updated date is shown at the top of this page.
11. Contact
For any questions regarding data protection: nichescope.app