Privacy policy
Last updated: June 22, 2026
1. Data controller
The controller for the personal data collected via Compass is Thinqbase GmbH, a limited liability company under Swiss law. For any question: privacy@thinqbase.com.
2. Data we collect
- Account: name, email address, password (hashed), company, role.
- Accounting data: entries, receipts, invoices, customers, suppliers and other data entered into the Service.
- Support: content of emails and messages you send us.
- Usage and telemetry: technical logs, session identifiers, IP address, device and browser type — for security, stability and product improvement.
- Cookies: strictly necessary cookies for authentication and proper operation of the application.
3. Purposes and legal bases
- Providing and maintaining the Service (performance of the contract).
- Security, fraud prevention and logging (legitimate interest).
- Billing and legal accounting and tax obligations (legal obligation).
- Customer support and transactional communications (performance of the contract).
- Product improvement, based on aggregated or pseudonymised data (legitimate interest).
- Marketing communications: only with your consent, revocable at any time.
4. Data sharing — processors
We share strictly necessary data with:
- Lovable / Supabase: hosting of the application, database and storage of receipts (EU).
- Paddle.com: Merchant of Record for the sale of the Service — payments, subscriptions, billing and tax compliance.
- Resend: sending transactional emails (confirmations, invoices, notifications).
- Google: only if you choose to sign in with Google (OAuth).
- Competent authorities: where required by law.
5. International transfers
Your data is hosted primarily in the European Union. Where a transfer outside the EU/Switzerland is necessary, it is subject to appropriate safeguards (standard contractual clauses, adequacy decisions).
6. Retention
We keep your data as long as your account is active and as long as necessary to provide the Service. Accounting data may be retained for the period required by Swiss law (generally 10 years). Upon termination, your data is deleted or anonymised within a reasonable time, subject to legal retention obligations.
7. Your rights
In accordance with the Swiss FADP and, where applicable, the European GDPR, you have the following rights: access, rectification, erasure, restriction, portability, objection and withdrawal of consent. You may also lodge a complaint with the competent data protection authority (FDPIC in Switzerland). To exercise your rights: privacy@thinqbase.com. We reply within one month.
8. Security
We implement appropriate technical and organisational measures: encryption in transit (TLS) and at rest, role-based access controls, multi-tenant isolation (Row-Level Security), access logging and regular backups. More details on our Security page.
9. Cookies
We use only cookies strictly necessary for authentication and operation of the application. We do not use advertising cookies.
10. Changes
This policy may be updated. Material changes will be notified to you by email or via the application.
11. Contact
Thinqbase GmbH — privacy@thinqbase.com.