Privacy Policy

Last updated: July 13, 2026

1. Data controller

The controller of personal data of Users of the CommentTap service (available at commenttap.com, the "Service") is Michał Kołnierzak conducting business under the name "KOLM MICHAŁ KOŁNIERZAK", ul. Milenijna 43/2, 03-130 Warsaw, Poland, NIP 5361929091, REGON 367735680 (the "Controller", "Operator" or "we").

Contact for data protection matters: privacy@commenttap.com. General contact: hello@commenttap.com, support@commenttap.com.

We have not appointed a Data Protection Officer, as the conditions of Art. 37 GDPR do not apply.

2. Two roles of the Operator

CommentTap is a SaaS service and acts in two distinct roles:

  • Controller — for personal data of Users of the Service (account, billing, contact and technical login data). This Policy governs that processing.
  • Processor — for data of Contacts (Leads) that a User collects and processes through the Service while running their own campaigns. Here the User is the controller and we process such data only on the User's documented instructions, under the data processing agreement (DPA).

Requests from data subjects (e.g. Leads) regarding data collected by a User are directed to that User as controller; we forward them and assist the User.

3. What data we process (as controller)

As controller we process data of Users: account data (name, email, hashed password), billing data (company name, address, tax ID, payment history, Stripe identifiers), identifiers and access tokens of connected social accounts, technical data (IP address, logs, device/browser type, in-app events), support correspondence, and — where applicable — an email address for marketing.

Legal bases:

  • Providing and operating your account and the Service — Art. 6(1)(b) GDPR.
  • Billing, subscriptions, invoices and complaint handling — Art. 6(1)(b) and (c) GDPR (tax/accounting obligations).
  • Security, diagnostics, abuse prevention and analytics — Art. 6(1)(f) GDPR (legitimate interest).
  • Marketing communication — Art. 6(1)(a) GDPR (consent), where applicable.

4. Contact / Lead data (as processor)

Through the Service, a User may process data of people interacting with their profiles. Per the Service's data model this includes: platform identifiers (provider user id, username, display name), email address if provided, content of comments, story replies and messages, tags, notes, custom fields (lead fields), lead status, opt-out status and text, interaction timestamps, and delivery and link-click history. We process this data on behalf of the User under the DPA.

5. Sources of data

We obtain data: (a) directly from the User; (b) automatically during use of the Service (logs, cookies); (c) from social platforms via official APIs (Meta/Instagram), to the extent the User authorised when connecting an account.

6. Meta / Instagram integration

The Service uses official Meta (Instagram) APIs. We process only data necessary for the features the User has authorised (e.g. reading comments, sending messages in response to user-initiated interactions). For this we store access tokens for connected accounts (encrypted, with limited scopes). We use Meta platform data in accordance with the Meta Platform Terms and Developer Policies; we do not sell it or use it for purposes other than providing the Service.

You can disconnect an account at any time, which stops access to platform data. The Service also handles data deletion requests in line with Meta requirements (Data Deletion Request Callback). Status and instructions are available on the data deletion page.

7. Recipients and subprocessors

We entrust processing to trusted providers only to the extent necessary to run the Service:

  • Supabase — database, authentication, file storage — EU/EEA, Frankfurt (Germany).
  • Railway — application and API hosting — EU/EEA, EU West, Amsterdam (Netherlands).
  • Stripe — payments and subscriptions — EU + USA (see section 8).
  • inFakt — issuing and syncing accounting documents — Poland/EU.
  • Brevo — transactional and notification emails — EU/EEA.
  • Meta Platforms — Instagram/Facebook API integration — EU + USA (see section 8).
  • Sentry — error and performance monitoring (active when a DSN is configured) — EU + USA (see section 8).
  • Google (Google Analytics, Google Search Console) — traffic analytics and search-visibility measurement — EU + USA (see section 8).
  • Accounting office / advisor / law firm — Poland.

We provide the current subprocessor list on request. Data may also be disclosed to public authorities where required by law.

8. Transfers outside the EEA

Core infrastructure runs in the EU/EEA: database and file storage (Supabase) in Frankfurt (Germany); application and API hosting (Railway) in EU West, Amsterdam (Netherlands). Some subprocessors (Stripe, Meta, Google, Sentry) may also process data in the USA. Such transfers rely on safeguards compliant with Chapter V GDPR — in particular the Standard Contractual Clauses (SCC) and, where applicable, the EU-U.S. Data Privacy Framework (DPF). A copy of the safeguards is available at privacy@commenttap.com.

9. Data retention

  • Account and service data — for the term of the agreement and 30 days afterwards (export/recovery window), then deleted or anonymised.
  • Billing and accounting documents — for the period required by tax and accounting law, generally 5 years from the end of the calendar year in which the tax obligation arose.
  • Data processed based on consent (marketing) — until consent is withdrawn.
  • Technical and security logs — up to 12 months.
  • Backups — a rolling cycle of up to 30 days.
  • Contact/Lead data (as processor) — deleted within 30 days after the Service ends, or earlier at the User's request.

These periods are our current policy; automated enforcement (a retention job) is being implemented.

10. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal). We handle requests at privacy@commenttap.com. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.

If a request concerns data collected by a User in their campaigns (Leads), that User is the controller — we forward your request to them.

11. Automated decision-making

The Service uses campaign automation mechanisms (rules, triggers). We do not make automated decisions producing legal or similarly significant effects on Users within the meaning of Art. 22 GDPR.

12. Cookies and similar technologies

The Service uses cookies and similar technologies:

  • Essential — login, session, security and payment flow, e.g. the Supabase authentication session (`sb-*`), a CSRF token, and your saved cookie-consent choice. No consent required.
  • Analytics — traffic and usage measurement via Google Analytics (`_ga`, `_ga_*`); we use Google Search Console to monitor search visibility. Requires consent.
  • Functional / payments — payment provider (Stripe) cookies ensuring transaction security (`__stripe_mid`, `__stripe_sid`).
  • Marketing / remarketing — currently none; to be added if advertising pixels are introduced. Requires consent.

Cookie names may vary with provider versions. The Google Analytics script loads only after consent. For diagnostics we also use Sentry, which may process IP and technical data without cookies, based on legitimate interest. Consent for non-essential cookies is collected via a consent banner and can be withdrawn at any time.

13. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), access control, password hashing, backups, need-to-know access limits, and processing with providers offering an adequate level of security. Security reports: security@commenttap.com.

14. Changes to this Policy

We may update this Policy. We will inform Users of material changes electronically or in the Service in advance. The last-updated date is shown at the top.

15. Contact

Data protection matters: privacy@commenttap.com. Operator: KOLM MICHAŁ KOŁNIERZAK, ul. Milenijna 43/2, 03-130 Warsaw, NIP 5361929091.