Privacy Statement
Version 1.2 | Updated: August 2026
1. Who are we?
Siendr is an online marketplace for sports video clips, based in the Netherlands. Siendr acts as the data controller for personal data processed through the platform.
Trade name: Siendr
Address: The Netherlands
Email: louiejaysienders@gmail.com
2. What personal data do we process?
Buyers
- Email address: provided at purchase; used to deliver the download link and look up previous purchases. Providing this is required to perform the contract; without your email address we cannot deliver your download.
- Payment data: processed via Stripe; Siendr does not store card details.
- Technical data: IP address and session data, automatically collected for security and functionality.
Creators (videographers)
- Name and email address: provided at registration. Required for account management; without these no account can be created.
- Business name and VAT number: where applicable; required for correct tax processing.
- Banking details (IBAN): shared with Stripe for payouts via Stripe Connect.
- Upload metadata: title, description, and file information for uploaded clips.
All visitors: searches
- The search term itself: what was typed, how many results it returned, and the time. We use this to see what people look for without finding it, so we can arrange for those matches to be filmed.
- Approximate location: country, region and city, plus the time zone and the coordinates of that city's centre. This is determined by our hosting provider Vercel from the IP address of the request. We do not store the IP address itself. We keep only the location derived from it, which is no more precise than city level. No profile is built, and searches are not linked to an account or to each other.
3. Legal basis for processing
- Performance of a contract (Art. 6(1)(b) GDPR): processing purchases, delivering download links, and paying out creators.
- Legal obligation (Art. 6(1)(c) GDPR): retaining financial and tax records for 7 years under Dutch law.
- Legitimate interest (Art. 6(1)(f) GDPR) — abandoned purchases: if you start checking out and do not finish, we keep your email address and the clip you wanted so we can remind you once. This interest outweighs your privacy interest because you had just entered that address to make the purchase, we send at most one message, and the data is deleted after 60 days. You can object via the address under “Your rights”.
- Legitimate interest (Art. 6(1)(f) GDPR) — searches: logging search terms together with a city-level location, to see which sports and places there is demand for that we do not yet serve. This interest outweighs your privacy interest because we do not retain the IP address, the location is no more precise than a city, no profile is built, and the data is not linked to your account or to other searches. You can object via the address under “Your rights”.
- Legitimate interest (Art. 6(1)(f) GDPR): securing the platform and preventing fraud and abuse. The legitimate interest pursued is: (a) protecting platform integrity, (b) fraud detection and prevention, and (c) securing accounts and transactions. This interest outweighs data subject privacy interests because processing is minimal and limited to what is necessary for security purposes.
4. Retention periods
- Buyer email address: retained for 7 years after the purchase date under Dutch tax retention law.
- Creator account data: retained while the account is active, plus 7 years after closure due to tax retention obligations.
- Creator banking details: retained while the Stripe Connect account is active; upon closure per Stripe's policy.
- Upload metadata: retained while the clip is listed; deleted when a clip is removed.
- Technical log data: retained for a maximum of 90 days.
- Abandoned purchases: your email address and the clip you wanted, kept for a maximum of 60 days and then deleted automatically.
- Searches: retained for a maximum of 12 months, then deleted automatically. Twelve months so we can compare a full season with the previous one; longer serves no purpose.
5. Processors and transfers outside the EEA
We only share personal data with the following processors. We have a data processing agreement (Art. 28 GDPR) with each of them, or they are certified under the EU-US Data Privacy Framework (DPF).
- Stripe (VS): payment processing and Stripe Connect payouts. Transfer to the US under the EU-US DPF. Stripe is DPF-certified.
- Supabase (VS): database and authentication. Transfer to the US under Standard Contractual Clauses (SCCs).
- Resend: transactional email (download links, confirmations).
- Cloudflare R2 (VS): video file storage. EU-region storage where possible. Transfer to the US under the EU-US DPF.
- Vercel (VS): website hosting platform. Transfer to the US under SCCs.
We never sell your data to third parties.
6. Cookies
Siendr only uses functional cookies required for login, session management (via Supabase Auth), and remembering your language preference. We do not place tracking, analytics, or advertising cookies. No consent is required for these functional cookies.
7. Automated decision-making
Siendr does not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals (Art. 22 GDPR).
8. Your rights
Under the GDPR you have the following rights:
- Access (Art. 15 GDPR): request what data we hold about you.
- Rectification (Art. 16 GDPR): correct inaccurate data.
- Erasure (Art. 17 GDPR): request deletion, where no legal retention obligation applies.
- Restriction (Art. 18 GDPR): restrict processing in certain circumstances.
- Portability (Art. 20 GDPR): receive your data in a structured format.
Right to object (Art. 21 GDPR)
You have the right at any time to object to processing of your personal data based on legitimate interest (Art. 6(1)(f) GDPR), including processing for fraud prevention and platform security. Upon objection we will stop the processing, unless we can demonstrate compelling legitimate grounds which override your interests.
To exercise any right, email louiejaysienders@gmail.com with subject"GDPR request". Include your name and email address. We respond within 30 days. We may ask you to verify your identity.
9. Filing a complaint
If you believe we are not processing your personal data correctly, you may file a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
PO Box 93374, 2509 AJ The Hague, Netherlands
www.autoriteitpersoonsgegevens.nl
10. Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS/TLS), role-based access controls, and secure storage through certified processors.
11. Changes
We may update this privacy statement. For material changes we will notify you by email. The current version is at siendr.com/privacy. Questions? louiejaysienders@gmail.com