In short
sharepa stores as little as possible. For an account we need your email address, nothing else. Visits to your pages are counted on the server, without IP address, without cookie and without identifier. The data is kept at Cloudflare in the EU. We do not sell anything on and we show no advertising.
The rest of this page explains that in detail.
Controller
Software & Automatisierung Kirner
Owner: Konrad Kirner
Erlachstrasse 3, 3012 Bern, Switzerland
hallo@getsharepa.ch
For everything you send to sharepa (account, pages, enquiries), the provider above is the controller. For the data of the visitors to your pages, you are the controller, and sharepa works for you as a processor. More on this in the section Visitors to your pages.
Which law applies
The Swiss Federal Act on Data Protection (FADP) applies. Because sharepa is also open to people in the EU and the EEA, we additionally comply with the General Data Protection Regulation (GDPR). Where this policy speaks of legal bases, it means the GDPR; under Swiss law, processing does not need its own legal basis as long as it is lawful and proportionate.
Your account
When you sign in or publish a page, we create an account. For that we store:
- your email address and a normalised form of it (lowercase, without additions after a plus sign, for Gmail without dots), so that nobody can create several accounts with variants of the same address
- the language of your browser, so that the app appears in your language
- your plan (today always “free”), the time the account was created and the version of the terms of use you accepted
- if your account was blocked: the time and the reason
There is no password. When you sign in we send you a six-digit code and a link by email. Code and link are valid for ten minutes and are stored as a hash, not in plain text. Your session stays signed in for 30 days; for that we set a cookie (see Cookies).
Purpose: run the account, sign you in, reach you. Legal basis: contract (Art. 6(1)(b) GDPR). Retention: as long as your account exists. We delete expired codes and sessions one day after they expire.
Your pages
When you publish an artifact, we store the code you paste, the page built from it, the title, the address and every further version. If you set a page password, we store it encrypted so that you can view it again in the app. If you connect your own domain, we store the hostname and the status of the certificate.
When publishing, we check all links on your page against the list of known phishing and malware sites from Google Safe Browsing. Only the links go to Google, no data about you. If your page contains a match, it does not go live straight away, we take a look at it instead. If we block a page or an account, we note the reason and send you an email.
Purpose: deliver your page, manage versions, prevent abuse. Legal basis: contract (Art. 6(1)(b)) and legitimate interest in protecting the service (Art. 6(1)(f) GDPR). Retention: until you delete the page or your account. Deleted pages disappear from the web immediately and are deleted for good after 30 days, so that a mistake can be undone for a short while.
Counting visits
For each of your pages you see in the app how often it was visited. This counting works without a cookie, without a script in the browser and without an identifier: our server counts every request and remembers only the country, the device type (phone or not), the origin of the request (the referring website) and whether the request came from a known bot. IP addresses are not stored for this. Individual visitors cannot be recognised from it.
We count the requests to this website and to the app in the same way.
Purpose: show you how your page is doing; understand our service. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Because no personal data arises, no consent is needed. Retention: daily figures per page remain as long as the page exists.
Visitors to your pages
When somebody opens your page under sharepa.page or under your domain, sharepa delivers the page. The following happens:
- Cloudflare, our hosting provider, processes the visitor’s IP address in order to deliver the page and to fend off attacks. We do not store the IP address.
- We count the visit as described above, without an identifier.
- If your page has a password, we set a cookie after the correct entry so that the visitor does not have to type it on every visit. It is valid for 30 days and contains no personal data.
- On free pages we show the sharepa branding in the bottom right corner: a small logo with a link to the app. It loads nothing from third parties.
Whatever your page does beyond that, an embedded video or a form for instance, you built, and it is your responsibility. For the data of the visitors you are the controller within the meaning of data protection law; sharepa is your processor. The rules for this are in the Annex on data processing of the terms of use.
Protection against abuse
So that nobody overloads the service or guesses codes, we limit requests per IP address: when signing in, when checking addresses, when building pages and when entering page passwords. The IP address is only counted briefly for this (one minute) and is not stored.
Each account can publish at most 30 new versions per day. We do not allow known disposable addresses.
Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Emails
We only send you emails when there is a reason: sign-in code, confirmation when your domain is active, notice when a page has been reviewed or blocked, confirmation when your account is deleted, and changes to the terms of use. There is no newsletter and no advertising.
Sending runs through Cloudflare’s Email Service with the sender hallo@getsharepa.ch. If you write to us at hallo@getsharepa.ch, your message lands in a mailbox at Infomaniak in Switzerland. We keep correspondence for as long as it is needed to answer it and for any follow-up questions, at most two years.
Cookies
sharepa sets two cookies, both are technically necessary. That is why we need no cookie notice.
- Session in the app (app.getsharepa.ch): keeps you signed in for 30 days. Contains a random value, no personal data.
- Access on password-protected pages: remembers for 30 days that the password was entered correctly. Contains a hash, no personal data.
This website (getsharepa.ch) sets no cookies and loads nothing from third parties, not even fonts.
Where the data is kept
Account, pages, versions and statistics are kept at Cloudflare in data centres in the European Union (database D1 and storage R2 with the region setting “EU”). Your pages are delivered through Cloudflare’s worldwide network so that they load quickly everywhere; copies of your page are briefly cached in the nearest data centre for this.
Every night we back up the database to the storage in the EU. We delete these backups after 30 days. In addition, Cloudflare keeps a 30-day recovery option for the database.
Service providers
We work with a few service providers who process data on our behalf:
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Hosting, database, storage, delivery of the pages, counting, email sending, certificates for custom domains. Cloudflare is certified under the Swiss-U.S. Data Privacy Framework and the EU-U.S. Data Privacy Framework; the basis is the Cloudflare data processing agreement with standard contractual clauses. Data location for stored data: EU.
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Safe Browsing: we send the links on your page to Google in order to detect phishing and malware. No data about you or your visitors is transmitted.
- Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Geneva, Switzerland. Mailbox for hallo@getsharepa.ch and registration of the domain getsharepa.ch.
There are no other recipients, unless we are legally obliged, for example towards authorities.
Transfer abroad
Cloudflare and Google are based in the USA. Your stored data stays in the EU. Where data can nevertheless reach the USA, for instance during delivery through the Cloudflare network or during support, we rely on the certification under the Data Privacy Framework, which the Swiss Federal Council and the European Commission have recognised as adequate, and additionally on standard contractual clauses.
Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection. This is how you exercise them:
- Deletion: in the app under “Account” you can delete your account yourself, together with all pages and connected addresses. Pages disappear immediately, backups within 30 days. If your account is blocked, write to us and we will delete it.
- Information, rectification, export: write to hallo@getsharepa.ch from the address of your account. We answer within 30 days. You can view and copy the code of your page in the app at any time.
- Complaint: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC). If you live in the EU or the EEA, with the data protection authority at your place of residence.
Changes
If something changes at sharepa that affects this policy, we adapt it. The date above shows the current state. In the case of substantial changes we inform you by email to the address of your account.