Privacy Policy
Last updated: 2026-05-07This Privacy Policy explains how Startup Valleys (startupvalleys.com, operated as a community / non-commercial personal project) collects, uses, and protects your personal data when you visit our website, submit information through our forms, or create an account.
Startup Valleys is a worldwide directory of startup ecosystems — not limited to Europe. Visitors and contributors from any country can use the Service. We comply with the Swiss Federal Act on Data Protection (FADP / revDSG) and the EU General Data Protection Regulation (GDPR), and we extend the same data-subject rights (access, rectification, erasure, portability, objection) to users worldwide on a best-effort basis, regardless of residency.
1. Data Controller
2. What Data We Collect
2.1 Information you provide
When you register or submit a company / incubator / event / job, we collect:
- Account data: email, password hash (argon2id — never plaintext), display name
- OAuth provider ID + email when you sign in with Google / Microsoft / LinkedIn / Apple
- Submission payload (name, description, location, URL, dates, tags)
- Job applications: name, email, optional phone + cover letter + résumé
- Event RSVPs: name + email
2.2 Information collected automatically
- Technical data: IP address, browser + device, operating system, referrer URL
- Usage data: pages visited, time on site, interactions (clicks, map zoom, filters)
- Performance data: page load times, error reports
2.3 Data we do NOT collect
- No cross-site advertising tracking
- We do not sell or share your data with advertisers
- Private HR contact data is never exposed through the public API
3. Legal Basis for Processing (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Displaying the map and public content | Legitimate interest (Art. 6(1)(f)) |
| Operating your account | Contract (Art. 6(1)(b)) |
| Processing submissions, applications, RSVPs | Consent (Art. 6(1)(a)) + legitimate interest |
| Payment processing | Contract (Art. 6(1)(b)) |
| Security logging + fraud prevention | Legitimate interest (Art. 6(1)(f)) |
4. Third-Party Processors
We use the following services to operate Startup Valleys. Your data may be transferred to these providers.
⚠︎ Hosting provider (e.g. Hetzner Online GmbH) — Hosting (servers, Mongo, Redis)
Processes: all account and submission data at rest + in transit
Privacy: https://www.hetzner.com
Resend Inc. (USA) — Transactional email (verify, password reset, claims)
Processes: recipient email, template data (company name, etc.)
Privacy: resend.com/legal/privacy-policy
Stripe Inc. (USA) — Payment processing for job posts and event tiers
Processes: your card data (Stripe-hosted checkout — we never see raw card data), billing email
Privacy: stripe.com/privacy
Mapbox Inc. (USA) — Geocoding addresses to coordinates
Processes: the address submitted with a company or event
Privacy: mapbox.com/legal/privacy
International transfers: some processors are located outside the EU/EEA. Where required we rely on Standard Contractual Clauses (SCC) approved by the European Commission to ensure an adequate level of data protection.
5. Cookies & Local Storage
| Name | Type | Purpose | Duration |
|---|---|---|---|
| sv_refresh | HttpOnly cookie | Refresh your signed-in session | 30 days |
| sv:locale | localStorage | Remember your language preference | Persistent |
| sv:mapStyle | localStorage | Remember your map style (light / dark / sat) | Persistent |
| sv:wizard:* | localStorage | Remember contribute-flow drafts so refreshes don’t lose progress | Until submitted |
6. Your Rights (GDPR & FADP)
You have the following rights regarding your personal data:
- Right of access — request a copy of data we hold about you
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion (“right to be forgotten”)
- Right to restrict processing — limit how we use your data
- Right to data portability — receive your data in a structured format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — for processing based on consent
- Right to lodge a complaint — with the Swiss FDPIC or your local EU data protection authority
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
7. Data Retention
- Account data: retained while your account is active; deleted within 30 days of account deletion request
- Published listings: retained indefinitely as long as the listing is live; anonymised or deleted on request
- Submission metadata: retained in the audit log for 12 months then automatically purged
- Payment records: retained per Swiss tax/commercial law (10 years)
8. Data Security
- HTTPS/TLS encryption for all traffic
- Passwords hashed with argon2id — we never store plaintext
- Admin accounts optionally protected by TOTP 2FA
- Private data (HR contacts) not exposed via public API; RBAC enforced server-side
- Nightly encrypted backups with 30-day retention
9. Children’s Privacy
This website is not directed to children under 16. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be announced on the homepage. The “Last updated” date at the top of this page reflects the current version.