Privacy Policy

Last updated: 3 September 2026

Privogrid is operated by WaveLinker OÜ, a company registered in Estonia (the "controller", "we", "us"). This policy explains what we collect, why, where it goes and how you can control it. By using Privogrid you agree to this policy.

1. What we collect

2. What we do NOT collect

3. Why we use it (legal basis)

We do not sell your data and we do not use it for advertising.

4. Who processes it for us

Each processor only receives what it needs for its job. Some of them operate outside the EU under standard contractual clauses or an adequacy decision.

5. How long we keep it

6. Security

Passwords are salted and hashed (PBKDF2). Synced data is encrypted with AES-256-GCM before it leaves your device. All traffic uses HTTPS (HSTS). Accounts are protected with rate-limiting, automatic blocking of abusive traffic and session-token expiry. Found a vulnerability? See our security page or write to [email protected].

7. Your rights (GDPR)

You can ask us to access, correct, export or erase your personal data, to restrict or object to processing, and you have the right to lodge a complaint with your supervisory authority — in Estonia, the Andmekaitse Inspektsioon.

8. Cookies

The website sets no advertising or tracking cookies. The dashboard keeps your login token in your browser's local storage so you stay signed in; Stripe sets its own cookies on its checkout pages. Cloudflare may set a security cookie to protect against bots.

9. Changes

We may update this policy. Material changes will be posted on this page with a new "Last updated" date, and announced in the dashboard or by email if they affect how your data is used.

10. Contact

WaveLinker OÜ, Estonia · [email protected] (privacy requests) · [email protected] (security reports).

← Back to home