Legal
Privacy Policy
This policy explains what personal data TrainStack collects through trainstackapp.com, why we collect it, who it reaches, how long we keep it, and what you can require us to do with it.
It covers this website only. If we go on to operate a subscription app for a creator, that app carries its own privacy notice for its members.
01
Who we are
TrainStack is a trading name of RNM Rainmaker GmbH ("we", "us"), a limited liability company registered in Austria under FN 505325 a at the Handelsgericht Wien, with its registered office at Auerspergstraße 1, 1080 Wien, Austria. That company operates trainstackapp.com and is the controller of the personal data described here, which means it decides why the data is collected and what happens to it.
We are established in the European Union, so this policy is written to the GDPR as it applies in Austria, together with the Austrian Data Protection Act (Datenschutzgesetz) where that adds to it.
Our contact address for everything in this policy - questions, requests about your data, and complaints - is office@trainstackapp.com. It reaches a person, not a ticketing queue. You may also write to the registered office above, though email will always be faster.
We have not appointed a Data Protection Officer. The processing described here is small in scale, is not systematic monitoring, and involves no special-category data, so Article 37 of the GDPR does not require one. Questions that a DPO would answer should go to the same address.
02
What we collect
Almost everything we hold about you is something you typed into the application form. There is no account to create, no password to set, and nothing to pay, so we hold no credentials and no payment details.
- The application form, when you submit it. Only two fields are required: your name and your email address. Two more are optional and collected only if you choose to fill them in: a link to your social profile, and any notes you want to add. We deliberately do not ask for anything else at this stage - if we need more, we ask you in a reply.
- Two anti-spam signals collected with that submission: a hidden field that is never shown to you and should stay empty, and how many milliseconds elapsed between the form loading and you submitting it. Both are checked at the moment of submission and then discarded - neither is stored or passed on.
- Correspondence: the content of any email you send us and our replies, including anything you choose to add beyond the form.
- Your IP address, when you submit the form. It is used only to count submissions per address, is held in the server’s memory for one hour, and is never written to a file, a database or an email.
- Ordinary web server logs, kept briefly on our own server so the site can be operated and debugged - the kind of technical record every web server produces. We do not use them to build a profile of you.
- Measurement data, and only if you allow it: the Cookie Policy lists every tag, every cookie it sets and how long each lasts.
- If, and only if, you allow the analytics category: a record of how you used the site. That means the pages you opened, which sections of them stayed on your screen long enough to have been read, where you clicked and scrolled, roughly where in the world your visit came from, the sort of device and browser you used, the site or advert you arrived from, and a session replay - a reconstruction of the visit, assembled from the page as we served it plus the timing of your scrolling and clicking. It is a rebuild of our own page, not a video of your screen: nothing outside this website is captured.
- Your IP address reaches our analytics provider with each of those events, because every web request carries one. It is used to work out the approximate location above and for nothing else: the provider is configured to discard it as soon as that is done, so it is not stored alongside your visit. We do not use it to identify you, and it is never matched against the address recorded when you submit the form.
- What that record deliberately does not contain: anything you typed. Every form field is masked in your browser before a single byte is sent, so the name, email address, link and notes on the application form never reach our analytics provider. Nor does it contain the content of any request or response. We also never link this record to your application - we never call the identification function that would attach your email address to it - so to the provider you remain a random identifier stored in your own browser.
03
Why we use it, and on what legal basis
We rely on the bases below under the EU General Data Protection Regulation, and we apply the same standard to every applicant wherever they live rather than only to those the GDPR covers. Each basis serves a specific purpose, and we do not reuse your data for another one without telling you first.
- To read your application, assess it, and reply to you about it - because it is necessary to take steps at your request before entering into a contract (Article 6(1)(b)), and because we have a legitimate interest in evaluating partnerships proposed to us (Article 6(1)(f)).
- To keep a declined or dormant application on file, so we can come back to you if circumstances change - our legitimate interest in not losing track of creators we may want to work with later (Article 6(1)(f)). You can ask us to delete it at any time and we will.
- To protect the site from spam, automated submissions and abuse, through rate limiting and the two checks described above - our legitimate interest in keeping the service available and our inbox usable (Article 6(1)(f)).
- To meet legal obligations that apply to us, such as responding to a valid request from an authority, and to keep the records that tax and accounting rules require once a partnership is under way (Article 6(1)(c)).
- To establish, exercise or defend a legal claim, in the unlikely event one arises (Article 6(1)(f)).
- To measure how the site is used, including by recording how a visit moves through a page, and how our campaigns perform - on the basis of your consent (Article 6(1)(a)). Nothing in this category runs until you allow it, and you can withdraw permission at any time from the Cookie Policy page, which lists each technology in full.
05
Sending data outside the EEA
We are established in Austria and we keep processing inside the EEA. The server that runs this site and receives your application is in Frankfurt, Germany. Our email sending is configured in Resend’s European region, so application mail is processed in Ireland, and the inbox is provided by Google’s Irish entity. Our analytics project is on PostHog’s EU region, so the usage record and any session replays are stored in Frankfurt as well; the US region was not used, and choosing it would have made this paragraph untrue. In ordinary operation your data does not leave the EEA.
Several of those providers are nevertheless US-incorporated companies, and Cloudflare operates a global network, so access from outside the EEA cannot be ruled out. The United States is not covered by a general adequacy decision, which means a specific safeguard is required for that possibility.
We rely on the European Commission’s Standard Contractual Clauses, incorporated into the data processing terms each provider publishes, together with the technical measures described under Security below. Where a provider additionally holds a certification under the EU–U.S. Data Privacy Framework, that certification applies alongside those clauses.
You may ask us for details of the safeguard that applies to a particular provider by writing to the address at the end of this page.
06
How long we keep it
We keep each category only for as long as the purpose above requires, then delete it. These are the periods we work to:
- An application that does not lead to a partnership: 24 months from the date you submitted it, so we can reconsider you if your audience or our capacity changes. Ask us to delete it sooner and we will, without needing a reason.
- An application that does lead to a partnership: for as long as the partnership lasts, and for six years afterwards, which covers the usual limitation and accounting periods.
- Correspondence: 24 months from the last message in the thread, unless it forms part of a live partnership record.
- The IP address used for rate limiting: one hour, in the server’s memory. It is discarded when the hour ends, and also whenever the server restarts.
- Web server logs: rotated automatically on the server and kept only for a short period, after which they are overwritten. We do not copy them anywhere else.
- The usage record, if you allowed it: session replays are deleted after 30 days, and the events behind our reports - pages opened, sections read, buttons clicked - after 12 months. Both periods are set in the analytics project itself, so they apply whether or not anyone remembers this page. Withdrawing consent stops new data immediately and clears the identifiers from your browser; ask us at the address below and we will delete what was already collected.
- Your cookie choice: it stays in your own browser until you change it or clear your browser storage. It is never sent to us.
07
Your rights
You can exercise any of the rights below by emailing office@trainstackapp.com. We will not charge you, and we will reply within one month - if a request is genuinely complex we may extend that by a further two months, and we will tell you why within the first month. We may ask you to confirm your identity, but only where we cannot otherwise be confident who is asking.
- Access - ask whether we hold data about you, and receive a copy of it along with the information in this policy.
- Rectification - have anything inaccurate corrected, and anything incomplete filled in. If your follower count or your concept has moved on, simply tell us.
- Erasure - have your data deleted where we no longer need it, where you withdraw a consent we were relying on, or where you successfully object to our processing.
- Restriction - have us pause processing while an accuracy dispute or an objection is being resolved.
- Portability - receive the data you gave us in a structured, commonly used, machine-readable format, or have us send it directly to another controller where that is technically feasible.
- Objection - object at any time to processing we base on legitimate interests, including keeping a declined application on file. We will stop unless we can show compelling grounds that override your interests.
- Withdrawal of consent - withdraw any consent you have given, at any time, without affecting anything already done on the basis of it.
- No automated decision-making - you are not subject to any. Every application on this site is read and decided by a person; nothing here profiles you or scores you automatically.
- Complaint - raise the matter with a supervisory authority if you think we have got something wrong. Because we are established in Austria, our lead authority is the Austrian Data Protection Authority (Datenschutzbehörde), but you may equally complain to the authority in the EU or EEA country where you live or work. We would rather you came to us first so we can put it right, but you do not have to.
- Österreichische Datenschutzbehörde - Austrian Data Protection AuthorityOur lead supervisory authority: Barichgasse 40–42, 1030 Vienna, Austria. It handles complaints about how we process personal data.
- European Data Protection Board - national supervisory authoritiesThe official list of data protection authorities in each EU and EEA country. You may complain to the one where you live, where you work, or where you believe the problem occurred.
08
Security
The measures below are the ones this site actually implements, rather than a general statement of intent. No method of transmission or storage is ever completely secure and we cannot promise absolute safety, but these are concrete and checkable:
- Everything is served over HTTPS, with HSTS set for two years including subdomains, so a browser will not connect over an unencrypted channel.
- Applications are not stored in a database on this website. The form posts to a server-side route which validates the submission and hands it straight to our inbox, so there is no store of applications on the public internet to breach.
- The route accepts JSON only, rejects any body over 24 KB, and validates every field against a strict schema before anything is done with it. Text is sanitised and escaped before it reaches an email, so a submission cannot inject content into what we read.
- Submissions are limited to five per IP address per hour, and submissions that trip the hidden-field or timing check are dropped without reaching us.
- The site sends a conservative set of security headers on every response: no MIME sniffing, no framing by other origins, a restrictive referrer policy, and a permissions policy that switches off camera, microphone, geolocation and cohort-based tracking.
- The only third-party code that loads without being asked for is Cloudflare Turnstile, on the application page alone, to check that a submission comes from a real browser. Everything that measures - analytics, session recording, campaign pixels - is fetched at the moment you allow the matching category and never before: decline, or simply ignore the banner, and that code is not downloaded to your browser at all, rather than downloaded and told to keep quiet.
- Session recording is configured to mask every form field in the browser before anything is transmitted, and to record no request or response content. The application form’s contents therefore cannot appear in a replay even if a recording is running while you fill it in.
- Access to the inbox that receives applications is limited to the people who need it and protected by multi-factor authentication.
10
Children
This site is aimed at professional creators, coaches and trainers running a business, and is not directed at children. We do not knowingly collect personal data from anyone under 16, and we do not offer anything on this site directly to a child.
If you believe someone under 16 has sent us their details, tell us at office@trainstackapp.com and we will delete the record.
11
Changes to this policy
We update this page whenever what we do with personal data changes, and before the change reaches the site rather than after. The date shown alongside the contents is the date of the current version.
If a change materially affects your rights or how we use data you have already given us, we will say so at the top of this page and, where we hold your email address and the change warrants it, write to you directly.
Questions about this document? Write to office@trainstackapp.com.