Personal dataLast changed 17 September 2026
Privacy
What Plauso stores, why, where it sits and for how long. And who is responsible for what, because you and we hold different roles.
DraftThis text will be reviewed by a lawyer before launch.
We wrote it ourselves, as plainly as we could, and it describes how Plauso actually works today. But it has not been read by a lawyer, and we are not going to pretend otherwise. The review happens before the service launches for real.
Who is responsible
Plauso is run by Nordkod Media AB. We are the controller for the data about you as our customer: your account, your order, your invoice and your contact with us.
- Company
- Nordkod Media AB
- Company registration number
- 559591-6759
- VAT number
- SE559591675901
- Address
- Bultgatan 38, 442 40 Kungälv, Sweden
- Service
- plauso.app
- Contact
- support@plauso.app
Two roles, kept apart
For your own customers' details, you are the controller. You met them and you decide who gets the request. We are your processor and handle the details only according to what you do in the service.
As a processor we do nothing of our own with them. We do not sell them, do not lend them to another customer, and do not use them to train any model. If one of your customers wants to know what is stored, we help you answer, and if data leaks we tell you without undue delay.
The terms for that processing belong in a data processing agreement — what we may do, for how long, and which sub-processors may be used. That agreement will be in place once the legal review is done.
What we store
- Your account: business name, email address, text sender name, and the link to your review profile if you add it.
- Customers you add: first name and mobile number or email address, when you added them, and your confirmation that the customer bought from you.
- The sending: when a text or email went out, whether it arrived, and whether the recipient opted out.
- Your short link and QR code: number of clicks per day and channel. We store no IP addresses.
- If you order signs: order number, what you bought, the delivery address and the basis for the invoice.
- Profile check: we only fetch the home page you enter and store nothing from the check itself.
If you sign in with Google
If you choose Google instead of waiting for a code by email, we ask Google for two things: openid and email. The first is what makes it a sign-in at all, the second is what tells us which address you are signing in with. We do not ask for your name, profile picture, contacts, Gmail, Calendar or Drive — and what we do not ask for, we cannot receive.
We also do not ask for the right to reach anything at Google once you have left. The permission applies at the moment of signing in, and no longer.
Here is everything we get, line by line, and what happens to it:
| Item | What it is | What we do with it | Stored by us? |
|---|---|---|---|
| Your email address at Google. | Looks up whether that address already has a Plauso account. If it has none, it becomes the account's address when you create one. | Yes — as the account's email address, nowhere else. | |
| email_verified | Google's word that the address has been proven. | If Google does not say it is proven, the sign-in stops. An unproven address proves nothing. | No. |
| sub | Google's own stable identifier for the account. | Holds the sign-in together for the minutes it takes to confirm which address you want to use. | No — it sits in a cookie for at most 15 minutes and is never written to our storage. |
| Everything else | Name, profile picture, contacts, Gmail, Calendar, Drive. | We do not ask for it. The permission we request is openid and email, nothing more. | No — we never have it. |
Limited use of Google user data
Google's User Data Policy sets four requirements on what an app may do with data from Google. We follow them, and here is what they mean here:
- The data is used only to sign you in — the feature you pressed yourself. We use it for nothing else.
- We do not pass it on. Not to ad networks, not to data brokers, not to any analytics supplier. Your address leaves us only when we email you at it.
- No human sits and reads it. The address appears in your own account, and to us when we debug a fault you told us about or when the law requires it — never as a list someone browses.
- We do not sell it, do not use it for advertising, retargeting or credit scoring, and train no AI model on it.
Google Places and your profile
When you connect your business profile, the search text you type goes to Google and you point yourself out in the list. Of everything Google answers with, we store a single field: place_id, the profile's id. The name and address in the list are shown on screen and thrown away.
The rating and the number of reviews we fetch fresh every time they are shown, and never write to our storage — Google's terms do not allow them to be stored. So there is no rating history to build on here, and if the fetch does not go through we show nothing at all rather than an old number.
The link that takes your customer to the review box is built from place_id the moment someone clicks. That is not stored either.
If you sign in with BankID
The BankID sign-in goes through Idura, who own the connection to BankID. From there we receive your Swedish personal identity number — and it never leaves that part of the code in the clear. What gets stored is a keyed hash of the number, which can only be compared against itself and not reversed.
So we never store your personal identity number, neither in storage nor in a cookie. BankID gives us no email address, so we ask for one and confirm it with a code.
Why, and on what basis
The account and the sending are needed to deliver what you signed up for. The basis is the agreement between us.
Invoice records we keep because Swedish accounting law requires it. Operational logs and abuse limits we keep so the service stays safe and works; there the basis is our legitimate interest in running it.
We do not use any of it to profile you or to make automated decisions about you.
Who sees the data
We run nothing in a server room of our own. The suppliers below see data, and only the part they need for what they do. The list is the whole list — a supplier not on it is not switched on. The fuller version, with what we require of them, is in the sub-processors document.
| Supplier | What they do for us | What they can see | Status |
|---|---|---|---|
| Vercel | Runs the site and the storage where the account sits. | Everything stored in the service: the account, the customers you added, the orders. | In use today. |
| Resend | Sends the email — sign-in codes and the request to your customers. | The recipient's address, the first name and the text of the email. | In use today. |
| 46elks | Sends text messages. Swedish company, traffic stays inside the EU. | The recipient's mobile number, the sender name and the text. | In use when text messages are switched on. |
| Twilio | An alternative route for text messages, an American company. | The same as the row above. | Standby. Which route is used is set inside the service. |
| Finds your business profile when you connect it, and supplies the rating when it is shown. | The search text you type and your place_id. Never your customers. | In use today. | |
| Idura | The BankID sign-in. | Your personal identity number, at their end. Only a hash of it reaches us. | Ordered. Not switched on yet. |
| Stripe | Card payment for sign orders. | The amount and your card details, which never pass through us. | Not switched on yet — sign orders are invoiced. |
| Anthropic | The language model that drafts text suggestions for your Google profile. | Only what you typed into the form yourself. Never a customer detail, never anything from Google. | The key is in place, but text suggestions are not switched on yet. |
| PostNord and DHL | Deliver the parcel with the signs. | The name and address on the parcel. | In use when you order signs. |
Transfers outside the EU and EEA
Several of the suppliers above are American companies. Where the data physically sits depends on the region the service runs in.
Exactly which region Plauso uses, and what safeguard covers transfers outside the EU and EEA, is one of the points the legal review will settle before launch. We would rather write that plainly than claim something we have not checked.
How long
We keep the account while you use the service. Ask us to delete it and we remove the account and the customers you added.
Invoice records we must keep for seven years under Swedish accounting law, even if you close the account. There the law weighs heavier than a deletion request.
Your short link keeps pointing at your profile until you ask us to close it, so signs you already handed out do not stop working.
How we protect it
The storage is private and reached only with a key that sits in the running environment, never in a browser. Signing in rests on a signed cookie, and the code we email is tied to the browser that asked for it — a forwarded email signs nobody else in.
Secrets such as personal identity numbers and sign-in codes are stored hashed, not in the clear, and the logs must never contain them. If a secret leaks anyway, we tell you without undue delay.
Cookies
The site uses no tracking cookies. Which ones exist, and why they need no consent, is on the cookie page.
Your rights
You can ask what data we hold about you, have it corrected or deleted, have it moved, and object to its use. Write to support@plauso.app and we will answer.
If you signed in with Google you can also remove Plauso's access at any time inside your Google account, under Security and the list of apps with access to the account. The Google button then stops working for you, but the account remains and the code by email works as usual.
If you think we handle your data wrongly you can complain to the Swedish authority, imy.se, or to the data protection authority in your own country. If you are a customer of someone using Plauso, go to the business that asked you — they are responsible for the data about you.
- Company
- Nordkod Media AB
- Company registration number
- 559591-6759
- VAT number
- SE559591675901
- Address
- Bultgatan 38, 442 40 Kungälv, Sweden
- Service
- plauso.app
- Contact
- support@plauso.app