Privacy Policy
Last updated: August 2026
LaunchAmp is a very small, clearly defined service, and this privacy policy is correspondingly short. We use no tracking, no advertising networks, no analytics services and no social media plugins. Public pages of launchamp.eu load no content whatsoever from third-party servers — no fonts and no JavaScript libraries from a CDN either. Your IP address is therefore not transmitted to anyone outside our hosting provider when you visit this website.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the operation of this website and of the LaunchAmp service is:
Christopher RichterKirchweg 7a
21244 Buchholz
Germany
Email: hello@launchamp.eu
We have not appointed a data protection officer; the statutory conditions of Section 38 BDSG (German Federal Data Protection Act) are not met. For all data protection enquiries, please use the email address above.
2. What LaunchAmp does
LaunchAmp helps with Product Hunt launches, and does three separate things which are described separately throughout this document because they process different data:
- Advice before a launch — a paid written assessment of a launch you are planning (clause 10). This is the only part where you send us text of your own.
- Board comparison after a launch — free since 26 September 2026, in exchange for a confirmed email address; until then a one-time paid unlock. We store the Product Hunt address you enter and the figures publicly reported for that launch. What happens to the email address is set out under “Launch-data email” below. Records of the earlier paid unlocks are kept for as long as tax law requires us to keep the receipt.
- Data access — a subscription (29 € per month) to the launch days we have measured. This concerns no personal data of yours beyond your account: the figures are our own counts of publicly visible launch days. We store which account holds access, until when it is paid for, and how often data was exported.
- Free analysis and measurements — the tools at /launch-check, /launch-stats and /launch-platforms, which need no account and are described in clauses 8 and 9.
Understanding this scope explains everything else in this document: we need an account in order to assign purchased content to you, a payment process in order to collect the price, and access to the public Product Hunt interface in order to fetch the figures shown. Nothing more happens.
3. Hosting and email delivery
This website, the database and the email mailbox are operated at:
STRATO AGOtto-Ostrowski-Strasse 7
10249 Berlin
Germany
The servers are located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with STRATO AG. Emails sent by LaunchAmp (e.g. replies to support enquiries) are routed via the STRATO mail server smtp.strato.de and therefore likewise via German infrastructure.
As with any web server, our hosting provider records technical access data in server log files when a page is retrieved, including the IP address. These log files are created and administered by STRATO AG; we do not evaluate them and do not combine them with other data. The scope and retention period of these host-side logs are governed by STRATO AG's own information.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and functional operation of the website).
4. Data we store ourselves
4.1 Account data
- Email address — to identify your account, for signing in and for messages concerning the purchase.
-
Password only as a hash — stored using bcrypt (PHP
password_hash()). The plaintext password is never stored at any point and is not known to us. - Username — generated automatically from the part of your email address before the @ sign plus a random number. You do not enter it yourself.
- Time the account was created.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures).
4.2 Resetting your password
If you use "Forgot password?" on the sign-in page, we generate a one-time link and email it to the address stored for your account. For this we store, for that link: a cryptographic hash of the token, the account it belongs to, its expiry time and the time it was used.
The token itself — the part in the emailed link — is not stored, only its hash. Anyone reading our database therefore cannot use it to take over an account. The link expires after one hour and works exactly once. Requesting a new one immediately invalidates any earlier link.
The page answers identically whether or not an account exists for the address you enter. This is deliberate: otherwise the form could be used to find out which people hold an account with us.
These records are deleted together with your account (see clause 15).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract — restoring access to your account) and Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the sign-in process).
4.3 Data from earlier sign-ins with Google
Signing in with Google is no longer offered. There is no Google button on our sign-in or registration pages, no redirect to Google takes place, and no data is transmitted to Google at any point — no Google scripts, fonts or tracking pixels are embedded on our pages.
While the option existed, accounts created through it received two pieces of data from Google: the email address and the unique Google account identifier (the so-called sub). Where such an account still exists, we continue to store both. We never stored further profile data such as name or profile picture.
That identifier is now dormant: it is not used for signing in and is not passed on to anyone. It is erased together with the account — either when you delete the account yourself in your dashboard under "Account", or on request to hello@launchamp.eu.
If your account was created this way and you have no password, you can still reach it: use "Forgot password?" on the sign-in page. We will email you a link that lets you set a password for the account.
Legal basis for continuing to store this data: Art. 6(1)(b) GDPR (performance of a contract — it identifies the account). The transfer to Google that took place at the time was based on Art. 6(1)(a) GDPR (consent by clicking the sign-in button) in conjunction with Art. 49(1)(a) GDPR; the provider was Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy: policies.google.com/privacy.
4.4 Launch data
For every launch you create, we store the details you enter or that follow directly from them:
- the Product Hunt URL of your launch that you entered,
- the product name and tagline of the launch,
- an internal short identifier derived from it (slug),
- the contact email address of the launch,
- the address of your own website, if you enter one in the dashboard — it is used solely as the link target behind your product name in the "Recently Featured" list on our homepage, and can be removed there again at any time,
- the public metrics retrieved from Product Hunt: upvote count, aggregated rating and up to three public comments (see clause 6),
- the payment status, the time of purchase and the time of the last update via the Product Hunt interface.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
5. Payment processing via Stripe
For all paid services we use the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When making a purchase you are redirected to a payment page operated by Stripe. You enter your payment details exclusively there. Card numbers, bank details or other payment method data are never transmitted to LaunchAmp and are consequently not stored by us.
In order to create the payment, we transmit to Stripe:
- your email address (as the buyer identifier in the payment process),
- the name of the product and the amount paid,
- internal identifiers for assigning the payment to your launch (the internal launch number, your user number and the slug of the launch).
From Stripe we receive back only the confirmation that the payment was successful. In our database, this confirmation sets the payment status of the launch concerned to "paid" and records the time of purchase. We do not store a Stripe customer number or payment ID.
Stripe belongs to a group of companies headquartered in the USA (Stripe, Inc.), so a transfer to a third country may take place. Stripe bases this transfer on the European Commission's standard contractual clauses and is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the third-country transfer, Art. 46(2)(c) GDPR (standard contractual clauses). Stripe's privacy policy: stripe.com/privacy.
Invoices and payment records are kept at Stripe and retained there in accordance with commercial and tax law retention periods.
6. Retrieval of public data from Product Hunt
So that we can count launch days and look up an individual launch rather than estimate it, LaunchAmp retrieves data via Product Hunt's official GraphQL interface. Important for understanding this:
- This query originates from our server and uses our own developer token. Your visitors' browsers never contact Product Hunt themselves. No website visitor's IP address is therefore transmitted to Product Hunt.
- Only the launch whose Product Hunt URL you yourself provided is queried — never anyone else's data.
- What is retrieved and cached in your record: the upvote count, the aggregated rating and up to three public comments on your launch, each consisting of the publicly displayed name of the commenting person, the comment text and the creation date.
- Retrieval happens at most once per hour per launch.
The comments are content which the persons concerned have themselves published publicly on Product Hunt. We cache them in order to display them in the same form in which they are publicly visible on Product Hunt.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in accurately presenting publicly available responses to a launch; no non-public data is processed). If, as a commenting person, you do not wish your comment to be displayed via LaunchAmp, an informal message to hello@launchamp.eu is sufficient — we will then remove it from the cache.
7. Prospect list for approaching new customers
For our own customer acquisition we maintain an internal list of recent Product Hunt releases. It stores exclusively publicly available information that Product Hunt's official interface provides about a published product: product name, tagline, Product Hunt URL, the product's own website, the publicly displayed name of the maker, the maker's public Product Hunt profile URL, the maker's public X (Twitter) username, the upvote count and the time of retrieval. No email addresses are collected — Product Hunt's interface deliberately does not expose any, and we do not invent any. This list is visible only to the operator and is not published, not sold and not passed on to third parties.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in approaching potential business customers in a B2B context on the basis of publicly accessible information). You may object to this storage at any time under Art. 21 GDPR; we will then delete the entry concerned without undue delay. An informal message to hello@launchamp.eu is sufficient.
8. Reach measurement without personal reference
We count how often our public pages are called up. This is deliberately built so that no personal data arises. Exactly one row is stored per page view, containing:
| What is stored | Example |
|---|---|
| the path called up, without the query string | /pricing.php |
| only the host of the referring page, not the full referrer URL | google.com |
| a coarse device category, not the user agent | mobile or desktop |
| the time | 2026-08-12 09:14:22 |
What is expressly not stored:
- the IP address — neither in full, nor truncated, nor as a hash. A hash of an IP address remains personal data, because the IPv4 address space is small enough to try out every possible value. We therefore do not store it at all.
- any visitor identifier, session identifier, fingerprint or other characteristic that could link several page views by the same person,
- the full user agent string,
- the full referrer URL (which could contain a search query),
- the query string of the page called up.
There is therefore no way to reconstruct from this data what a particular person did on this website. It is a pure page-view counter, not visitor analytics. No cookie is set for this measurement, and no information on your device is accessed in any other way either. Section 25 TDDDG (formerly TTDSG) therefore does not apply and no consent is required — which is why LaunchAmp shows no cookie banner.
Requests from recognisable search engine crawlers, preview bots and script clients are not stored in the first place.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in usage statistics), insofar as one would classify the stored information as personal data at all.
9. Free launch analysis (/launch-check)
On /launch-check you can enter the address of a Product Hunt launch and have it compared against the rest of its launch day. No account and no registration are required for this.
The launch itself is fetched from Product Hunt live for each enquiry, shown to you and then discarded. Its name, tagline, image and comments are not stored by us.
What we do keep is one row per launch that has been analysed at least once, containing:
| What is stored | Example |
|---|---|
| the Product Hunt address of the launch (the slug) | launchamp |
| the launch day | 2026-08-12 |
| the number of upvotes and the placement within that day | 128, #14 |
| how often this launch has been analysed, and when it was first and last analysed | 3, 2026-08-14 10:02 |
What is expressly not stored:
- no IP address — neither in full, nor truncated, nor as a hash (same reasoning as in clause 8),
- no user agent, no session and no visitor identifier of any kind,
- no email address and no other contact detail — the analysis asks you for nothing about yourself,
- no content from the Product Hunt page: no product name, no tagline, no image, no comments.
These entries therefore record which launch was looked at, never who looked at it. Two different people analysing the same launch produce one entry with two enquiries; they cannot be distinguished from one another.
Purpose: to see which launches our free tool is used for, and to be able to approach the operators of those products about our paid offering. The address of a launch is a publicly accessible product identifier, not information about you as a visitor. Where a product can nevertheless be attributed to a single natural person — a solo founder, for instance — you may object to this at any time and have the entry deleted; see clause 16.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the evaluation and further development of our own free offering and in direct advertising, Recital 47).
9a. Launch-data email (signing up on the free check)
Under the result of the free launch check you can enter an email address. Doing so does two things: it opens up the board comparison for the launch you looked up, and it puts the address on our launch-data mailing list. What you are signing up for: One email a month: what it actually took to get featured that month — on Product Hunt and on the other boards we measure — plus the occasional note about what we build here.
Double opt-in. Entering an address is not yet a subscription. We send one confirmation email to it and nothing else. Only when the link in that email is clicked does the address go on the list. If the link is never clicked, the entry stays dormant and is never written to again — which is also what protects you if somebody else types your address into the form.
What we store: the email address, the wording you agreed to, the launch you were looking at, the times of the entry and of the confirmation, and the IP addresses at those two moments.
The two IP addresses are the one place on this website where we store an IP at all — reach measurement deliberately does not (see clause 8). They are kept for a single purpose: we have to be able to prove that a subscription was actually confirmed and by whom, otherwise every mailing we send is open to challenge. They are not used for statistics, are not combined with anything else, and are not displayed anywhere in our administration.
Unsubscribing takes one click on the link at the foot of every one of these emails, with no login and no reason given. The entry is then marked as unsubscribed rather than deleted — that marking is how we make sure the address does not end up back on the list later. If you would rather have it erased completely, ask us and it will be; see clause 16.
Legal basis: Art. 6(1)(a) GDPR (consent), § 7(2) no. 2 UWG. Consent can be withdrawn at any time with effect for the future; the withdrawal does not affect the lawfulness of anything sent before it.
10. Launch Kit requests (/launch-kit)
On /launch-kit you can request a paid written assessment of a Product Hunt launch you are planning. This is the one place on this website where you send us free text about yourself and your product, so it is described separately from everything above.
What is stored when you submit the form:
| What is stored | Why |
|---|---|
| your email address | to reply to you at all, and to send you the review |
| what you are launching (a link, or your own description) | it is the subject of the assessment |
| your intended launch date | to judge that date, and to tell you if we cannot make it in time |
| your own statement about the audience you can reach | the largest factor in how a launch goes, and the one nobody can look up for you |
| anything you write in the notes field | you decide what goes in it — the field is optional |
| the time of the request and its processing status | so a request cannot be lost or answered twice |
We store the entry before we send ourselves a notification about it. That is deliberate: a review has a deadline, and an email that fails to arrive must not be able to make your request disappear.
What is expressly not stored:
- no IP address, in any form, and no browser fingerprint,
- no account — a review request creates no user account and no password,
- no payment data. Nothing is charged until we confirm we can take the review on; if it comes to that, payment runs through Stripe as described in clause 5.
Purpose and use: your entry is used to write your review and to correspond with you about it. It is not added to any mailing list, not used for advertising other services, and not passed to anyone else.
Legal basis: Art. 6(1)(b) GDPR — pre-contractual measures taken at your request, and performance of the resulting contract. Retention: see clause 15.
11. Cookies
LaunchAmp uses exactly two cookies, neither for advertising nor analytics purposes:
-
Session cookie (
PHPSESSID) — technically necessary in order to recognise you after signing in and to protect forms against cross-site request forgery. It is set with the HttpOnly and SameSite=Lax flags, is transmitted exclusively via cookies (not via the URL) and additionally carries the Secure flag on the live website. It is deleted when you close your browser or sign out. -
Operator opt-out cookie (
la_notrack) — serves solely to ensure that the operator's own page views are not counted in the statistics described in clause 8. It can only be set from within the password-protected administration area, contains no personal information whatsoever and is never set in the browser of ordinary visitors.
No consent is required, as only strictly necessary cookies within the meaning of Section 25(2) no. 2 TDDDG are used.
12. No third-party services embedded on public pages
- Fonts, stylesheets and JavaScript libraries (including Tailwind CSS and Alpine.js) are served entirely from our own server. No content delivery network is embedded.
- There are no Google Fonts, no analytics tools, no advertising networks, no social media plugins, no tracking pixels and no embedded videos.
- Merely calling up a public page of launchamp.eu therefore creates not a single connection to a third-party server.
14. Recipients of data
- STRATO AG — hosting of the website, the database and the email mailbox (processor, servers in Germany).
- Stripe Payments Europe, Ltd. — payment processing (see clause 5).
- Google Ireland Limited — only if you actively use the sign-in with Google (see clause 4.3).
- Product Hunt, Inc. — receives only our server-side request for the public data of your launch; no data of your website visitors is transmitted (see clause 6).
Beyond this we do not pass on any data. We do not sell personal data and do not use it for automated decision-making or profiling.
15. Retention periods
- Account data: until the account is deleted. You can do this yourself at any time under "Account" in your dashboard, without asking us and without giving a reason. The deletion takes effect immediately and removes the account together with every launch it contains, including paid ones, and any password reset records (clause 4.2). It cannot be undone, and it does not trigger a refund — see the note on payment records below.
- Launch data: the launches you add to your account, and the figures publicly reported for them, are kept for as long as the account exists. You can delete your account yourself in the dashboard at any time; the launches belonging to it are deleted with it.
- Data access: which account holds access, until when it is paid for, whether it has been cancelled, and how often data was exported. Retained after the access has expired for as long as needed to answer questions about the payment, and deleted with the account.
- Payment records: are kept at Stripe and retained there in accordance with the statutory retention periods (up to 10 years, Section 147 AO, German Fiscal Code).
- Reach measurement rows: contain no personal data (see clause 8) and are retained permanently as pure counter values.
- Entries from the free launch analysis: until the purpose ceases to apply, at the latest 24 months after the last enquiry, or without undue delay following an objection (clause 9).
- Launch Kit requests (clause 10): deleted 12 months after the review was delivered or the request declined, and at any earlier point on request. Where a review was paid for, the payment record itself stays with Stripe under the statutory period above — but the free text you sent us is not part of that and goes with the rest.
- Prospect list entries: until the purpose ceases to apply, at the latest 24 months after retrieval, or without undue delay following an objection.
- Server log files of the hosting provider: according to STRATO AG's specifications.
16. Your rights
You have the following rights vis-à-vis us:
- right of access to the data stored about you (Art. 15 GDPR)
- right to rectification of inaccurate data (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing that we base on a legitimate interest (Art. 21 GDPR) — this concerns clauses 7 and 8 in particular
- right to withdraw a consent given, with effect for the future (Art. 7(3) GDPR)
An informal message to hello@launchamp.eu is sufficient to exercise these rights. We reply within the statutory period of one month.
You do not have to wait for us in order to exercise your right to erasure (Art. 17 GDPR): under "Account" in your dashboard you can delete your account and all launches in it yourself, taking effect immediately. The same section lets you change your password. What we cannot delete on request are the payment records held at Stripe, which are subject to the statutory retention periods stated in clause 15.
Independently of this, you have a right to lodge a complaint with a data protection supervisory authority. The authority responsible for our place of business is:
Die Landesbeauftragte für den Datenschutz Niedersachsen(State Commissioner for Data Protection of Lower Saxony)
Prinzenstrasse 5
30159 Hannover
Germany
17. Data security
- Transmission between your browser and our servers is encrypted via SSL/TLS.
- Passwords are stored exclusively as a bcrypt hash, never in plaintext.
- All database access uses prepared statements and is bound to the respective session.
- Forms in the administration area are protected against cross-site request forgery; payment notifications from Stripe are cryptographically signature-verified before they unlock a purchase.
- Operator accounts are completely separate from customer accounts and live in their own table.
18. Changes to this privacy policy
We adapt this policy when the scope of LaunchAmp's functionality or the legal requirements change. The current version is always available at launchamp.eu/legal/datenschutz. The version published at the time of your visit is the authoritative one.