Privacy Policy
Last updated: July 18, 2026
Who we are
LaunchPanda is operated by Welsenes Brothers V.O.F., registered at Nieuwe Prinsengracht 92-2, 1018VW Amsterdam, The Netherlands (KVK 77647157, VAT NL861078937B01). When we say “we”, “us”, or “LaunchPanda”, we mean this entity.
What data we collect
We collect the minimum data needed to provide the service:
- Account information. You can sign in with Google or with a passwordless email magic link. If you use Google, we receive your name, email address, and profile picture. If you use the email magic link, we receive the email address you enter and send you a one-time sign-in link through Resend. We use this to identify your account and send transactional email.
- Startup Profile data. The product information you enter (tool name, tagline, descriptions, website URL, category, pricing model, founder name, X handle, logo URL). Stored to pre-fill directory submissions and to submit on your behalf when you buy Auto Launch.
- Submission progress. Which directories you have marked as completed, the submission state recorded per directory, and the launch order snapshot. Stored to track your progress and keep your profile's history accurate.
- Payment data. When you buy Pro, Auto Launch, or a Featured slot, Stripe collects your billing address, VAT ID (if applicable), and payment method. We never see or store your card details. We store the Stripe customer ID, the Stripe session ID, and the order metadata so we can reconcile payments and grant entitlements.
- Email activity. When we send you transactional or marketing email through Resend, we store the send timestamp, the recipient address, the message ID, and the delivery status. Used for deduplication, debugging, and compliance with your opt-out preferences.
- Marketing preferences. A
marketingOptOutflag on your profile and a per-account unsubscribe token. Used to respect opt-outs across devices without requiring sign-in. - Feedback. If you submit feedback via the in-app widget, we store your message, the page URL, and your user ID (if signed in).
- Community content and public profile. If you post in the community, comment, or like a post, we store that content along with your user ID and a snapshot of your display name, avatar, and account tier at the time you posted. Your profile (display name, avatar, tier, and a public profile slug) is shown publicly on pages such as your profile page, the community feed, the leaderboard, and public launch listings.
- Testimonials. If you submit a testimonial, we store your note, optional before/after Domain Rating figures, and the associated Startup Profile. Testimonials may be displayed publicly on the site.
- Direct messages. If you message another user, we store the message content, the participants, and timestamps so the conversation is available in your inbox. If you block a user, we store that block to stop messages between you. When enabled, we may send a “new message” email notification through Resend.
- Waitlist + referral data. If you join a waitlist we store your email. If you arrive through a partner referral link (e.g.
?ref=verifieddr), we set a first-party cookie (lp_ref) for up to 30 days and attach the partner identifier to any subsequent Stripe checkout so revenue can be attributed correctly. The cookie value is the partner's short slug, nothing else. - Browser extension data. The LaunchPanda Directory Autofill Chrome extension stores an authentication token in your browser's local storage to connect to your account, and reads your Startup Profile fields (name, email, website URL, description, and similar) from your account to fill them into directory submission forms. It reads the form fields on the page you are actively on only to autofill them. This happens locally in your browser and the page contents are not sent to our servers. The extension does not collect your browsing history, keystrokes, or personal communications.
- Analytics. We use a small set of analytics tools to understand how the product is used:
- DataFast, privacy-friendly traffic analytics. It sets first-party cookies (
datafast_visitor_id,datafast_session_id) to count unique visitors and sessions. No personal data is sent to DataFast. - PostHog, product analytics. PostHog records page views, page leaves, and in-app interactions (such as clicks) and sets its own first-party cookies. When you are signed in, we associate your PostHog activity with your account ID, email address, and name so we can tie usage back to your account, debug issues, and support you. We do not use PostHog for advertising or cross-site tracking.
- Vercel Analytics, aggregate traffic and performance measurement provided by our host. It does not set cookies and does not collect personal data.
- DataFast, privacy-friendly traffic analytics. It sets first-party cookies (
How Auto Launch shares your data with third parties
When you purchase Auto Launch, you instruct us to submit your product information to the vetted directories included in your plan (30, 50 or 100) on your behalf. We send the profile fields you provided (name, description, website URL, logo, category, pricing model, X handle) to a fixed set of partner APIs:
- VibeCodingList, partner-API submission. Their team emails you a claim link separately.
- EasyLaunch, partner-API submission to easylaunch.dev.
- EasyDoFollow, partner-API submission to easydofollow.dev.
- LemonLaunch, partner-API submission.
- VerifiedDR, partner-API submission to verifieddr.com.
- The remaining directories in your profile's blueprint. For each, we either submit via their public form or coordinate with the directory operator directly. The exact list is visible inside your /launched page after purchase.
Each directory has its own privacy policy. Once your product is listed on a directory, that directory's terms govern the data on its site. We do not control how individual directories store or display the information you provided.
Browser extension (Directory Autofill)
The LaunchPanda Directory Autofill Chrome extension is an optional tool that fills your Startup Profile details into directory submission forms in your browser. Its single purpose is autofill.
- What it reads. Your Startup Profile fields (such as name, email, website URL, description, and category), fetched from your account, and the form fields on the page you are actively autofilling.
- What it stores. An authentication token and your autofill preferences in your browser's local storage. The token is used only to connect the extension to your LaunchPanda account and is removed when you disconnect.
- What it never does. It does not send the contents of the pages you visit to our servers, and it does not collect your browsing history, keystrokes, mouse activity, or personal communications. Reading a page's form fields happens locally, on the page you choose to autofill, at the moment you trigger it.
The data handled by the extension is the same account and Startup Profile data described above and is governed by this same policy.
Community, public profiles, and direct messages
LaunchPanda includes social features: a community feed, comments and likes, public profiles, a leaderboard, and direct messages between users.
- What is public. Anything you post to the community, along with your display name, avatar, account tier, and public profile slug, is visible to other users and, for public pages, to anyone on the internet. Do not post anything you are not comfortable making public.
- Direct messages. Messages you send to another user are visible to that user and stored so both of you can read the thread. You can block a user to stop messages in both directions.
- Moderation. We may review, hide, or remove community content and restrict accounts to keep the platform safe and to comply with our Terms of Use.
Legal basis for processing (GDPR)
We process your personal data based on:
- Contract performance. Processing your account data, Startup Profile information, and payment data is necessary to provide the service you signed up for.
- Legitimate interest. We process usage data to improve the service, fix bugs, prevent abuse, and personalize directory recommendations.
- Legal obligation. Payment records are retained by Stripe and reflected on our side to meet Dutch tax and accounting rules.
- Consent. For non-transactional marketing email (lifecycle nudges, product announcements, weekly digests). You can withdraw consent at any time by clicking unsubscribe in any email we send, or by visiting your account settings.
Where your data is stored
Your data is stored on servers operated by our third-party providers. These servers may be located outside the European Economic Area (EEA), primarily in the United States.
- Convex, database and backend functions. Servers in the United States.
- Vercel, frontend hosting, serverless functions, and aggregate traffic analytics (Vercel Analytics). Global edge network with primary infrastructure in the United States.
- Stripe, payment processing and invoice generation. Stripe Inc. is based in the United States; for EU customers payments are processed by Stripe Payments Europe.
- Resend, transactional and marketing email delivery. Servers in the United States.
- DataFast, product analytics. Servers as per DataFast's privacy notice.
- PostHog, product analytics. Servers as per PostHog's privacy notice.
- Supabase, storage for waitlist signups. Servers in the United States.
- Google, OAuth authentication only.
Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards as provided by our service providers to ensure an adequate level of data protection.
How we store your data
Your data is stored in our database (hosted on Convex) and is encrypted in transit (HTTPS/TLS) and at rest. Authentication tokens are stored securely in your browser's local storage. Stripe handles all card data and is PCI DSS Level 1 certified.
Data retention
We retain your data for as long as your account is active.
- Account + profile data. Retained until you request account deletion.
- Submission progress. Retained until you reset progress or delete your account.
- Feedback. Retained for up to 2 years for product improvement, then deleted.
- Payment + invoice records. Retained by us and by Stripe for 7 years to satisfy Dutch tax law (Algemene wet inzake rijksbelastingen art. 52). These cannot be deleted on request.
- Email send logs. Retained for 24 months for dedup, deliverability, and abuse prevention.
- Marketing opt-out token. Retained permanently even after account deletion. Required to honor your opt-out if your email reappears in any future signup.
How we use your data
- To operate and improve LaunchPanda
- To pre-fill directory submissions and submit on your behalf when you purchase Auto Launch
- To process payments, calculate VAT, and issue invoices
- To send transactional email (welcome, order confirmation, Auto Launch progress reports, badge install reminders, testimonial requests)
- To send marketing email (lifecycle nudges, product updates, weekly digests), unless you have opted out
- To personalize directory recommendations based on your product's category, stage, and existing backlinks
- To operate the community, public profiles, and direct messaging, and to moderate content
- To attribute revenue to partners who referred you, where applicable
- To prevent fraud, abuse, and rate-limit violations
What we never do
- We never sell your personal data to third parties
- We never share your data outside the directories you signed up to be submitted to
- We never use your data for cross-site advertising or profiling
- We never store your payment card details, all payment processing is handled by Stripe
- We never email you marketing content if you have opted out
Cookies
We use first-party cookies for authentication, session management, referral attribution (lp_ref), and analytics. Our analytics cookies are set by DataFast (datafast_visitor_id, datafast_session_id) and by PostHog (its own first-party cookies, prefixed ph_). Vercel Analytics does not set cookies. We do not use third-party advertising cookies, retargeting pixels, or social tracking. The DataFast cookies do not contain personal data.
Your rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Access. Request a copy of all personal data we hold about you.
- Rectification. Update or correct your personal data through your account settings or by contacting us.
- Erasure. Request deletion of your account and all associated data (payment + invoice records excepted, see retention).
- Data portability. Request your data in a machine-readable format.
- Object. Object to processing based on legitimate interest.
- Withdraw consent. Unsubscribe from marketing email at any time using the link in any email we send.
To exercise any of these rights, contact us using the address below. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Children
LaunchPanda is intended for adults and businesses. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this privacy policy from time to time. If we make significant changes we will notify you by email or by placing a notice on the site. Your continued use of the service after changes constitutes acceptance of the updated policy.
Contact
For privacy questions, data access requests, or to exercise your GDPR rights:
- Welsenes Brothers V.O.F.
- Nieuwe Prinsengracht 92-2, 1018VW Amsterdam, The Netherlands
- Email: welsenes.brothers@gmail.com