Skip to content
gomomo

<!--

GoMomo Privacy Policy

Version: 1.0

REQUIRED BEFORE PUBLICATION:

1. Replace every value enclosed in [SQUARE BRACKETS].

2. Confirm that the production Supabase project is hosted in Frankfurt.

3. Confirm that every processor listed below is actually enabled in production.

4. Ensure the application's deletion, retention, cookie and security behaviour

matches this Policy.

5. Obtain review from a qualified Dutch privacy lawyer.

-->

Privacy Policy

Version: 1.0

Last updated: 30 July 2026

This Privacy Policy explains how GoMomo collects, uses, stores, shares and

protects personal data when you visit our website, create an account, use the

GoMomo web or mobile applications, contact us, or purchase a subscription.

In this Policy, the website, applications, pricing tools and related services

are collectively called the “Service.”

Nothing in this Policy limits any mandatory privacy rights or remedies that

apply to you under applicable law.

1. Who is responsible

GoMomo is a trading name operated by [FULL LEGAL NAME], a sole

proprietorship established in the Netherlands.

Business address: [BUSINESS ADDRESS]

KVK number: [KVK NUMBER]

Privacy contact: [PRIVACY EMAIL — recommended: privacy@gomomo.app]

For the personal data described in Section 3, GoMomo is generally the **data

controller**, meaning that we determine why and how that data is processed.

When a business customer enters personal data about its own customers,

prospects, suppliers, employees or other individuals into the Service, that

business customer is normally the controller of that data and GoMomo acts as

its data processor or service provider. Section 2 explains this distinction.

2. Our role when you upload data about other people

GoMomo lets users enter business, cost, capacity, service, pricing, quote,

customer and supplier information.

Where this information contains personal data about another person:

data is processed;

by law;

Service, subject to our agreement with you; and

Addendum.

You must not use GoMomo as a repository for information that is unnecessary

for pricing or managing your services.

The Service is not designed for patient files, medical records, legal case

files, government identity documents, full payment-card details, biometric

data, criminal records, or other special-category or highly sensitive personal

data. You must not upload such information unless GoMomo has expressly agreed

in writing that the relevant feature supports it.

3. Personal data we collect

3.1 Account and profile data

When you register or manage an account, we may collect:

your readable password;

3.2 Business and pricing data

Information you or authorised users enter into the Service may include:

Some of this information may be commercially sensitive even when it is not

personal data.

3.3 Personal data about your contacts

Where you choose to enter it, Customer Data may include limited information

about your customers, prospects, suppliers or other business contacts, such as:

You should enter only the information reasonably necessary for your use of the

Service.

3.4 Payment and billing data

When you purchase a subscription, we or our payment provider may process:

and

Payments are processed by Stripe or another payment provider identified at

checkout. GoMomo does not receive or store your full card number or card

security code when payment is made through the provider’s secure payment

interface.

The payment provider may process certain information as an independent

controller for activities such as identity verification, fraud prevention,

regulatory compliance and management of its own services. Its own privacy

notice also applies to that processing.

3.5 Communications and support data

When you contact us, request support, respond to a survey or otherwise

communicate with us, we may collect:

Please do not include passwords, full payment-card details or unnecessary

sensitive information in support messages.

3.6 Technical, device and security data

When you use the Service, we may automatically receive limited technical data,

including:

incidents.

We use this information to operate and secure the Service, not to build

advertising profiles.

3.7 Cookies and local storage

We use cookies, browser storage and similar technologies that are necessary to:

More information is provided in Section 15.

3.8 Information received from third parties

We may receive information from:

fraud, verify a business or comply with law.

4. Why we use personal data and our legal bases

Where the General Data Protection Regulation or a similar law applies, we rely

on the following legal bases:

Processing purposePersonal data involvedLegal basis
Creating and administering your accountAccount, profile and authentication dataPerformance of our contract with you
Providing pricing, quoting, storage and related functionalityAccount data and business dataPerformance of our contract with you
Processing subscriptions and paymentsBilling, subscription and transaction dataPerformance of our contract; legal obligations
Providing customer supportAccount, communication and relevant business dataPerformance of our contract; legitimate interests
Protecting accounts and preventing fraud, abuse and security incidentsTechnical, authentication, device and security dataLegitimate interests; legal obligations
Monitoring reliability and resolving errorsLimited technical and diagnostic dataLegitimate interests
Maintaining financial and tax recordsBilling, invoice and transaction dataLegal obligation
Sending essential service communicationsContact and account dataPerformance of our contract; legitimate interests
Sending optional product news or marketingContact details and communication preferencesConsent where required; otherwise legitimate interests where permitted
Improving the ServiceUsage patterns, feedback and aggregated or de-identified informationLegitimate interests
Establishing, exercising or defending legal claimsRelevant account, communication, billing and security dataLegitimate interests; legal obligations
Complying with lawful requestsData required by the relevant requestLegal obligation

Our legitimate interests include operating a secure and reliable SaaS service,

preventing misuse, understanding whether features work, improving the Service,

communicating with customers, and protecting our legal rights.

Where we rely on legitimate interests, we consider whether our interests are

outweighed by your privacy rights. You may object to this processing as

described in Section 13.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not

affect processing that occurred before consent was withdrawn.

5. Service communications and marketing

We may send communications necessary to provide the Service, including:

These are service communications and may continue while you maintain an

account.

We send optional marketing messages only where permitted by law. Every

marketing email will include a way to unsubscribe. Unsubscribing from

marketing does not stop essential account, security, billing or service

communications.

6. How we use business data

We use your business data to provide the features you request, including

calculations, scenarios, recommendations, quotes and reports.

We do not:

We may use aggregated or de-identified information to understand and improve

the Service, provided that the information does not reasonably identify you,

your organisation or another person.

If GoMomo introduces a feature that sends Customer Data to an artificial-

intelligence provider, we will identify the provider and relevant processing

before enabling that processing where required by law.

7. Who we share data with

We disclose personal data only where reasonably necessary for the purposes

described in this Policy.

7.1 Core service providers

Our anticipated core providers include:

ProviderPurposeProcessing location or relevant information
SupabaseDatabase, authentication, file storage and backend functionsThe primary production database is intended to be hosted in the Central EU region in Frankfurt. Supabase and its subprocessors may process limited data in other locations for support, security and service operation.
VercelWebsite and application hosting, content delivery, server-side functions, deployment, security and technical logsVercel operates a globally distributed infrastructure. Static content, requests and limited technical data may be processed or cached in multiple countries.
StripeSubscription billing, payment processing, invoicing and fraud preventionStripe operates internationally and may process information in the United States and other countries. Stripe may act as our processor or as an independent controller depending on the activity.
ResendTransactional and service email deliveryEmail addresses, message metadata and message content may be processed for delivery, security and troubleshooting.
Sentry, if enabledApplication error monitoring and reliability diagnosticsLimited technical and diagnostic information may be processed. GoMomo configures the integration to minimise personal and business information sent in error reports.

A provider may use its own subprocessors to deliver its service. We require

appropriate contractual and data-protection commitments where required by law.

The providers used in production may change as the Service evolves. We will

update this Policy or otherwise provide notice when a change materially affects

how personal data is processed.

7.2 Other disclosures

We may also disclose relevant data:

subject to confidentiality obligations;

where required by law or a valid legal process;

or violations of our agreements;

part of the business, subject to appropriate confidentiality and privacy

protections; or

We review legal requests and disclose only information that we reasonably

believe we are legally required to provide.

8. Where personal data is processed

GoMomo is established in the Netherlands.

The primary Supabase production database is intended to be located in

Frankfurt, Germany. However, use of an EU database region does not mean that

all processing takes place exclusively in the European Economic Area.

For example:

support or security purposes; and

We therefore do not represent that all personal data will remain exclusively

within the Netherlands or European Union.

9. International data transfers

Where personal data protected by European, United Kingdom or Swiss data-

protection law is transferred to a country that has not been recognised as

providing adequate protection, we use an approved transfer mechanism where

required.

Depending on the provider and destination, these mechanisms may include:

Information about a provider’s applicable transfer mechanism can be requested

through the privacy contact in Section 1.

10. How we protect data

We use technical and organisational measures designed to provide a level of

security appropriate to the nature of the data and the risks involved.

Depending on the system and environment, these measures include:

We periodically review these measures and may change them as technology,

threats and the Service evolve.

No internet service, software system or storage method is completely secure.

For that reason, we cannot promise or guarantee that unauthorised access,

disclosure, alteration, loss or destruction will never occur. This statement

does not reduce any responsibility that cannot lawfully be excluded.

You are responsible for:

If we become aware of a personal-data breach, we will investigate it and notify

the competent supervisory authority and affected individuals where and within

the timeframe required by applicable law.

11. How long we retain data

We retain personal data only for as long as reasonably necessary for the

purpose for which it was collected, including providing the Service, meeting

legal obligations, resolving disputes and enforcing agreements.

Our standard retention approach is:

Data categoryNormal retention
Account and profile dataFor the life of the account and normally deleted or anonymised from active systems within 30 days after account closure
Customer Data and business dataUntil you delete it or close the account, subject to the account-deletion process and any applicable customer agreement
Authentication and security logsNormally up to 12 months, or longer where required to investigate an incident, prevent abuse or establish a legal claim
Support communicationsNormally up to 24 months after the support matter is closed, unless a longer period is reasonably necessary
Marketing recordsUntil you unsubscribe or withdraw consent; limited suppression information may be retained to honour the opt-out
GoMomo invoices, payments and tax recordsAt least 7 years where required under Dutch tax and accounting law
Records relevant to a dispute or legal claimUntil the matter and applicable limitation periods have ended

Deletion from active systems does not always remove every copy immediately.

Residual copies may remain temporarily in disaster-recovery, backup, security

or logging systems until they are overwritten through the applicable normal

retention cycle. Such copies remain protected and are not restored except for

legitimate recovery, security or legal purposes.

We may retain limited information after account deletion where necessary to:

Where possible, retained information will be minimised or anonymised.

12. Finalised records and account deletion

Certain records may become final or locked after an event, such as when a quote

is sent, accepted, rejected or superseded.

While an account remains active, a finalised record may not be editable in

place. Corrections may instead be recorded through a new version, adjustment

or superseding record. This protects the reliability and audit history of the

record.

Technical immutability does not automatically create a right for GoMomo to keep

personal data indefinitely. When you exercise a valid deletion right, we will

delete or anonymise the relevant personal data unless continued retention is

required or permitted by law.

You are responsible for exporting and retaining copies of any business,

accounting, quote, contract or tax records that you are legally required to

keep. Closing your GoMomo account may permanently delete Customer Data after

the applicable deletion period. GoMomo is not your statutory archive unless we

have expressly agreed otherwise in writing.

GoMomo’s own invoices, payment records and accounting records may be retained

for at least seven years to comply with Dutch tax and accounting obligations.

13. Your privacy rights

Depending on where you live and the law that applies, you may have the right

to:

format;

feasible;

To exercise a right, contact [PRIVACY EMAIL].

We may need to verify your identity before completing a request. We will use

information provided for verification only to process and document the request.

Where the GDPR applies, we normally respond within one month. That period may

be extended by up to two additional months where permitted because of the

complexity or number of requests. We will tell you if an extension is needed.

Some rights are subject to exceptions. For example, we may retain information

that is required for tax compliance, legal claims, security or fraud

prevention.

If GoMomo processes personal data solely on behalf of one of our business

customers, we may direct your request to that customer or assist the customer

in responding.

European Economic Area

You may complain to the supervisory authority in the country where you live,

work or believe an infringement occurred.

GoMomo’s lead supervisory authority is expected to be:

Autoriteit Persoonsgegevens

The Dutch Data Protection Authority

You are not required to contact us before making a complaint, although we

welcome the opportunity to address your concern.

United Kingdom and Switzerland

Residents of the United Kingdom and Switzerland may exercise the equivalent

rights provided by their applicable data-protection laws and may complain to

their local supervisory authority.

United States

Where an applicable United States state privacy law gives you additional

rights, you may request access, correction, deletion or portability and may

appeal a refusal where the applicable law requires an appeal process.

GoMomo does not sell personal data or share it for cross-context behavioural

advertising. We do not discriminate against a person for exercising an

applicable privacy right.

Where legally required, we recognise browser-based opt-out preference signals,

including Global Privacy Control, for processing to which those signals apply.

Other countries

You may have additional rights under the law of your country or region. We

will consider and respond to verified requests in accordance with applicable

law.

14. Automated calculations and recommendations

The Service may use the data and assumptions you provide to generate pricing

calculations, simulations, indicators or recommendations.

These outputs are intended to support your professional judgement. They are

not used by GoMomo to make solely automated decisions about individuals that

produce legal or similarly significant effects.

You remain responsible for reviewing assumptions and deciding whether and how

to use a generated calculation or recommendation.

15. Cookies

We currently use cookies and similar technologies that are strictly necessary

for authentication, security, session management and essential preferences.

We do not currently use advertising cookies or cookies for cross-site

behavioural advertising.

If we introduce optional analytics, personalisation or marketing cookies, we

will:

Blocking essential cookies may prevent the Service from working correctly.

16. Third-party integrations and external links

The Service may allow you to connect to a third-party service or follow a link

to another website.

When you deliberately enable an integration, we may exchange information with

that provider as necessary to perform your request. The third party’s own

terms and privacy notice govern its independent processing.

GoMomo is not responsible for the privacy practices of websites or services

that we do not control.

17. Children

The Service is intended for business and professional use and is not directed

to anyone under 18 years of age.

We do not knowingly collect personal data directly from children for the

purpose of creating a GoMomo account. If you believe that a child has provided

personal data to us without appropriate authorisation, contact

[PRIVACY EMAIL].

18. Changes to this Policy

We may update this Policy to reflect changes to:

The version number and date at the top show when the Policy was last updated.

Where a change materially affects your rights or the way we use personal data,

we will provide reasonable advance notice through the Service, by email or by

another appropriate method where required by law.

19. Contact us

Questions, concerns and privacy requests should be sent to:

GoMomo — Privacy

Legal operator: [FULL LEGAL NAME]

Address: [BUSINESS ADDRESS]

Email: [PRIVACY EMAIL]

KVK number: [KVK NUMBER]