Privacy Policy
Last updated: September 1, 2026
1. Data controller
This Privacy Policy explains how HereIsMySaaS ("we", "us") processes personal data when you use hereismysaas.com (the "Service"), in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national law. Data controller: HereIsMySaaS Contact for privacy requests: contact@hereismysaas.com We have not appointed a Data Protection Officer (DPO). For any question about your personal data, contact us at the address above.
2. Scope
This policy applies to visitors, registered users, and SaaS submitters. It does not apply to third-party websites linked from the directory, which have their own privacy policies.
3. Personal data we process
Depending on how you use the Service, we may process: • Account data: email address, name (optional), password hash (if you sign up with email), profile image (if provided by Google sign-in), user role, account creation date. • Listing data: product name, tagline, website URL, hostname, favicon URL, category, optional category suggestion, submission and publication status, click count. • Authentication data: session tokens and OAuth identifiers managed by our authentication provider. • Technical data: IP address, browser type, and server logs generated when you access the Service. • Local browser data: a local storage entry used to avoid counting duplicate listing clicks from the same browser.
4. Purposes and legal bases (Article 6 GDPR)
We process personal data only where we have a valid legal basis: • Creating and managing your account, publishing listings, and operating the directory — Performance of a contract (Art. 6(1)(b) GDPR). Providing account data is necessary to use submission features; without it, you cannot submit or manage listings. • Sending transactional emails (e.g. approval or rejection of a submission) — Performance of a contract (Art. 6(1)(b)) and, where applicable, legitimate interest in communicating about your submission (Art. 6(1)(f)). • Measuring listing clicks and displaying aggregate statistics — Legitimate interest (Art. 6(1)(f)) in operating and improving a fair directory. Our legitimate interest is to provide transparent usage metrics to listing owners and visitors; you may object as described in Section 10. • Keeping authentication sessions secure — Legitimate interest (Art. 6(1)(f)) in protecting accounts and the Service from unauthorised access. • Moderating submissions and preventing abuse — Legitimate interest (Art. 6(1)(f)) in maintaining directory quality and security. • Complying with legal obligations — Legal obligation (Art. 6(1)(c)) where applicable. We do not use your personal data for automated decision-making or profiling within the meaning of Article 22 GDPR.
5. Cookies and similar technologies
We use the following storage mechanisms: • Essential session cookies (e.g. authentication session cookie) — required to keep you signed in. Legal basis: legitimate interest / strictly necessary for the Service you request. • Local storage (click tracking key) — used only to prevent duplicate click counting in your browser. Legal basis: legitimate interest. We do not currently use non-essential analytics or advertising cookies. If this changes, we will update this policy and, where required, collect your consent before placing such cookies.
6. Recipients and processors
We share personal data only when necessary and with appropriate safeguards: • Infrastructure and hosting provider — hosting the application and database. • Email delivery provider (SMTP) — sending transactional emails. • Google (optional) — if you choose "Sign in with Google", Google processes authentication data under its own privacy policy. • Public directory pages — published listing information (product name, tagline, URL, favicon) is visible to all visitors. We do not sell your personal data. Processors act on our instructions under data processing agreements where required by Article 28 GDPR.
7. International transfers
Your data is primarily processed within the European Economic Area (EEA). If you use Google sign-in or if a sub-processor transfers data outside the EEA (for example to the United States), such transfers rely on appropriate safeguards under Chapter V GDPR, such as the EU–US Data Privacy Framework where applicable, Standard Contractual Clauses (SCCs), or equivalent mechanisms. You may contact us for more information about transfer safeguards.
8. Retention periods
We keep personal data only as long as necessary for the purposes above: • Account data — until you request deletion or the account is inactive for 24 months, then deleted or anonymised within 30 days. • Listing data — until you delete a listing, it is removed by us, or your account is deleted. • Server logs — up to 12 months for security and troubleshooting. • Transactional email records — up to 3 years for evidence in case of disputes. When data is no longer needed, we delete or anonymise it securely.
9. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or alteration, including encrypted connections (HTTPS), access controls, and secure password hashing.
10. Your rights under the GDPR
Subject to conditions in the GDPR, you have the right to: • Access your personal data (Art. 15) • Rectify inaccurate data (Art. 16) • Erase your data (Art. 17) — you may delete published listings from "My SaaS"; contact us to delete your account • Restrict processing (Art. 18) • Data portability (Art. 20) — for data you provided, in a structured, commonly used format • Object to processing based on legitimate interests (Art. 21) — including click measurement • Withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing (Art. 7(3)) To exercise your rights, email us at contact@hereismysaas.com. We will respond within one month, as required by Article 12 GDPR. We may ask for information to verify your identity.
11. Right to lodge a complaint
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In France, the competent authority is the CNIL (Commission nationale de l'informatique et des libertés): https://www.cnil.fr We encourage you to contact us first at contact@hereismysaas.com so we can address your concern.
12. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last updated" date at the top will be revised accordingly. Material changes will be communicated where appropriate.