Privacy Policy
Last updated: 2026-08-03 Version: 2026-08-en
This policy explains how SIA SpontLabs collects and uses personal data through the website spontup.app and its subdomains.
This policy covers the SpontUp landing page and waitlist only. The SpontUp application, when released, will be covered by a separate privacy policy.
The authoritative version of this policy is the Latvian one. English and Russian versions are provided for convenience; in the event of a discrepancy, the Latvian text prevails.
1. Who we are
SIA SpontLabs ("we", "us") is the data controller for the processing described in this policy.
- Registration number: 40203761858
- Registered address: Bauskas iela 6–23, Daugavpils, LV-5404, Latvia
- Contact: info@spontup.app
We have not appointed a Data Protection Officer. Our processing does not meet the criteria in Article 37 of the GDPR: we are not a public authority, our core activities do not involve large-scale systematic monitoring, and we do not process special categories of personal data.
2. What data we collect
Data you provide. When you join the waitlist, you submit your name and email address.
Data collected automatically when you use the form. Your IP address, the time of submission, and the time of your confirmation. We also record which version of the consent wording you were shown and in which language.
Data collected for security purposes. Cloudflare Turnstile and our rate-limiting measures process your IP address and technical signals from your browser and device in order to distinguish human visitors from automated traffic.
Server logs. Our servers record IP addresses, user-agent strings, and request metadata for a short period.
Analytics. We use Cloudflare Web Analytics, which does not use cookies and does not fingerprint visitors. It provides us with aggregate statistics only. We do not receive information identifying individual visitors.
Correspondence. If you email us, we process the contents of your message and your email address in order to reply.
3. Why we process your data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Adding you to the waitlist and sending you launch announcements and related promotional messages | Your consent — GDPR Art. 6(1)(a) |
| Sending the confirmation email to verify that the address belongs to you | Your consent — GDPR Art. 6(1)(a) |
| Keeping a record of your consent (wording, language, timestamps, IP) | Compliance with our accountability obligation — GDPR Art. 6(1)(c), read with Art. 5(2) and Art. 7(1) |
| Retaining unconfirmed signups for a limited period | Our legitimate interests — GDPR Art. 6(1)(f) |
| Preventing automated abuse, spam submissions, and attacks on the site | Our legitimate interests — GDPR Art. 6(1)(f) |
| Measuring aggregate site traffic | Our legitimate interests — GDPR Art. 6(1)(f) |
| Responding to your correspondence | Our legitimate interests — GDPR Art. 6(1)(f) |
| Maintaining a suppression list so that unsubscribed addresses are not re-added | Compliance with a legal obligation and our legitimate interests — GDPR Art. 6(1)(c) and 6(1)(f) |
Where we rely on legitimate interests, those interests are: operating the waitlist securely; being able to demonstrate that a confirmation email was sent in response to a genuine form submission, should a recipient complain that it was unsolicited; understanding how many people visit the site; and honouring unsubscribe requests reliably. We have considered the impact on you and consider these interests not to be overridden by your rights, given the small amount of data involved and the short retention periods.
Providing your data is voluntary. You are not required by law or contract to join the waitlist. If you choose not to provide your name and email address, you simply will not be added to it. There is no other consequence.
4. Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not carry out profiling. Our bot-detection and rate-limiting measures are security controls and do not make decisions about you as a person.
5. How long we keep your data
| Data | Retention period |
|---|---|
| Confirmation token | 24 hours from submission, after which the link expires |
| Unconfirmed signup (name, email, submission metadata) | 30 days from submission, then deleted |
| Confirmed waitlist entry (name, email) | Until you unsubscribe |
| Consent record | 3 years after you unsubscribe |
| Suppression list entry (unsubscribed address) | 3 years after you unsubscribe |
| Server logs | 7 days |
| Analytics data | Aggregate only; no personal data retained |
| Correspondence | For as long as needed to handle your enquiry and for a reasonable period afterwards |
We retain consent records after you unsubscribe so that we can demonstrate, if challenged, that we had a valid basis for having contacted you. We retain unconfirmed signups for 30 days so that we can respond to any complaint that a confirmation email was unsolicited.
6. Who we share your data with
We do not sell your personal data and we do not share it for anyone else's marketing purposes.
We use the following service providers, who process personal data on our instructions under data processing agreements:
| Provider | Role | Data location |
|---|---|---|
| Cloudflare, Inc. (United States) | Website hosting, application runtime, database (waitlist entries and consent records), bot protection (Turnstile), web application firewall, email routing, analytics | Primarily the European Union; Cloudflare operates a global network and data may be processed elsewhere |
| Resend (United States) | Sending transactional and marketing email; storage of the confirmed waitlist | United States |
| Google Ireland Limited | Receiving email sent to our contact address, which is forwarded to a mailbox operated by Google | European Union and United States |
We may also disclose personal data where we are required to do so by law, or where necessary to establish, exercise, or defend legal claims.
7. Transfers outside the European Economic Area
Some of our service providers are established in the United States. Where personal data is transferred outside the EEA, that transfer is made on the basis of the Standard Contractual Clauses adopted by the European Commission, which are incorporated into our agreements with those providers.
You may request a copy of the safeguards we rely on by contacting us at the address in section 1.
8. Cookies and similar technologies
We do not use cookies for advertising, tracking, or analytics, and therefore we do not ask you for cookie consent.
The following are set for strictly necessary purposes:
__cf_bm— set by Cloudflare to distinguish bots from human visitors. Expires within 30 minutes.cf_clearance— set by Cloudflare when a security challenge is completed, so that you are not challenged repeatedly.
Both are necessary to provide the service you have requested and are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive and its Latvian implementation.
We do not use localStorage, sessionStorage, or browser fingerprinting for tracking. Fonts and other assets are served from our own domain, not from third-party content networks.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and to receive a copy of it
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict our processing in certain circumstances
- Data portability — receive the data you gave us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible
- Object to processing based on our legitimate interests, on grounds relating to your particular situation
- Object to direct marketing at any time, with no need to give a reason
Withdrawing consent. You may withdraw your consent at any time. Every email we send contains an unsubscribe link, and unsubscribing takes effect immediately. You can also write to us at the address in section 1. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at info@spontup.app. We will respond within one month. That period may be extended by two further months for complex requests, in which case we will tell you within the first month and explain why.
Complaints. If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with the Latvian supervisory authority:
Datu valsts inspekcija Elijas iela 17, Rīga, LV-1050, Latvia pasts@dvi.gov.lv · www.dvi.gov.lv
You may also complain to the supervisory authority in your country of residence.
10. Security
We protect your data using HTTPS across the whole site, bot protection and rate limiting on the signup form, restricted access to production credentials, and by keeping to a minimum the data we collect and how long we hold it.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Datu valsts inspekcija within 72 hours of becoming aware of it, and we will notify you directly where the breach is likely to result in a high risk to you.
11. Children
The waitlist is not directed at children. Under Latvian law, a child may consent to information society services from the age of 13; below that age, consent must be given or authorised by a parent or guardian. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has submitted data to us, contact us and we will delete it.
12. Changes to this policy
We may update this policy. The current version and its date always appear at the top of this page.
If we make a material change — in particular, a change to what we use your email address for — we will notify you by email before the change takes effect, and where the change requires it, we will ask for your consent again.
Previous versions are archived and available on request.