Join our new Affiliate Program!

Privacy Policy

Note: This English version is provided for convenience only. The French version is the only legally binding version.

Updated April 14, 2026

For visitors to dotb.io, we do not collect any personal data. An affiliate cookie may be placed if you arrive via an affiliate link. If you decide to create an account, we ask for the bare minimum and only share this information with services absolutely necessary for the proper functioning of the application.

At Dotb, we are committed to complying with GDPR, CCPA, PECR and other privacy regulations on our website and our web analytics product as well. The privacy of your data — and it is your data, not ours! — is very important to us.

In this policy, we explain what data we collect and why, how your data is handled and your rights over your data. We promise to never sell your data: we have never done so and we never will.

As a visitor to the dotb.io website:

  • No personal information is collected

  • An affiliate cookie may be stored in your browser if you arrive on our site via an affiliate link. This cookie, managed by Tolt, is only used to track the referral source for affiliate compensation purposes. It does not contain any personally identifiable data and expires after 15 days. See Tolt’s privacy policy for full details.

  • No information is shared, sent or sold to third parties

  • No information is shared with advertising companies

  • No information is collected or mined for personal or behavioral trends

  • No information is monetized

  • We use the Plausible Analytics script to collect some anonymous usage data for statistical purposes. The goal is to track overall trends in our website traffic, not to track individual visitors. All data is in aggregate only. No personal data is collected. See Plausible’s privacy policy for full details.

  • Data collected includes referral sources, top pages, visit duration, information from the devices (device type, operating system, country and browser) used during the visit and more.

Our guiding principle is to collect only what we need and to process this information only to provide you with the service you have subscribed to.

We use a limited number of trusted external service providers for certain service offerings. These service providers are carefully selected and meet high standards of data protection, privacy and security.

We only share information necessary for the services offered with them and contractually bind them to keep all information we share with them confidential and to process personal data only according to our instructions.

Here is what this means in practice:

What we collect and how we use it

  • An email address is required to create an account. You must provide us with your email address if you want to create a Dotb account.
  • A persistent cookie is stored to remember that you are logged in. If you log in to your Dotb account, you give us permission to use cookies so that you do not have to log in for every session. This makes it easier for you to use our product. A cookie is a piece of text stored by your browser. You can adjust cookie retention settings in your own browser. Cookies already stored can be deleted at any time.
  • All data we collect is fully secured, encrypted and hosted on a server powered by 100% renewable energy in Nuremberg, Germany. The server is owned by Hetzner, a European company. A Data Processing Agreement (DPA) under GDPR Article 28 has been signed with Hetzner. This ensures that all site data is covered by the strict European Union data protection laws. Your site data never leaves the EU. See Hetzner’s privacy policy for full details.
  • All emails are sent via a third-party email provider. Transactional emails and email reports (if you choose to subscribe to them) are sent via Postmark. We have disabled open tracking and link tracking on all emails sent. See Postmark’s privacy policy for full details.
  • When you write to us with a question or request for help. We keep this correspondence, including the email address, so that we have a history of past correspondence to refer to if you contact us in the future. We use this data only in connection with answering the requests we receive.
  • The payment process is handled by a third-party payment provider. If you choose to upgrade to a paid Dotb plan, billing information and the payment process are handled by Stripe. Stripe may place cookies in your browser for fraud prevention and payment security purposes. See Stripe’s Privacy Policy for full details.
  • We use Crisp as our customer support chat service. Crisp may place cookies in your browser to identify your session and provide continuity in support conversations. See Crisp’s Privacy Policy for full details.
  • Some Dotb features use artificial intelligence. These features are powered by Google (Gemini). Data sent to these services is processed in accordance with their respective privacy policies. See Google’s Privacy Policy for full details.
  • Interactive product demos in our documentation are powered by Supademo. When you view a demo, Supademo may collect usage data such as interactions and page views. See Supademo’s Privacy Policy for full details.
  • We use Nolt to collect product feedback and display our public roadmap. When you interact with the Nolt widget, Nolt may collect usage data. See Nolt’s Privacy Policy for full details.
  • We use Datadog for error tracking and application monitoring. Datadog may collect technical data such as error logs, stack traces, and anonymised user identifiers to help us diagnose and fix issues. See Datadog’s Privacy Policy for full details.

Dotb browser extension

When you use the Dotb browser extension, the following data is collected and stored on Dotb servers:

  • Vinted account information: Your Vinted account ID, name, and email address are collected. This information is strictly required for Dotb to function and connect to your Vinted account.
  • Listings and reposts: When you save a listing or create a repost using Dotb, a copy of that listing — including its photos — is stored on Dotb servers. Photos are stored on Backblaze B2 cloud storage on EU-based servers (Netherlands). See Backblaze’s Privacy Policy for full details. This allows Dotb to manage and automate your reposts on your behalf.
  • Orders: If you use the orders sync feature for accounting or management purposes, your Vinted orders are backed up on Dotb servers.

All of this data belongs to you. You can request deletion at any time using the Delete Account feature in the Dotb dashboard, or by deleting your Dotb account entirely. All data is permanently deleted within 15 days of an account deletion request.

Buyer data

In the context of the orders and accounting features, certain information concerning buyers (such as delivery address, billing details, or order history) is displayed to the User because it originates directly from their activity on Vinted.

This data is used exclusively for the operation of the Service and is not transmitted to third parties, except to fulfil legal obligations or to strictly necessary technical providers.

When a Dotb account is deleted, data relating to buyers is deleted or rendered non-identifying in accordance with appropriate procedures, subject to applicable legal retention obligations. Aggregated and non-identifying information (e.g. number of sales, overall volume) may be retained for statistical purposes.

The User remains solely responsible for compliance with legal and regulatory obligations relating to the personal data of their buyers.

For personal data relating to buyers originating from third-party platforms (including Vinted), Dotb acts exclusively as a data processor within the meaning of Article 28 of the GDPR, on behalf of the User, who remains the controller of such data.

This data is processed only to enable the User to manage their sales, logistics and administrative obligations, without autonomous reuse by Dotb, without enrichment or use for commercial or marketing purposes.

Buyer data is retained for the period necessary for Service performance, then deleted or rendered non-identifying within a reasonable time. Processing of any such data ceases upon account deletion and Dotb does not retain identifiable buyer data beyond legal requirements.

YouTube videos (third-party content)

Certain pages on dotb.io may display videos hosted by YouTube. Playing these videos may result in the placement or reading of trackers by YouTube/Google, independently of Dotb. We recommend consulting Google’s Privacy Policy for full details on how YouTube handles your data.

Payment (Stripe Checkout)

When upgrading to a paid plan, the User is redirected to a payment page operated by Stripe (Stripe Checkout). On this occasion, Stripe may place or read trackers necessary for the proper functioning of the payment process and the prevention of fraud and abuse. Dotb does not control the trackers placed on Stripe pages. See Stripe’s Privacy Policy for full details.

Data controller

The data controller responsible for your personal data is:

Dotb.io 16 Rue Jules Vallès, 75011 Paris, France SIREN: 102015443 Intra-community VAT: FR89102015443 Contact: hello@dotb.io

We process your personal data on the following legal bases under GDPR Article 6:

Data Legal basis
Account creation and login (email, session cookie) Contract performance — Article 6(1)(b)
Vinted account data, listings, orders, buyer data Contract performance — Article 6(1)(b)
Billing and payment information Contract performance — Article 6(1)(b)
Anonymous analytics (Plausible) Legitimate interest — Article 6(1)(f)
Support chat (Crisp) Legitimate interest — Article 6(1)(f)
Affiliate cookie (Tolt) Consent — Article 6(1)(a)
Support correspondence Legitimate interest — Article 6(1)(f)

Your rights

Under the GDPR and applicable privacy regulations, you have the following rights regarding your personal data:

  • Right of access: You may request a copy of the personal data we hold about you.
  • Right of rectification: You may request that inaccurate or incomplete data be corrected.
  • Right of erasure: You may request that your personal data be deleted. You can also do this directly at any time via the Delete Account feature in your dashboard.
  • Right to restriction of processing: You may request that we limit the processing of your data in certain circumstances.
  • Right to data portability: You may request your data in a structured, commonly used and machine-readable format.
  • Right to object: You may object to processing based on legitimate interest at any time.
  • Right to withdraw consent: Where processing is based on consent (e.g. affiliate cookies), you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority. In France, this is the CNIL (Commission Nationale de l’Informatique et des Libertés).

To exercise any of these rights, send a request to hello@dotb.io. We will respond within 30 days.

Data transfers outside the European Union

Some of the third-party services we use are based outside the European Union. In such cases, data transfers are carried out under appropriate safeguards, typically Standard Contractual Clauses (SCCs) approved by the European Commission:

Service Country Purpose
Stripe United States Payment processing
Postmark United States Transactional emails
Google (Gemini) United States AI features
Supademo United States Interactive demos
Nolt United States Product feedback & roadmap
Datadog United States Error tracking & monitoring
Backblaze B2 European Union (Netherlands) Photo storage — no transfer
Crisp European Union (France) Support chat — no transfer
Hetzner European Union (Germany) Hosting — no transfer
Plausible European Union Analytics — no transfer

Automated decision-making and profiling

Dotb does not make any automated decisions that produce legal or similarly significant effects on users. No profiling of users is carried out for marketing, scoring, or any other purpose. AI features (powered by Google Gemini) are used solely to assist the User with specific in-product tasks and do not result in any automated decision-making within the meaning of GDPR Article 22.

Data retention

We will retain your information as long as your account is active, as long as needed to provide you with the services or as otherwise stated in this policy.

We will also retain and use this information to the extent necessary for the purposes set out in this policy and to the extent necessary to comply with our legal obligations, resolve disputes, enforce our agreements and protect Dotb’s legal rights.

Changes and questions

We may update this policy as needed to comply with relevant regulations and reflect any new practices.

Contact us at hello@dotb.io if you have any questions, comments or concerns about this privacy policy, your data or your rights regarding your information.