Back to home

Privacy Policy

Last updated: 2026-10-04·Effective: 2026-06-18

This Privacy Policy explains how PlenDesk ("we", "us") collects, uses, and protects personal data in connection with myID (QR tags and lost-and-found item recovery) and BuyKeep (receipts, documents and saved purchase details) ("Services"). It is written to satisfy the Swiss Federal Act on Data Protection (nDSG, as revised in 2023) and the EU General Data Protection Regulation (GDPR) where applicable.

1. Controller

The controller responsible for your personal data is:

Jürgen Walter
Lindachstrasse 13
3038 Kirchlindach BE
Switzerland
Email: privacy@plendesk.com

PlenDesk is a Swiss sole proprietorship. If you have any question about this Policy or about how we process your personal data, please contact us at the email above.

2. What personal data we collect

When you use our Services, we may collect:

  • Account data — name, email address, login metadata, preferences. Collected when you create an account via Clerk.
  • myID tag data — tag labels, public finder page text, QR-code paths, optional custom slugs, item categories, and tag status. Collected when you create or manage a myID tag.
  • Finder messages — messages submitted through a public myID finder page, optional finder contact details, message timestamps, scan metadata, and anonymous chat tokens.
  • BuyKeep data — receipts, invoices, photos and PDFs, merchant and purchase details, amounts, product and serial numbers, notes, categories, custom fields, saved dates, AI suggestions and your review decisions. Export requests also store temporary copies of these details, progress, expiry and download-attempt records.
  • Billing data — plan, credit balance, invoice metadata. Payment card data is processed by the payment provider shown at checkout and never reaches our servers.
  • Technical data — IP address, browser type, device information, error events. Used only for operating and securing the Services.

3. Purposes and legal bases

  • Providing the Services (nDSG Art. 31 para. 2 lit. a / GDPR Art. 6(1)(b) — contract performance). Includes creating QR tags, showing public finder forms, delivering finder messages, storing and organising BuyKeep documents, extracting details when you request AI assistance, providing downloads, authenticating users, and managing billing.
  • Security and abuse prevention (nDSG Art. 31 para. 2 lit. c / GDPR Art. 6(1)(f) — legitimate interest). Includes error monitoring, rate limiting, fraud detection.
  • Compliance with legal obligations (GDPR Art. 6(1)(c)) — e.g. tax record-keeping, regulatory requests.
  • Communications about the Services — transactional emails such as account, billing, support, and finder-message notifications. We do not send marketing messages.

4. Who we share your data with

We use carefully selected external service providers to operate the Services. Provider details and available data-processing documentation are listed below and maintained in our compliance registry.

BuyKeep stores encrypted document files in private DigitalOcean Spaces storage and document metadata in Convex. The BuyKeep server decrypts files for authorised viewing and downloads. If you start AI extraction, the selected document content is decrypted for processing through Vercel AI Gateway and the configured model provider. AI suggestions require your review before they become saved purchase details. AI extraction is optional. DigitalOcean's processing terms are available in its Data Processing Agreement.

ProviderPurposeCountryLegal basis for transferDPA
Clerk
clerk.com
Authentication, account management, and session securityUnited StatesDPA, SCCs, and applicable data transfer safeguardsView DPA
Convex
convex.dev
Application database, server functions, and real-time data syncUnited StatesDPA, SCCs, and applicable data transfer safeguardsView DPA
Vercel
vercel.com
Hosting, edge routing, deployment, and web analyticsUnited StatesDPA, SCCs, and applicable data transfer safeguardsView DPA
Sentry
sentry.io
Error monitoring, diagnostics, and security troubleshootingUnited StatesDPA, SCCs, and applicable data transfer safeguardsView DPA
Resend
resend.com
Transactional emails such as account, support, and finder messagesUnited StatesDPA, SCCs, and applicable data transfer safeguardsView DPA
Polar
polar.sh
Intended payment provider and Merchant of Record for paid checkout when enabledUnited StatesPayment processing terms and applicable data transfer safeguardsView DPA

Some of these providers in turn rely on their own sub-processors (e.g. infrastructure providers such as AWS). A consolidated list is maintained via the DPA links above; we update this page when the underlying providers change.

5. International transfers

Most of our providers are headquartered in the United States. Transfers from Switzerland and the EU are covered by the Swiss-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, as referenced in each provider's DPA linked above. We do not transfer personal data to countries without an adequate level of protection unless such safeguards are in place.

6. How long we keep your data

  • Account data — for as long as your account is active, plus a reasonable window for deletion requests and legal obligations.
  • myID tag data — for as long as the tag exists in your account, unless you delete or retire it earlier.
  • Finder messages and anonymous chats — retained so you can recover the tagged item and review your recent contact history; deleted when the related tag or account is deleted unless a legal obligation requires retention.
  • BuyKeep documents — retained while saved in your account. Moving a receipt to the trash schedules deletion after 30 days; you can restore it during that period. Export preparation is available for 24 hours from its creation. After expiry, scheduled cleanup removes its temporary metadata and attempt records. ZIP/JSON files are generated during download and are not stored as additional server-side archives. Copies you download remain on your own device until you delete them.
  • Security and access logs — retained for a limited period needed to operate, secure, and troubleshoot the Services.
  • Verification codes — deleted on use or after expiry (minutes to hours).
  • Billing records — retained for as long as Swiss tax law requires (currently 10 years).

Request account deletion through the available account controls or by contacting privacy@plendesk.com. The deletion of a login alone does not confirm completed deletion in every connected app. We process the request across the affected services and explain any retention required by law.

7. Your rights

Under nDSG and GDPR you have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — request deletion using account controls or privacy@plendesk.com.
  • Restriction — ask us to limit how we process your data.
  • Objection — object to processing based on our legitimate interest.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — where processing is based on consent, at any time.

To exercise any of these rights, email privacy@plendesk.com. We respond within 30 days.

If you are in Switzerland and believe we process your data unlawfully, you may also lodge a complaint with the Federal Data Protection and Information Commissioner (EDÖB). If you are in the EU, you may lodge a complaint with your local data protection authority.

8. Cookies and tracking

PlenDesk uses strictly functional cookies that are necessary to operate the Services (authentication session, CSRF protection). No advertising or cross-site tracking cookies are used.

Our administrator dashboards may use Sentry Session Replay to record UI interactions when an error occurs, strictly for debugging. Text input and media are masked by default; token-bearing public finder and contact pages are excluded from recording entirely.

9. Security

We implement technical and organisational measures appropriate to the risk, including TLS encryption in transit, authentication via Clerk, role-based access control, and continuous error monitoring. Public finder pages use bot protection and rate-limiting to prevent abuse. Despite our efforts, no system is perfectly secure; please contact us immediately if you suspect a breach.

10. Children's privacy

The Services are not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have, please contact us so we can delete it.

11. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top reflects the current version. Material changes will be communicated through the Services.

12. Governing law

This Policy is governed by Swiss law. Any disputes are subject to the exclusive jurisdiction of the competent courts of Kirchlindach, Switzerland.