Vector BoyVectorize images PNG>SVG Open tool ↗

Legal

ImprintPrivacy PolicyTerms and ConditionsCancellation PolicyPrices and Contract Information

Privacy Policy

1. Controller

O.D.E.R.S.O. GmbH, Labesstraße 7, 27404 Zeven, Germany, represented by Managing Director Fynn Kliemann.

Privacy contact: Fynn Kliemann, mail@vector-boy.com

2. Image processing stays local

Images selected for editing and vectorization are processed locally in your browser. They are not uploaded to our servers, Stripe, Vercel, Neon or our email provider. Account, payment, credit and technical connection data are processed separately from image data.

3. Hosting and technical delivery

The website is provided by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Static content may be delivered through a global content delivery network; application functions are configured in the Frankfurt region. When you access the site, technically necessary data such as IP address, time, requested resource, browser identifier and referrer is processed to provide the service securely and reliably. The legal basis is Article 6(1)(f) GDPR. Technical application logs are generally retained for no more than 30 days unless a security incident requires longer preservation.

4. Privacy-friendly audience measurement

We count how many visitors and page views Vector Boy receives each day. We do not set analytics cookies or store an analytics identifier in your browser. The IP address and browser identifier are processed only briefly in server memory to create a non-reversible daily value using a secret key. This value changes every calendar day in the Europe/Berlin time zone and cannot be used to recognize a visitor across days. Raw data, full IP addresses, selected image files and image content are not stored in the analytics database. Do Not Track and Global Privacy Control are respected.

We store the calendar day, hour, daily pseudonymous value and number of page views. This lets us see only in the protected dashboard at which times of day the website is used. Pseudonymous individual records are deleted after no more than two calendar days; only aggregated hourly and daily values remain. The purpose is simple audience measurement and improvement of the service. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is understanding the use and technical load of our own service without advertising profiles or third-party analytics. You may object on grounds relating to your particular situation by contacting mail@vector-boy.com.

5. Optional analytics with Google Analytics and Google Ads conversion measurement

Google Analytics 4 is loaded only after you agree in the privacy banner. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Our measurement ID is G-S4S27JJVRK. Without consent, the Google script is not loaded and no analytics or conversion data is sent to Google.

Google Analytics helps us understand which pages and features are used and where Vector Boy can be improved technically or editorially. The data processed may include viewed pages, interactions such as image upload, preview, export click and checkout start, approximate location, referrer, device, browser and language information, as well as online identifiers. If you purchase credits after consenting, we also send a purchase event containing an anonymous Stripe transaction identifier, currency, gross amount, tax, Stripe fee and net revenue. We do not send your email address, name, image files or image content to Google. After consent, Google may set cookies including names such as _ga, _ga_... and _gcl_....

We run ads on Google Ads. With your consent we use the same Google integration to measure whether a click on one of our ads led to a purchase. For this purpose Google may store a click identifier (for example gclid) in a cookie and associate the events listed above with the ad click. We have disabled personalised advertising, remarketing and Google signals in our implementation; your data is not used to show you ads on other websites.

After you agree, we also keep the channel through which you first reached Vector Boy in the browser's session storage. If you create an account or start a purchase, we store this information in our own database and associate it with the account or first payment. It may include UTM source, medium, campaign, term and content, a Google Ads click identifier, the first landing page, and the domain and path of an external referring page. We do not store full referrer query parameters, IP addresses or image data for this purpose. The attribution helps us understand which content and campaigns lead to purchases. It is deleted when consent is withdrawn while signed in, or after no more than 25 months.

The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG for storing or accessing information on your device. Google may also process data in the United States. Applicable safeguards such as the EU-US Data Privacy Framework and standard contractual clauses are used where required. More information is available at https://policies.google.com/privacy and https://support.google.com/analytics/answer/12017362.

You can change your decision at any time through “Privacy settings” at the bottom of the page. Withdrawal applies to future processing. We attempt to remove analytics cookies already set when you withdraw; you can also delete them through your browser.

6. Accounts and sign-in

When credits are purchased for the first time, an account is automatically created with the email address used in Stripe Checkout. We process the email address, a one-way protected password, sessions, credit balance, preferred language and necessary usage data. A one-time password setup link is valid for 24 hours. A separate one-time secret kept only in the purchasing browser may claim the account and continue the download for up to two hours after confirmed payment. Only cryptographic hashes are stored for these secrets. The legal basis is Article 6(1)(b) GDPR. Sessions expire after no more than 30 days. Expired links, payment completion secrets and sessions are deleted regularly.

When an account deletion is confirmed, access is disabled immediately, sessions are deleted and directly associated contact data is pseudonymized. Download and credit details that are no longer required are deleted. Tax, invoice and contract records are retained only where statutory retention or legal defence obligations apply. The account cannot be restored.

7. Database

Account, contract, credit and billing data is stored in a PostgreSQL database operated by Neon, Inc. The production project runs in the Frankfurt region. Neon may use subprocessors and transfer data to third countries on the basis of appropriate safeguards. The legal bases are Article 6(1)(b), (c) and (f) GDPR.

8. Payments, invoices and taxes through Stripe

Only when you start a purchase and open Stripe Checkout do we send the information required for checkout, payment processing, invoices, fraud prevention and automatic tax calculation to Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and affiliated Stripe companies. This includes email address, billing address, tax ID, payment, device and transaction data. We do not store complete payment credentials in our systems.

Stripe processes certain data as an independent controller where required for payment processing, its own legal duties, fraud prevention and the security of the Stripe network. Where Stripe acts on our behalf, Stripe's applicable data processing terms apply. The legal bases are Article 6(1)(b) and (c) GDPR and, for abuse prevention, Article 6(1)(f) GDPR. Stripe may process data outside the EEA using recognized safeguards. More information: https://stripe.com/privacy

9. Transactional emails

We use email infrastructure from STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, for required contract confirmations and account or password messages. Recipient address, subject, message content and technical delivery data are processed. The legal bases are Article 6(1)(b) and (c) GDPR. We do not send marketing email without a separate legal basis.

10. Credits, downloads and invoices

We store purchases, credit movements, download times and file formats to maintain balances, authorize downloads, match invoices and prevent abuse. The processed image is not transmitted. A download authorization contains only a random request key and the selected file format.

Invoices, payments and tax records are generally retained for eight years. Contract acceptances are retained for as long as required to demonstrate the transaction and until relevant limitation periods expire. Operational download details are deleted or aggregated when no longer required for account history, abuse prevention or legal claims.

11. Referral program

When a personal invitation link is used, its referral code is stored locally in the browser and transmitted only during registration or a guest checkout. We process the relationship between inviting and invited accounts, registration time, first confirmed payment status and the resulting credit reward. The invited person's email is shown to the inviter only in masked form. Processing is required to operate and protect the voluntary referral program under Article 6(1)(b) and (f) GDPR. Referral credits may be reversed after refunds, chargebacks or abuse.

12. Cookies and local storage

We use a strictly necessary session cookie to keep signed-in users authenticated. Presets, image-processing preferences, language selection, referral codes and pending checkout details may be stored locally in your browser. These entries support requested functionality and are not advertising trackers. Your analytics choice is also stored locally. Google Analytics cookies are set only after consent. You can remove local storage through your browser settings; doing so also removes local presets and pending state.

13. Recipients and international transfers

Recipients are limited to providers required for hosting, database, payment, tax, invoice and email delivery, as well as authorities where required by law. Where data is processed outside the EEA, adequacy decisions, standard contractual clauses or another legally recognized transfer mechanism are used where necessary.

14. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, data portability and objection. You may withdraw consent for the future where processing is based on consent. You may also complain to a competent data protection authority. Contact mail@vector-boy.com to exercise these rights.

15. Security

We use encrypted connections, HttpOnly session cookies, one-way password hashing, expiring single-use tokens, rate limits and server-side authorization. No internet service is completely risk-free. Keep your password confidential and sign out on shared devices.

Last updated: 12 September 2026