Privacy policy

1. Overview

This policy sets out what personal data we process when you visit Gearome, why, and your rights under the EU General Data Protection Regulation (GDPR). Analytics run without cookies and store nothing on your device, we build no user profiles, and you can switch analytics off at any time (see your analytics choice).

Last updated: August 28, 2026

2. Who is responsible

The controller responsible for the processing described here is the operator of Gearome:

Philip Pock
Prinz Eugenstraße 6/10
7400 Oberwart, Austria
hello@gearome.com
+43 681 81117450

Full disclosure details are on our legal notice. We have not appointed a Data Protection Officer, as we are not legally required to do so.

3. What we process and why

We use one analytics tool, PostHog, plus the infrastructure that runs the site. Your browser, operating system, device type and language are derived in your browser; your raw User-Agent and IP address are removed before anything reaches PostHog (see section 5).

  • Page and navigation data - the path you visit and the page you came from. Query strings are removed from both, and a saved plan's identifier is removed from the path: a visit to /plans/<id> is recorded as /plans/[id], so the share link never reaches PostHog. Purpose: reach measurement.
  • Campaign parameters - if a link you followed is tagged (utm_source, utm_campaign and similar), those values are recorded as separate fields. They describe the link, not you. Advertising click identifiers such as gclid are recorded as <masked> instead of their value. Purpose: which channels bring people here.
  • How you use the site - which rack you pick, which filters you set, what you add, move or remove, when you copy a share link, and when you follow a link to a merchant. Slot labels and the names you give your own items are never sent, so we see that something was labelled, not what it was called. Purpose: knowing which parts of the planner work.
  • Browser, operating system and device type, with versions - e.g. "Chrome", "Linux", "Desktop". Purpose: making the site work across devices.
  • Language preference - the coarse language code ("en", not "en-US"). Purpose: knowing our audience.
  • Country - derived at the network edge from your IP address (e.g. "AT"), which is itself never stored and never reaches PostHog (see section 5). Purpose: audience geography and feature targeting.
  • Pseudonymous, daily-rotating identifiers - a distinct_id, device_id and session_id computed on our server (see section 5). They change every day and are not stored on your device. Purpose: counting visits and sessions without identifying you.
  • An opaque reference to a saved plan - a one-way hash of the plan's identifier (plan_ref), sent when a plan is saved, opened or its link copied. It cannot be turned back into a share link; it only tells one plan from another. Purpose: whether shared plans get opened.
  • Performance metrics (Web Vitals) - anonymous load and responsiveness timings. Purpose: finding performance problems.
  • Active feature-flag assignments - which variant of a staged feature you were shown (e.g. $feature/<key>). Purpose: rolling out changes.
  • Saved rack plans - when you save a plan we store what you built under a random identifier: which rack, which equipment in which slot, any labels you typed, and the names and specs of any custom items. Nothing else, and nothing about you. Purpose: retrieving and sharing the plan.
  • Abuse prevention - your IP address, held for one minute to count requests. Purpose: keeping the service available and free of abuse.

Browser, OS, device type and language together remain a limited fingerprinting surface. We rotate the identifiers daily, store no analytics data on your device, and do not use any of it to re-identify anyone.

Contacting us by email

A separate context from the analytics above. If you email hello@gearome.com, or we reply, we process the personal data in that exchange.

  • What we process: your email address, your name, the content of your message, and anything else you include.
  • Why: to handle and answer your inquiry, and any follow-up.
  • Legal basis: our legitimate interest in answering inquiries (Art 6(1)(f) GDPR); if your inquiry concerns a potential contract, also pre-contractual steps at your request (Art 6(1)(b) GDPR).
  • Recipient: Google Workspace (Google Cloud EMEA Limited) as our processor; see sections 7 and 8.
  • Retention: inquiries with no business connection are deleted at the latest 12 months after the matter is settled. Correspondence that leads to a business relationship or counts as accounting evidence is kept for the statutory periods (in Austria generally 7 years under § 132 BAO) on that separate basis (legal obligation, Art 6(1)(c) GDPR).

4. Legal basis

We process the data above on the basis of our legitimate interests (Art 6(1)(f) GDPR): operating a functioning website, measuring its reach, improving the product, rolling out features safely, and keeping the service secure and free of abuse.

We have weighed these interests against your rights and freedoms. The processing is cookieless, stores no analytics data on your device, builds no user profiles, removes your IP and raw User-Agent before data reaches PostHog, and uses only pseudonymous identifiers that rotate daily. We therefore consider the impact on you low and not enough to override those interests.

Your right to object (Art 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. The reliable way to do so is the analytics opt-out toggle on this page. It covers every analytics purpose listed above: your browser stops sending analytics, our server drops anything that still arrives, and no flags are evaluated, so no identifier is computed from your request at all. Because analytics are served first-party from our own domain, tracking-protection lists and content blockers are not a reliable control here. You can also object by writing to hello@gearome.com.

Your analytics choice

Analytics run under our legitimate interest by default. You can turn them off here at any time; this is your objection under Art 21 GDPR. The setting is a simple on/off preference stored in your browser; it is not a tracking identifier, and turning analytics off does not degrade the site.

Loading your analytics preference…

5. How analytics works

Our analytics are cookieless by design: no analytics or tracking cookies, and no local or session storage for analytics. Analytics requests go first-party through a proxy that is part of this site, rather than to a third party directly.

How the identifiers are formed. Every request carries your IP address and User-Agent. Both reach our server and go no further: neither is stored, and neither is passed to PostHog. Our server uses them twice on the way past, to resolve your country and, combined with our domain and a secret we replace daily, to compute the distinct_id, device_id and session_id that count visits and sessions. The old secret is deleted, so yesterday's identifiers cannot be recreated or matched to today's.

Feature flags are evaluated on our server, and the variant you were shown appears on analytics events. Switch analytics off and no flags are evaluated and no identifier is computed: you see the standard version of every feature.

6. Cookies and similar technologies

We use no analytics or tracking cookies, and no local or session storage for analytics. Besides the cookies below, the only things kept on your device are functional: the colour-scheme setting (nuxt-color-mode, which follows your operating system), if you build custom equipment or racks, their names and specs (gearome-custom-equipment, gearome-custom-racks), your autosaved plans (one entry per plan, under gearome-plan:), and, if you save a rack plan, a key that lets this browser edit or delete it later (gearome-plan-tokens). Clearing your browser's local storage deletes them. Whether you read measurements in millimetres or inches is kept in a cookie (gearome_unit_system) rather than local storage, because the page has to know before it draws. All are strictly necessary for features you asked for, so consent-free under §165 TKG 2021 / Art 5(3) ePrivacy.

What reaches our server, and when. Nothing about the plan you are building. Power, weight and fit are worked out in your browser, so a plan reaches us only when you save it, and an autosaved draft never does. The one exception is the anonymous usage events described in your analytics choice: those record which catalogue item you placed and at which rack unit. For equipment you defined yourself they carry its category and the identifier your browser generated for it, never the name you typed, and never the label you gave a mounting.

We set three strictly necessary cookies and no others. Cloudflare, our hosting and security provider, sets two against malicious traffic: __cf_bm (bot management) and cf_clearance (challenge clearance). Ours is gearome_analytics_optout, a plain on/off flag holding your opt-out choice so our server can honour it too. None is used for analytics or advertising.

Why there is no consent banner: §165 TKG 2021 and the ePrivacy Directive require consent to store information on your device, or to read information already stored there, unless it is strictly necessary for the service you asked for. Our assessment is that this does not arise here, because our analytics sets no cookies and stores nothing on your device; you can object at any time using the toggle above.

7. Processors and recipients

We share data with the following processors:

  • PostHog - product analytics. Data is sent to PostHog's EU Cloud. We act as controller and PostHog as our processor under PostHog's data processing agreement. See PostHog's privacy policy, DPA and list of sub-processors.
  • Cloudflare - hosting, CDN, security, edge compute and data storage, under its data processing agreement. See Cloudflare's privacy policy, DPA and list of sub-processors. Operating and protecting the service generates logs on its platform which may contain IP addresses; we keep them for 7 days under our legitimate interest in the security and stability of the service. Cloudflare also asks your browser to report failed connections (DNS, TLS or network errors) to its own endpoint, so problems that never reach a server stay visible; only failures are reported, never successful requests. Its network also holds the one-minute abuse counters described in section 3. Apart from those logs, these reports and those counters, no IP address is retained anywhere.
  • Google - email hosting (Google Workspace), provided by Google Cloud EMEA Limited. Google processes the contents of email correspondence on our behalf (see "Contacting us by email" above). See Google's Cloud Data Processing Addendum and list of Workspace sub-processors.

We do not sell personal data or use it for advertising.

Outbound and affiliate links. Some listings link out to merchants such as Amazon. They are independent controllers with their own privacy policies, not our processors. An affiliate link may carry an associate tag that lets the merchant credit the referral to us; that tag identifies Gearome, not you, and we pass them nothing about you. Once you leave Gearome, the merchant's policy governs.

8. International data transfers

Data stored for analytics is held in the EU (PostHog EU Cloud). Cloudflare operates a global network, so a request may be processed transiently at a location outside the EU and some operational data (such as security logs) may be processed outside the EU. Email correspondence is processed by Google, a US-based provider. For these transfers to the US we rely on the EU-US Data Privacy Framework, under which both Cloudflare and Google are certified, with the EU Standard Contractual Clauses as a fallback safeguard.

Saved rack plans are held in Cloudflare's storage network, which replicates worldwide rather than within the EU alone.

9. Retention

  • Analytics events (PostHog): retained for 1 year.
  • Cookieless salts: expire automatically after roughly 28 hours, after which that day's identifiers can no longer be reconstructed.
  • Saved rack plans: deleted 30 days after they were last saved or edited. Editing a plan resets its 30 days; an untouched plan still expires on schedule. You can also delete a plan yourself from the plan page, if your browser still holds the key it was saved with (see section 6).
  • Custom items and your plans (local storage): kept in your browser until you delete them or clear your browser data. This covers drafts you have not saved and your own copy of each plan you have saved, which stays on the device even after the link expires. Deleting a plan removes its copy too. We have no access to any of it; these copies are never sent to us, and custom items reach us only in a plan you save.
  • Analytics opt-out cookie: kept for 1 year, or until you switch analytics back on or clear your cookies.
  • Cloudflare operational / request logs: retained for 7 days.
  • Abuse-prevention counters: one minute.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art 15);
  • have inaccurate data corrected (Art 16);
  • have your data erased (Art 17);
  • restrict processing (Art 18);
  • object to processing based on legitimate interests (Art 21; see section 4);
  • data portability (Art 20).

To exercise any of these, write to hello@gearome.com (see "Contacting us by email" above).

A practical limit applies to the analytics data: its identifiers are pseudonymous, rotate daily and are never stored on your device, and we remove your IP and raw User-Agent. We therefore cannot tell which records relate to you (Art 11 GDPR) and may be unable to action an access, correction, erasure or portability request for that data. We will say so if it applies to yours. To stop further collection, use the analytics opt-out above.

A saved rack plan is a different case. Its link lets anyone view it, but only the browser that saved it, or last edited it, holds the key that can change or delete it (section 6); we store only a fingerprint of that key, not the key itself, so we cannot edit or delete a plan on your behalf either. Holding the link alone does not establish authorship, so we do not act on a deletion request based on the link alone: that would let anyone the link was shared with destroy it. Every plan expires by itself after 30 days if untouched (see section 9). If your browser has lost its key, or a plan contains personal data about you, write to us and we will weigh a request to remove it against the plan itself, which a claim to have written it is not.

We do not carry out automated decision-making, including profiling, in the sense of Art 22 GDPR.

11. Supervisory authority

If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority: in the EU member state where you live, where you work, or where the suspected infringement took place (Art 77 GDPR). The competent authority for Austria, where we are established, is:

Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Wien, Austria
dsb@dsb.gv.at
+43 1 52 152-0
www.dsb.gv.at

12. Changes to this policy

We may update this policy as the service or the law changes. The date it was last updated is shown at the top of this page. Where changes are material, we will take reasonable steps to make them apparent.