Controller
StartupBench is a product operated by Marco Herz, trading as StartupBench, Siegfriedstr. 7, 80803 München, Germany. Privacy requests can be sent to support@startupbench.app.
Data processed
Depending on how the service is used, StartupBench processes:
- the URL or domain submitted for scoring;
- publicly accessible page text, metadata, links, headings, calls to action, logos, screenshots, and other observable website signals;
- research sources, AI judgments, criterion scores, summaries, confidence values, timestamps, and method versions;
- a salted one-way hash derived from the requesting IP address for abuse prevention, rather than the raw address in the application database;
- technical request, hosting, and security logs held by infrastructure providers;
- Stripe checkout, payment-status, amount, currency, payment-intent, and webhook identifiers for optional listings. StartupBench does not receive or store full payment-card details.
Purposes and legal bases
Where the GDPR applies, data is processed to:
- provide a requested score, share page, listing, or ranking update under Article 6(1)(b) GDPR;
- cache results, prevent duplicate AI runs, enforce rate limits, secure the service, investigate errors, and maintain a consistent benchmark under Article 6(1)(f) GDPR;
- process payments, refunds, accounting records, and legally required documentation under Article 6(1)(b) and (c) GDPR;
- respond to support, correction, privacy, removal, and security requests under the applicable contractual, legitimate-interest, or legal-obligation basis.
Public scores and website operators
Every completed score is public and may appear in recent activity. Score pages contain a domain, startup name, logo, public-site link, numeric scores and criterion ratings. Detailed analysis is stored separately and is accessible only with the purchased domain access key; it is not included in public result responses or share images. A paid listing makes an eligible score visible on the global board but does not alter its value or rank. Fetching a submitted page also sends a normal web request to its operator, which may process request information under its own privacy notice.
Providers and international transfers
StartupBench uses Vercel for hosting, Supabase for the EU-region database and public activity queries, OpenAI for requested AI scoring, Stripe for hosted checkout and payment confirmation, ScrapeBadger for public-page retrieval, rendering and search-result research, Thum.io for website screenshots, and Google's favicon service as a fallback for public website icons. These providers process data under their own terms, privacy notices, and applicable data-processing agreements. Some processing may occur outside the EEA using an adequacy decision, standard contractual clauses, or another lawful transfer mechanism.
AI processing
Public website evidence and relevant public research context are sent to OpenAI through a server-side API request. The application requests non-persistent Responses API processing with store: false. Provider-side abuse monitoring and retention remain governed by the active OpenAI account configuration and API terms. Scores can be incomplete, inaccurate, or biased and are not used for legally significant decisions about individuals.
Cookies and browser storage
To let you return to an evaluation, your browser remembers recent run links and their last-known progress for up to 24 hours. The current status is saved server-side and accessed through the run link. This storage is not used for advertising. Clearing it does not delete completed public reports.
StartupBench does not currently use advertising or non-essential analytics cookies. Necessary network, security, and payment technologies may be used to deliver the page, refresh activity, and open Stripe's hosted checkout. Stripe applies its own storage and cookie practices on its domain. If non-essential analytics or advertising is introduced, this policy and any required consent mechanism will be updated before use.
Starting an initial listing checkout saves a necessary, HttpOnly management cookie for that domain in the purchaser’s browser, for up to 400 days. Its one-way hash is stored server-side. This capability authorizes detailed analysis access and later listing updates; deleting it removes browser access until restored with a saved backup key or through support after purchase verification. You may download the key to a private file for recovery. It is not used for advertising or tracking.
Retention
Public scores and their reproducibility records may remain stored while the benchmark is operated or until a justified correction or removal request is completed. Domain cache and lease data is kept for service reliability. Progress links expire after 24 hours; expired operational records are removed during subsequent scoring activity. Security and request records are retained only as long as reasonably necessary for abuse prevention and troubleshooting. Payment and accounting records are retained for applicable statutory, fraud-prevention, dispute, and tax periods. Backups may retain deleted data for a limited recovery cycle.
Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, and information about recipients; object to legitimate-interest processing; and withdraw consent where processing relies on consent. Requests should include enough information to identify the relevant score or request. A complaint may also be made to the competent data-protection authority.
Children, sensitive data, and changes
The service is not directed to children. Do not submit private areas, credentials, special-category data, or confidential third-party material. This policy will be updated when the product, providers, purposes, or legal requirements materially change.