Legal

Privacy Policy

This page explains how StoryPointLab may process personal data when you use the website, create an account, collaborate in sessions, or work inside a team workspace.

Overview

StoryPointLab is a web application for agile planning, estimation, retrospectives, and checklist workflows.

This privacy policy explains what personal data may be processed when you use the website, create an account, join a team, or interact with shared sessions.

Controller

Christian Weiss

Paul-Heyse-Strasse 34

80336 Muenchen

Deutschland

E-Mail: christian.wc.weiss@gmail.com

Data processed when using StoryPointLab

When you create or use an account, your name, email address, authentication-related identifiers, and selected team or workspace context may be processed.

When you use collaborative tools, session data such as room IDs, participant display names, votes, cards, templates, checklists, saved scenarios, and team settings may be stored.

When you contact StoryPointLab directly, your contact details and message content may be processed to respond to your request.

Authentication and infrastructure

Email and password authentication may be handled through Supabase.

Application and collaboration data may be stored or processed through AWS services such as API Gateway, Lambda, DynamoDB, and SES.

These services are used to operate user accounts, team workspaces, invites, persistent settings, and shared tool sessions.

Cookies, local storage, analytics, and advertising

StoryPointLab may use cookies and local storage to keep sessions working, remember consent choices, and preserve product state such as the selected team.

If analytics are enabled after consent, usage information may be processed through Google Analytics.

If advertising is enabled, Google AdSense or related Google advertising services may process information needed to deliver and measure ads, including cookie-based signals where applicable.

You can decline optional analytics through the cookie controls made available in the app. Additional controls may be introduced if advertising cookies or personalized advertising features are enabled.

Purpose and legal basis

Data is processed to provide the website, enable accounts and team workspaces, operate collaborative sessions, respond to support requests, and maintain security and stability.

Where consent is required, processing is based on that consent. Other processing may be based on contract performance, legitimate interests, or legal obligations, depending on the context.

Sharing and retention

Data is shared only to the extent necessary with infrastructure and service providers involved in running StoryPointLab.

Data is retained only for as long as needed for the relevant feature, account relationship, legal obligation, or legitimate operational purpose.

Your rights

You may have rights of access, rectification, deletion, restriction, objection, and data portability, depending on the applicable law.

You may also have the right to withdraw consent at any time where processing is based on consent.

For privacy-related requests, please contact christian.wc.weiss@gmail.com.

Cookies for analytics

We only enable optional Google services like Analytics after consent. Core tool features stay available either way.