Privacy policy
How Passionate Talents B.V. handles personal data for RightDoor: your account and billing data, the addresses customers send to the API, and visits to this website.
Last updated 8 October 2026.
1. Who we are
RightDoor is a product of Passionate Talents B.V., Graan voor Visch 19905, 2132 WR Hoofddorp, the Netherlands. KvK 92791360. VAT NL866173882B01. In this policy, "we" and "us" mean Passionate Talents B.V.
We are the controller for the personal data we collect to run RightDoor accounts, to bill customers and to run this website. For addresses that customers send to the API, the customer is the controller and we are its processor. The data processing agreement covers that role.
Privacy questions and requests: support@rightdoor.eu. We have not appointed a data protection officer; this address reaches the people who run RightDoor.
2. The short version
- Addresses sent to the API are compared with the official registers in memory and then forgotten. We never store them and never log them.
- We keep the account and billing data we need to run your account, and nothing more.
- No marketing emails, no advertising, no tracking pixels, no analytics on this website. We don't sell personal data.
- The API and the database run in the EU, in Frankfurt. Some service providers are US companies; section 10 explains how transfers are protected.
3. Addresses sent to the API
Our customers, mostly developers and web shops, send us their shoppers' shipping addresses to check them. An address line can contain a name or a company name. For this data the customer is the controller and we process it only on the customer's behalf, under the data processing agreement.
What happens to an address:
- It arrives over an encrypted connection (TLS) at our API in Frankfurt.
- We compare it with the Kadaster BAG and BeST Address registers, in memory.
- We send back the result and discard the address. It is never written to the database, to log files or to error reports.
Our logs hold only the route, the status code, the response time, the API key or account id and a request id. To detect bulk extraction, we count per customer and per day how many distinct postcodes were looked up. The postcodes stay in memory for that day only; we store only the count. We also keep counts per country of verdicts and issue codes, to spot broken imports. Those counts contain no customer or address data.
When a shop uses our address form, the shopper's browser calls our API directly, so we also receive the shopper's IP address. We use it only in memory, to limit how many requests one device can make, and forget it by the end of the day (UTC). It is never stored or logged.
The registers themselves are public open data. They list addresses and buildings, not the people who live there.
If you are a shopper and want to know what happened to your address, contact the shop you ordered from. We can't look up your address, because we don't keep it.
4. Account and billing data
When you create a RightDoor account in the dashboard at app.rightdoor.eu, we process the data below. The legal bases are explained in section 8.
| Data | Why | Legal basis |
|---|---|---|
| Name and email address | To create your account, sign you in and send you service emails. | Contract |
| Password hash, or the link to your GitHub account if you sign in with GitHub | To sign you in. We never store your password itself. | Contract |
| Two-factor secret (encrypted) and backup codes (hashed or encrypted) | To protect your account with two-factor authentication. | Contract; legitimate interest in security |
| Sessions, with IP address and browser (user agent) | To keep you signed in and to detect misuse of your account. | Contract; legitimate interest in security |
| Audit log of security and billing actions, with IP address and user agent | To protect your account, investigate incidents and show who changed what. | Legitimate interest in security and evidence |
| API keys: a hash, the last four characters and the name you gave the key | To check API requests. The full key is shown once and never stored. | Contract |
| Daily usage counts per endpoint, and the daily count of distinct postcodes | To count verifications, apply quotas, bill you and detect abuse. | Contract; legitimate interest in preventing abuse |
| Plan, billing state, Stripe customer and subscription ids | To run your subscription. | Contract |
| Invoices and billing records | To keep the accounts the law requires. | Legal obligation |
| Emails you send us | To answer your question or request. | Contract; legitimate interest |
Stripe holds your billing address, VAT ID and payment method. We store only the Stripe customer and subscription ids, and we see your billing details in Stripe when we need them, for example to answer a question about an invoice.
5. Visitors of this website
This website sets no cookies and has no analytics, trackers or third-party scripts. It remembers your light or dark theme choice in your browser's local storage (rd-theme). That choice stays in your browser and is never sent to us.
To deliver a page, our hosting provider receives your IP address and browser details, as every web server does. We don't use them to identify you or to build a profile.
7. Emails
We send only service emails: account confirmation, password reset, security notices, notices about your API keys, usage notices (for example at 80% and 100% of your included verifications) and billing notices. They are part of the service, so you can't turn them off while you have an account. We send no marketing emails. If we ever send product news, it will be only to people who opted in, with an unsubscribe link in every message.
8. Legal bases
- Contract (GDPR article 6(1)(b)): to provide the account and the service you signed up for.
- Legitimate interest (article 6(1)(f)): to keep the service and your account secure, to prevent abuse such as bulk extraction of the address data, and to answer questions. We keep this processing small: counts instead of contents, and no profiles. You can object, see section 13.
- Legal obligation (article 6(1)(c)): to keep invoices and billing records for the Dutch tax authorities.
9. Service providers
We use the service providers below. Each processes personal data only to provide its service to us, under a data processing agreement. Stripe also processes some payment data as an independent controller, for example to prevent fraud and to meet financial regulations, under its own privacy policy. GitHub does the same for your GitHub account.
| Provider | What it does | Personal data | Where |
|---|---|---|---|
| Prisma Compute and Prisma PostgresPrisma Data, Inc., Wilmington, Delaware, United States | Runs the API, the dashboard and this website, and hosts the database. | All account and billing data we hold. Addresses sent to the API, in memory only. | EU: Frankfurt, Germany (AWS eu-central-1). |
| StripeStripe Payments Europe, Limited, Ireland | Payments, subscriptions, invoices and tax calculation. | Name, email, billing address, VAT ID, payment method, plan, invoices, daily verification counts. | EU and United States. |
| ResendPlus Five Five, Inc., San Francisco, United States | Delivers our emails (account confirmation, password reset, security, key, usage and billing notices). | Email address, first name, email content, delivery status. | EU (Ireland). |
| PostHog (EU Cloud)PostHog, Inc., San Francisco, United States | Error tracking only. No analytics, no session recording. | Scrubbed error reports: error type and stack trace, route, status, request id, account id. No request bodies, query strings, headers, addresses or credentials. | EU: Frankfurt, Germany. |
| Better StackBetter Stack, Inc., United States | Uptime monitoring and the status page at status.rightdoor.eu. | No customer data. It checks our public health endpoints from outside. | EU and United States. |
| CloudflareCloudflare, Inc., San Francisco, United States | DNS for our domains, and the redirect from rightdoor.eu to www.rightdoor.eu. | Technical request data (IP address, browser details) of visitors who use the bare domain, for the redirect. No account data, no API requests. | Worldwide network. |
| Google WorkspaceGoogle Cloud EMEA Limited, Dublin, Ireland | Our company email, including support@rightdoor.eu and contact@rightdoor.eu. | Emails you send us and our replies. | EU and United States. |
| GitHubGitHub B.V., Amsterdam, the Netherlands, and GitHub, Inc., San Francisco, United States | Sign-in with GitHub, only if you choose it. | Your GitHub account id, name and email address, which GitHub sends us when you sign in. | EU and United States. |
In the API's request path, only Prisma handles the addresses customers send, in memory, in Frankfurt. We share personal data with authorities only when the law requires it, and with our accountant and legal advisers when they need it, under a duty of confidentiality. We don't sell personal data.
10. International transfers
We keep data in the EU where we can. The API and the database run in Frankfurt, and PostHog's EU Cloud stores error reports in Frankfurt. Several providers are US companies or also process data in the United States. For those transfers we rely on:
| Provider | Safeguard |
|---|---|
| Prisma Compute and Prisma Postgres | EU-US Data Privacy Framework (Prisma Data, Inc. is certified). |
| Stripe | EU-US Data Privacy Framework and EU Standard Contractual Clauses. |
| Resend | EU-US Data Privacy Framework and EU Standard Contractual Clauses. |
| PostHog (EU Cloud) | EU-US Data Privacy Framework and EU Standard Contractual Clauses, for any access from outside the EU. |
| Better Stack | EU-US Data Privacy Framework and EU Standard Contractual Clauses. |
| Cloudflare | EU-US Data Privacy Framework and EU Standard Contractual Clauses. |
| Google Workspace | EU-US Data Privacy Framework (Google LLC) and EU Standard Contractual Clauses. |
| GitHub | EU-US Data Privacy Framework and EU Standard Contractual Clauses. |
You can ask us for a copy of the safeguards that apply at support@rightdoor.eu.
11. How long we keep data
| Data | How long |
|---|---|
| Addresses sent to the API | Not kept. Discarded as soon as the response is sent. Postcodes for the daily distinct count stay in memory until the end of that day. |
| Account data | As long as your account exists. When you delete your account (Account page in the dashboard), we delete it at once; copies in our database backups are gone within 30 days. |
| Sessions and the audit log | 24 months. |
| Daily usage counts | As long as we need them for billing and to answer billing questions. After that we keep only totals that no longer point to an account. |
| Invoices and billing records | 7 years, as Dutch tax law requires. |
| Error reports | For PostHog's standard retention period, which we can't shorten. They contain no addresses or request contents. |
| Emails you send us | As long as we need them to help you, and at most 24 months after the conversation ends, unless they are billing records. |
12. How we protect data
- All traffic to the API, the dashboard and this website is encrypted with TLS. Browsers are told to use HTTPS only (HSTS).
- Passwords are stored as hashes. API keys are stored as a keyed hash (HMAC-SHA256 with a secret); the full key is shown once and never stored.
- Two-factor secrets are encrypted. Two-factor authentication is required before you create a live API key or change your plan.
- Hosting and the database are in the EU, in Frankfurt.
- Least data: addresses are never stored, logs hold no request contents, and error reports are scrubbed before they leave the service.
- Rate limits and abuse detection protect accounts and the service.
13. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have incorrect data corrected (rectification);
- have your data deleted (erasure);
- have our processing restricted;
- receive your data in a machine-readable format (portability);
- object to processing based on our legitimate interest.
You can do the two most common things yourself, on the Account page of the dashboard: download your data as a JSON file, and delete your account. For anything else, email support@rightdoor.eu, preferably from the email address of your account. We may ask you to confirm your identity first. We answer within one month, free of charge. Some data we must keep anyway, such as invoices.
For addresses sent to the API, the shop or developer that sent them is the controller. Ask them. We hold no copy, so there is nothing we could show, correct or delete.
14. Complaints
If you think we handle your data wrongly, tell us first at support@rightdoor.eu so we can fix it. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live or work.
15. No automated decisions about people
We make no automated decisions with legal or similarly significant effects about individuals, and we don't profile people. The API judges addresses against the registers and returns advice to our customer. The customer decides what to do with it.
16. Changes to this policy
We update this policy when the service or the law changes. The date at the top shows the latest version. If a change matters to account holders, we email them before it takes effect.
17. Contact
Passionate Talents B.V., Graan voor Visch 19905, 2132 WR Hoofddorp, the Netherlands. Privacy requests and security reports: support@rightdoor.eu. Anything else: contact@rightdoor.eu.
Passionate Talents B.V., Graan voor Visch 19905, 2132 WR Hoofddorp, the Netherlands. KvK 92791360 · VAT NL866173882B01. Questions: support@rightdoor.eu.