Niche Nudge
  • CRM
  • Attribution
  • Marketing
  • Fractional
  • Work
  • About
Talk to us →
  • CRM
  • Attribution
  • Marketing
  • Fractional
  • Work
  • About
  • Talk to us →

Legal

Privacy policy

Last updated: 2026-07-28

This policy explains what data we collect, why we collect it, how we use it, and the rights you have over it. It is written for clarity, not legal density. If you want the legally precise version or have questions, contact us at privacy@nichenudge.com.

1. Who we are

The controller of the data described in this policy is Niche Nudge LLC, a Delaware limited liability company, 24A Trolley Square #1312, Wilmington, DE 19806-3334, United States. Day-to-day operations are conducted from Barcelona, Spain, and we serve clients globally. For anything in this policy: privacy@nichenudge.com.

2. What this policy covers

This policy covers the public website at nichenudge.com and the application at nichenudge.com/app. It describes data we decide the purposes for (where we act as controller). Data our clients bring to the platform is handled differently — see section 7.

3. Data we collect from visitors

When you visit the site, our hosting providers record standard HTTP request data (IP address, browser type, referrer, pages requested) in short-lived server logs. With your consent — and only with it — we also collect analytics events (Google Analytics 4 plus a first-party event log) and, inside the dashboard only, session-replay data (Microsoft Clarity). Neither loads before you consent.

When you submit a calculator or contact form, we collect the email address you provide, the inputs you entered, and the resulting calculations, so we can send you what you asked for and follow up with relevant content.

4. If you have an account

For dashboard accounts we process: your email address and display name, your role assignments, and a record of sign-ins and administrative actions (our audit log). Signing in also updates your contact record in our email platform (last-login time) and records a login analytics event.

If you set up sign-in security factors, we store the public half of any WebAuthn passkey you register together with a device nickname, and an encrypted secret for your authenticator app. Passkey biometrics — your fingerprint or face — are verified on your device and are never sent to us. Session cookies used to keep you signed in are strictly necessary and always on.

5. Bank account connections (Plaid)

For our internal bookkeeping we connect the company’s own bank accounts through Plaid, which acts as our processor for that connection. Plaid provides us account identifiers, balances, and transaction data for those company accounts, which become part of our accounting records. Plaid’s handling of data is described in the Plaid End User Privacy Policy . When a bank connection is closed, we invalidate the access token with Plaid and delete it. We do not currently ask visitors or clients to connect bank accounts; if that ever changes, this policy will be updated first.

6. Why we use data (lawful bases)

We rely on: contract — operating accounts and delivering the reporting our clients engaged us for; consent — analytics, session replay, and marketing emails, each withdrawable at any time; legitimate interests — securing the platform, keeping audit records of administrative actions, and preventing abuse; and legal obligation — retaining financial and accounting records for statutory periods.

7. Data we process for clients

Clients bring their own data to the platform — for example subscriber lists, campaign statistics, and lead records. For that data the respective client is the controller and Niche Nudge acts as a processor under the client’s instructions and a data processing agreement. We do not use client-provided end-user data for our own purposes. If your data reached us through one of our clients, please direct requests to that client; we support them in fulfilling data subject rights.

8. Who we share data with

We use processors acting under our instructions: Supabase (database and authentication), Vercel and Fly.io (hosting and compute), Cloudflare (DNS, CDN, object storage), Loops (email delivery), Google (analytics), Microsoft (session replay), Sentry (error monitoring, with personal identifiers scrubbed before events leave our systems), and Plaid (bank connections, section 5). We do not sell your data, we do not share it with advertisers, and there are no advertising networks on this site.

9. International transfers

We are a US company operating from Spain, and our processors run in the United States and the European Union. Where personal data of people in the EU/EEA or UK is transferred to a country without an adequacy decision, we rely on appropriate safeguards — Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework. You can request a copy of the relevant safeguards via privacy@nichenudge.com.

10. How long we keep it

Financial and accounting records (including bank data received via Plaid): 7 years from the close of the relevant fiscal year. Plaid access tokens: for the life of the connection, then invalidated and deleted. Account data: life of the account plus 30 days. Administrative audit logs: at least 24 months. Analytics events: 90 days. Server and error logs: at most 90 days, provider-managed. Marketing and lifecycle contact data: until the purpose ends, you unsubscribe, or you ask us to erase it. Client reporting data: the engagement plus 90 days. Encrypted database backups roll over a 7-day window, so deleted data ages out of backups within a week.

11. Your rights

Under GDPR you can access the data we hold about you, correct it, delete it, restrict or object to its processing, and port it elsewhere; where processing rests on consent, you can withdraw it at any time without affecting prior processing. Email privacy@nichenudge.com and we’ll respond within 30 days. You can also complain to your local data protection authority — in Spain, the AEPD (aepd.es). Depending on where you live, other laws may give you additional rights; write to us and we’ll honour what applies.

12. Cookies and consent

Strictly necessary cookies (session sign-in, and the cookie that remembers your consent choice) are always on. Everything else is off until you choose: on your first visit a consent banner offers Accept all, Reject all, or Customize, with separate choices for analytics and for session replay (dashboard only). Nothing optional loads before you decide, and the banner returns on each visit until you make a choice. You can withdraw consent at any time by clearing this site’s cookies — the banner will reappear and your new choice applies from then on.

13. Children

Neither the site nor the application is directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@nichenudge.com and we will delete it.

14. Automated decision-making

We do not make automated decisions about you that produce legal or similarly significant effects.

15. Changes to this policy

We update this policy when our practices change. The “last updated” date at the top reflects the most recent revision. Material changes will be highlighted on the homepage for at least two weeks before taking effect.

16. Contact

Questions, requests, or complaints: privacy@nichenudge.com.

Services

  • CRM
  • Attribution
  • Marketing
  • Fractional leadership

Company

  • About
  • Work
  • Contact
  • Perks and Partners

Tech & Legal

  • Status
  • Privacy
  • Terms

© 2026 Niche Nudge. All rights reserved.