Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how MAKOA LLC (“flagwise”, “we”, “us”) collects and uses personal data when you use flagwise.me (the “Service”). We are the controller of your personal data.
Contact: MAKOA LLC, 3833 Powerline Rd, Suite 201, Fort Lauderdale, FL 33309, USA · hello@flagwise.me
1. Who we are and scope
flagwise is operated from the United States and offered to a global, English-speaking audience. Because we offer the Service to people in the European Economic Area (EEA) and the UK, we apply the EU/UK General Data Protection Regulation (GDPR) to their personal data, alongside applicable US law.
EU representative (Article 27 GDPR). MAKOA LLC has appointed the following representative in the European Union: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria — online contact form: https://app.prighter.com/portal/15448555534. Please quote reference ID-15448555534 in all correspondence with the representative.
2. Privacy by design — what we deliberately do not collect
- The answers you enter under “Your situation” (citizenship, tax residence, income band, assets, occupation, etc.) are stored in your browser (localStorage). They are sent to our server only momentarily to compute your results and are not stored on our servers or linked to your identity.
- Our jurisdiction-research pipeline processes country/jurisdiction data only. It does not process your personal data.
3. What we collect, why, and the legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address | Provide the account; save/sync your flags and reports | Art. 6(1)(b) contract |
| Saved flags, bookmarked reports, situation summary (if signed in) | Deliver the saved-content feature | Art. 6(1)(b) |
| Freshness-alert subscription (email + country/topic) | Send the change notifications you asked for | Art. 6(1)(a) consent |
| Community contributions / confirmations (and display name if signed in) | Operate and attribute the community layer | Art. 6(1)(b) / 6(1)(f) |
| Bug reports and screenshots | Diagnose and fix issues | Art. 6(1)(f) legitimate interest |
| Server logs & IP address | Operate and secure the Service | Art. 6(1)(f) legitimate interest |
| Product analytics (page views, activation events, referral/UTM) | Understand usage and improve the Service | Art. 6(1)(f) — cookieless (§6) |
We do not knowingly process special-category data. Please do not enter sensitive personal data into free-text fields, bug reports, or screenshots.
4. Community contributions (public content)
If you contribute or confirm a report, your contribution and (if signed in) your display name and reputation may be shown publicly. Do not submit other people’s personal data. Community content must come from public sources and must not contain personal data (see our Community Guidelines). You can request removal of your contribution at any time via hello@flagwise.me.
5. Who we share data with (processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Account authentication and database | United States (US East) |
| Vercel | Website hosting, content delivery, logs | United States / global edge |
| PostHog | Product analytics | EU (eu.i.posthog.com) |
| Resend | Sending account and alert emails | United States |
| Linear | Bug-report / issue management | United States |
Donations are handled by Stripe via a Stripe Payment Link. When you donate, you interact with Stripe directly; Stripe processes your payment data as an independent controller under its own privacy policy. We do not receive your full payment-card details.
We do not sell your personal data.
6. Cookies and analytics
We use PostHog in a cookieless configuration for product analytics. We do not set non-essential tracking cookies, and we therefore do not show a cookie banner. Analytics are processed on the basis of our legitimate interest in understanding and improving the Service (Art. 6(1)(f)), and you can opt out at any time — see §9.
Strictly necessary technical storage (e.g. keeping you signed in, remembering local settings such as your saved flags) is always used and does not require consent.
7. International data transfers
We are based in the United States, and several of our providers process data in the United States. Where personal data of EEA/UK users is transferred outside the EEA/UK, we put in place data-processing agreements incorporating the European Commission’s Standard Contractual Clauses, and we rely on the EU–US Data Privacy Framework where a provider is certified. You may request information about the relevant safeguards via hello@flagwise.me.
8. How long we keep data
| Data | Retention |
|---|---|
| Account & saved content | Until you delete your account (backups purged within 30 days after) |
| Alert subscription | Until you unsubscribe |
| Community contributions | Until you withdraw them or delete your account |
| Bug reports / screenshots | Until the issue is resolved + 180 days |
| Server logs | 30 days |
9. Your rights
If the GDPR applies to you, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time (without affecting prior processing). To exercise any right, email hello@flagwise.me. You also have the right to lodge a complaint with your local data-protection authority.
Opting out of analytics: email hello@flagwise.me or use your browser’s tracking-protection settings.
10. US / California privacy
If you are a California resident, you may have rights under the CCPA/CPRA, including to know, delete, and correct personal information, and to opt out of “sale” or “sharing.” We do not sell your personal information. To exercise these rights, email hello@flagwise.me.
11. Children
The Service is intended for users 18 and older. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact hello@flagwise.me.
12. Changes
We may update this Policy. Material changes will be indicated by updating the “Last updated” date and, where appropriate, by notice in the Service.