<!--
GoMomo Privacy Policy
Version: 1.0
REQUIRED BEFORE PUBLICATION:
1. Replace every value enclosed in [SQUARE BRACKETS].
2. Confirm that the production Supabase project is hosted in Frankfurt.
3. Confirm that every processor listed below is actually enabled in production.
4. Ensure the application's deletion, retention, cookie and security behaviour
matches this Policy.
5. Obtain review from a qualified Dutch privacy lawyer.
-->
Privacy Policy
Version: 1.0
Last updated: 30 July 2026
This Privacy Policy explains how GoMomo collects, uses, stores, shares and
protects personal data when you visit our website, create an account, use the
GoMomo web or mobile applications, contact us, or purchase a subscription.
In this Policy, the website, applications, pricing tools and related services
are collectively called the “Service.”
Nothing in this Policy limits any mandatory privacy rights or remedies that
apply to you under applicable law.
1. Who is responsible
GoMomo is a trading name operated by [FULL LEGAL NAME], a sole
proprietorship established in the Netherlands.
Business address: [BUSINESS ADDRESS]
KVK number: [KVK NUMBER]
Privacy contact: [PRIVACY EMAIL — recommended: privacy@gomomo.app]
For the personal data described in Section 3, GoMomo is generally the **data
controller**, meaning that we determine why and how that data is processed.
When a business customer enters personal data about its own customers,
prospects, suppliers, employees or other individuals into the Service, that
business customer is normally the controller of that data and GoMomo acts as
its data processor or service provider. Section 2 explains this distinction.
2. Our role when you upload data about other people
GoMomo lets users enter business, cost, capacity, service, pricing, quote,
customer and supplier information.
Where this information contains personal data about another person:
- you or the organisation whose account you use determine why that personal
data is processed;
- you are responsible for having a valid legal basis to collect and use it;
- you are responsible for giving the person any privacy information required
by law;
- GoMomo processes that data only to provide, secure, maintain and support the
Service, subject to our agreement with you; and
- where required, our processing is governed by a separate Data Processing
Addendum.
You must not use GoMomo as a repository for information that is unnecessary
for pricing or managing your services.
The Service is not designed for patient files, medical records, legal case
files, government identity documents, full payment-card details, biometric
data, criminal records, or other special-category or highly sensitive personal
data. You must not upload such information unless GoMomo has expressly agreed
in writing that the relevant feature supports it.
3. Personal data we collect
3.1 Account and profile data
When you register or manage an account, we may collect:
- your name;
- email address;
- account identifier;
- password-related authentication records, although we do not have access to
your readable password;
- company or business name;
- country, language, timezone and currency preferences;
- subscription plan and account status;
- role and account permissions;
- authentication history and active-session information; and
- multi-factor authentication and security settings, where enabled.
3.2 Business and pricing data
Information you or authorised users enter into the Service may include:
- business and company information;
- operating costs and cost categories;
- working capacity, availability and utilisation assumptions;
- services, packages and pricing structures;
- margins, mark-ups and pricing calculations;
- customer and supplier records;
- quotes, proposals and related status information;
- assumptions, scenarios and simulation results;
- uploaded files, notes and descriptions; and
- other information you choose to store in the Service.
Some of this information may be commercially sensitive even when it is not
personal data.
3.3 Personal data about your contacts
Where you choose to enter it, Customer Data may include limited information
about your customers, prospects, suppliers or other business contacts, such as:
- name;
- business email address;
- business telephone number;
- company;
- job title;
- billing or business address;
- customer or supplier reference; and
- information included in a quote or business record.
You should enter only the information reasonably necessary for your use of the
Service.
3.4 Payment and billing data
When you purchase a subscription, we or our payment provider may process:
- billing name and address;
- business name;
- tax or VAT number;
- subscription plan;
- invoice and transaction identifiers;
- payment amount, currency and date;
- payment status;
- payment-provider customer identifier;
- payment method type;
- limited card information, such as card brand, expiry date and final digits;
and
- information used to prevent fraud or payment abuse.
Payments are processed by Stripe or another payment provider identified at
checkout. GoMomo does not receive or store your full card number or card
security code when payment is made through the provider’s secure payment
interface.
The payment provider may process certain information as an independent
controller for activities such as identity verification, fraud prevention,
regulatory compliance and management of its own services. Its own privacy
notice also applies to that processing.
3.5 Communications and support data
When you contact us, request support, respond to a survey or otherwise
communicate with us, we may collect:
- your contact details;
- the content of your request;
- attachments you provide;
- support history;
- feedback and survey responses; and
- information needed to investigate and resolve the issue.
Please do not include passwords, full payment-card details or unnecessary
sensitive information in support messages.
3.6 Technical, device and security data
When you use the Service, we may automatically receive limited technical data,
including:
- IP address;
- browser and device type;
- operating system;
- application version;
- language and timezone;
- date and time of access;
- requested pages or application routes;
- authentication and security events;
- approximate location inferred from an IP address;
- diagnostic and error information;
- performance information; and
- identifiers needed to protect accounts, prevent abuse and investigate
incidents.
We use this information to operate and secure the Service, not to build
advertising profiles.
3.7 Cookies and local storage
We use cookies, browser storage and similar technologies that are necessary to:
- keep you signed in;
- maintain secure sessions;
- prevent cross-site request forgery and other attacks;
- remember essential settings;
- route requests correctly; and
- detect suspicious or abusive activity.
More information is provided in Section 15.
3.8 Information received from third parties
We may receive information from:
- payment providers, such as payment and subscription status;
- authentication and infrastructure providers;
- another user who invites you to an account;
- your employer or organisation when it creates or administers your account;
- integrations you deliberately connect to the Service; and
- publicly available business sources where reasonably necessary to prevent
fraud, verify a business or comply with law.
4. Why we use personal data and our legal bases
Where the General Data Protection Regulation or a similar law applies, we rely
on the following legal bases:
| Processing purpose | Personal data involved | Legal basis |
|---|---|---|
| Creating and administering your account | Account, profile and authentication data | Performance of our contract with you |
| Providing pricing, quoting, storage and related functionality | Account data and business data | Performance of our contract with you |
| Processing subscriptions and payments | Billing, subscription and transaction data | Performance of our contract; legal obligations |
| Providing customer support | Account, communication and relevant business data | Performance of our contract; legitimate interests |
| Protecting accounts and preventing fraud, abuse and security incidents | Technical, authentication, device and security data | Legitimate interests; legal obligations |
| Monitoring reliability and resolving errors | Limited technical and diagnostic data | Legitimate interests |
| Maintaining financial and tax records | Billing, invoice and transaction data | Legal obligation |
| Sending essential service communications | Contact and account data | Performance of our contract; legitimate interests |
| Sending optional product news or marketing | Contact details and communication preferences | Consent where required; otherwise legitimate interests where permitted |
| Improving the Service | Usage patterns, feedback and aggregated or de-identified information | Legitimate interests |
| Establishing, exercising or defending legal claims | Relevant account, communication, billing and security data | Legitimate interests; legal obligations |
| Complying with lawful requests | Data required by the relevant request | Legal obligation |
Our legitimate interests include operating a secure and reliable SaaS service,
preventing misuse, understanding whether features work, improving the Service,
communicating with customers, and protecting our legal rights.
Where we rely on legitimate interests, we consider whether our interests are
outweighed by your privacy rights. You may object to this processing as
described in Section 13.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not
affect processing that occurred before consent was withdrawn.
5. Service communications and marketing
We may send communications necessary to provide the Service, including:
- account verification;
- password resets;
- security alerts;
- invitations;
- payment and subscription notices;
- changes affecting your account;
- service availability notices; and
- material changes to our legal terms.
These are service communications and may continue while you maintain an
account.
We send optional marketing messages only where permitted by law. Every
marketing email will include a way to unsubscribe. Unsubscribing from
marketing does not stop essential account, security, billing or service
communications.
6. How we use business data
We use your business data to provide the features you request, including
calculations, scenarios, recommendations, quotes and reports.
We do not:
- sell your business data or personal data;
- rent personal data to third parties;
- share personal data for cross-context behavioural advertising;
- use your customers’ details for our own marketing; or
- use Customer Data to train general-purpose artificial-intelligence models.
We may use aggregated or de-identified information to understand and improve
the Service, provided that the information does not reasonably identify you,
your organisation or another person.
If GoMomo introduces a feature that sends Customer Data to an artificial-
intelligence provider, we will identify the provider and relevant processing
before enabling that processing where required by law.
7. Who we share data with
We disclose personal data only where reasonably necessary for the purposes
described in this Policy.
7.1 Core service providers
Our anticipated core providers include:
| Provider | Purpose | Processing location or relevant information |
|---|---|---|
| Supabase | Database, authentication, file storage and backend functions | The primary production database is intended to be hosted in the Central EU region in Frankfurt. Supabase and its subprocessors may process limited data in other locations for support, security and service operation. |
| Vercel | Website and application hosting, content delivery, server-side functions, deployment, security and technical logs | Vercel operates a globally distributed infrastructure. Static content, requests and limited technical data may be processed or cached in multiple countries. |
| Stripe | Subscription billing, payment processing, invoicing and fraud prevention | Stripe operates internationally and may process information in the United States and other countries. Stripe may act as our processor or as an independent controller depending on the activity. |
| Resend | Transactional and service email delivery | Email addresses, message metadata and message content may be processed for delivery, security and troubleshooting. |
| Sentry, if enabled | Application error monitoring and reliability diagnostics | Limited technical and diagnostic information may be processed. GoMomo configures the integration to minimise personal and business information sent in error reports. |
A provider may use its own subprocessors to deliver its service. We require
appropriate contractual and data-protection commitments where required by law.
The providers used in production may change as the Service evolves. We will
update this Policy or otherwise provide notice when a change materially affects
how personal data is processed.
7.2 Other disclosures
We may also disclose relevant data:
- to accountants, lawyers, auditors, insurers and other professional advisers
subject to confidentiality obligations;
- to competent courts, regulators, tax authorities or law-enforcement bodies
where required by law or a valid legal process;
- where reasonably necessary to investigate fraud, abuse, security incidents
or violations of our agreements;
- to protect the rights, safety or property of GoMomo, our users or others;
- in connection with a financing, reorganisation, sale or transfer of all or
part of the business, subject to appropriate confidentiality and privacy
protections; or
- where you have instructed or authorised us to make the disclosure.
We review legal requests and disclose only information that we reasonably
believe we are legally required to provide.
8. Where personal data is processed
GoMomo is established in the Netherlands.
The primary Supabase production database is intended to be located in
Frankfurt, Germany. However, use of an EU database region does not mean that
all processing takes place exclusively in the European Economic Area.
For example:
- Vercel operates a global content-delivery and hosting network;
- payment, email, security and support providers may operate internationally;
- provider personnel may access systems from other countries for legitimate
support or security purposes; and
- subprocessors may be established outside the European Economic Area.
We therefore do not represent that all personal data will remain exclusively
within the Netherlands or European Union.
9. International data transfers
Where personal data protected by European, United Kingdom or Swiss data-
protection law is transferred to a country that has not been recognised as
providing adequate protection, we use an approved transfer mechanism where
required.
Depending on the provider and destination, these mechanisms may include:
- an adequacy decision;
- participation in an applicable Data Privacy Framework;
- the European Commission’s Standard Contractual Clauses;
- the United Kingdom International Data Transfer Addendum or Agreement;
- contractual safeguards required under Swiss law; and
- supplementary technical and organisational measures.
Information about a provider’s applicable transfer mechanism can be requested
through the privacy contact in Section 1.
10. How we protect data
We use technical and organisational measures designed to provide a level of
security appropriate to the nature of the data and the risks involved.
Depending on the system and environment, these measures include:
- encrypted network connections;
- provider-managed encryption at rest;
- tenant-separation controls enforced through database access policies;
- role-based and least-privilege access;
- separation of development, staging and production environments;
- controls intended to prevent secret keys from being exposed to browsers;
- multi-factor authentication for privileged systems where available;
- logging and monitoring of security-relevant activity;
- dependency, code and security testing;
- restrictions on production database access;
- procedures for investigating security events;
- minimisation and redaction of data sent to error-monitoring systems; and
- contractual security obligations for relevant service providers.
We periodically review these measures and may change them as technology,
threats and the Service evolve.
No internet service, software system or storage method is completely secure.
For that reason, we cannot promise or guarantee that unauthorised access,
disclosure, alteration, loss or destruction will never occur. This statement
does not reduce any responsibility that cannot lawfully be excluded.
You are responsible for:
- using a strong and unique password;
- protecting your account credentials and devices;
- enabling available security features;
- ensuring that authorised users have appropriate permissions;
- promptly removing access that is no longer required; and
- notifying us promptly if you suspect unauthorised access.
If we become aware of a personal-data breach, we will investigate it and notify
the competent supervisory authority and affected individuals where and within
the timeframe required by applicable law.
11. How long we retain data
We retain personal data only for as long as reasonably necessary for the
purpose for which it was collected, including providing the Service, meeting
legal obligations, resolving disputes and enforcing agreements.
Our standard retention approach is:
| Data category | Normal retention |
|---|---|
| Account and profile data | For the life of the account and normally deleted or anonymised from active systems within 30 days after account closure |
| Customer Data and business data | Until you delete it or close the account, subject to the account-deletion process and any applicable customer agreement |
| Authentication and security logs | Normally up to 12 months, or longer where required to investigate an incident, prevent abuse or establish a legal claim |
| Support communications | Normally up to 24 months after the support matter is closed, unless a longer period is reasonably necessary |
| Marketing records | Until you unsubscribe or withdraw consent; limited suppression information may be retained to honour the opt-out |
| GoMomo invoices, payments and tax records | At least 7 years where required under Dutch tax and accounting law |
| Records relevant to a dispute or legal claim | Until the matter and applicable limitation periods have ended |
Deletion from active systems does not always remove every copy immediately.
Residual copies may remain temporarily in disaster-recovery, backup, security
or logging systems until they are overwritten through the applicable normal
retention cycle. Such copies remain protected and are not restored except for
legitimate recovery, security or legal purposes.
We may retain limited information after account deletion where necessary to:
- comply with tax, accounting or other legal obligations;
- record that a person has opted out of marketing;
- detect or prevent fraud and abuse;
- establish, exercise or defend legal claims;
- comply with a preservation obligation or lawful order; or
- document the deletion request and our response.
Where possible, retained information will be minimised or anonymised.
12. Finalised records and account deletion
Certain records may become final or locked after an event, such as when a quote
is sent, accepted, rejected or superseded.
While an account remains active, a finalised record may not be editable in
place. Corrections may instead be recorded through a new version, adjustment
or superseding record. This protects the reliability and audit history of the
record.
Technical immutability does not automatically create a right for GoMomo to keep
personal data indefinitely. When you exercise a valid deletion right, we will
delete or anonymise the relevant personal data unless continued retention is
required or permitted by law.
You are responsible for exporting and retaining copies of any business,
accounting, quote, contract or tax records that you are legally required to
keep. Closing your GoMomo account may permanently delete Customer Data after
the applicable deletion period. GoMomo is not your statutory archive unless we
have expressly agreed otherwise in writing.
GoMomo’s own invoices, payment records and accounting records may be retained
for at least seven years to comply with Dutch tax and accounting obligations.
13. Your privacy rights
Depending on where you live and the law that applies, you may have the right
to:
- obtain confirmation that we process your personal data;
- request access to your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict particular processing;
- object to processing based on legitimate interests;
- receive certain data in a structured, commonly used and machine-readable
format;
- ask us to transfer eligible data to another provider where technically
feasible;
- withdraw consent at any time;
- opt out of marketing;
- complain to a supervisory authority; and
- receive information about safeguards used for international transfers.
To exercise a right, contact [PRIVACY EMAIL].
We may need to verify your identity before completing a request. We will use
information provided for verification only to process and document the request.
Where the GDPR applies, we normally respond within one month. That period may
be extended by up to two additional months where permitted because of the
complexity or number of requests. We will tell you if an extension is needed.
Some rights are subject to exceptions. For example, we may retain information
that is required for tax compliance, legal claims, security or fraud
prevention.
If GoMomo processes personal data solely on behalf of one of our business
customers, we may direct your request to that customer or assist the customer
in responding.
European Economic Area
You may complain to the supervisory authority in the country where you live,
work or believe an infringement occurred.
GoMomo’s lead supervisory authority is expected to be:
Autoriteit Persoonsgegevens
The Dutch Data Protection Authority
You are not required to contact us before making a complaint, although we
welcome the opportunity to address your concern.
United Kingdom and Switzerland
Residents of the United Kingdom and Switzerland may exercise the equivalent
rights provided by their applicable data-protection laws and may complain to
their local supervisory authority.
United States
Where an applicable United States state privacy law gives you additional
rights, you may request access, correction, deletion or portability and may
appeal a refusal where the applicable law requires an appeal process.
GoMomo does not sell personal data or share it for cross-context behavioural
advertising. We do not discriminate against a person for exercising an
applicable privacy right.
Where legally required, we recognise browser-based opt-out preference signals,
including Global Privacy Control, for processing to which those signals apply.
Other countries
You may have additional rights under the law of your country or region. We
will consider and respond to verified requests in accordance with applicable
law.
14. Automated calculations and recommendations
The Service may use the data and assumptions you provide to generate pricing
calculations, simulations, indicators or recommendations.
These outputs are intended to support your professional judgement. They are
not used by GoMomo to make solely automated decisions about individuals that
produce legal or similarly significant effects.
You remain responsible for reviewing assumptions and deciding whether and how
to use a generated calculation or recommendation.
15. Cookies
We currently use cookies and similar technologies that are strictly necessary
for authentication, security, session management and essential preferences.
We do not currently use advertising cookies or cookies for cross-site
behavioural advertising.
If we introduce optional analytics, personalisation or marketing cookies, we
will:
- update this Policy or publish a separate Cookie Policy;
- provide appropriate information about the technology and provider; and
- request consent before setting non-essential cookies where required by law.
Blocking essential cookies may prevent the Service from working correctly.
16. Third-party integrations and external links
The Service may allow you to connect to a third-party service or follow a link
to another website.
When you deliberately enable an integration, we may exchange information with
that provider as necessary to perform your request. The third party’s own
terms and privacy notice govern its independent processing.
GoMomo is not responsible for the privacy practices of websites or services
that we do not control.
17. Children
The Service is intended for business and professional use and is not directed
to anyone under 18 years of age.
We do not knowingly collect personal data directly from children for the
purpose of creating a GoMomo account. If you believe that a child has provided
personal data to us without appropriate authorisation, contact
[PRIVACY EMAIL].
18. Changes to this Policy
We may update this Policy to reflect changes to:
- the Service;
- our providers;
- our processing activities;
- security practices; or
- applicable legal requirements.
The version number and date at the top show when the Policy was last updated.
Where a change materially affects your rights or the way we use personal data,
we will provide reasonable advance notice through the Service, by email or by
another appropriate method where required by law.
19. Contact us
Questions, concerns and privacy requests should be sent to:
GoMomo — Privacy
Legal operator: [FULL LEGAL NAME]
Address: [BUSINESS ADDRESS]
Email: [PRIVACY EMAIL]
KVK number: [KVK NUMBER]