Privacy Policy

Last updated: 29 April 2026 · Version 1.0

Short version: We collect only what we need to run your account. Your data is stored in the EU (Ireland, eu-west-1). We never sell it. You can delete everything at any time.

1. Who We Are

NoxReach is operated by Gregorgus (GEEZ), a sole trader based in Cologne, Germany. Contact: hello@noxreach.io

For purposes of EU data protection law, Gregorgus is the data controller for all personal data processed through NoxReach.

2. What Data We Collect

Account data

Usage data you create

Technical data

We do not use advertising trackers, third-party analytics (Google Analytics, Meta Pixel, etc.), or any behavioural profiling.

3. Why We Process Your Data

Legal basis: contract performance (Art. 6(1)(b) GDPR) — we need your data to provide the NoxReach service you signed up for.

4. Where Your Data Is Stored

All data is stored on Supabase hosted in AWS eu-west-1 (Dublin, Ireland) — within the European Economic Area. No data leaves the EEA for processing.

The NoxReach app is hosted on Vercel. Vercel may log request metadata (IP, browser) via its edge network. See Vercel's Privacy Policy.

5. Your Rights Under GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, email hello@noxreach.io. We will respond within 30 days. You also have the right to lodge a complaint with the German data protection authority (LDI NRW) or the supervisory authority in your country of residence.

6. Data Retention

We retain your data for as long as your account is active. If you delete your account, all lead, gig, and profile data is permanently erased within 30 days. Authentication records are deleted from Supabase Auth within 90 days per Supabase's deletion schedule.

Backups may retain data for up to 30 additional days after deletion.

7. Third-Party Services

No other third-party services receive your data.

8. Cookies

NoxReach uses only functional cookies necessary to keep you logged in (Supabase Auth session token). We do not use advertising, analytics, or tracking cookies. No cookie consent banner is required for strictly necessary cookies under GDPR.

9. Children

NoxReach is intended for users aged 18 and over. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it.

10. Changes to This Policy

We will notify active users by email if we make material changes to this policy. The "Last updated" date at the top of this page always reflects the current version.

11. Contact

Data controller: Gregorgus (GEEZ)
Email: hello@noxreach.io
Address: Cologne, Germany (full address in Impressum)