Privacy Policy
Last updated: 9 August 2026
1. Data Controller
TORCHTECHNOLOGY LTD (a private company limited by shares under the Companies Law (Cap. 113) of the Republic of Cyprus, company registration number HE 496008)
Registered office: 25 Martiou 27, D. Michael Tower, Flat/Office 105A, Egkomi, 2408 Nicosia, Republic of Cyprus
Email: hello@torchtechnology.de
2. Overview of Data Processing
We only process personal data to the extent necessary to provide our website and services. The processing of personal data is generally only carried out with the user's consent or when processing is permitted by law.
A complete list of the service providers that process personal data on our behalf, including the country of processing and the applicable transfer safeguards, is set out in Section 11 (Subprocessors).
3. Hosting
Our website and the Torch application services are hosted on the infrastructure of Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA ("Railway"). When you visit our pages, information is automatically stored in server log files that your browser transmits: browser type and version, operating system, referrer URL, hostname of the accessing device, time of request, and IP address. This data is technically necessary to deliver the site, is not merged with other data sources, and is collected on the basis of Art. 6(1)(f) GDPR — our legitimate interest in the secure and efficient operation of our services.
Railway is a US company and operates parts of its platform from the United States; the Torch product applications are deployed in Railway's EU region (Amsterdam, Netherlands). Transfers of personal data to the United States are safeguarded by Railway's active certification under the EU-US Data Privacy Framework and, in addition, by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated into Railway's Data Processing Agreement (railway.com/legal/dpa). Railway's representative in the EU under Art. 27 GDPR is DP-Dock GmbH, Ballindamm 39, 20095 Hamburg, Germany.
4. Contact Form
When you contact us via the contact form, your details (name, email address, subject, message) are stored for the purpose of processing your inquiry. We will not share this data without your consent.
Contact messages are delivered through our email service provider Resend (see Section 11).
Processing is based on Art. 6(1)(b) GDPR if your inquiry is related to contract fulfillment or pre-contractual measures. In all other cases, processing is based on Art. 6(1)(f) GDPR.
5. Demo Booking
If you book a demo, we process your name, email address, company details you choose to provide, and the selected time slot in order to schedule and hold the appointment. Slot reservations are stored in a datastore operated by Upstash, Inc. (San Jose, CA, USA); Upstash holds an active certification under the EU-US Data Privacy Framework, and its Data Processing Agreement additionally incorporates the EU Standard Contractual Clauses. Confirmation emails are sent through Resend (see Section 11).
Add-to-calendar links on the confirmation page open your own calendar application; we do not transmit your booking data to Google or any other calendar provider.
Processing is based on Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).
6. Payment Processing with Stripe
When you book a paid plan through our checkout, we process the data required to conclude the contract, bill you, and provide access, in particular name, email address, billing address, company and VAT details, selected plan, payment status, and Stripe customer number.
Payments are processed through Stripe. Our contracting entity is Stripe Payments Europe, Limited (Ireland); payment data may be transferred onward to Stripe, LLC in the United States, which holds an active certification under the EU-US Data Privacy Framework, with the EU Standard Contractual Clauses applying as a fallback under Stripe's Data Processing Agreement (stripe.com/legal/dpa). We do not receive full card or bank details.
The legal bases are Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(c) GDPR for tax and commercial-law obligations, and Art. 6(1)(f) GDPR for fraud prevention and payment security.
7. Cookies
Our website does not use cookies for tracking or analytics purposes. Our web analytics (see section 8) also works entirely without cookies. Should this change, we will update this privacy policy accordingly and implement a consent solution if required.
8. Analytics and Advertising
We use the privacy-friendly, cookieless web analytics service Plausible Analytics on this website, operated by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia (EU).
Plausible sets no cookies and stores no personal data. Only aggregated usage data is collected (e.g. pages visited, referrer, browser and device type, country of origin) along with anonymous interaction events (e.g. clicking the demo button, submitting the contact form). IP addresses are processed only transiently, are not stored, and are not shared with third parties; identifying individual visitors is not possible. All data is processed exclusively on servers within the EU.
Processing is based on Art. 6(1)(f) GDPR; our legitimate interest is the statistical analysis of website usage to improve our offering. For more information, see Plausible's data policy: https://plausible.io/data-policy. If you choose "Reject" in the cookie notice, web analytics remains fully disabled in your browser. We do not use advertising services.
9. Data Processing in the Torch Products
When you use the Torch products (Torch Platform, Torch Listings, Torch Studio, Torch Trends), we process the data you provide in your workspace: account and login data, organization and billing details, and the content you upload or create — product data, images, brand information and prompts ("customer content"). Processing is based on Art. 6(1)(b) GDPR.
Databases, authentication and file storage are operated by Supabase Pte. Ltd. (Singapore). Our database, authentication and storage instances are pinned to Supabase's EU region (Frankfurt, Germany); Supabase support and platform telemetry may involve processing in the United States or Singapore. These transfers are safeguarded by the EU Standard Contractual Clauses (2021/914, Modules Two and Three) incorporated into Supabase's Data Processing Addendum (supabase.com/legal/dpa).
To generate text, we send the relevant parts of your customer content (prompts and product data) to OpenRouter, Inc. (New York, USA), an AI model gateway. OpenRouter does not use your inputs or outputs for model training and by default does not retain prompt content; the model providers OpenRouter routes requests to (for example OpenAI, Anthropic or Google) act as OpenRouter's own subprocessors under its Data Processing Agreement, which incorporates the EU Standard Contractual Clauses (Module Two).
To generate and edit images, we send image prompts and product images to fal – Features & Labels, Inc. (San Francisco, USA), an AI inference platform. fal processes this data only as our processor, retains it no longer than the term of our agreement, claims no rights in the generated outputs, and may use only de-identified data to improve its services. Transfers are safeguarded by the EU Standard Contractual Clauses (Module Two) incorporated into fal's Data Processing Addendum (fal.ai/legal/data-processing-addendum).
Invitation and notification emails are sent through Resend, a service of Plus Five Five, Inc. (San Francisco, USA), which holds an active certification under the EU-US Data Privacy Framework (EU and UK; email data is stored in the United States) and whose Data Processing Agreement additionally incorporates the EU Standard Contractual Clauses. Account-confirmation and sign-in emails are sent via our authentication provider, Supabase.
We do not sell personal data, and we do not use customer content for advertising.
10. Collection of Publicly Available Marketplace Data
Torch Listings and Torch Trends analyze publicly available marketplace data — product listings, prices, rankings, reviews and seller information from e-commerce marketplaces such as Amazon. Where such data relates to identifiable persons (for example, sole traders selling under their own name), the following applies (Art. 14 GDPR):
Categories: publicly listed product, price, ranking, review and seller information. Source: publicly accessible marketplace pages and marketplace data services. Purpose: market and trend analyses for our customers. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest, and that of our customers, in market intelligence compiled from public sources.
We collect this data through the specialised services Apify Technologies s.r.o. (Prague, Czech Republic), oxylabs, UAB (Vilnius, Lithuania) and Keepa GmbH (Kemnath, Germany).
You may object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR) by writing to hello@torchtechnology.de.
11. Subprocessors
We use the following service providers to process personal data on our behalf. For providers outside the European Economic Area, the listed transfer safeguard applies. Status of this list: 9 August 2026.
Railway Corporation (USA) — hosting of the website and all Torch application services (EU deployment region: Amsterdam); server logs and IP addresses. Safeguards: EU-US Data Privacy Framework (active certification) and EU Standard Contractual Clauses (railway.com/legal/dpa).
Supabase Pte. Ltd. (Singapore) — databases, authentication and file storage for the Torch products, pinned to the EU region Frankfurt; support and telemetry may be processed in the US/Singapore. Safeguards: EU Standard Contractual Clauses, Modules Two and Three (supabase.com/legal/dpa).
Stripe Payments Europe, Limited (Ireland) — payment processing and billing. Onward transfers to Stripe, LLC (USA) are safeguarded by Stripe LLC's active EU-US Data Privacy Framework certification and the EU Standard Contractual Clauses (stripe.com/legal/dpa).
OpenRouter, Inc. (USA) — AI gateway for text generation; carries prompts and product copy. No training on customer inputs or outputs; no prompt retention by default. Safeguards: EU Standard Contractual Clauses, Module Two (openrouter.ai/data-processing-agreement).
fal – Features & Labels, Inc. (USA) — AI image generation; carries image prompts and product images. No model training on customer content (de-identified data only); retention bounded by the contract term. Safeguards: EU Standard Contractual Clauses, Module Two, under fal's Data Processing Addendum (fal.ai/legal/data-processing-addendum).
Apify Technologies s.r.o. (Czech Republic, EU) — collection of publicly available marketplace data; run data is processed in the EU and the United States (AWS, MongoDB Atlas, Mezmo, Snowflake). Safeguards for processing outside the EEA: EU Standard Contractual Clauses under Apify's Data Processing Addendum (docs.apify.com/legal/data-processing-addendum).
oxylabs, UAB (Lithuania, EU) — collection of publicly available marketplace data. EU-established provider; Data Processing Agreement at oxylabs.io/legal/oxylabs-data-processing-agreement.
Keepa GmbH (Germany, EU) — Amazon product and price history. EU-established provider.
Plus Five Five, Inc. d/b/a Resend (USA) — transactional email (invitations, contact and booking confirmations). Safeguards: EU-US Data Privacy Framework (active certification, EU and UK extensions) and EU Standard Contractual Clauses (resend.com/legal/dpa).
Plausible Insights OÜ (Estonia, EU) — cookieless web analytics; visitor data does not leave the EU.
Upstash, Inc. (USA) — datastore for demo-booking slot reservations. Safeguards: EU-US Data Privacy Framework (active certification) and EU Standard Contractual Clauses (upstash.com/trust/dpa.pdf).
We will update this list when a provider is added or replaced. Business customers can request our Data Processing Agreement, including subprocessor flow-down terms, at hello@torchtechnology.de.
12. SSL/TLS Encryption
This site uses SSL/TLS encryption for security and to protect the transmission of confidential content. You can recognize an encrypted connection by the address bar of your browser changing from "http://" to "https://" and by the lock icon in your browser bar.
13. EU Compliance and Artificial Intelligence
TORCHTECHNOLOGY LTD develops and operates its products in conformity with European Union law. Personal data is processed in accordance with the EU General Data Protection Regulation (GDPR), and our services and AI features are designed to align with the EU Artificial Intelligence Act (AI Act).
Where our products generate content using artificial intelligence, a provenance record identifying that content as AI-generated is stored with each generated version, a human remains in control of what is published, and the systems are operated with appropriate human oversight. We do not use AI for practices prohibited under the AI Act.
Personal data is hosted and processed within the European Union wherever possible. Details on your data-protection rights can be found in the sections above.
14. Your Rights
You have the right to free information about your stored personal data, its origin and recipients, and the purpose of data processing, as well as a right to correction or deletion of this data (Art. 15–17 GDPR).
You have the right to request restriction of processing of your personal data (Art. 18 GDPR) and the right to data portability (Art. 20 GDPR).
Where we process your personal data on the basis of Art. 6(1)(f) GDPR (e.g. server log files, web analytics and marketplace data), you have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). Simply send your objection to hello@torchtechnology.de.
If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
15. Objection to Promotional Emails
The use of contact data published as part of the legal notice obligation for sending unsolicited advertising is hereby objected to. The operator expressly reserves the right to take legal action in the event of unsolicited promotional information, such as spam emails.