Privacy Policy

At Twilee (“we,” “our,” or “us”), your privacy is of utmost importance to us. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services (collectively, the "Service"). By using our Service, you agree to the terms outlined in this Privacy Policy.

1. Information We Collect

We collect and process the following categories of personal data:

2. How We Use Your Information

Your personal data is used only for purposes that are legitimate and necessary, including:

We do not sell your personal data, use it for targeted advertising, or share it with third parties for marketing purposes.

3. Payment and Billing Information

All payment-related information is securely processed by our third-party provider Stripe. We only receive limited details (e.g., transaction status, last 4 digits of your card, expiration date) necessary to confirm and manage subscriptions.

For details on Stripe’s practices, please refer to Stripe Privacy Policy.

4. Cookies and Tracking

We use only the minimal cookies strictly necessary for the proper functioning of the Service, such as:

We do not use cookies for advertising, profiling, or third-party tracking.

Usage analytics. We measure how our website and application are used with PostHog, hosted in the European Union and acting as our data processor. This measurement stores nothing on your device: no analytics cookie, no local storage, no fingerprinting. That is why it requires no cookie consent banner. On our public pages, it is anonymous. When you are signed in, usage events are linked to your account so we can see which parts of the product help and which get in the way, on the basis of our legitimate interest in improving the Service. We also record a sample of signed-in sessions to diagnose usability problems, with the contents of form fields hidden.

Scans of your QR codes are never sent to our analytics provider. Scan statistics are processed in our own systems, as described in section 1. A small number of product indicators are derived there from data we already process for those statistics, for example whether the first scan of a new QR code came from the device that created it. This derivation adds no new collection.

Links in our emails and campaigns may carry a plain source tag in the address, such as ?src=save40. That tag identifies the campaign, never you.

For more information, please see our Cookies Policy.

5. Data Hosting and Storage

6. Data Sharing and Third Parties

We limit sharing of your personal data strictly to:

All third parties we work with are required to comply with GDPR standards.

7. Automated Processing and Artificial Intelligence

We use artificial intelligence systems provided by Mistral AI (Mistral AI SAS, Paris, France), acting as a data processor and processing data on servers located in the European Union, for the following purposes:

The legal basis for moderation is our legitimate interest in keeping the Service lawful and safe, as well as compliance with our legal obligations.

Moderation may lead to the automatic blocking of a QR code. If this happens, you are informed, and a member of our team then reviews the blocking and informs you of the outcome. You can also write to [email protected] to add context. You retain the right to obtain human intervention, to express your point of view, and to contest the decision.

8. International Data Transfers

Your personal data is hosted and processed in the European Union. Some of our sub-processors may, under their own data processing agreements, transfer limited data outside the European Economic Area (EEA) with appropriate safeguards (e.g., Standard Contractual Clauses, adequacy decisions) in accordance with GDPR. See our Sub-Processors page for details.

9. Your Rights under GDPR

You have the following rights regarding your personal data:

To exercise your rights, contact us at [email protected]. We will respond within the one-month period required by GDPR.

10. Data Security

We use technical and organizational measures to protect your personal data, including encryption (in transit and at rest), firewalls, monitoring, and restricted access controls. However, no system can be 100% secure, and you acknowledge that risks inherent to Internet-based services remain.

11. Data Retention

We retain your personal data only as long as necessary:

After these periods, your data will be deleted or anonymized.

12. Changes to this Policy

We may update this Privacy Policy from time to time to reflect legal or technical changes. We will notify you by email or on our website before significant changes take effect.

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us: