Privacy policy

Explained plainly: which data we process, and what for.

1. Controller

Enes Kurt
Gemminger Str. 33, 75031 Eppingen, Germany
Email: support@listimo.ai

2. Overview: what happens with your data?

3. Legal bases

Processing takes place in order to perform the contract or to take steps prior to entering into a contract (Art. 6(1)(b) GDPR), on the basis of legal obligations such as retention duties under commercial and tax law (point (c)), and on the basis of our legitimate interest in secure, stable operation (point (f)).

4. Service providers used (processors)

Supabase (user accounts & database)

Account and balance data as well as your Academy progress (section 6) are stored with Supabase (Supabase Inc.). The project's data centre is located in the EU (AWS region eu-west-1, Ireland) — these data are not transferred to third countries outside the EU. A data processing agreement (DPA) is in place with Supabase.

Signing in with Google, Apple, Microsoft or Facebook (optional)

Instead of using an email address and password, you can sign in with an existing account at Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), Apple (Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland), Microsoft (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) or Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland); the sign-in page shows which of these options are offered. If you choose a provider, you are redirected to its page and sign in there; the sign-in is handled through our database provider Supabase (see above). In doing so, the provider transmits to us your email address, an identifier of your account with that provider and — where stored there — your name and profile picture; we never learn your password with that provider. We store this information in your Listimo account, show the name and profile picture in your profile, and record when, during this sign-in, you accepted the terms and confirmed that you act as a business. The respective provider learns that you are signing in to Listimo and processes the sign-in under its own responsibility according to its privacy terms; this may involve a transfer to the USA (basis: EU-US Data Privacy Framework). The legal basis is the performance of the user contract or of pre-contractual steps which you yourself initiate by choosing this sign-in route (Art. 6(1)(b) GDPR). Signing in with an email address and password always remains possible as well.

Stripe (payment processing)

When you buy credits you are redirected to Stripe (Stripe Payments Europe, Ltd., Ireland). Stripe processes your payment data as a separate controller or as a processor; we only receive a confirmation of the payment and the details needed for bookkeeping. More at stripe.com/privacy.

Digistore24 (seller packs & partner attribution)

We sell our large credit packs (“seller pack”) through Digistore24 (Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Germany). Digistore24 acts as the retailer: the purchase contract is concluded with Digistore24, Digistore24 handles the payment, issues the invoice and is separately responsible for the payment data collected in the process (more at digistore24.com/page/privacy). After a purchase, Digistore24 automatically sends us a purchase notification with your name, your email address, your address and the order data (order number, product, amount, payment method, date). We use this information exclusively to add the purchased credits to your account (or to send you a redemption code if no account exists for your email address), to inform you about this by email, and to book refunds or chargebacks correctly. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). We also keep the complete purchase notification as evidence towards Digistore24, for example in the event of queries or disputes about a booking (legitimate interest, Art. 6(1)(f) GDPR); name, address and phone number are automatically removed from it after 12 months (section 9). After the purchase, Digistore24 forwards you to our confirmation page and passes on your order number; we use it to show you the status of your credit there (with the email address shown in shortened form). The order number is not additionally stored for this.

On the pages about the seller pack and the Digistore24 partner programme we embed a script from digistore24-scripts.com (the Digistore24 “promocode”). It recognises whether you came to us through the referral link of a Digistore24 partner (affiliate) and remembers that attribution in your browser so that the partner receives their commission on a later purchase through Digistore24. For technical reasons, your IP address is transmitted to Digistore24 when the script is loaded; this does not involve any analysis of your behaviour on our pages. The legal basis is our legitimate interest in correctly remunerating our sales partners (Art. 6(1)(f) GDPR). The script is only loaded on those sales and partner pages — not in the tool itself and not on the other pages.

ClickBank (credit packs in US dollars)

We also sell credit packs in US dollars through ClickBank (Click Sales, Inc., 1444 S. Entertainment Ave., Suite 410, Boise, ID 83709, USA). ClickBank acts as the retailer: the purchase contract is concluded with ClickBank, ClickBank handles the payment, issues the payment receipt, processes refunds and is separately responsible for the payment data collected in the process (more in the ClickBank privacy policy). After a purchase, a refund or a chargeback, ClickBank automatically sends us an encrypted purchase notification with your name, your email address, your address and, where applicable, phone number, as well as the order data (order number, product, quantity, amount, payment method, date, identifier of a referring ClickBank partner). We use this information exclusively to add the purchased credits to your account (or to send you a redemption code if no account exists for your email address), to inform you about this by email, and to book refunds or chargebacks correctly. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). We also keep the complete purchase notification as evidence towards ClickBank (legitimate interest, Art. 6(1)(f) GDPR); name, address and phone number are automatically removed from it after 12 months (section 9).

After the purchase, ClickBank forwards you to our confirmation page and appends the order number, time of purchase, item number, a proof of purchase as well as your name, your email address, your country and your postcode to the address. Name and email address are only displayed in your browser and are then removed from the address bar; only the order number, time of purchase, item number and proof of purchase are sent to our server in order to display the status of your credit, and these are not additionally stored for that purpose. The request itself appears in the server log files like any other page request (see “Hosting”, deleted after 14 days at the latest). If you come through the referral link of a ClickBank partner, ClickBank attributes the commission through its own redirect and its own cookies on ClickBank's pages; we do not embed any ClickBank script on our pages for this. The transfer to the USA takes place on the basis of the EU-US Data Privacy Framework, under which Click Sales, Inc. is certified.

OpenAI (AI generation)

To create the images and copy, the product photos and product details you upload are transmitted to OpenAI (OpenAI, L.L.C., USA — transfer on the basis of the EU-US Data Privacy Framework or standard contractual clauses). Under OpenAI's API policies, content submitted through the programming interface (API) is not used to train the AI models. Even so, please do not upload photos showing people or third-party protected content unless you hold the rights to do so.

EvoLink (product video, beta)

If you create a product video, a photo of your product is transmitted as the starting frame — depending on the method, along with the scene images generated for your video — to the video service EvoLink for animation (EVO GLOBAL TECHNOLOGIES LIMITED, Flat 2304, 23/F Ho King Commercial Centre, 2-16 Fa Yuen Street, Mong Kok, Hong Kong — transfer to a third country without an adequacy decision on the basis of the EU standard contractual clauses). For this, the relevant image is made available briefly (no longer than 20 minutes) at an unguessable address on our server so that EvoLink can fetch it; no account data are transferred. According to the provider, the generated clips remain available at EvoLink for 24 hours. The legal basis is the performance of the video you commissioned (Art. 6(1)(b) GDPR). The director's prompt for the video and, depending on the method, the script, scene images and quality check are produced by OpenAI (see above).

ScraperAPI (retrieving public Amazon pages)

We retrieve publicly visible Amazon pages through the service ScraperAPI (ScraperAPI, USA). This happens during the listing check (with and without an account, including when reloading the data and when re-checking a reworked listing), when you use an ASIN or an Amazon link in the listing generator (for example as a reference ASIN) or in the product video, when loading the photos of colour variants, when comparing with the top results of an Amazon search for a search term, and for the analyses behind our email outreach to sellers (section 7). Only the ASIN, the marketplace or Amazon domain, a search term formed from the product data in the case of a search, and the addresses of the retrieved Amazon pages (product page, offer list, seller page) are transmitted. The requests are made from our server; your IP address and your account data are not transmitted to ScraperAPI. The transfer to the USA takes place on the basis of the EU standard contractual clauses. Where the function includes an AI assessment, the retrieved product data (including title, bullet points, images, description) are then passed on to OpenAI (see above). The legal basis is the performance of the function you requested (Art. 6(1)(b) GDPR) or — when used without an account and for seller outreach — our legitimate interest in providing these functions (Art. 6(1)(f) GDPR).

Hosting

The service is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in a data centre in Nuremberg (Germany). When the pages are opened, the server automatically processes what are known as server log files: IP address, date and time of access, the page/file requested, the volume of data transferred as well as the browser and operating system used. This serves secure, stable operation and the prevention of attacks (legal basis: legitimate interest, Art. 6(1)(f) GDPR). The log files are deleted automatically after 14 days at the latest. A data processing agreement (DPA) is in place with Hetzner.

Also exclusively on this server, we determine the country of origin from your IP address when the homepage is opened — using a locally stored country database (GeoLite2 by MaxMind). Your IP address is not transmitted to anyone for this and is not stored beyond the server log files mentioned above; the result serves solely to redirect visitors outside Germany, Austria and Switzerland to the English version of the homepage (/en/). A language choice made with the DE | EN switch always takes precedence (section 8). The legal basis is our legitimate interest in showing you the site in a language you understand (Art. 6(1)(f) GDPR). This website includes GeoLite2 data created by MaxMind, available from www.maxmind.com.

Brevo (email delivery)

For our optional newsletter we use Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany). You only receive the newsletter if you have expressly signed up for it — by ticking the box during registration or using the switch in your profile (legal basis: consent, Art. 6(1)(a) GDPR; the time of your sign-up is logged). For this we transmit your email address, your display name and your language setting to Brevo. To improve our newsletters, we evaluate whether emails are opened and links are clicked. You can unsubscribe at any time — using the unsubscribe link in every email or the switch in your profile; your data are then removed from the distribution list. You can therefore withdraw your consent at any time with effect for the future. A data processing agreement (DPA) is in place with Brevo. More at brevo.com/legal/privacypolicy.

We also send service- and contract-related emails through Brevo, for example replies to your support and enterprise enquiries (including acknowledgements of receipt) and notifications about the partner programme. The legal basis for this is the performance of the contract or our legitimate interest in communicating with you (Art. 6(1)(b) or (f) GDPR); separate consent is not required for this. Our emails to Amazon sellers and creators are also sent through Brevo (section 7).

Google Ads conversion measurement (consent mode)

We use the Google Ads tag of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) in order to measure whether visitors who come to us through a Google ad subsequently register. In doing so we use Google Consent Mode v2; the extent of the processing depends on your choice in the cookie banner:

The data may also be transferred to servers in the USA (transfer on the basis of the EU-US Data Privacy Framework). You can change your selection at any time: reset cookie selection — the banner then appears again. More in Google's privacy policy.

Google Analytics 4 (consent mode)

We also use Google Analytics 4, a web analytics service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), in order to understand how our pages are used — for example which pages are opened and at which point visitors abandon the registration or purchase process. Google Consent Mode v2 applies here too; the extent of the processing depends on your choice in the cookie banner:

Here too the data may be transferred to servers in the USA (EU-US Data Privacy Framework). More in Google's privacy policy.

TikTok pixel

We also use the TikTok pixel of TikTok Technology Limited (10 Earlsfort Terrace, Dublin 2, Ireland) in order to measure whether our advertising on TikTok works and to be able to reach visitors of our website there later with relevant ads (retargeting). Unlike the Google services, there is no cookieless variant here: the TikTok pixel is only loaded if you choose “accept all” in the cookie banner — without your consent, TikTok is not contacted from our site at all. With consent, TikTok sets cookies and records your page views as well as events such as a completed registration or a purchase. The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG), which you can withdraw at any time with effect for the future (reset cookie selection). The data may also be transferred to servers outside the EU (including the USA; transfer on the basis of the EU-US Data Privacy Framework or standard contractual clauses). More in TikTok's privacy policy.

Meta pixel

We use the Meta pixel of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) in order to measure whether our advertising on Facebook and Instagram works and to be able to reach visitors of our website there later with relevant ads (retargeting). As with the TikTok pixel, there is no cookieless variant here: the Meta pixel is only loaded if you choose “accept all” in the cookie banner — without your consent, Meta is not contacted from our site at all. With consent, Meta sets cookies and records your page views as well as events such as a completed registration or a purchase (for a purchase, also the amount). Meta also processes this data for its own purposes; in that respect we and Meta are joint controllers (Art. 26 GDPR), with the details set out in Meta's controller addendum. The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG), which you can withdraw at any time with effect for the future (reset cookie selection). The data may also be transferred to servers outside the EU (including the USA; transfer on the basis of the EU-US Data Privacy Framework or standard contractual clauses). More in Meta's privacy policy.

Anonymous usage statistics

To improve our offering, we count page views and a small number of feature events (for example “registration completed”) in anonymous form: without cookies, without storing IP addresses and without user-related identifiers — we assign neither a user nor a device identifier for these statistics. For each event we record only the time, the type of event, the page opened, the language setting, the rough device category (mobile or desktop — derived from the browser identifier, which is itself not stored) and the origin details described below. It is therefore not possible to draw conclusions about individual persons or to combine the data into a user profile (legal basis: legitimate interest in improving our offering, Art. 6(1)(f) GDPR).

We also determine how many different visitors open our pages on a given day. For this, an irreversible check value is formed from the IP address, the browser identifier and a random value newly generated each day; it exists only in memory and is discarded when the day changes. Only the total per day is stored — neither the check value nor the IP address. Recognition beyond that day is therefore technically impossible (legal basis as above: Art. 6(1)(f) GDPR).

For each of these events we additionally count how the visit reached us:

This information describes the route to the page, not the person: it contains no features identifying you and is not assigned to any user account. Whether it is remembered in your browser beyond the individual visit depends solely on your consent (section 8).

5. Partner programme and payouts

If you take part in our voluntary referral and partner programme, we process the data required to run it: your personal referral code, the qualified referrals attributed to you, and the resulting credits and commissions. Referred customers are only shown to you in aggregated form; we do not disclose personal data of referred customers to you.

So that you can judge how your links perform, we also count how often your referral links are opened. Only the referral code, the day and the number of views are recorded — on request separated by a campaign label you assign in the link (for example “youtube”), which names the channel, not the person opening it. Details about the person clicking — IP address, browser identifier or other identifiers — are neither transmitted nor stored for this count; it is therefore not possible to draw conclusions about individual visitors (legal basis: performance of the participation agreement with the referrer, Art. 6(1)(b) GDPR).

If you request a cash payout, we additionally process the payout and tax details you have provided — depending on the method chosen, your IBAN or PayPal address, the name of the account holder, your tax status (private individual, small business under section 19 of the German VAT Act, or standard taxation) and, where applicable, your VAT identification number. We use this information exclusively to process the payout (SEPA transfer or PayPal) and to create the tax statement under the self-billing procedure. The legal basis is the performance of the participation agreement (Art. 6(1)(b) GDPR) and the fulfilment of our obligations under tax and commercial law (point (c)). The terms of participation for the referral programme apply in addition.

6. Listimo Academy and certificates

You can use parts of our free training (“Listimo Academy”) entirely without an account; in that case we process no data other than for any other page visit (sections 4 and 8). If you use the Academy with your free account, we store your progress: your quiz results per lesson (lesson, score, time) as well as passed final exams per learning track (track, score, certificate code, time). The purpose is to show you your progress across devices, to provide your certificate and to ensure the one-off credit award per track. Storage is with our database provider Supabase (section 4); the legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

Certificate with public verification: if you pass the final quiz of a track (at least 80 %), we create a certificate with an individual verification code. At listimo.ai/academy/zertifikat/ anyone you give this code to (for example a client) can check that it is genuine — the track, the date it was passed and your display name are shown (your user name; if you have not set one, the part of your email address before the @ — you can control this yourself at any time by setting a user name in your profile). Without the code no retrieval is possible; only pass the code on if you want it to be displayed. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). When your account is deleted, progress and completions are deleted; your certificate can then no longer be retrieved.

7. Email outreach to Amazon sellers and creators

We contact individual Amazon sellers as well as creators (for example YouTube or TikTok channels about selling on Amazon) by email in order to introduce them to Listimo or to our partner programme. This section is addressed to the people we contact: where we got the information, what we do with it and how you can object.

Sellers — origin of the data: the starting point is publicly available information on Amazon: product data of an offer (ASIN, brand, category, title, images, review counts) as well as the name, seller identifier and country of the seller, which we partly compile with the market-data tool Helium 10. The contact details — email address, business name and, where applicable, phone number — are read from the public seller page on amazon.de (seller information or legal notice), retrieved through ScraperAPI (section 4); in individual cases we enter them by hand. In order to check whether a brand sells its own offer, we also record the names of the other sellers of that offer.

Sellers — what we store and send: for every seller contacted we store the information mentioned, an automated analysis of the public listing, the text of the email, the date, subject and recipient address of each send, the processing status (for example “contacted” or “declined”) and, where applicable, a personal form of address. The text of the email is drafted by OpenAI's AI (section 4); for this we transmit the brand, company, product title, ASIN, category, analysis values and the form of address, which may contain a name. The email contains an image card with the analysis and a personal link to the full assessment, valid for 30 days; it is sent through Brevo (section 4). If an account is created through that link, we note this in the seller record. If the email goes unclicked, a single reminder may follow after a few days.

Creators — origin of the data and sending: we use publicly available channel information (name, channel name, platform, channel address, subscriber, video and view counts, main topic) and the publicly stated contact or collaboration address from the channel description or the legal notice. We store our assessment of whether the channel is a fit for Listimo, the processing status and, per email, the date, address and subject. These emails are sent from a fixed template through Brevo; we do not use AI for them.

Open and click measurement: we evaluate whether our emails are opened and links are clicked. For emails to sellers, an email counts as opened when the embedded image card is loaded from our server, and as clicked when the assessment is opened through the personal link. Emails to creators contain an invisible counting pixel (an image file at listimo.ai/p/…) and a click link (listimo.ai/k/…) that redirects to our website. In each case only the number of retrievals and the time of the first and the last retrieval are stored — no IP address and no browser identifier (apart from the short-lived server log files, see section 4, Hosting). Some email programs load images automatically and security filters open links in advance; the figures are therefore only a rough indication. If your email program does not load images automatically, no open measurement takes place.

Legal basis and objection: we process these data on the basis of our legitimate interest in introducing Listimo to business users and initiating collaborations (Art. 6(1)(f) GDPR). You can object to this processing at any time without giving reasons (Art. 21 GDPR) — using the unsubscribe link in our email, by replying to the email, or informally to support@listimo.ai. After an objection we add your email address (on request your entire domain as well) to a block list that is checked before every send; seller records are additionally set to “declined”.

Retention: no automatic deletion period is currently set for this information. We keep it for as long as it is needed for outreach and for traceability of our contacts, and delete it on request. We keep the block list entry (email address or domain, reason and date) even after that, because it is the only way we can make sure not to contact you again.

8. Cookies & local storage

We use technically necessary cookies and local browser storage (localStorage) for your login session, for settings such as dismissed notices and for your local learning comfort in the Listimo Academy (unlocked chapters and checklist ticks, values “ak-kap:…” and “ak-cl:…” — they stay in your browser and are not transmitted to us) — all of this is required for the function you are using (section 25(2) TDDDG) and does not require consent. Also without consent, we record your decision from the cookie banner itself (value “consent_marketing” with the content “ja” or “nein”) — only in this way can we respect your choice on every further visit instead of asking you again. In the same way we record your choice in the DE | EN language switch in the cookie “siteLang” (content “de” or “en”, lifetime one year): the site then appears in your language on your next visit, and the language routing by country of origin (section 4, Hosting) does not override your choice.

If you use the free listing check without an account, your browser generates a random device identifier once and stores it locally (localStorage value “listimoGeraet”); it also remembers the time of your last free analysis (“lst_free_check”). The device identifier is transmitted to our server during an analysis so that the free analysis can be limited to one per device and day — even where several devices share an IP address, for example in an office or on a mobile network. It contains no information about your person and is required for this function you are using (section 25(2) TDDDG); the legal basis for the processing is our legitimate interest in a fair limitation of the free offering (Art. 6(1)(f) GDPR). You can remove both values by clearing the website data in your browser.

Only with your consent to advertising measurement, up to three further local values are added which record your origin: “lst_k” (the code of the campaign through which you came to us), “lst_q” (the origin channel, for example “ads” or “direkt”) and “lst_m” (the medium, for example “cpc”). They serve solely to attribute a later registration to the channel through which you found us (section 4) and expire automatically 30 days after the visit during which they were created. Without your consent they are not stored; the origin is then only evaluated within the individual page request.

We only set advertising and analytics cookies (Google Ads, Google Analytics 4, the TikTok pixel and the Meta pixel, see section 4) if you expressly agree in the cookie banner; without agreement the Google services work exclusively without cookies and without identifiers that identify you (consent mode, section 4), and the TikTok pixel and the Meta pixel are not loaded at all. You can change your agreement at any time: reset cookie selection. We do not currently use any other analytics or advertising services.

On the pages about the seller pack and the Digistore24 partner programme, the Digistore24 script embedded there (section 4) stores a partner identifier in your browser (cookie “ds24c.v1”) if you came through the link of a Digistore24 partner. It contains no information about your person, only the identifier of the referring partner, and serves solely to attribute commission on a purchase through Digistore24 (legitimate interest, Art. 6(1)(f) GDPR). Digistore24 determines the lifetime; more at digistore24.com/page/privacy.

The same applies to our own referral programme (section 5): if you open our pages through the referral link of a Listimo user (address with “?ref=…”), we store the referral code it contains in your browser for 30 days (cookie and localStorage value “lst_ref”). It contains no information about your person, only the referrer's code, and serves solely to attribute a later registration to the referrer and to grant you any benefits from the referral (for example a discount) (legitimate interest or steps prior to a contract, Art. 6(1)(f)/(b) GDPR). In addition, your browser remembers only for the duration of the session that opening the link has already been counted (sessionStorage value “lst_ref_klick”) — so that reloading the page is not counted twice in the anonymous click count in section 5; this value expires when the browser is closed.

9. Retention periods

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object on grounds relating to your particular situation; you can object at any time and without giving reasons to processing for direct marketing purposes — such as our email outreach (section 7) — (Art. 21(2) and (3) GDPR). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). Simply contact support@listimo.ai or open a support ticket. You also have the right to lodge a complaint with a data protection supervisory authority.

11. No automated decision-making

Automated decision-making producing legal effects concerning you within the meaning of Art. 22 GDPR does not take place. The AI used merely generates the images and copy you request; it does not take decisions about you as a person.

12. Obligation to provide data

Providing an email address and password is required in order to create an account; without them the service cannot be used. All further details are voluntary.

Last updated: 20 September 2026 · English version added 16 September 2026

This English text is a translation provided for convenience. In case of any discrepancy, the German version at listimo.ai/datenschutz.html is the authoritative one.