Privacy Policy
Last updated: May 2026
Mandate, Kraków, Poland. This policy applies to the Mandate landing page at mandateapp.co and covers personal data collected through the waitlist and contact forms.
Privacy questions: privacy@mandate.app
What data we collect
Data you provide: Your email address; your name, if provided; any message you send via the contact form.
Data collected automatically via our analytics provider: Aggregated and anonymised site usage data, which may include pages visited, session duration, device category, and approximate geographic region. We do not use advertising or fingerprinting tools.
How we use your data
To add you to the waitlist and send product updates (where you have consented); to respond to contact form messages; to understand site usage and improve the product; to detect and prevent abuse.
Legal basis
Consent - waitlist signup and associated communications. Legitimate interests - analytics and abuse prevention, where our interests do not override your rights. Legal obligation - where required by law.
Who we share data with
We do not sell or share data for advertising. We use the following processors, each bound by a data processing agreement: website hosting provider; email delivery provider; analytics provider. Processors may not use your data for their own purposes.
International transfers
Where processors operate outside the EEA, we rely on Standard Contractual Clauses approved by the European Commission.
Retention
Waitlist data: until you unsubscribe or request deletion, or until the waitlist closes. Contact form messages: up to 12 months. Analytics data: retained in aggregated or anonymised form only.
Your rights
If you are in the EEA, you have the right to access, rectify, erase, restrict, object to, or port your data, and to withdraw consent at any time. Email privacy@mandate.app - we will respond within 30 days. You may also lodge a complaint with the Polish supervisory authority: UODO, uodo.gov.pl.
Cookies
We use only essential and analytics cookies. We do not use advertising or cross-site tracking cookies.
Security
We use TLS/HTTPS for all data transmission and apply reasonable technical and organisational measures to prevent unauthorised access or loss.
Changes
We may update this policy. Material changes will be communicated by email to waitlist subscribers. The date above reflects the latest revision.