Exercise your rights: Privacy request
You can request access to, correction of, or deletion of personal data at any time — no sign-in required — using our Privacy request form. If you already have an account, you can also delete it yourself under Account settings in your dashboard.
1. Controller
The controller responsible for processing personal data through MakerShake is:
**Dominic Müller** DOMU.STUDIO Sole proprietor Mainzer Straße 19 50678 Cologne Germany
Email: contact@domu.studio
MakerShake is a product operated by DOMU.STUDIO.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with MakerShake, including data relating to:
- visitors to makershake.com;
- registered users and makers;
- people who create, claim, edit, or publish project profiles;
- users who comment, upvote, save, follow, share, or otherwise interact with projects;
- users who send or receive direct messages;
- visitors who contact makers;
- users who purchase or manage paid plans;
- users who request website feedback or audits;
- people who submit reports, complaints, or appeals;
- people who contact us for support; and
- people whose publicly available information appears on a website submitted to MakerShake.
Where MakerShake obtains personal data from a publicly accessible submitted website rather than directly from the person concerned, the relevant source is generally that publicly accessible website.
3. What is personal data?
Personal data means information relating to an identified or identifiable natural person.
Depending on the context, this may include:
- names;
- handles and usernames;
- email addresses;
- avatars or profile photographs;
- IP addresses;
- account identifiers;
- authentication identifiers;
- billing information;
- messages and comments;
- website content relating to identifiable founders or makers;
- device and browser information;
- usage information;
- online identifiers;
- social links; and
- other information that can reasonably be linked to an identifiable person.
Information relating only to a company or product is not necessarily personal data. It may become personal data where it relates to an identifiable founder, maker, employee, sole proprietor, or other individual.
4. Data processed when you visit MakerShake
When you visit MakerShake, we and our technical service providers may process technical access information, including:
- IP address;
- date and time of access;
- requested page or URL;
- referring page or referrer information;
- browser type and version;
- operating system;
- device type;
- language settings;
- approximate location derived from IP information;
- server and application logs;
- security events;
- consent preferences; and
- other technical request information.
We process this information to:
- provide the website;
- maintain security and stability;
- prevent attacks, spam, fraud, and abuse;
- diagnose technical errors;
- protect users and infrastructure;
- maintain technical compatibility; and
- comply with legal obligations.
The legal basis is generally Article 6(1)(f) GDPR for secure and reliable operation. Article 6(1)(b) GDPR may apply where technical processing is necessary to provide a service expressly requested by you. Article 6(1)(c) GDPR applies where processing is necessary to comply with a legal obligation.
5. Account and maker profile data
If you register for MakerShake, we may process:
- your email address;
- display name;
- username or handle;
- avatar or profile image;
- biography or profile description;
- authentication identifiers;
- account ID;
- login information;
- account settings;
- profile visibility settings;
- project associations;
- plan and subscription status;
- feature preferences;
- account activity;
- communication preferences;
- support history; and
- security logs.
We process this information to:
- create and administer your account;
- authenticate you;
- display your maker profile;
- associate projects with your account;
- provide dashboard and community functionality;
- manage plan limits;
- provide support;
- send operational communications;
- prevent unauthorized access and abuse; and
- enforce our Terms of Service and Acceptable Use Policy.
The legal basis is primarily Article 6(1)(b) GDPR. Security and abuse-prevention processing may additionally be based on Article 6(1)(f) GDPR.
6. Creating project profiles from a URL
MakerShake allows users to generate a project profile from a publicly accessible website URL.
When a URL is submitted, MakerShake may access and process publicly available information from that website, including:
- website URL and domain;
- app or project name;
- page title;
- tagline;
- product description;
- page text;
- metadata;
- Open Graph metadata;
- favicon;
- Open Graph or title images;
- publicly available images;
- screenshots;
- categories and topics;
- tags;
- pricing information;
- technology information;
- founder or team information;
- public social links;
- public contact details; and
- other information relevant to creating the project profile.
We process this information to:
- generate a starter project profile;
- identify relevant project information;
- suggest descriptions, categories, and tags;
- generate screenshots;
- create SEO and social-sharing information;
- avoid duplicate profiles;
- help users edit and publish their project; and
- operate MakerShake's discovery directory.
Where personal data appearing on the submitted website was not obtained directly from that person, its source is generally the publicly accessible submitted website.
The legal basis is generally Article 6(1)(b) GDPR where processing is necessary to provide the URL-to-profile feature requested by the submitting user.
Article 6(1)(f) GDPR may also apply to processing publicly available information where necessary to operate the directory, prevent duplicate or misleading profiles, maintain accurate project information, and protect MakerShake against misuse.
You must not submit private, restricted, confidential, or password-protected websites without authorization.
You should not submit URLs containing passwords, authentication tokens, private document identifiers, or sensitive personal information.
7. Automatically generated profile content
MakerShake may automatically create or suggest:
- project names;
- descriptions;
- taglines;
- SEO titles and descriptions;
- categories;
- tags;
- technology information;
- summaries;
- landing-page suggestions; and
- other profile content.
Generated content may be based on publicly available website content, user-provided information, MakerShake taxonomy information, and automated or AI-based analysis.
Automatically generated content may be inaccurate, incomplete, or outdated.
Users remain responsible for reviewing and correcting information before or after publication.
8. AI-assisted processing through Lovable and OpenAI
MakerShake uses AI-assisted functionality for profile generation and related features.
These functions may be routed through the Lovable AI Gateway to OpenAI.
Depending on the feature, information processed may include:
- text retrieved from a submitted project website;
- website URLs;
- page titles and metadata;
- product descriptions;
- user-provided profile text;
- project names and taglines;
- selected categories and tags;
- technology information;
- prompts and system instructions; and
- technical request identifiers.
We use AI services to:
- create starter project descriptions;
- generate or improve taglines;
- generate SEO titles and descriptions;
- summarize publicly available information;
- suggest categories and tags;
- identify product characteristics;
- generate landing-page suggestions; and
- provide other AI-assisted functions.
MakerShake currently uses OpenAI models for these functions. The availability of another model through Lovable does not mean that MakerShake sends data to that provider.
We aim to minimize personal information transmitted to AI services where reasonably possible.
You must not submit passwords, authentication credentials, complete payment details, health data, private customer databases, confidential business information, or other sensitive information that is not necessary for the requested feature.
MakerShake does not use community comments, direct messages, saves, follows, or private contact-form messages to train AI models.
The legal basis is generally Article 6(1)(b) GDPR where AI processing is required to provide a feature requested by you. Article 6(1)(f) GDPR may also apply to efficient service operation and improvement.
9. Website screenshots through ScreenshotOne
MakerShake uses ScreenshotOne to generate screenshots and visual previews of submitted project websites.
When a screenshot is requested, information sent to ScreenshotOne may include:
- the submitted website URL;
- screenshot configuration;
- viewport dimensions;
- image format or quality settings;
- rendering and timing instructions;
- browser-rendering parameters; and
- technical request information.
ScreenshotOne loads the submitted website through an automated browser environment and returns the generated visual result.
A screenshot may contain information publicly visible on the target website, such as:
- names;
- profile photographs;
- testimonials;
- social-media content;
- public user content; and
- other personal data displayed on the page.
We use ScreenshotOne to:
- create project title images;
- generate project screenshots;
- preview submitted websites;
- create complete project profiles; and
- refresh screenshots when requested or technically necessary.
If you submit a website, you must ensure that you are authorized to submit it and that the resulting use through MakerShake is lawful.
The legal basis is generally Article 6(1)(b) GDPR for providing the screenshot feature. Article 6(1)(f) GDPR may additionally apply to presenting and maintaining directory profiles effectively.
10. Uploaded images and files
Users may upload:
- screenshots;
- logos;
- title images;
- profile images;
- avatars; and
- other files supported by MakerShake.
We may process:
- the uploaded file;
- filename;
- file type;
- file size;
- dimensions;
- upload timestamp;
- associated account;
- associated project;
- storage identifier;
- technical metadata; and
- security or moderation information.
You are responsible for ensuring that you have the necessary rights and permissions for material you upload, including the rights relating to identifiable individuals shown in an image.
11. Public project and maker profiles
MakerShake is a public directory and community.
Depending on the information provided, a public maker or project profile may display:
- maker name;
- handle;
- avatar;
- biography;
- project name;
- website URL;
- descriptions;
- screenshots;
- title images;
- categories and tags;
- technology information;
- pricing information;
- availability badges;
- social links;
- engagement counts;
- comments;
- follower counts;
- project links; and
- other profile information.
Public content may be:
- viewed by anyone;
- shared by visitors;
- indexed by search engines;
- cached by browsers or search providers;
- shown in social-media previews;
- processed by search or AI-discovery systems; and
- archived by independent third parties.
Removing content from MakerShake cannot guarantee its immediate deletion from independent search engines, archives, caches, or third-party services.
Only publish information that you are comfortable making publicly available.
12. Comments
Signed-in users may comment on projects and reply to other comments.
We may process:
- your account identifier;
- public profile information displayed with the comment;
- comment text;
- reply relationships;
- the relevant project;
- timestamps; and
- anti-spam and abuse-prevention information.
Comments and the public profile information attached to them are publicly visible wherever the relevant project is publicly available.
We process comments to provide community functionality, enable discussion, operate moderation, and prevent abuse.
The legal basis is Article 6(1)(b) GDPR for providing the requested interaction and Article 6(1)(f) GDPR for moderation, security, and abuse prevention.
13. Upvotes and shares
If you upvote or share a project, we may process:
- your account identifier, where applicable;
- the relevant project;
- timestamps;
- interaction records; and
- aggregate counts.
Individual upvotes are not necessarily shown as a public user list.
Aggregate counts may be displayed publicly and may contribute to MakerShake discovery or sorting.
For users who are not signed in, a share interaction may be recorded without identifying the visitor as a MakerShake account holder.
The legal basis is Article 6(1)(b) GDPR for interactions actively requested by users and Article 6(1)(f) GDPR for aggregate engagement signals, discovery, fraud prevention, and prevention of manipulation.
14. Saved projects
MakerShake allows signed-in users to save projects.
We may process:
- your account identifier;
- the saved project;
- the save timestamp; and
- aggregate save information.
Your list of saved projects is private to your account.
However, if MakerShake provides the relevant maker with a notification that you saved their project, that notification may identify you using information from your public MakerShake profile.
Aggregate save counts may be used for discovery or engagement analysis.
The legal basis is Article 6(1)(b) GDPR for providing the save functionality and Article 6(1)(f) GDPR for notifications, aggregated engagement signals, and prevention of manipulation.
You can remove a saved project at any time.
15. Follows
Users may follow other makers.
We may process:
- the follower's account identifier;
- the followed maker's account identifier;
- the time the follow was created; and
- follower and following counts.
Following is not confidential.
The followed maker may be notified and may be able to see who follows them.
Follower and following counts may appear publicly on MakerShake.
The legal basis is Article 6(1)(b) GDPR for providing the follow feature and Article 6(1)(f) GDPR for related notifications and community discovery.
16. In-app notifications
MakerShake may generate in-app notifications concerning relevant activity.
Examples include:
- new followers;
- comments and replies;
- saved projects;
- project interactions;
- direct messages;
- moderation updates; and
- new projects published by makers a user follows.
Notification records may include:
- account identifiers;
- public profile information;
- related project information;
- notification type;
- timestamps;
- read status; and
- archived or deleted status.
We process this information to provide account and community functionality.
The legal basis may be Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
17. Direct messages between makers
MakerShake offers private one-to-one messaging between eligible users.
A conversation may be limited to users who meet MakerShake's messaging requirements, for example mutual follows.
We may process:
- account identifiers of the participants;
- conversation records;
- message content;
- sender information;
- timestamps;
- read status;
- most-recent-message information; and
- technical information used for spam prevention, rate limiting, security, and abuse detection.
Messages are stored using MakerShake's backend infrastructure so conversations remain available across sessions and devices.
Messages are not public.
They are not used for advertising profiling or AI-model training.
Messages may be technically accessible to DOMU.STUDIO as operator. We access message content only where reasonably necessary to:
- operate or repair the service;
- provide requested support;
- investigate a report;
- investigate a security incident;
- enforce the Terms or Acceptable Use Policy; or
- comply with a legal obligation.
New-message notifications may contain the sender's name and a link to the conversation rather than the complete message text.
The legal basis is Article 6(1)(b) GDPR for providing messaging and Article 6(1)(f) GDPR for security, spam prevention, abuse prevention, support, and legal defense.
Article 6(1)(c) GDPR applies where retention or disclosure is required by law.
If you delete your account, your account data is deleted, anonymized, or restricted according to the applicable retention rules. Messages previously sent may remain within another participant's conversation history where preserving the conversation is necessary and legally permitted.
Where appropriate, identifying account information may be minimized or replaced after account deletion.
If a message is reported, we may preserve the relevant message and associated records for as long as reasonably necessary to investigate the report, prevent repeated abuse, or establish, exercise, or defend legal claims.
18. Contact forms and maker inquiries
MakerShake may allow visitors to contact makers through project pages.
Depending on the form, we may process:
- sender name;
- sender email address;
- company or organization;
- message;
- subject;
- related project;
- purpose of the inquiry;
- timestamp;
- IP address;
- browser information;
- anti-spam signals; and
- delivery status.
This may include contact flows relating to:
- general inquiries;
- "Available for work";
- commissions;
- contract work;
- collaborations; and
- "Available to remix" inquiries.
Contact messages may be:
- stored in the maker's MakerShake inbox;
- delivered to a nominated contact address through Resend; or
- both,
depending on the recipient's account settings.
We process contact data to transmit the inquiry, allow the maker to respond, prevent spam and abuse, and operate the feature.
The legal basis may be Article 6(1)(b) GDPR where the communication concerns pre-contractual measures requested by the sender and Article 6(1)(f) GDPR for delivery, security, spam prevention, and abuse prevention.
Once a maker receives an inquiry, that maker may become an independent controller for their subsequent use of the sender's data.
19. Available for work
If a maker enables an "Available for work" or similar status, that status is publicly displayed.
Messages connected to that status may contain:
- names;
- professional contact information;
- company information;
- project details;
- budget information;
- availability information; and
- other voluntarily supplied professional information.
Users should avoid submitting sensitive or confidential information through an initial inquiry unless necessary.
20. Available to remix
If a maker enables an "Available to remix" or similar status, this status becomes public.
Related inquiries may contain personal, creative, or business information voluntarily submitted by the sender.
The badge itself does not grant an intellectual-property license.
Any later sharing of additional information or contractual terms takes place between the relevant parties.
21. Profile analytics
Eligible MakerShake plans may receive analytics concerning project performance.
This may include:
- profile views;
- outbound-link clicks;
- interaction counts;
- time-based activity;
- traffic sources;
- approximate device information;
- approximate geographic information;
- aggregate engagement; and
- comparative analytics across a maker's projects.
We may process technical and usage information to:
- provide analytics;
- calculate counts;
- prevent artificial traffic;
- filter bots;
- identify manipulation;
- improve discovery;
- diagnose errors; and
- operate paid features.
Where possible, maker-facing analytics are aggregated or statistical.
Users must not attempt to identify individual visitors through MakerShake analytics unless they have an independent lawful basis.
The legal basis may include Article 6(1)(b) GDPR for analytics included in a requested plan and Article 6(1)(f) GDPR for fraud prevention, abuse prevention, service analysis, and reliable reporting.
22. Google Analytics
MakerShake uses Google Analytics to understand how visitors interact with the website, measure usage, and improve the service.
Google Analytics may process:
- cookie identifiers;
- online identifiers;
- device information;
- browser information;
- approximate location;
- page views;
- session information;
- interaction events;
- referrer information;
- navigation data; and
- technical usage information.
Google Analytics is used only after the visitor has provided consent where consent is legally required.
The legal basis for personal-data processing is Article 6(1)(a) GDPR.
The storage of or access to information on the visitor's device is also based on consent where required under applicable German law governing cookies and similar technologies.
Visitors may refuse or withdraw consent at any time through MakerShake's cookie or consent settings.
Withdrawal applies for the future and does not affect processing carried out lawfully before withdrawal.
MakerShake aims to configure Google Analytics in a privacy-conscious manner, including appropriate retention settings and restricted use of data where available.
Google may process personal data in the United States and other countries. Relevant transfers are handled using Google's applicable data-protection terms and legally recognized transfer mechanisms.
Further details about analytics cookies and similar technologies are provided in the MakerShake Cookie Policy.
23. Email delivery through Resend
MakerShake uses Resend for transactional, operational, and service-related email.
Emails may include:
- registration emails;
- authentication emails;
- project notifications;
- contact-form messages;
- subscription notifications;
- cancellation confirmations;
- moderation decisions;
- report and appeal correspondence;
- support messages;
- security notices; and
- legal or policy communications.
Resend may process:
- sender and recipient addresses;
- recipient name;
- email subject;
- email content;
- email headers;
- message identifiers;
- delivery status;
- bounce information;
- spam complaints;
- IP-related technical data; and
- delivery metadata.
We use this information to send requested or necessary service communications and maintain reliable email delivery.
The legal basis may include Article 6(1)(b), Article 6(1)(f), Article 6(1)(c), or Article 6(1)(a) GDPR depending on the communication.
MakerShake does not intentionally enable email-open or link-interaction tracking unless it is transparently disclosed and legally permitted.
24. Website tips and private audits
Eligible MakerShake plans may provide automated or manually prepared website tips or private audits.
Depending on the feature, we may process:
- website URLs;
- publicly accessible website content;
- screenshots;
- metadata;
- project information;
- user instructions;
- automated analysis;
- audit notes;
- recommendations; and
- correspondence.
We process this data to provide the requested assessment or feedback.
The legal basis is generally Article 6(1)(b) GDPR.
Private audits are not published unless the user chooses to publish information from them.
Users should not provide passwords, sensitive personal information, confidential customer information, or private analytics credentials unless explicitly requested and an appropriate arrangement has been established.
25. Payments and subscriptions through Stripe
MakerShake uses Stripe to process paid plans, recurring subscriptions, additional project slots, checkout, invoices, cancellations, refunds, and related payment functions.
Depending on the transaction, MakerShake may process or receive:
- Stripe customer identifiers;
- customer name;
- billing email address;
- billing address;
- selected plan;
- additional project-slot information;
- subscription status;
- billing period;
- invoice information;
- VAT or tax information;
- transaction identifiers;
- payment status;
- payment-method type;
- cancellation status;
- refund status;
- dispute or chargeback information; and
- fraud-prevention signals.
Stripe processes complete payment-method information, such as card details, directly. MakerShake generally does not receive complete card numbers or card-security codes.
We use payment-related information to:
- conclude and perform paid contracts;
- activate paid plans;
- manage recurring subscriptions;
- provide additional project slots;
- issue and store invoices;
- process cancellations;
- manage refunds;
- handle failed or disputed payments;
- prevent fraud;
- maintain payment security; and
- meet tax, accounting, and legal obligations.
The legal bases may include:
- Article 6(1)(b) GDPR for processing and administering payments and subscriptions;
- Article 6(1)(c) GDPR for tax, accounting, and statutory record-keeping obligations; and
- Article 6(1)(f) GDPR for fraud prevention, payment security, and legal defense.
Stripe may process certain information as an independent controller for purposes such as regulatory compliance, fraud prevention, payment-network operation, and management of its payment infrastructure.
Stripe may use cookies or similar technologies as part of checkout, authentication, payment processing, and fraud prevention. Further information is provided in the MakerShake Cookie Policy.
26. Cookies and similar technologies
MakerShake may use:
- cookies;
- local storage;
- session storage;
- authentication tokens;
- SDKs;
- pixels;
- consent signals; and
- similar technical technologies.
Essential technologies
Essential technologies may be required for:
- authentication;
- account sessions;
- security;
- CSRF protection;
- consent preferences;
- profile editing;
- server-side functionality;
- rate limiting;
- fraud prevention;
- abuse protection;
- subscription management;
- checkout;
- payment processing; and
- cancellation flows.
Strictly necessary technologies may be used without consent where legally permitted.
Analytics technologies
Google Analytics and comparable non-essential analytics technologies are used only with consent where legally required.
The legal basis is Article 6(1)(a) GDPR.
Payment technologies
Stripe may use technologies necessary for:
- checkout;
- authentication;
- fraud prevention;
- payment processing;
- subscription management;
- invoice functionality; and
- cancellation flows.
Some Stripe technologies may be strictly necessary to provide a payment function expressly requested by a user. Non-essential technologies are subject to applicable consent requirements.
Further information is provided in MakerShake's Cookie Policy and consent interface.
27. Reports, moderation, and appeals
If you report a user, message, profile, comment, project, or other content, we may process:
- your name;
- email address;
- account identifier;
- reported content;
- relevant URLs;
- explanation or report reason;
- evidence;
- timestamps;
- IP and technical data;
- communications with affected users;
- internal review notes;
- moderation decisions; and
- appeal information.
We process this information to:
- investigate reported content;
- protect users;
- enforce our Terms and Acceptable Use Policy;
- prevent repeated abuse;
- comply with legal obligations; and
- establish, exercise, or defend legal claims.
The legal basis may include Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.
Automated safety screening of submitted websites
Every website address submitted to MakerShake is screened automatically before a listing can be published, and published listings are re-screened periodically for as long as they remain online. A report submitted by a user may also trigger a fresh screening of the reported project.
For that purpose we process:
- the submitted website address, its host, and the final address reached after redirects;
- the redirect chain and HTTP response information;
- domain-name resolution results;
- publicly available homepage content of the submitted website;
- the results of automated technical address checks;
- threat-feed and blocklist matches;
- the resulting classification, verdict, and reasons;
- the account identifier of the submitting user and the related project;
- a shortened, irreversible hash of the IP address in the case of anonymous reports or events; and
- timestamps, review status, and internal review notes.
We process this information to keep unlawful, deceptive, malicious, and prohibited websites off MakerShake, to protect visitors from malware and phishing, to detect websites that change after publication, to limit automated and bulk submissions, and to document moderation decisions.
The legal basis is Article 6(1)(f) GDPR (our legitimate interest and the interest of our users in a safe, non-deceptive directory), Article 6(1)(b) GDPR where screening is a necessary part of publishing the listing you requested, and Article 6(1)(c) GDPR where screening supports a legal obligation.
Screening is automated and can produce incorrect results. A clear-cut negative result can prevent a listing from being published or unpublish it. You can contest such a decision — see the sections on automated processing and on appeals — and every non-passing result is reviewed by a person on request.
28. Technical platform and infrastructure
MakerShake is developed and operated using Lovable and Lovable Cloud.
Depending on MakerShake's configuration, this infrastructure may support:
- hosting;
- frontend and backend functionality;
- account registration;
- authentication;
- databases;
- file storage;
- server functions;
- project and profile management;
- integrations;
- AI processing;
- consent functionality;
- subscriptions;
- cancellation functionality;
- security; and
- technical logging.
Lovable Cloud may use Supabase-based infrastructure.
Cloudflare infrastructure may be used through Lovable for:
- application delivery;
- routing;
- edge processing;
- security;
- performance; and
- protection against abusive or malicious traffic.
Possible information processed through the technical platform includes:
- IP addresses;
- account information;
- authentication identifiers;
- email addresses;
- project profiles;
- uploaded files;
- direct messages;
- contact-form messages;
- database records;
- website URLs;
- technical requests;
- browser data;
- application logs;
- security events; and
- configuration information.
DOMU.STUDIO remains the controller for MakerShake's processing purposes and means except where a provider acts as an independent controller for its own processing.
29. Service providers and recipients
MakerShake uses the following providers in connection with the service:
Lovable
Purpose: Application development and operating platform, deployment, integrations, account functionality, AI Gateway, and technical services.
Possible data: Account information, profile information, technical data, configuration data, application records, usage information, and logs.
Lovable Cloud / Supabase-based infrastructure
Purpose: Database, authentication, storage, realtime functionality, server functions, and backend infrastructure.
Possible data: Account records, authentication identifiers, email addresses, project profiles, uploaded images, messages, contact information, subscription status, database records, and technical logs.
Cloudflare
Purpose: Edge delivery, routing, security, performance, serverless processing, and protection against malicious or abusive traffic.
Possible data: IP addresses, request information, browser and device data, security events, routing data, and technical logs.
Cloudflare public DNS resolver (1.1.1.1)
Purpose: Confirming that the domain name of a submitted website resolves, as part of automated safety screening.
Possible data: The domain name of the submitted website and technical request information. No account or visitor data is sent.
abuse.ch (URLhaus)
Purpose: Checking submitted and published website addresses against a public malware-distribution threat feed.
Possible data: The submitted website address or its host and technical request information. No account or visitor data is sent.
Google Safe Browsing
Purpose: Optional additional check of submitted and published website addresses against Google's malware and phishing threat lists. This check is prepared but not currently active; this Privacy Policy will state when it is enabled.
Possible data: The submitted website address and technical request information. No account or visitor data would be sent.
ScreenshotOne
Purpose: Automated website screenshots and project imagery.
Possible data: Submitted website URLs, screenshot settings, rendered website content, generated images, and technical request information.
OpenAI
Purpose: AI-assisted text generation, summarization, classification, SEO text, tagging, and related profile functionality.
Possible data: Public website text, metadata, project-profile text, prompts, categories, tags, and technical request information.
Resend
Purpose: Transactional and operational email delivery.
Possible data: Names, email addresses, message content, email headers, delivery information, bounce information, and technical metadata.
Google Analytics
Purpose: Consent-based measurement of website use and interaction.
Possible data: Cookie identifiers, online identifiers, device information, browser information, approximate location, page views, and usage events.
Stripe
Purpose: Checkout, subscription payments, invoices, cancellations, refunds, tax-related processing, payment security, and fraud prevention.
Possible data: Customer information, billing information, subscription information, payment information, transaction records, and fraud-prevention information.
Providers may act as processors, subprocessors, or independent controllers depending on the particular processing operation.
Where required, we enter into data-processing arrangements with processors.
30. International data transfers
Some providers or their subprocessors may process data outside Germany or the European Economic Area.
This may include processing involving:
- Lovable;
- Lovable infrastructure providers;
- Cloudflare;
- ScreenshotOne;
- OpenAI;
- Resend;
- Google;
- Stripe; and
- their subprocessors.
Where personal data is transferred to a country that does not benefit from an applicable adequacy decision, we use an appropriate transfer mechanism where required.
This may include:
- Standard Contractual Clauses;
- an applicable adequacy decision;
- participation in the EU-U.S. Data Privacy Framework where applicable;
- contractual safeguards;
- organizational and technical safeguards; or
- another legally recognized transfer mechanism.
International data transfers may involve additional risks, particularly where foreign authorities may access information under local law.
31. Legal bases
MakerShake processes personal data only where a valid legal basis applies.
Article 6(1)(a) GDPR — Consent
Used where you have voluntarily consented to processing, such as:
- Google Analytics;
- optional cookies;
- optional tracking; or
- other optional features requiring consent.
You may withdraw consent at any time for the future.
Article 6(1)(b) GDPR — Contract and pre-contractual measures
Used where processing is necessary to:
- create and administer your account;
- generate project profiles;
- provide community features;
- provide direct messaging;
- deliver contact inquiries;
- provide analytics included in a paid plan;
- provide screenshots;
- provide AI-assisted features;
- process subscriptions and payments;
- provide website audits; or
- respond to pre-contractual requests.
Article 6(1)(c) GDPR — Legal obligation
Used where processing is necessary for:
- tax or accounting obligations;
- legally required notices;
- court or authority orders;
- statutory reporting; or
- other legal obligations.
Article 6(1)(f) GDPR — Legitimate interests
Used where necessary for legitimate interests such as:
- service security;
- spam and abuse prevention;
- fraud prevention;
- moderation;
- protection from account takeover;
- duplicate-profile detection;
- technical debugging;
- accurate engagement counts;
- protection against artificial traffic;
- maintaining public directory quality;
- internal administration;
- payment security;
- legal defense; and
- protection of users and third parties.
Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the affected person.
32. Data retention
We retain personal data only for as long as necessary for the relevant processing purpose, unless a longer period is required or permitted by law.
Retention may depend on account status, contractual obligations, security requirements, moderation needs, provider settings, and legal requirements.
Server and security logs
Generally retained only for a limited operational period unless longer retention is necessary to investigate security incidents, abuse, fraud, technical problems, or legal claims.
Account data
Retained while the account is active. After account deletion, account information is deleted, anonymized, or restricted after a reasonable technical period unless retention is necessary for contractual obligations, payments, security, moderation, legal defense, or statutory obligations.
Public maker and project profiles
Retained while published or while necessary to provide the service. Deleted content may remain temporarily in backups, technical caches, moderation records, or third-party search and archive systems.
Comments and interactions
Comments, upvotes, saves, and follows remain while the relevant interaction exists. Where you remove an interaction, the active record is deleted or anonymized where appropriate, although information may remain temporarily in backups, security records, or moderation documentation.
Notifications
Retained for a limited period necessary to operate account notifications and may then be archived or deleted.
Direct messages
Retained while necessary to provide the conversation to its participants. Messages may remain in a recipient's conversation after another participant deletes their account where legally permitted and necessary to preserve the conversation. Reported messages may be retained longer for moderation, abuse prevention, evidence, or legal defense.
Contact-form messages
Retained for as long as necessary to deliver and administer the inquiry, resolve disputes, prevent abuse, and protect legal interests. Recipients may retain messages independently after receiving them.
Generated and uploaded images
Retained while associated with an active project or account and deleted after they are no longer required, subject to backups, legal requirements, and technical retention.
AI-generated and submitted website information
Retained for as long as necessary to create, maintain, and edit profiles and according to applicable provider settings.
Reports and moderation records
Retained for as long as reasonably necessary to resolve the matter, prevent repeated abuse, comply with legal obligations, or establish, exercise, or defend legal claims.
Safety-screening records
Screening results for a listing are retained while the listing exists and are replaced by each later re-screening. Records of refused, blocked, or removed submissions and blocked domains are retained for as long as necessary to prevent resubmission and repeated abuse, and to document the decision.
Payment and invoice data
Retained according to applicable German tax, accounting, and commercial record-retention requirements.
Support communications
Retained for as long as needed to answer the request and for a reasonable period afterward for documentation and legal defense.
Google Analytics data
Google Analytics information is retained according to MakerShake's configured Google Analytics retention settings and the visitor's consent choices.
Consent records
Consent information may be retained for as long as reasonably necessary to demonstrate the existence, scope, modification, or withdrawal of consent.
Backups
Deleted data may remain temporarily in encrypted or access-restricted backups until the relevant backup is overwritten or expires.
33. Security
We use technical and organizational measures intended to protect personal data.
Depending on the relevant infrastructure, these may include:
- HTTPS encryption;
- authentication controls;
- restricted administrative access;
- role-based or row-level access controls;
- provider-side infrastructure security;
- logging and monitoring;
- spam and abuse controls;
- rate limiting;
- secure API authentication;
- secure payment processing through Stripe;
- data minimization;
- backups; and
- security configuration reviews.
No online service can guarantee absolute security.
If you believe your MakerShake account or data has been compromised, contact us at contact@domu.studio.
34. Children
MakerShake is not specifically directed at children.
We do not knowingly seek to collect personal data from children who are not legally able to use the relevant online service without required parental or guardian consent.
Users must not submit children's personal data through MakerShake without a valid legal basis and any required consent.
If you believe personal data relating to a child has been processed unlawfully, contact us so we can investigate.
35. Automated processing
MakerShake uses automated systems for functionality including:
- extracting website information;
- generating profile text;
- categorizing projects;
- suggesting tags;
- generating screenshots;
- identifying duplicate submissions;
- filtering spam;
- screening submitted and published website addresses for malware, phishing, deception, and prohibited content;
- limiting the number of submissions per account within 24 hours;
- detecting artificial activity;
- operating rankings and discovery signals; and
- supporting moderation.
These systems may influence:
- initial profile content;
- suggested categories or tags;
- inclusion in certain discovery areas;
- traffic counted in analytics; or
- whether a listing can be published, stays published, or is queued for human review; or
- whether content is flagged for review.
Automated safety screening can refuse or unpublish a listing without prior human involvement where the result is clear-cut, for example a match in a malware feed or a domain that does not resolve. You can contest such a decision, obtain a human review, and state your position by contacting us or using the available appeal route.
Apart from that, MakerShake does not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
36. Your GDPR rights
Subject to applicable legal requirements and exceptions, you may have the following rights:
- right of access to personal data concerning you;
- right to rectification of inaccurate personal data;
- right to erasure in applicable circumstances;
- right to restriction of processing;
- right to data portability where the statutory requirements are met;
- right to object to processing based on legitimate interests;
- right to withdraw consent at any time for the future;
- rights concerning certain automated decisions; and
- right to lodge a complaint with a data-protection supervisory authority.
To exercise your rights, contact:
We may need to verify your identity before acting on a request.
Rights may be subject to statutory restrictions, particularly where processing must continue to comply with legal obligations, protect the rights of another person, or establish, exercise, or defend legal claims.
37. Right to object
Where we process personal data under Article 6(1)(f) GDPR, you have the right to object on grounds relating to your particular situation.
If you object, we will stop processing the relevant data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is required to establish, exercise, or defend legal claims.
You may object to processing for direct-marketing purposes at any time.
38. Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
This may include consent for:
- Google Analytics;
- optional cookies;
- optional tracking; or
- other consent-based features.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Cookie consent may be managed using MakerShake's available consent settings.
39. Supervisory authority
You have the right to lodge a complaint with a data-protection supervisory authority.
You may generally contact the authority responsible for your residence, place of work, or the place where the alleged infringement occurred.
The supervisory authority generally responsible for DOMU.STUDIO in North Rhine-Westphalia is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestraße 2–4 40213 Düsseldorf Germany
40. Third-party projects and websites
MakerShake contains links to third-party apps, projects, websites, and services.
When you open such a link, the third party may independently process information such as:
- your IP address;
- browser and device information;
- referrer information;
- cookies;
- payment data; and
- other information you provide directly.
MakerShake does not determine or control the privacy practices of independently operated third-party websites.
Review the relevant third party's own privacy information before submitting personal information.
41. Data you should not submit
Unless explicitly necessary and appropriately protected, do not submit through MakerShake:
- health information;
- biometric information;
- genetic information;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- sexual-orientation information;
- criminal-offence data;
- identity-document numbers;
- full payment-card information outside approved Stripe payment flows;
- passwords;
- authentication tokens;
- private API credentials;
- confidential client databases;
- private analytics exports;
- trade secrets;
- non-public source code; or
- private document URLs.
In particular, avoid including sensitive or confidential information in:
- submitted URLs;
- project descriptions;
- public screenshots;
- comments;
- direct messages;
- AI requests;
- contact forms; or
- support requests,
unless doing so is necessary and lawful.
42. Legal disclosures
We may preserve or disclose personal data where required or permitted by law.
Potential recipients may include:
- courts;
- law-enforcement authorities;
- regulators;
- tax authorities;
- other competent public authorities;
- professional legal or tax advisers;
- hosting or technical providers;
- security providers;
- payment providers; and
- affected persons or rights holders where disclosure is legally justified.
We may also preserve information where reasonably necessary to:
- investigate abuse;
- prevent fraud;
- protect users;
- comply with legal orders;
- enforce contracts; or
- establish, exercise, or defend legal claims.
43. Business transfers
If MakerShake, DOMU.STUDIO, or relevant assets are sold, merged, transferred, assigned, or reorganized, personal data may form part of the transferred business assets where legally permitted.
Depending on the transaction, this may include:
- accounts;
- profile information;
- project information;
- messages;
- uploaded media;
- subscriptions;
- billing identifiers;
- analytics information;
- support records;
- moderation records; and
- contractual information.
The recipient may continue to process relevant information for purposes compatible with this Privacy Policy unless a new policy applies.
Affected users will be informed where required by law.
44. Service shutdown
If MakerShake is permanently shut down or materially discontinued, we may process account and contact information to:
- notify users;
- manage subscriptions;
- process required refunds;
- administer account closure;
- delete or export project information;
- meet accounting and tax obligations;
- preserve legally required information; and
- complete an orderly shutdown.
Information may continue to be retained in backups, invoices, contractual records, moderation evidence, or legal documentation where required or permitted.
45. Changes to this Privacy Policy
We may update this Privacy Policy when:
- MakerShake introduces new functionality;
- community functionality changes;
- service providers change;
- analytics or payment functionality changes;
- legal requirements change;
- processing activities change; or
- security and moderation practices change.
The current version will be published on MakerShake with an updated "Last updated" date.
Where required by law, we may provide additional notice concerning material changes.
46. Contact
For privacy questions, access requests, deletion requests, objections, consent withdrawals, or other data-protection concerns, contact:
DOMU.STUDIO Dominic Müller Mainzer Straße 19 50678 Cologne Germany
Email: contact@domu.studio