Skip to main content

Privacy Policy

Last updated: March 17, 2026

smile ("we", "us", or "our") operates the website smile-list.vercel.app. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR/DSGVO) and Austrian data protection law.

1. Data Controller

The data controller responsible for processing your personal data is smile supplement directory, based in Austria. For contact details regarding data protection inquiries, please see the Contact section below.

2. Data We Collect

Account Data

When you create an account, we collect your email address and display name. Account authentication is managed through Supabase Auth.

Usage Data

We automatically collect certain information when you visit our website, including your IP address, browser type, operating system, referring URLs, pages viewed, and the date and time of your visit. This data is collected through Vercel Analytics.

User-Generated Content

If you submit reviews or other content, we store that content along with your display name and the date of submission.

3. Legal Basis for Processing

  • Consent (Art. 6(1)(a) GDPR): For optional analytics cookies and marketing communications.
  • Contract performance (Art. 6(1)(b) GDPR): For providing account services and features you have requested.
  • Legitimate interest (Art. 6(1)(f) GDPR): For website security, fraud prevention, and improving our services.

4. Cookies

We use cookies that are necessary for the operation of our website:

  • Supabase authentication cookies: Essential for maintaining your login session and account security.
  • Vercel Analytics: Used to understand website usage patterns and improve our service.

5. Third-Party Services

Supabase

We use Supabase for user authentication and database services. Supabase processes your account data (email, display name) and user-generated content on our behalf. Supabase Inc. is based in the United States; data transfers are covered by Standard Contractual Clauses (SCCs).

Vercel

Our website is hosted on Vercel. Vercel processes usage data including IP addresses and page views for hosting and analytics purposes. Vercel Inc. is based in the United States; data transfers are covered by Standard Contractual Clauses (SCCs).

Affiliate Partners

When you click on affiliate links (e.g., Amazon, iHerb, or other supplement retailers), you will be redirected to the respective third-party website. These partners may set their own cookies and collect data according to their own privacy policies. We do not control or have access to the data collected by affiliate partners.

6. Your Rights (DSGVO Art. 15–21)

Under the GDPR/DSGVO, you have the following rights regarding your personal data:

  • Right of access (Art. 15): You can request information about the personal data we hold about you.
  • Right to rectification (Art. 16): You can request correction of inaccurate personal data.
  • Right to erasure (Art. 17): You can request deletion of your personal data ("right to be forgotten").
  • Right to data portability (Art. 20): You can request your data in a structured, machine-readable format.
  • Right to object (Art. 21): You can object to the processing of your personal data based on legitimate interest.
  • Right to restriction (Art. 18): You can request restriction of processing in certain circumstances.

7. Data Retention

We retain your account data for as long as your account is active. If you delete your account, your personal data will be removed within 30 days, except where we are required to retain it by law. Usage data collected through analytics is retained in aggregated, anonymized form. User-generated content (reviews) will be anonymized upon account deletion.

8. Contact for Data Requests

To exercise any of your data protection rights, or if you have questions about this Privacy Policy, please contact us at the email address provided in our Impressum. We will respond to your request within one month as required by the GDPR.

9. Right to Lodge a Complaint

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde): Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria. Website: dsb.gv.at