Legal

Privacy Policy

Last updated: February 19, 2026

1. Controller

The controller responsible for data processing on this website is:

Sunderlabs UG (haftungsbeschränkt)

Rechbergstrasse 28

70794 Filderstadt, Germany

Managing Director: Sebastian Boehler

Email: contact@sunderlabs.com


2. Overview of Data Processing

We take the protection of your personal data seriously. We process personal data only in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This privacy policy explains what data we collect, why we collect it, and your rights regarding your data.


3. Hosting

This website is hosted by Vercel Inc., 440 N Baxter St, Covina, CA 91723, USA. When you visit our website, Vercel may process your IP address and other technical data to deliver the website content. This processing is based on Art. 6(1) lit. f GDPR (legitimate interest in reliable website delivery).

We use Google Cloud Platform (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for cloud storage and backend services. Data may be transferred to the USA under the EU-US Data Privacy Framework. More information: cloud.google.com/privacy.


4. Server Log Files

Our hosting provider automatically collects and stores information in server log files that your browser transmits. This includes:

  • Browser type and version
  • Operating system
  • Referrer URL
  • IP address (anonymized)
  • Date and time of access

This data is not combined with other data sources. Processing is based on Art. 6(1) lit. f GDPR (legitimate interest in technical security and optimization).


5. Analytics

We use Vercel Analytics to understand how visitors interact with our website. Vercel Analytics is a privacy-focused analytics tool that does not use cookies and does not collect personally identifiable information. Aggregated, anonymized usage data (page views, web vitals) is processed to improve our website. Legal basis: Art. 6(1) lit. f GDPR (legitimate interest in website optimization).


6. Cookies

This website uses only technically necessary cookies required for the operation of the website (e.g., session management, authentication). These cookies are essential and cannot be disabled. We do not use tracking cookies or third-party advertising cookies. Legal basis: Art. 6(1) lit. f GDPR.


7. Contact via Email

When you contact us by email, we store your email address and the content of your message to process your inquiry. This data is processed based on Art. 6(1) lit. b GDPR (contract performance or pre-contractual measures) or Art. 6(1) lit. f GDPR (legitimate interest in responding to inquiries). We delete this data once the purpose of storage no longer applies, unless statutory retention obligations require otherwise.


8. Third-Party Services

Google Cloud Storage

We use Google Cloud Storage to host media assets (images, audio, video). Files are served from Google's CDN. Google may process technical connection data. Privacy policy: policies.google.com/privacy.

Google Fonts

We use Google Fonts served via Next.js font optimization, which self-hosts the font files. No requests are made to Google servers when loading fonts.

MongoDB Atlas

We use MongoDB Atlas (MongoDB, Inc., 1633 Broadway, New York, NY 10019, USA) as our primary database. Metadata about content, orders, and app configuration is stored there. Data is hosted in the EU (Frankfurt region). Privacy policy: mongodb.com/legal/privacy-policy.


8a. E-Commerce, Shopify & Payments

Shopify

Our online store is operated via Shopify Inc. (151 O'Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada). When you visit or make a purchase in our store, Shopify processes the following categories of data on our behalf as a data processor:

  • Name, email address, shipping and billing address
  • Order details, product selections, and cart contents
  • IP address, browser type, and device information
  • Payment method type (not full card details — see Payments below)
  • Custom line item properties (e.g., AI-generated preview image URLs for custom products)

Legal basis: Art. 6(1) lit. b GDPR (contract performance). Shopify is certified under the EU-US Data Privacy Framework. Privacy policy: shopify.com/legal/privacy.

Shopify Web Pixels & Customer Privacy API

Our Shopify store may use Shopify Web Pixels — a sandboxed tracking framework that runs in an isolated environment and cannot directly access the page DOM or cookies. Pixels may collect behavioral data such as page views, product views, add-to-cart events, and checkout steps for analytics and conversion measurement purposes.

We use Shopify's Customer Privacy API to manage consent. Tracking pixels that require consent (e.g., marketing or analytics pixels beyond strictly necessary functionality) are only activated after the visitor has provided explicit consent via the cookie banner. Visitors in the EU/EEA are presented with granular consent options (Strictly Necessary / Analytics / Marketing) in accordance with the ePrivacy Directive and GDPR Art. 6(1) lit. a.

Currently active pixel categories:

  • Strictly necessary: Shopify checkout, cart, session management
  • Analytics (consent required): Shopify Analytics (aggregate, anonymized)
  • Marketing pixels: None currently active — will be disclosed here when added

Payment Processing — Stripe (planned)

We plan to integrate Stripe (Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA / Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland for EU customers) as our payment processor.

When Stripe is active, payment data (card number, expiry, CVC) is entered directly into Stripe's PCI-DSS-compliant hosted fields and is never transmitted to or stored on our servers. We receive only a payment token and the last four digits of the card for order confirmation purposes.

Stripe may also use cookies and device fingerprinting for fraud prevention (Stripe Radar). This processing is based on Art. 6(1) lit. f GDPR (legitimate interest in fraud prevention) and Art. 6(1) lit. b GDPR (contract performance). Stripe is certified under the EU-US Data Privacy Framework. Privacy policy: stripe.com/privacy.

Printful (order fulfillment)

For print-on-demand products (e.g., custom pet portraits, stickers), orders are fulfilled by Printful Inc. (11025 Westlake Dr, Charlotte, NC 28273, USA / Printful Latvia SIA, Plienciema 1, Riga, LV-1046, Latvia for EU orders). Printful receives the shipping name, address, and product specification necessary to produce and ship your order. Legal basis: Art. 6(1) lit. b GDPR. Privacy policy: printful.com/policies/privacy.

AI-generated product images (custom products)

For custom AI-generated products (pet portraits, stickers), images uploaded or described by the customer are sent to our AI generation backend and to third-party AI model providers (currently OpenRouter / Google Gemini) solely to generate the requested product image. Uploaded images are stored temporarily in Google Cloud Storage (max. 30 days for previews; permanent for print-ready files required for fulfillment). We do not use customer-uploaded images to train AI models. Legal basis: Art. 6(1) lit. b GDPR.

Order data retention

Order data (name, address, order contents) is retained for 10 years in accordance with § 147 AO / § 257 HGB (German statutory retention obligations for commercial and tax records). After this period, data is deleted or anonymized.


9. ChatGPT Apps

Sunderlabs publishes apps in the ChatGPT app directory built with the OpenAI Apps SDK. These apps are MCP servers that extend ChatGPT conversations with additional data and functionality. This section describes how data is handled within those apps.

General principles (all ChatGPT Apps)

  • Our apps receive only the specific inputs the user or ChatGPT model explicitly passes to a tool (e.g., a company name or search query). We do not receive, reconstruct, or store the full conversation history.
  • Tool inputs are used solely to fulfill the stated purpose of the tool call. They are not used for advertising, profiling, or training AI models.
  • We do not collect payment card information, protected health information, government identifiers, or authentication credentials through any ChatGPT App.
  • No personal data is stored persistently by our apps unless explicitly stated below for a specific app. Tool calls are stateless — each request is independent.
  • Server-side request logs (IP address, timestamp, tool name) may be retained for up to 30 days for security and reliability purposes, then deleted automatically.

Handelsregister Search

  • Data received: Company name (required), optional city or register number — as entered by the user in conversation.
  • Purpose: To query the German commercial register (handelsregister.de) and Wikidata for publicly available company registration data and financial KPIs.
  • Data sources: handelsregister.de (public register, no personal data beyond company names and addresses of registered entities) and Wikidata (public domain, CC0 licensed).
  • Data storage: No user data is stored. Query inputs are not logged beyond standard server request logs (see above). Results are returned directly to ChatGPT and not retained on our servers.
  • Third-party transfers: Queries are forwarded to our backend API (hosted on a European cloud provider), which in turn queries handelsregister.de and Wikidata. No user-identifying data is included in these downstream requests.
  • Legal basis: Art. 6(1) lit. f GDPR — legitimate interest in providing accurate, publicly available company data in response to the user's explicit request.

For questions about data handling in our ChatGPT Apps, contact contact@sunderlabs.com.


10. AI-Generated Content

Sunderlabs uses artificial intelligence systems to generate content, including text, images, audio, and video. These systems run on our own infrastructure or via third-party API providers (e.g., OpenAI, Google, xAI, fal.ai, Replicate). When you interact with our AI-powered features, your inputs may be sent to these providers for processing. We do not share personal data with AI providers beyond what is technically necessary for the service.


11. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) — request information about your stored data
  • Right to rectification (Art. 16 GDPR) — correct inaccurate data
  • Right to erasure (Art. 17 GDPR) — request deletion of your data
  • Right to restriction (Art. 18 GDPR) — restrict processing of your data
  • Right to data portability (Art. 20 GDPR) — receive your data in a structured format
  • Right to object (Art. 21 GDPR) — object to processing based on legitimate interest

To exercise any of these rights, contact us at contact@sunderlabs.com.


12. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for our company is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg

Lautenschlagerstraße 20

70173 Stuttgart, Germany

baden-wuerttemberg.datenschutz.de


13. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at sunderlabs.com/privacy.