Legal

Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how MAKOA LLC (“flagwise”, “we”, “us”) collects and uses personal data when you use flagwise.me (the “Service”). We are the controller of your personal data.

Contact: MAKOA LLC, 3833 Powerline Rd, Suite 201, Fort Lauderdale, FL 33309, USA · hello@flagwise.me

1. Who we are and scope

flagwise is operated from the United States and offered to a global, English-speaking audience. Because we offer the Service to people in the European Economic Area (EEA) and the UK, we apply the EU/UK General Data Protection Regulation (GDPR) to their personal data, alongside applicable US law.

EU representative (Article 27 GDPR). MAKOA LLC has appointed the following representative in the European Union: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria — online contact form: https://app.prighter.com/portal/15448555534. Please quote reference ID-15448555534 in all correspondence with the representative.

2. Privacy by design — what we deliberately do not collect

3. What we collect, why, and the legal basis

DataPurposeLegal basis (GDPR Art. 6)
Email addressProvide the account; save/sync your flags and reportsArt. 6(1)(b) contract
Saved flags, bookmarked reports, situation summary (if signed in)Deliver the saved-content featureArt. 6(1)(b)
Freshness-alert subscription (email + country/topic)Send the change notifications you asked forArt. 6(1)(a) consent
Community contributions / confirmations (and display name if signed in)Operate and attribute the community layerArt. 6(1)(b) / 6(1)(f)
Bug reports and screenshotsDiagnose and fix issuesArt. 6(1)(f) legitimate interest
Server logs & IP addressOperate and secure the ServiceArt. 6(1)(f) legitimate interest
Product analytics (page views, activation events, referral/UTM)Understand usage and improve the ServiceArt. 6(1)(f) — cookieless (§6)

We do not knowingly process special-category data. Please do not enter sensitive personal data into free-text fields, bug reports, or screenshots.

4. Community contributions (public content)

If you contribute or confirm a report, your contribution and (if signed in) your display name and reputation may be shown publicly. Do not submit other people’s personal data. Community content must come from public sources and must not contain personal data (see our Community Guidelines). You can request removal of your contribution at any time via hello@flagwise.me.

5. Who we share data with (processors)

ProviderPurposeLocation
SupabaseAccount authentication and databaseUnited States (US East)
VercelWebsite hosting, content delivery, logsUnited States / global edge
PostHogProduct analyticsEU (eu.i.posthog.com)
ResendSending account and alert emailsUnited States
LinearBug-report / issue managementUnited States

Donations are handled by Stripe via a Stripe Payment Link. When you donate, you interact with Stripe directly; Stripe processes your payment data as an independent controller under its own privacy policy. We do not receive your full payment-card details.

We do not sell your personal data.

6. Cookies and analytics

We use PostHog in a cookieless configuration for product analytics. We do not set non-essential tracking cookies, and we therefore do not show a cookie banner. Analytics are processed on the basis of our legitimate interest in understanding and improving the Service (Art. 6(1)(f)), and you can opt out at any time — see §9.

Strictly necessary technical storage (e.g. keeping you signed in, remembering local settings such as your saved flags) is always used and does not require consent.

7. International data transfers

We are based in the United States, and several of our providers process data in the United States. Where personal data of EEA/UK users is transferred outside the EEA/UK, we put in place data-processing agreements incorporating the European Commission’s Standard Contractual Clauses, and we rely on the EU–US Data Privacy Framework where a provider is certified. You may request information about the relevant safeguards via hello@flagwise.me.

8. How long we keep data

DataRetention
Account & saved contentUntil you delete your account (backups purged within 30 days after)
Alert subscriptionUntil you unsubscribe
Community contributionsUntil you withdraw them or delete your account
Bug reports / screenshotsUntil the issue is resolved + 180 days
Server logs30 days

9. Your rights

If the GDPR applies to you, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time (without affecting prior processing). To exercise any right, email hello@flagwise.me. You also have the right to lodge a complaint with your local data-protection authority.

Opting out of analytics: email hello@flagwise.me or use your browser’s tracking-protection settings.

10. US / California privacy

If you are a California resident, you may have rights under the CCPA/CPRA, including to know, delete, and correct personal information, and to opt out of “sale” or “sharing.” We do not sell your personal information. To exercise these rights, email hello@flagwise.me.

11. Children

The Service is intended for users 18 and older. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact hello@flagwise.me.

12. Changes

We may update this Policy. Material changes will be indicated by updating the “Last updated” date and, where appropriate, by notice in the Service.