Founder Repo OS · SUPPE LABS
Privacy Policy
Last updated: August 18, 2026. This Privacy Policy explains how SUPPE LABS processes personal data when you use the Founder Repo OS website and its customer-facing services.
1. Controller
Suppe Labs – Daniel Djogic
Sole proprietorship
Lange Gasse 73a
2491 Neufeld an der Leitha
Austria
Email: office@suppelabs.com
2. General information
We process personal data in accordance with applicable data protection law, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act and, where applicable, the Austrian Telecommunications Act 2021.
3. Website and server logs
This website is provided through Vercel. When you visit it, technically necessary log data may be processed, including IP address, date and time, requested page, data volume, browser and operating-system information, referrer URL, and technical status and error information.
This processing is based on Art. 6(1)(f) GDPR and serves the secure, stable and error-free operation of the website and the prevention of misuse and attacks. Log data is retained only for as long as necessary for these purposes or to meet legal obligations.
4. Privacy-focused website analytics
We use Vercel Web Analytics on the public Founder Repo OS marketing pages to understand aggregated website use and improve the website. This processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to understand whether the public website and its essential product paths are useful and usable without building advertising or behavioural profiles.
- Vercel Web Analytics records aggregate page-view information such as page path, referrer subject to the browser and site referrer policy, approximate country, browser, operating system and device category.
- Query parameters are removed before analytics events are sent. The integration is not loaded on checkout, customer account, setup, administration, callback or API routes.
- We use only these custom events: pricing_view, scorecard_start, scorecard_complete, checkout_click, agency_request_open, agency_request_submit and github_docs_click. The only event properties are plan and placement where needed.
- We do not send names, email addresses, payment, customer, Paddle, GitHub, repository, token, form, Scorecard-answer, Scorecard-score or Scorecard-result data to Web Analytics.
- We do not use advertising pixels, session recording, heatmaps, cross-site advertising tracking, fingerprinting scripts, or our own persistent analytics identifiers. Vercel Web Analytics does not use cookies for its Web Analytics service.
- Scorecard answers, score and result remain in the current browser session and are not transmitted to or stored by this website. The Copy Summary feature writes to your local clipboard only after you activate it.
5. Agency inquiry form and email contact
The Repository Agency inquiry form collects the name, work email, optional company, subject and message you submit. We use these details only to assess and respond to your inquiry and, where relevant, to take steps towards a business relationship. The form does not create a customer account, subscription or marketing profile.
Form submissions are transmitted through the Founder Repo OS setup runtime hosted by Vercel and delivered to our business inbox through Resend. We do not write the submitted form content to the Founder Repo OS customer database or include it in application logs.
If you contact us by email, we process the information you provide to handle and respond to your enquiry and, where relevant, to take steps towards a business relationship. The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns pre-contractual steps and otherwise Art. 6(1)(f) GDPR. Business email is hosted by ALL-INKL.COM.
We do not use email enquiries for advertising or marketing without a separate legal basis.
6. Live purchases and subscriptions
Paddle provides the live checkout and acts as Merchant of Record. Information entered in Paddle's checkout, including contact, company, address, country, tax and payment details, is processed by Paddle under the notices and terms shown there. Founder Repo OS does not receive or store full payment-card or bank-account details.
After a completed order, Paddle sends signed transaction and subscription events to the Founder Repo OS setup runtime. We process the verified buyer email, Paddle customer, transaction and subscription references, selected plan, quantity, subscription status and access period to fulfil the order, operate the subscription and prevent fraudulent or duplicate activation.
The legal basis is Art. 6(1)(b) GDPR where processing is necessary for a contract with the data subject or requested pre-contractual steps, Art. 6(1)(f) GDPR for authorized business contacts and secure service operation, and Art. 6(1)(c) GDPR where records must be retained to meet a legal obligation.
7. Customer account and persistent service data
The customer application uses Neon PostgreSQL to store the transactional state required to provide and protect the service. This includes internal account identifiers, subscription entitlement and status, plan and quantity, access period, provider references, repository bindings, setup state, branch and draft-pull-request records, installation receipts and security, audit and reconciliation records.
A buyer receives a short-lived, single-use account link. Founder Repo OS stores only the cryptographic token hash together with its account binding, expiry and use status, not the raw link token. The data is processed to provide the purchased service, enforce plan limits, maintain account security and document customer-controlled setup operations.
8. GitHub connection and repository setup
When a customer connects GitHub, Founder Repo OS processes the GitHub account and installation identifiers, repository identifier and name, repository visibility, permissions, default-branch information and the repository data needed to scan the selected repository and prepare the reviewed setup. GitHub processes authentication and GitHub App activity under its own terms and privacy information.
After explicit customer approval, the GitHub App may create a dedicated setup or update branch, commits, an installation receipt and a draft pull request. Founder Repo OS does not write directly to the default branch and does not merge automatically. The customer controls review and merge.
9. Transactional customer email
Resend delivers service emails to the buyer address verified through Paddle. These emails may include the purchased plan, current access period, customer-application URL and short-lived account link. We process the delivery status and redacted provider reference needed to detect delivery failures and prevent duplicate sends. These messages are necessary for order fulfilment and account access and are not marketing emails.
10. Controlled Sandbox tests
If a clearly labelled Paddle Sandbox test checkout is made available on a controlled test route, Paddle.js loads only after you actively open that test checkout. Test contact, country, business-tax and payment information is entered directly into Paddle's interface and is processed under Paddle's Sandbox notices and settings, not through a custom Founder Repo OS payment form.
A clearly labelled Sandbox test is not a live sale and does not create a live payment, invoice, customer access, licence or delivery.
11. Recipients and international transfers
Vercel provides hosting, infrastructure and the Web Analytics service, ALL-INKL.COM provides business email hosting, Neon provides the PostgreSQL database, Resend provides transactional email delivery, Paddle provides checkout and Merchant-of-Record services, and GitHub provides authentication and the customer-approved repository workflow. They receive data only insofar as necessary for their respective services. Some providers may process data outside the EU or EEA. Where an international transfer takes place, it relies on safeguards under Art. 44 et seq. GDPR, including adequacy decisions or Standard Contractual Clauses, where applicable.
12. Cookies and similar technologies
The public website does not use analytics, marketing or tracking cookies. The customer and administration applications use technically necessary, secure HTTP-only session and authentication cookies to sign users in, protect requests and retain the authorized session. These cookies are not used for advertising or cross-site tracking. If we introduce non-essential cookies or similar technologies in the future, we will obtain the required consent first and update this Privacy Policy.
13. Retention
We retain personal data only as long as necessary for the respective purpose. Enquiries that do not lead to a business relationship are deleted once further retention is no longer necessary. The same principle applies to Agency form submissions delivered to our business inbox. Account, subscription, repository-binding and setup records are retained while needed to provide the service, enforce the purchased scope, resolve support or security issues and establish or defend legal claims. Raw account-link tokens are never stored. Their hashes and related security records are retained only for the bounded period needed to prevent replay and document use. Statutory retention obligations may apply to a business relationship; tax and accounting records are generally retained for seven years.
14. Your rights and complaints
Subject to the applicable legal requirements, you have rights of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent for the future. To exercise your rights, contact us at office@suppelabs.com.
You may lodge a complaint with a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
15. Security and changes
We take appropriate technical and organisational measures to protect personal data. We will update this Privacy Policy when services, processing operations or legal requirements change. This website does not use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR.