Skip to main content

Privacy Policy

This Privacy Policy explains how Mepage ("we", "us", "our") collects, uses, and protects personal data when you use our website and services (the "Service"). It applies to both registered users and visitors who view a Mepage card or page. By using the Service, you agree to the practices described here.

1. Data Controller & Contact

Mepage is the data controller of your personal data within the meaning of Article 4(7) of the EU General Data Protection Regulation (GDPR) and a "business" under the California Consumer Privacy Act (CCPA).

To exercise any of the rights described below, or to ask questions about your data, contact us at privacy@mepage.cc. We respond to verified requests within 30 days (GDPR) / 45 days (CCPA).

2. Information We Collect

2.1 Account information

The name and email you provide when you sign up, plus any details you choose to add — bio, contact info, portfolio, experience, services, and so on. This data is required to provide the Service and is retained for as long as your account is active.

2.2 Booking guest data

When a visitor books a time slot with a Mepage user, we collect the name, email, optional phone number, and notes that the guest submits. This data is shared with the profile owner and is necessary to fulfill the booking.

2.3 Analytics data

When someone visits your card or page, we collect the following anonymous behavior data to power your analytics:

  • Page views
  • Time on page
  • Scroll depth (25% / 50% / 75% / 100%)
  • Button clicks (e.g., CTA buttons, social links)
  • Device type (mobile or desktop)
  • Referrer (e.g., direct, other sites)
  • Emoji reactions (chosen by the visitor)

This data is linked using a randomly generated anonymous identifier. It contains no personally identifiable information (such as IP address or browser fingerprint). The data is used solely to provide analytics to the card owner — it is never sold or used for advertising.

Visitors can reset this anonymous identifier by clearing site data in their browser.

2.4 Technical & security data

To protect the Service we temporarily process IP addresses for rate limiting, CSRF protection, and abuse prevention. IP addresses are not stored in analytics datasets; they may appear in short-lived security logs (see Section 7 on retention).

3. Legal Basis for Processing (GDPR Art. 6)

We process personal data only on the following legal bases:

  • Performance of a contract — providing your account, hosting your card, and processing bookings you send or receive.
  • Consent — loading non-essential analytics identifiers in your browser. You can withdraw consent at any time by clearing site data.
  • Legitimate interests — automated content moderation, rate limiting, and security logging to protect the Service and other users.
  • Legal obligation — retaining specific records where required by applicable law.

4. How We Use Information

The information we collect is used to: provide and maintain the Service, deliver booking and notification emails, generate aggregated analytics for card owners, prevent abuse and fraud, and respond to your support requests. We never sell your personal information to third parties.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for marketing purposes.

5. Third-Party Processors

We share limited personal data with the following subprocessors, each bound by written data processing agreements:

  • Neon — hosted PostgreSQL database storing account, profile, and booking records.
  • Cloudflare R2 — object storage for user-uploaded images (avatars, covers).
  • Resend — transactional email delivery for magic links, booking confirmations, and notifications.
  • Sentry — error and performance monitoring. Sentry receives sanitized error metadata only, never full user content.
  • Upstash — serverless Redis used for rate limiting and short-lived caches.

We do not transfer personal data to any third party for advertising or cross-site tracking.

6. International Data Transfers

Your data may be processed in regions other than your country of residence, including the United States (Neon, Resend, Sentry, Upstash) and the European Union (Cloudflare R2, depending on bucket location). Where data leaves the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by transfer impact assessments where required.

7. Data Retention

  • Account data — retained while your account is active; deleted within 30 days of account deletion.
  • Booking records — retained for 24 months after the slot date for audit and dispute resolution, then automatically purged.
  • Analytics data — retained on a rolling 13-month basis; older identifiers and events are automatically expired.
  • Moderation & security logs — retained for 90 days, then automatically deleted.
  • Email logs — retained for 30 days for delivery troubleshooting.

8. Content Moderation & Security Logging

To maintain platform safety, Mepage performs automated moderation on user-published text. The moderation runs server-side without human review of complete user content.

  • Content scanning: detects sensitive keywords in submitted text.
  • Moderation logs: record the moderation result (risk level, matched category) without storing complete content.
  • IP logging: moderation logs record the submitter's IP address at the time of submission, used only for security tracing.

Moderation logs are retained for 90 days and then automatically deleted.

9. Cookies & Local Storage

We use strictly necessary cookies to keep you signed in and to power basic security features (CSRF protection, session continuity). We use the browser's localStorage to maintain the anonymous visitor identifier and saved-card data. We do not use third-party tracking or advertising cookies and do not require a cookie banner for non-essential categories.

10. Your Rights — EEA, UK & Switzerland (GDPR)

Subject to the conditions of the GDPR, you have the following rights:

  • Access — receive a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — request deletion of your data.
  • Restriction of processing — ask us to limit how we use your data.
  • Data portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdrawal of consent — withdraw consent at any time without affecting prior lawful processing.
  • Right to lodge a complaint — with your local supervisory authority (e.g., EDPB members) before contacting us or after.

To exercise any of these rights, email privacy@mepage.cc with the request and we will verify your identity before responding.

11. Your Rights — California (CCPA / CPRA)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Know — request the categories and specific pieces of personal information we have collected about you in the preceding 24 months, the categories of sources, the business or commercial purpose for collecting, and the categories of third parties to whom we disclose.
  • Delete — request deletion of personal information we collected from you, subject to exceptions under Cal. Civ. Code § 1798.105.
  • Correct — request correction of inaccurate personal information.
  • Opt-out of sale or share — Mepage does not sell personal information and does not share it for cross-context behavioral advertising, so no opt-out is necessary.
  • Limit use of sensitive personal information — we do not process sensitive personal information as defined by CPRA beyond what is necessary to perform the Service.
  • Non-discrimination — we will not discriminate against you for exercising any CCPA right.
  • Authorized agent — you may submit a request through an authorized agent with written permission.

Submit CCPA requests to privacy@mepage.cc. We will verify your identity before fulfilling the request.

12. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected such data, contact privacy@mepage.cc and we will delete it promptly.

13. Data Storage & Security

Your data is stored on our subprocessor infrastructure and protected by industry-standard security measures including TLS in transit, encrypted credentials, scoped access tokens, and least-privilege database roles.

Despite these measures, no system can be guaranteed 100% secure. In the event of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority without undue delay, in accordance with GDPR Art. 33–34.

14. Platform Disclaimer

As a neutral technology service provider, Mepage only provides tools for creating and displaying personal pages and is not responsible for content published by users through this platform.

Users bear full legal responsibility for all content they publish, including but not limited to:

  • Truthfulness and legality of content
  • Any harm caused to third parties by the content
  • Any legal disputes arising from the content

Mepage reserves the right to remove or block violating content, and to restrict or terminate service access for violating users, in accordance with legal requirements or our Terms of Service.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated version on this page and update the "Last updated" date below. For material changes, we will also notify you by email or an in-product banner at least 30 days before the change takes effect.

Last updated: July 2026