Privacy policy
Explained plainly: which data we process, and what for.
1. Controller
Enes Kurt
Gemminger Str. 33, 75031 Eppingen, Germany
Email: support@listimo.ai
2. Overview: what happens with your data?
- User account: email address, user name, optionally your name and profile picture, plus your credit balance and your transaction history.
- Product photos and details: the photos and product information you upload are processed to create your listing and stored together with the results so that you can retrieve them later (“My listings”, the last 120 generations).
- Payment data: payments run entirely through the payment service provider Stripe or — for the seller pack — through the retailers Digistore24 and ClickBank; we neither receive nor store card details. After a purchase, Digistore24 or ClickBank sends us a purchase notification with name, address, email and order data so that we can add the credits (section 4).
- Support tickets and enterprise enquiries: your email address and your message, in order to answer your request; for enterprise enquiries additionally company, name, planned volume and — voluntarily — your phone number, in order to prepare a quote.
- Listing check: if you enter an ASIN or an Amazon link, we retrieve the publicly visible product data of that listing and have it assessed by AI. No sign-up is required for this; without an account, one free analysis per day and device is possible, for which your browser stores a random device identifier (section 8).
- Signing in with Google, Apple, Microsoft or Facebook (optional): if you use one of these sign-in routes, the provider gives us your email address and — where stored there — your name and profile picture (section 4).
- Email outreach to Amazon sellers and creators: anyone we have contacted for business purposes will find in section 7 where we got the contact details, how we count opens and clicks, and how to object.
- Listimo Academy (optional): if you use our free training with an account, we store your progress — quiz results per lesson as well as passed final exams including the certificate code (details in section 6, which also covers the public verifiability of your certificate).
- Partner programme (optional): if you take part in the partner programme and request a cash payout, we process your payout and tax details (for example IBAN or PayPal address, account holder, tax status, VAT ID if applicable).
- Language by country of origin: when the homepage is opened, our server determines only the country of origin from your IP address — locally on the server, without passing it on and without storing it — and shows visitors outside Germany, Austria and Switzerland the English version. Your choice in the language switch always takes precedence (section 8).
- Advertising measurement: we only set advertising cookies with your consent. Without consent, the Google Ads tag measures in cookieless form only and without identifiers that identify you (details in section 4). Analytics cookies (Google Analytics 4) as well as the TikTok pixel and the Meta pixel are likewise only set with your consent; without consent Google Analytics works exclusively without cookies, and the TikTok pixel and the Meta pixel are not loaded at all (details in section 4).
3. Legal bases
Processing takes place in order to perform the contract or to take steps prior to entering into a contract (Art. 6(1)(b) GDPR), on the basis of legal obligations such as retention duties under commercial and tax law (point (c)), and on the basis of our legitimate interest in secure, stable operation (point (f)).
4. Service providers used (processors)
Supabase (user accounts & database)
Account and balance data as well as your Academy progress (section 6) are stored with Supabase (Supabase Inc.). The project's data centre is located in the EU (AWS region eu-west-1, Ireland) — these data are not transferred to third countries outside the EU. A data processing agreement (DPA) is in place with Supabase.
Signing in with Google, Apple, Microsoft or Facebook (optional)
Instead of using an email address and password, you can sign in with an existing account at Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), Apple (Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland), Microsoft (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) or Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland); the sign-in page shows which of these options are offered. If you choose a provider, you are redirected to its page and sign in there; the sign-in is handled through our database provider Supabase (see above). In doing so, the provider transmits to us your email address, an identifier of your account with that provider and — where stored there — your name and profile picture; we never learn your password with that provider. We store this information in your Listimo account, show the name and profile picture in your profile, and record when, during this sign-in, you accepted the terms and confirmed that you act as a business. The respective provider learns that you are signing in to Listimo and processes the sign-in under its own responsibility according to its privacy terms; this may involve a transfer to the USA (basis: EU-US Data Privacy Framework). The legal basis is the performance of the user contract or of pre-contractual steps which you yourself initiate by choosing this sign-in route (Art. 6(1)(b) GDPR). Signing in with an email address and password always remains possible as well.
Stripe (payment processing)
When you buy credits you are redirected to Stripe (Stripe Payments Europe, Ltd., Ireland). Stripe processes your payment data as a separate controller or as a processor; we only receive a confirmation of the payment and the details needed for bookkeeping. More at stripe.com/privacy.
Digistore24 (seller packs & partner attribution)
We sell our large credit packs (“seller pack”) through Digistore24 (Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Germany). Digistore24 acts as the retailer: the purchase contract is concluded with Digistore24, Digistore24 handles the payment, issues the invoice and is separately responsible for the payment data collected in the process (more at digistore24.com/page/privacy). After a purchase, Digistore24 automatically sends us a purchase notification with your name, your email address, your address and the order data (order number, product, amount, payment method, date). We use this information exclusively to add the purchased credits to your account (or to send you a redemption code if no account exists for your email address), to inform you about this by email, and to book refunds or chargebacks correctly. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). We also keep the complete purchase notification as evidence towards Digistore24, for example in the event of queries or disputes about a booking (legitimate interest, Art. 6(1)(f) GDPR); name, address and phone number are automatically removed from it after 12 months (section 9). After the purchase, Digistore24 forwards you to our confirmation page and passes on your order number; we use it to show you the status of your credit there (with the email address shown in shortened form). The order number is not additionally stored for this.
On the pages about the seller pack and the Digistore24 partner programme we embed a script from digistore24-scripts.com (the Digistore24 “promocode”). It recognises whether you came to us through the referral link of a Digistore24 partner (affiliate) and remembers that attribution in your browser so that the partner receives their commission on a later purchase through Digistore24. For technical reasons, your IP address is transmitted to Digistore24 when the script is loaded; this does not involve any analysis of your behaviour on our pages. The legal basis is our legitimate interest in correctly remunerating our sales partners (Art. 6(1)(f) GDPR). The script is only loaded on those sales and partner pages — not in the tool itself and not on the other pages.
ClickBank (credit packs in US dollars)
We also sell credit packs in US dollars through ClickBank (Click Sales, Inc., 1444 S. Entertainment Ave., Suite 410, Boise, ID 83709, USA). ClickBank acts as the retailer: the purchase contract is concluded with ClickBank, ClickBank handles the payment, issues the payment receipt, processes refunds and is separately responsible for the payment data collected in the process (more in the ClickBank privacy policy). After a purchase, a refund or a chargeback, ClickBank automatically sends us an encrypted purchase notification with your name, your email address, your address and, where applicable, phone number, as well as the order data (order number, product, quantity, amount, payment method, date, identifier of a referring ClickBank partner). We use this information exclusively to add the purchased credits to your account (or to send you a redemption code if no account exists for your email address), to inform you about this by email, and to book refunds or chargebacks correctly. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). We also keep the complete purchase notification as evidence towards ClickBank (legitimate interest, Art. 6(1)(f) GDPR); name, address and phone number are automatically removed from it after 12 months (section 9).
After the purchase, ClickBank forwards you to our confirmation page and appends the order number, time of purchase, item number, a proof of purchase as well as your name, your email address, your country and your postcode to the address. Name and email address are only displayed in your browser and are then removed from the address bar; only the order number, time of purchase, item number and proof of purchase are sent to our server in order to display the status of your credit, and these are not additionally stored for that purpose. The request itself appears in the server log files like any other page request (see “Hosting”, deleted after 14 days at the latest). If you come through the referral link of a ClickBank partner, ClickBank attributes the commission through its own redirect and its own cookies on ClickBank's pages; we do not embed any ClickBank script on our pages for this. The transfer to the USA takes place on the basis of the EU-US Data Privacy Framework, under which Click Sales, Inc. is certified.
OpenAI (AI generation)
To create the images and copy, the product photos and product details you upload are transmitted to OpenAI (OpenAI, L.L.C., USA — transfer on the basis of the EU-US Data Privacy Framework or standard contractual clauses). Under OpenAI's API policies, content submitted through the programming interface (API) is not used to train the AI models. Even so, please do not upload photos showing people or third-party protected content unless you hold the rights to do so.
EvoLink (product video, beta)
If you create a product video, a photo of your product is transmitted as the starting frame — depending on the method, along with the scene images generated for your video — to the video service EvoLink for animation (EVO GLOBAL TECHNOLOGIES LIMITED, Flat 2304, 23/F Ho King Commercial Centre, 2-16 Fa Yuen Street, Mong Kok, Hong Kong — transfer to a third country without an adequacy decision on the basis of the EU standard contractual clauses). For this, the relevant image is made available briefly (no longer than 20 minutes) at an unguessable address on our server so that EvoLink can fetch it; no account data are transferred. According to the provider, the generated clips remain available at EvoLink for 24 hours. The legal basis is the performance of the video you commissioned (Art. 6(1)(b) GDPR). The director's prompt for the video and, depending on the method, the script, scene images and quality check are produced by OpenAI (see above).
ScraperAPI (retrieving public Amazon pages)
We retrieve publicly visible Amazon pages through the service ScraperAPI (ScraperAPI, USA). This happens during the listing check (with and without an account, including when reloading the data and when re-checking a reworked listing), when you use an ASIN or an Amazon link in the listing generator (for example as a reference ASIN) or in the product video, when loading the photos of colour variants, when comparing with the top results of an Amazon search for a search term, and for the analyses behind our email outreach to sellers (section 7). Only the ASIN, the marketplace or Amazon domain, a search term formed from the product data in the case of a search, and the addresses of the retrieved Amazon pages (product page, offer list, seller page) are transmitted. The requests are made from our server; your IP address and your account data are not transmitted to ScraperAPI. The transfer to the USA takes place on the basis of the EU standard contractual clauses. Where the function includes an AI assessment, the retrieved product data (including title, bullet points, images, description) are then passed on to OpenAI (see above). The legal basis is the performance of the function you requested (Art. 6(1)(b) GDPR) or — when used without an account and for seller outreach — our legitimate interest in providing these functions (Art. 6(1)(f) GDPR).
Hosting
The service is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in a data centre in Nuremberg (Germany). When the pages are opened, the server automatically processes what are known as server log files: IP address, date and time of access, the page/file requested, the volume of data transferred as well as the browser and operating system used. This serves secure, stable operation and the prevention of attacks (legal basis: legitimate interest, Art. 6(1)(f) GDPR). The log files are deleted automatically after 14 days at the latest. A data processing agreement (DPA) is in place with Hetzner.
Also exclusively on this server, we determine the country of origin from your IP address when the homepage is opened — using a locally stored country database (GeoLite2 by MaxMind). Your IP address is not transmitted to anyone for this and is not stored beyond the server log files mentioned above; the result serves solely to redirect visitors outside Germany, Austria and Switzerland to the English version of the homepage (/en/). A language choice made with the DE | EN switch always takes precedence (section 8). The legal basis is our legitimate interest in showing you the site in a language you understand (Art. 6(1)(f) GDPR). This website includes GeoLite2 data created by MaxMind, available from www.maxmind.com.
Brevo (email delivery)
For our optional newsletter we use Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany). You only receive the newsletter if you have expressly signed up for it — by ticking the box during registration or using the switch in your profile (legal basis: consent, Art. 6(1)(a) GDPR; the time of your sign-up is logged). For this we transmit your email address, your display name and your language setting to Brevo. To improve our newsletters, we evaluate whether emails are opened and links are clicked. You can unsubscribe at any time — using the unsubscribe link in every email or the switch in your profile; your data are then removed from the distribution list. You can therefore withdraw your consent at any time with effect for the future. A data processing agreement (DPA) is in place with Brevo. More at brevo.com/legal/privacypolicy.
We also send service- and contract-related emails through Brevo, for example replies to your support and enterprise enquiries (including acknowledgements of receipt) and notifications about the partner programme. The legal basis for this is the performance of the contract or our legitimate interest in communicating with you (Art. 6(1)(b) or (f) GDPR); separate consent is not required for this. Our emails to Amazon sellers and creators are also sent through Brevo (section 7).
Google Ads conversion measurement (consent mode)
We use the Google Ads tag of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) in order to measure whether visitors who come to us through a Google ad subsequently register. In doing so we use Google Consent Mode v2; the extent of the processing depends on your choice in the cookie banner:
- Without consent (“necessary only”): the tag is loaded but sets no cookies and transmits no identifiers that identify you to Google. Only cookieless, aggregated event signals are sent (for technical reasons your IP address is transmitted in the process), from which Google statistically extrapolates conversions in aggregated form. The legal basis is our legitimate interest in measuring the success of our advertising in a non-user-related form (Art. 6(1)(f) GDPR).
- With consent (“accept all”): in addition, cookies are set and data about the ad click (for example the click identifier) are transmitted to Google in order to attribute conversions directly to your ad click. On registration we also transmit your email address in encrypted form (SHA-256 hash, “enhanced conversions”) — Google cannot reverse the email address from it, but can only match it against hashes of its own signed-in users. The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG), which you can withdraw at any time with effect for the future.
The data may also be transferred to servers in the USA (transfer on the basis of the EU-US Data Privacy Framework). You can change your selection at any time: reset cookie selection — the banner then appears again. More in Google's privacy policy.
Google Analytics 4 (consent mode)
We also use Google Analytics 4, a web analytics service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), in order to understand how our pages are used — for example which pages are opened and at which point visitors abandon the registration or purchase process. Google Consent Mode v2 applies here too; the extent of the processing depends on your choice in the cookie banner:
- Without consent (“necessary only”): no analytics cookies are set and no identifiers that identify you are transmitted; Google only receives cookieless, aggregated event signals (including, for technical reasons, your IP address), from which usage figures are statistically extrapolated. The legal basis is our legitimate interest in improving our offering in a non-user-related form (Art. 6(1)(f) GDPR).
- With consent (“accept all”): Google Analytics sets cookies and measures your use across sessions (for example pages visited, events triggered such as registration or purchase). The IP address is not stored by Google Analytics 4. The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG), which you can withdraw at any time with effect for the future (reset cookie selection).
Here too the data may be transferred to servers in the USA (EU-US Data Privacy Framework). More in Google's privacy policy.
TikTok pixel
We also use the TikTok pixel of TikTok Technology Limited (10 Earlsfort Terrace, Dublin 2, Ireland) in order to measure whether our advertising on TikTok works and to be able to reach visitors of our website there later with relevant ads (retargeting). Unlike the Google services, there is no cookieless variant here: the TikTok pixel is only loaded if you choose “accept all” in the cookie banner — without your consent, TikTok is not contacted from our site at all. With consent, TikTok sets cookies and records your page views as well as events such as a completed registration or a purchase. The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG), which you can withdraw at any time with effect for the future (reset cookie selection). The data may also be transferred to servers outside the EU (including the USA; transfer on the basis of the EU-US Data Privacy Framework or standard contractual clauses). More in TikTok's privacy policy.
Meta pixel
We use the Meta pixel of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) in order to measure whether our advertising on Facebook and Instagram works and to be able to reach visitors of our website there later with relevant ads (retargeting). As with the TikTok pixel, there is no cookieless variant here: the Meta pixel is only loaded if you choose “accept all” in the cookie banner — without your consent, Meta is not contacted from our site at all. With consent, Meta sets cookies and records your page views as well as events such as a completed registration or a purchase (for a purchase, also the amount). Meta also processes this data for its own purposes; in that respect we and Meta are joint controllers (Art. 26 GDPR), with the details set out in Meta's controller addendum. The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG), which you can withdraw at any time with effect for the future (reset cookie selection). The data may also be transferred to servers outside the EU (including the USA; transfer on the basis of the EU-US Data Privacy Framework or standard contractual clauses). More in Meta's privacy policy.
Anonymous usage statistics
To improve our offering, we count page views and a small number of feature events (for example “registration completed”) in anonymous form: without cookies, without storing IP addresses and without user-related identifiers — we assign neither a user nor a device identifier for these statistics. For each event we record only the time, the type of event, the page opened, the language setting, the rough device category (mobile or desktop — derived from the browser identifier, which is itself not stored) and the origin details described below. It is therefore not possible to draw conclusions about individual persons or to combine the data into a user profile (legal basis: legitimate interest in improving our offering, Art. 6(1)(f) GDPR).
We also determine how many different visitors open our pages on a given day. For this, an irreversible check value is formed from the IP address, the browser identifier and a random value newly generated each day; it exists only in memory and is discarded when the day changes. Only the total per day is stored — neither the check value nor the IP address. Recognition beyond that day is therefore technically impossible (legal basis as above: Art. 6(1)(f) GDPR).
For each of these events we additionally count how the visit reached us:
- Origin channel: for an entry through a Google ad, only the value “ads” is recorded — we do not store the ad's click identifier (gclid) itself. Otherwise the source label we assign in our own links (parameter “utm_source”), failing that the referring site (see below) or the value “direct”.
- Medium: the type of access from the parameter “utm_medium” (for example “cpc” for an ad click or “email”).
- Referring site: if you come from an external website, its host — that is, only the site name such as “google.com”, never the path opened and never search terms entered. Internal moves between our own pages are not counted as an origin.
- Campaign code: if you open a link distributed by us with a campaign label (parameter “k” or “utm_campaign”), we count its code. It names the campaign, not you — all visitors of the same campaign share the same code.
This information describes the route to the page, not the person: it contains no features identifying you and is not assigned to any user account. Whether it is remembered in your browser beyond the individual visit depends solely on your consent (section 8).
5. Partner programme and payouts
If you take part in our voluntary referral and partner programme, we process the data required to run it: your personal referral code, the qualified referrals attributed to you, and the resulting credits and commissions. Referred customers are only shown to you in aggregated form; we do not disclose personal data of referred customers to you.
So that you can judge how your links perform, we also count how often your referral links are opened. Only the referral code, the day and the number of views are recorded — on request separated by a campaign label you assign in the link (for example “youtube”), which names the channel, not the person opening it. Details about the person clicking — IP address, browser identifier or other identifiers — are neither transmitted nor stored for this count; it is therefore not possible to draw conclusions about individual visitors (legal basis: performance of the participation agreement with the referrer, Art. 6(1)(b) GDPR).
If you request a cash payout, we additionally process the payout and tax details you have provided — depending on the method chosen, your IBAN or PayPal address, the name of the account holder, your tax status (private individual, small business under section 19 of the German VAT Act, or standard taxation) and, where applicable, your VAT identification number. We use this information exclusively to process the payout (SEPA transfer or PayPal) and to create the tax statement under the self-billing procedure. The legal basis is the performance of the participation agreement (Art. 6(1)(b) GDPR) and the fulfilment of our obligations under tax and commercial law (point (c)). The terms of participation for the referral programme apply in addition.
6. Listimo Academy and certificates
You can use parts of our free training (“Listimo Academy”) entirely without an account; in that case we process no data other than for any other page visit (sections 4 and 8). If you use the Academy with your free account, we store your progress: your quiz results per lesson (lesson, score, time) as well as passed final exams per learning track (track, score, certificate code, time). The purpose is to show you your progress across devices, to provide your certificate and to ensure the one-off credit award per track. Storage is with our database provider Supabase (section 4); the legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
Certificate with public verification: if you pass the final quiz of a track (at least 80 %), we create a certificate with an individual verification code. At listimo.ai/academy/zertifikat/ anyone you give this code to (for example a client) can check that it is genuine — the track, the date it was passed and your display name are shown (your user name; if you have not set one, the part of your email address before the @ — you can control this yourself at any time by setting a user name in your profile). Without the code no retrieval is possible; only pass the code on if you want it to be displayed. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). When your account is deleted, progress and completions are deleted; your certificate can then no longer be retrieved.
7. Email outreach to Amazon sellers and creators
We contact individual Amazon sellers as well as creators (for example YouTube or TikTok channels about selling on Amazon) by email in order to introduce them to Listimo or to our partner programme. This section is addressed to the people we contact: where we got the information, what we do with it and how you can object.
Sellers — origin of the data: the starting point is publicly available information on Amazon: product data of an offer (ASIN, brand, category, title, images, review counts) as well as the name, seller identifier and country of the seller, which we partly compile with the market-data tool Helium 10. The contact details — email address, business name and, where applicable, phone number — are read from the public seller page on amazon.de (seller information or legal notice), retrieved through ScraperAPI (section 4); in individual cases we enter them by hand. In order to check whether a brand sells its own offer, we also record the names of the other sellers of that offer.
Sellers — what we store and send: for every seller contacted we store the information mentioned, an automated analysis of the public listing, the text of the email, the date, subject and recipient address of each send, the processing status (for example “contacted” or “declined”) and, where applicable, a personal form of address. The text of the email is drafted by OpenAI's AI (section 4); for this we transmit the brand, company, product title, ASIN, category, analysis values and the form of address, which may contain a name. The email contains an image card with the analysis and a personal link to the full assessment, valid for 30 days; it is sent through Brevo (section 4). If an account is created through that link, we note this in the seller record. If the email goes unclicked, a single reminder may follow after a few days.
Creators — origin of the data and sending: we use publicly available channel information (name, channel name, platform, channel address, subscriber, video and view counts, main topic) and the publicly stated contact or collaboration address from the channel description or the legal notice. We store our assessment of whether the channel is a fit for Listimo, the processing status and, per email, the date, address and subject. These emails are sent from a fixed template through Brevo; we do not use AI for them.
Open and click measurement: we evaluate whether our emails are opened and links are clicked. For emails to sellers, an email counts as opened when the embedded image card is loaded from our server, and as clicked when the assessment is opened through the personal link. Emails to creators contain an invisible counting pixel (an image file at listimo.ai/p/…) and a click link (listimo.ai/k/…) that redirects to our website. In each case only the number of retrievals and the time of the first and the last retrieval are stored — no IP address and no browser identifier (apart from the short-lived server log files, see section 4, Hosting). Some email programs load images automatically and security filters open links in advance; the figures are therefore only a rough indication. If your email program does not load images automatically, no open measurement takes place.
Legal basis and objection: we process these data on the basis of our legitimate interest in introducing Listimo to business users and initiating collaborations (Art. 6(1)(f) GDPR). You can object to this processing at any time without giving reasons (Art. 21 GDPR) — using the unsubscribe link in our email, by replying to the email, or informally to support@listimo.ai. After an objection we add your email address (on request your entire domain as well) to a block list that is checked before every send; seller records are additionally set to “declined”.
Retention: no automatic deletion period is currently set for this information. We keep it for as long as it is needed for outreach and for traceability of our contacts, and delete it on request. We keep the block list entry (email address or domain, reason and date) even after that, because it is the only way we can make sure not to contact you again.
8. Cookies & local storage
We use technically necessary cookies and local browser storage (localStorage) for your login session, for settings such as dismissed notices and for your local learning comfort in the Listimo Academy (unlocked chapters and checklist ticks, values “ak-kap:…” and “ak-cl:…” — they stay in your browser and are not transmitted to us) — all of this is required for the function you are using (section 25(2) TDDDG) and does not require consent. Also without consent, we record your decision from the cookie banner itself (value “consent_marketing” with the content “ja” or “nein”) — only in this way can we respect your choice on every further visit instead of asking you again. In the same way we record your choice in the DE | EN language switch in the cookie “siteLang” (content “de” or “en”, lifetime one year): the site then appears in your language on your next visit, and the language routing by country of origin (section 4, Hosting) does not override your choice.
If you use the free listing check without an account, your browser generates a random device identifier once and stores it locally (localStorage value “listimoGeraet”); it also remembers the time of your last free analysis (“lst_free_check”). The device identifier is transmitted to our server during an analysis so that the free analysis can be limited to one per device and day — even where several devices share an IP address, for example in an office or on a mobile network. It contains no information about your person and is required for this function you are using (section 25(2) TDDDG); the legal basis for the processing is our legitimate interest in a fair limitation of the free offering (Art. 6(1)(f) GDPR). You can remove both values by clearing the website data in your browser.
Only with your consent to advertising measurement, up to three further local values are added which record your origin: “lst_k” (the code of the campaign through which you came to us), “lst_q” (the origin channel, for example “ads” or “direkt”) and “lst_m” (the medium, for example “cpc”). They serve solely to attribute a later registration to the channel through which you found us (section 4) and expire automatically 30 days after the visit during which they were created. Without your consent they are not stored; the origin is then only evaluated within the individual page request.
We only set advertising and analytics cookies (Google Ads, Google Analytics 4, the TikTok pixel and the Meta pixel, see section 4) if you expressly agree in the cookie banner; without agreement the Google services work exclusively without cookies and without identifiers that identify you (consent mode, section 4), and the TikTok pixel and the Meta pixel are not loaded at all. You can change your agreement at any time: reset cookie selection. We do not currently use any other analytics or advertising services.
On the pages about the seller pack and the Digistore24 partner programme, the Digistore24 script embedded there (section 4) stores a partner identifier in your browser (cookie “ds24c.v1”) if you came through the link of a Digistore24 partner. It contains no information about your person, only the identifier of the referring partner, and serves solely to attribute commission on a purchase through Digistore24 (legitimate interest, Art. 6(1)(f) GDPR). Digistore24 determines the lifetime; more at digistore24.com/page/privacy.
The same applies to our own referral programme (section 5): if you open our pages through the referral link of a Listimo user (address with “?ref=…”), we store the referral code it contains in your browser for 30 days (cookie and localStorage value “lst_ref”). It contains no information about your person, only the referrer's code, and serves solely to attribute a later registration to the referrer and to grant you any benefits from the referral (for example a discount) (legitimate interest or steps prior to a contract, Art. 6(1)(f)/(b) GDPR). In addition, your browser remembers only for the duration of the session that opening the link has already been counted (sessionStorage value “lst_ref_klick”) — so that reloading the page is not counted twice in the anonymous click count in section 5; this value expires when the browser is closed.
9. Retention periods
- Account data: until your account is deleted. If you do not confirm your email address after signing up, we remind you by email once on each of the following three days (via Brevo, section 4; legal basis: pre-contractual measures, Art. 6(1)(b) GDPR) and then delete the unconfirmed account automatically, at the earliest on the fourth day after sign-up. Each of these emails states the deletion date.
- Academy progress and completions (section 6): until your account is deleted; with deletion your certificate also becomes unavailable. The local learning-comfort values (“ak-kap:…”, “ak-cl:…”) are held only in your browser and can be removed there at any time by clearing the website data.
- Generated listings: the last 120 generations per account are kept in your history; you can remove entries yourself at any time. The generated image and text files are deleted automatically after 90 days (please download important results as a ZIP beforehand).
- Product videos (beta): the finished video (16:9 and 9:16) including the preview image remains available for 90 days after creation (profile, “My listings”) and is then deleted automatically; the intermediate images from creation (scene images, working copies of your product photos) are deleted after 14 days. The moving scenes are produced through the service EvoLink (section 4); according to the provider, generated clips remain available there for 24 hours.
- Payment and invoice data: in accordance with statutory retention periods (up to 10 years).
- Purchase notifications from Digistore24 and ClickBank (section 4): the complete notification with name, address and phone number is kept for 12 months and then automatically reduced to the order data (order number, product, amounts, email address); these remain stored as an accounting record within the statutory retention periods (up to 10 years). Unredeemed redemption codes remain stored until they are redeemed or cancelled.
- Payout and tax details from the partner programme: for the duration of participation and afterwards within the statutory retention periods (up to 10 years).
- Support tickets and enterprise enquiries: until the matter is resolved and afterwards for up to 3 years (for traceability and to assert or defend against possible claims within the standard limitation period).
- Anonymous usage statistics (section 4): the counted events are stored by day and deleted automatically after 90 days.
- Origin values stored in the browser (“lst_k”, “lst_q”, “lst_m”, only with consent): 30 days, after which they expire automatically (section 8).
- Referral code in the browser (“lst_ref”, section 8): 30 days; the session marker “lst_ref_klick” expires when the browser is closed.
- Click counting for referral links (section 5, only referral code, day and number — without any personal reference): 2 years (731 days), so that the year-on-year comparison in the partner overview can show the previous year in full.
- Free listing checks without an account: we log the time, ASIN, marketplace, the beginning of the product title, the score, the language setting and a shortened, irreversible check value of the device identifier (section 8) — without an IP address; the log contains only the last 5,000 analyses, as does an identically structured note in our internal activity log. The limit of one free analysis per day is counted by the server using the IP address and device identifier in memory only; this counter expires after 24 hours.
- Email outreach to sellers and creators (section 7): no automatic deletion period; kept for as long as required for outreach and traceability, deleted on request. The personal link to the assessment is valid for 30 days. Block list entries following an objection are kept permanently.
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object on grounds relating to your particular situation; you can object at any time and without giving reasons to processing for direct marketing purposes — such as our email outreach (section 7) — (Art. 21(2) and (3) GDPR). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). Simply contact support@listimo.ai or open a support ticket. You also have the right to lodge a complaint with a data protection supervisory authority.
11. No automated decision-making
Automated decision-making producing legal effects concerning you within the meaning of Art. 22 GDPR does not take place. The AI used merely generates the images and copy you request; it does not take decisions about you as a person.
12. Obligation to provide data
Providing an email address and password is required in order to create an account; without them the service cannot be used. All further details are voluntary.
Last updated: 20 September 2026 · English version added 16 September 2026
This English text is a translation provided for convenience. In case of any discrepancy, the German version at listimo.ai/datenschutz.html is the authoritative one.