Skip to content

Legal

Privacy Policy

This policy explains what personal data TrainStack collects through trainstackapp.com, why we collect it, who it reaches, how long we keep it, and what you can require us to do with it.

It covers this website only. If we go on to operate a subscription app for a creator, that app carries its own privacy notice for its members.

01

Who we are

TrainStack is a trading name of RNM Rainmaker GmbH ("we", "us"), a limited liability company registered in Austria under FN 505325 a at the Handelsgericht Wien, with its registered office at Auerspergstraße 1, 1080 Wien, Austria. That company operates trainstackapp.com and is the controller of the personal data described here, which means it decides why the data is collected and what happens to it.

We are established in the European Union, so this policy is written to the GDPR as it applies in Austria, together with the Austrian Data Protection Act (Datenschutzgesetz) where that adds to it.

Our contact address for everything in this policy - questions, requests about your data, and complaints - is office@trainstackapp.com. It reaches a person, not a ticketing queue. You may also write to the registered office above, though email will always be faster.

We have not appointed a Data Protection Officer. The processing described here is small in scale, is not systematic monitoring, and involves no special-category data, so Article 37 of the GDPR does not require one. Questions that a DPO would answer should go to the same address.

02

What we collect

Almost everything we hold about you is something you typed into the application form. There is no account to create, no password to set, and nothing to pay, so we hold no credentials and no payment details.

  • The application form, when you submit it. Only two fields are required: your name and your email address. Two more are optional and collected only if you choose to fill them in: a link to your social profile, and any notes you want to add. We deliberately do not ask for anything else at this stage - if we need more, we ask you in a reply.
  • Two anti-spam signals collected with that submission: a hidden field that is never shown to you and should stay empty, and how many milliseconds elapsed between the form loading and you submitting it. Both are checked at the moment of submission and then discarded - neither is stored or passed on.
  • Correspondence: the content of any email you send us and our replies, including anything you choose to add beyond the form.
  • Your IP address, when you submit the form. It is used only to count submissions per address, is held in the server’s memory for one hour, and is never written to a file, a database or an email.
  • Ordinary web server logs, kept briefly on our own server so the site can be operated and debugged - the kind of technical record every web server produces. We do not use them to build a profile of you.
  • Measurement data, and only if you allow it: the Cookie Policy lists every tag, every cookie it sets and how long each lasts.
  • If, and only if, you allow the analytics category: a record of how you used the site. That means the pages you opened, which sections of them stayed on your screen long enough to have been read, where you clicked and scrolled, roughly where in the world your visit came from, the sort of device and browser you used, the site or advert you arrived from, and a session replay - a reconstruction of the visit, assembled from the page as we served it plus the timing of your scrolling and clicking. It is a rebuild of our own page, not a video of your screen: nothing outside this website is captured.
  • Your IP address reaches our analytics provider with each of those events, because every web request carries one. It is used to work out the approximate location above and for nothing else: the provider is configured to discard it as soon as that is done, so it is not stored alongside your visit. We do not use it to identify you, and it is never matched against the address recorded when you submit the form.
  • What that record deliberately does not contain: anything you typed. Every form field is masked in your browser before a single byte is sent, so the name, email address, link and notes on the application form never reach our analytics provider. Nor does it contain the content of any request or response. We also never link this record to your application - we never call the identification function that would attach your email address to it - so to the provider you remain a random identifier stored in your own browser.

04

Who we share it with

We do not sell your personal data, we do not share it for advertising, and we do not pass it to other creators or to anyone evaluating a competing application. It reaches only the providers that make the site, the form and our email work, each acting on our instructions.

  • DigitalOcean, LLC - the virtual server that runs this website and receives the form. The server is located in Frankfurt, Germany, and we administer it ourselves; DigitalOcean provides the infrastructure it runs on.
  • Cloudflare, Inc. - authoritative DNS for our domain; the email routing service that receives mail addressed to us and forwards it to our inbox, so every application notification and every message you send us passes through it; and Turnstile, which checks on the application page that a submission comes from a real browser rather than a script.
  • Resend (Plus Five Five, Inc.) - the email service that delivers each application to our inbox and sends our replies. Sending is configured in its European region, so the message is processed in Ireland. It handles the message in transit; it does not use the contents for its own purposes.
  • Google Ireland Limited - the mail service where our inbox sits and where applications and correspondence are stored and read.
  • Professional advisers, such as a lawyer or accountant, where we genuinely need their help on a matter that involves your data, and law enforcement or a regulator where we are legally required to respond.
  • PostHog, Inc. - the product analytics service that receives the usage record described above, including session replays, once you have allowed the analytics category. Our project is on its EU region, so the data is stored in Frankfurt, Germany. PostHog acts on our instructions as a processor and does not use what it receives for its own purposes; its list of sub-processors for that region is published at posthog.com/subprocessors.
  • The other measurement providers named in the Cookie Policy, and only after you have allowed the matching category.

05

Sending data outside the EEA

We are established in Austria and we keep processing inside the EEA. The server that runs this site and receives your application is in Frankfurt, Germany. Our email sending is configured in Resend’s European region, so application mail is processed in Ireland, and the inbox is provided by Google’s Irish entity. Our analytics project is on PostHog’s EU region, so the usage record and any session replays are stored in Frankfurt as well; the US region was not used, and choosing it would have made this paragraph untrue. In ordinary operation your data does not leave the EEA.

Several of those providers are nevertheless US-incorporated companies, and Cloudflare operates a global network, so access from outside the EEA cannot be ruled out. The United States is not covered by a general adequacy decision, which means a specific safeguard is required for that possibility.

We rely on the European Commission’s Standard Contractual Clauses, incorporated into the data processing terms each provider publishes, together with the technical measures described under Security below. Where a provider additionally holds a certification under the EU–U.S. Data Privacy Framework, that certification applies alongside those clauses.

You may ask us for details of the safeguard that applies to a particular provider by writing to the address at the end of this page.

06

How long we keep it

We keep each category only for as long as the purpose above requires, then delete it. These are the periods we work to:

  • An application that does not lead to a partnership: 24 months from the date you submitted it, so we can reconsider you if your audience or our capacity changes. Ask us to delete it sooner and we will, without needing a reason.
  • An application that does lead to a partnership: for as long as the partnership lasts, and for six years afterwards, which covers the usual limitation and accounting periods.
  • Correspondence: 24 months from the last message in the thread, unless it forms part of a live partnership record.
  • The IP address used for rate limiting: one hour, in the server’s memory. It is discarded when the hour ends, and also whenever the server restarts.
  • Web server logs: rotated automatically on the server and kept only for a short period, after which they are overwritten. We do not copy them anywhere else.
  • The usage record, if you allowed it: session replays are deleted after 30 days, and the events behind our reports - pages opened, sections read, buttons clicked - after 12 months. Both periods are set in the analytics project itself, so they apply whether or not anyone remembers this page. Withdrawing consent stops new data immediately and clears the identifiers from your browser; ask us at the address below and we will delete what was already collected.
  • Your cookie choice: it stays in your own browser until you change it or clear your browser storage. It is never sent to us.

07

Your rights

You can exercise any of the rights below by emailing office@trainstackapp.com. We will not charge you, and we will reply within one month - if a request is genuinely complex we may extend that by a further two months, and we will tell you why within the first month. We may ask you to confirm your identity, but only where we cannot otherwise be confident who is asking.

  • Access - ask whether we hold data about you, and receive a copy of it along with the information in this policy.
  • Rectification - have anything inaccurate corrected, and anything incomplete filled in. If your follower count or your concept has moved on, simply tell us.
  • Erasure - have your data deleted where we no longer need it, where you withdraw a consent we were relying on, or where you successfully object to our processing.
  • Restriction - have us pause processing while an accuracy dispute or an objection is being resolved.
  • Portability - receive the data you gave us in a structured, commonly used, machine-readable format, or have us send it directly to another controller where that is technically feasible.
  • Objection - object at any time to processing we base on legitimate interests, including keeping a declined application on file. We will stop unless we can show compelling grounds that override your interests.
  • Withdrawal of consent - withdraw any consent you have given, at any time, without affecting anything already done on the basis of it.
  • No automated decision-making - you are not subject to any. Every application on this site is read and decided by a person; nothing here profiles you or scores you automatically.
  • Complaint - raise the matter with a supervisory authority if you think we have got something wrong. Because we are established in Austria, our lead authority is the Austrian Data Protection Authority (Datenschutzbehörde), but you may equally complain to the authority in the EU or EEA country where you live or work. We would rather you came to us first so we can put it right, but you do not have to.

08

Security

The measures below are the ones this site actually implements, rather than a general statement of intent. No method of transmission or storage is ever completely secure and we cannot promise absolute safety, but these are concrete and checkable:

  • Everything is served over HTTPS, with HSTS set for two years including subdomains, so a browser will not connect over an unencrypted channel.
  • Applications are not stored in a database on this website. The form posts to a server-side route which validates the submission and hands it straight to our inbox, so there is no store of applications on the public internet to breach.
  • The route accepts JSON only, rejects any body over 24 KB, and validates every field against a strict schema before anything is done with it. Text is sanitised and escaped before it reaches an email, so a submission cannot inject content into what we read.
  • Submissions are limited to five per IP address per hour, and submissions that trip the hidden-field or timing check are dropped without reaching us.
  • The site sends a conservative set of security headers on every response: no MIME sniffing, no framing by other origins, a restrictive referrer policy, and a permissions policy that switches off camera, microphone, geolocation and cohort-based tracking.
  • The only third-party code that loads without being asked for is Cloudflare Turnstile, on the application page alone, to check that a submission comes from a real browser. Everything that measures - analytics, session recording, campaign pixels - is fetched at the moment you allow the matching category and never before: decline, or simply ignore the banner, and that code is not downloaded to your browser at all, rather than downloaded and told to keep quiet.
  • Session recording is configured to mask every form field in the browser before anything is transmitted, and to record no request or response content. The application form’s contents therefore cannot appear in a replay even if a recording is running while you fill it in.
  • Access to the inbox that receives applications is limited to the people who need it and protected by multi-factor authentication.

09

Cookies and your choice

Nothing at all is stored in your browser before you have made a choice. The record of your preference is written only once you answer the banner, and it stays on your device - we never receive a copy of it.

The Cookie Policy lists every cookie and similar technology in use, what each does, who sets it and how long it lasts, and it is generated from what this deployment actually loads rather than written by hand. You can change or withdraw your choice from the control at the bottom of that page, at any time, and the change takes effect immediately.

10

Children

This site is aimed at professional creators, coaches and trainers running a business, and is not directed at children. We do not knowingly collect personal data from anyone under 16, and we do not offer anything on this site directly to a child.

If you believe someone under 16 has sent us their details, tell us at office@trainstackapp.com and we will delete the record.

11

Changes to this policy

We update this page whenever what we do with personal data changes, and before the change reaches the site rather than after. The date shown alongside the contents is the date of the current version.

If a change materially affects your rights or how we use data you have already given us, we will say so at the top of this page and, where we hold your email address and the change warrants it, write to you directly.

Questions about this document? Write to office@trainstackapp.com.