Privacy policy
Last updated 10 October 2026
Who we are
Sterling Pick is run by Markus Skov (sole proprietorship, org.nr. 920 721 869), who is the controller for the personal data described here. Write to hello@sterlingpick.com about anything in this policy.
This policy covers the website, the founding-app interest form, buying a founding place and signing in. Before maker accounts open, we will update it and say what changed.
Visiting the website
- No cookies unless you sign in. Visiting sets no cookies and doesn’t track you across sites. Signing in sets a single cookie that keeps you signed in. It’s strictly necessary, so it needs no consent.
- Visitor statistics. We count page views with Vercel Web Analytics, which uses no cookies. It recognises a visit through a hash of the request that is discarded after 24 hours, and we see only totals. This is our legitimate interest in knowing how the site is used (GDPR Article 6(1)(f)).
- Performance. Vercel Speed Insights measures how fast pages load, without cookies and without identifying you.
- “Visit website” clicks. When you follow a listed app’s link, we count the click: one number per app per day, so its maker can see visits from Sterling Pick. Nothing about you is kept.
- Server logs. Like any website, our hosting provider handles your IP address and browser details to deliver pages and keeps short-lived logs for security and troubleshooting. This is our legitimate interest in running a secure service.
The founding-app interest form
If you register interest in a founding place, we store your email address, your name (if you give it), your app’s name and website, the platforms you choose, anything you write in the message field, and when you agreed to hear from us.
- Why: to confirm your email address and tell you when founding places open. The legal basis is your consent (Article 6(1)(a)). You can withdraw it at any time with the unsubscribe link in that email, by replying to any of our emails, or by writing to us. Withdrawing deletes your details.
- The announcement: we tell you when places open in one email, sent ahead of the opening time from news.sterlingpick.com. Its links pass through our email provider’s click counter, so we can see how many people followed each link, and it records that you clicked. We don’t track whether you open it. This is our legitimate interest in knowing which of our emails work (Article 6(1)(f)). Emails about an account or an application are never tracked.
- Confirmation: we email you a link to confirm your address. If you don’t confirm within 30 days, we delete your details.
- Campaign tags: if the link that brought you to the form carried campaign tags (the
utm_parts of a web address, such asutm_source=newsletter), we save them with your details, to learn which of our posts and emails bring makers to us. They describe the link, not you, and nothing is stored on your device. This is our legitimate interest in knowing what works (Article 6(1)(f)). - Bot protection: the form uses Cloudflare Turnstile to keep out automated spam. Turnstile looks at technical signals such as your IP address and browser characteristics, and sets no cookies. This is our legitimate interest in keeping the form free of abuse.
- How long: until 12 months after Sterling Pick launches, or sooner if you ask us to delete it or you become a listed maker, in which case the maker terms apply.
Buying a founding place
Stripe handles the payment: your card details go to Stripe, never to us. From Stripe we receive your name or business name, email address, billing address, any tax ID you enter, the app name and website you give, and what you paid.
- Why: to give you your founding place (the claim code), send your invoice, and refund you if the founding terms say so. The legal basis is our contract with you (Article 6(1)(b)), and the bookkeeping law that requires us to keep invoices and payment records (Article 6(1)(c)).
- Campaign tags: if a link with campaign tags brought you to the founding page, we keep the tags ourselves, give Stripe only a reference number for them, and save them with your founding place, to learn which of our posts and emails lead to purchases. Unused references are deleted after 30 days. This is our legitimate interest in knowing what works (Article 6(1)(f)).
- How long: invoices and payment records for five years after the end of the financial year, as Norwegian bookkeeping law requires. The rest until your place has been used or refunded, and then as long as the maker terms say.
- Stripe processes payment data for us, and also on its own account to prevent fraud and meet its legal obligations, under its own privacy policy.
Signing in
To sign in, you give us your email address and we email you a link. We keep your account (your email address and when it was created) and, while you’re signed in, a session: when it started and when it expires, but not your IP address or which browser you use.
- Why: to let you into your account. The legal basis is our contract with you, or the steps you ask for before one (Article 6(1)(b)). The sign-in form uses the same bot protection as the interest form.
- Passkeys: if you add one, we store its public key and when you added it. Your fingerprint, face or screen lock never leaves your device. While you use a passkey, a second, short-lived cookie holds that step together.
- Campaign tags: if a link with campaign tags brought you to the sign-in page, the sign-in email carries them, and we save them with your account. We keep two: the first, from when your account was created (or from your founding-app interest, if you registered it before), and the latest. They describe the links, not you, nothing is stored on your device, and they’re deleted with your account. This is our legitimate interest in knowing what brings makers to us (Article 6(1)(f)).
- How long: a session ends when you sign out or after 30 days without use. Your account stays until you delete it on your account page, or ask us to.
Applying to be listed
When you apply, we keep your answers about your app: its name, descriptions, category, platforms, pricing, links, support contact, legal owner, country and latest release date. Some of these can be personal data, for example if you sell your app as a sole trader.
- Why: to review your app and, if it’s approved, to list it. The legal basis is our contract with you, or the steps you ask for before one (Article 6(1)(b)).
- Submitting: we record that you accepted the terms of listing, and which version. Stripe handles the review fee as described under founding places, and we keep the invoice for bookkeeping.
- Icon and screenshots: we keep the images you upload in private storage in the EU, with their metadata (such as the device or a location) removed. Only you and the reviewer see them, unless your app is listed with them.
- Review access (a TestFlight link, a code or a test account) is encrypted, only the reviewer opens it, and we delete it 30 days after our decision.
- Questions during the review: if we need something from you, we email you the question and keep it, with your answer, alongside the application.
- Our decision stays with the application: our checklist and, if we don’t approve the app, the reasons we gave you.
- Corrections: if you ask us to correct your listing, we keep your request, and our answer, with the listing.
- How long: drafts, and their images, until you delete them. Applications you submit, for as long as the review and any listing that follows need them. When you delete your account, we delete your answers, images, review access and answers to our questions at once, and keep only invoices and payment records (five years, as bookkeeping law requires) and our own records of reviews and listings, without your contact details.
When you email us
We keep your messages for as long as we need them to answer and follow up, and delete them when they’re no longer needed.
Backups
Our database is backed up every night. Each backup is encrypted before it leaves the server that makes it, stored in the EU, and deleted after 35 days. So when we delete your data, it is gone from our backups within 35 days.
Error monitoring
When something breaks on our servers, Sentry records technical details about the error so we can fix it. We have configured it not to collect IP addresses, cookies, request contents or email addresses.
Who processes data for us
These providers process personal data on our behalf, under data processing agreements, and only to provide their service to us:
- Vercel: Hosts the website, and provides cookieless visitor statistics and performance measurements. United States company; the site's servers run in Frankfurt, Germany.
- Neon: Database. United States company; data stored in Frankfurt, Germany.
- Resend: Sends our emails, and counts clicks on the links in our announcements and newsletters. United States company; emails are sent from Ireland, account data and logs are kept in the US.
- Cloudflare: Bot protection on our forms (Turnstile), and storage (R2) for the images makers upload and for our encrypted database backups. United States company; images and backups are stored in the EU.
- GitHub: Runs our nightly backup job, which encrypts the backup before storing it. United States company.
- Sentry: Error monitoring. United States company; data stored in Germany.
- Stripe: Payments, invoices and refunds for founding places. Stripe Payments Europe (Ireland), with Stripe, Inc. in the United States.
- Proton: Our email inbox. Switzerland.
Where a provider is based outside the EEA, transfers rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses. Switzerland has an adequacy decision. We don’t sell personal data or share it for advertising.
Your rights
If you have an account, you can download a copy of your data yourself, as a JSON file, and delete your account, from your account page. You can also ask us for a copy of your personal data, and ask us to correct it, delete it, restrict its use or hand it over in a portable format. You can object to processing based on our legitimate interests and withdraw consent at any time. Write to hello@sterlingpick.com, and we will answer within a month.
You can also complain to the Norwegian Data Protection Authority (Datatilsynet) or to the data protection authority where you live.
Changes
When this policy changes, we update the date at the top. If a change affects you, we will tell you by email before it takes effect.