Privacy Policy
This Privacy Policy explains how Dreamer Studios [GmbH], trading as Elev8labs (“Elev8labs”, “we”, “us”), collects, uses and protects personal data when you use the mastroHQ platform and our websites. We comply with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
The short version
- We collect only what we need to run mastroHQ for you, and we never sell your data.
- Data about your own customers stays under your control — we process it on your behalf, not for our own purposes.
- We share data only with vetted providers (like Supabase and Stripe) who help us run the service.
- If you connect a Gmail mailbox, that data powers your inbox and nothing else — see the Google user data section below.
- You can access, correct, export or delete your data at any time.
- Written to the Swiss FADP and GDPR — questions go to privacy@mastrohq.com.
The short version is a friendly summary — the full text below is what applies. This is a working draft and will be reviewed by counsel before launch; items in square brackets are still to be filled in.
1. Controller and contact
For the personal data described in this policy that we process for our own purposes (for example account administration and our website), the controller is Dreamer Studios [GmbH], [Registered address, Basel-Stadt, Switzerland].
For personal data you upload about your own clients and projects (Customer Data), you are the controller and we act as your processor — see our Data Processing Agreement.
Privacy contact: privacy@mastrohq.com. If required, our representative in the EU/EEA is [EU representative — to be appointed if applicable].
2. The personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, business name, email, role, canton, team size | You, at sign-up / booking |
| Authentication | Magic-link tokens, OAuth identifiers, session cookies | You / identity providers (Google, Supabase Auth) |
| Billing | Plan, billing interval, payment status, last 4 digits / card brand (held by Stripe) | You / Stripe |
| Customer Data you upload | Your End Clients’ names, addresses, contact details, quotes, project notes, photos, signatures, messages | You and your Authorised Users |
| Communications | Emails, WhatsApp messages, and metadata routed through connected mailboxes / numbers | You and your correspondents |
| Usage & device | IP address, browser/device type, pages viewed, actions, log timestamps | Automatically, via our app and analytics |
| Support & marketing | Enquiries, demo requests, waitlist / newsletter sign-ups | You |
We do not intentionally collect special-category data. Please do not upload sensitive personal data unless strictly necessary for your work.
3. Why we use it and our legal basis
| Purpose | Legal basis (GDPR / revFADP) |
|---|---|
| Provide, operate and secure the Service; create and manage your account | Performance of a contract |
| Process payments and prevent fraud | Contract; legal obligation; legitimate interests |
| Provide support and respond to enquiries | Contract; legitimate interests |
| Improve, troubleshoot and develop the Service (incl. analytics) | Legitimate interests (a stable, useful product); consent where required for non-essential cookies |
| Send service messages | Contract; legitimate interests |
| Send marketing / newsletter | Consent (and you can opt out at any time) |
| Comply with legal, tax and accounting obligations | Legal obligation |
Under the revFADP we may process personal data where there is a justified interest and no overriding interest of the data subject prevails; the bases above map to the equivalent revFADP grounds.
4. Cookies and analytics
We use cookies and similar technologies as described in our Cookie Policy. Non-essential analytics (for example PostHog) are used to understand and improve the product, and are set in line with your cookie choices where consent is required.
5. Who we share data with (sub-processors)
We share personal data with carefully selected service providers who process it on our behalf under contract. Current providers include:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU [region to confirm] |
| Vercel | Application hosting and delivery | EU / global edge |
| Stripe | Payment processing | EU / US |
| Resend | Transactional & marketing email | EU / US |
| Twilio | WhatsApp / messaging | EU / US |
| Sign-in and Gmail mailbox sync (if you connect it) | EU / US | |
| OpenAI / Replicate | AI room renders (if used) | US |
| Cal.com | Demo booking | EU / US |
| PostHog | Product analytics | EU [region to confirm] |
We also disclose data where required by law, to protect our rights, or in connection with a merger or acquisition (with appropriate safeguards). We do not sell personal data.
6. Google user data (Google Sign-In and Gmail)
If you sign in with Google or connect a Gmail mailbox to mastroHQ, we receive data from Google APIs. This section describes exactly how that data is handled, in line with the Google API Services User Data Policy.
What we access
- Google Sign-In: your name, email address and profile picture, used only to create and authenticate your account.
- Gmail — read (
gmail.readonly, only if the account owner connects a mailbox in Settings → Connections): new messages arriving from the moment of connection onwards. For each message we store the sender and recipient addresses, subject, date, threading headers and the plain-text body (truncated). We do not store attachments, and drafts, spam and trash are excluded from sync. - Gmail — send (
gmail.send): used solely to send messages you compose and send from the mastroHQ inbox, from your own connected address.
How we use it
Google user data is used only to provide the user-facing features you see in the app: showing your email conversations threaded by client and project in the unified inbox, matching messages to your contacts, and sending the replies you write. We do not use Google user data for advertising, we do not sell it, and we do not use it for any purpose unrelated to these features. Google user data is not used to develop, improve or train generalised artificial-intelligence or machine-learning models, and is not transferred to third-party AI/ML services.
Who we share it with
We do not transfer Google user data to third parties except: to the sub-processors listed in section 5 that host and operate the Service (Supabase for storage, Vercel for hosting) strictly on our behalf; to the authorised users of your own organisation, according to their roles; and where required by law or to protect the security of the Service. It is never sold and never shared with data brokers or advertisers.
How we protect it
Gmail OAuth tokens are encrypted at rest with AES-256-GCM and are accessible only to our server tier — never to browsers or other organisations. Synced messages are protected by the same encryption in transit, database row-level security and multi-tenant isolation described in section 9.
Retention and deletion
Synced messages are retained as part of your organisation's records for as long as your account is active, and are deleted as described in section 8. You can disconnect a mailbox at any time in Settings → Connections: syncing stops immediately, we delete the stored OAuth token and revoke it with Google. You can also revoke mastroHQ's access at any time from your Google Account permissions, and request deletion of all synced Google data by contacting privacy@mastrohq.com.
Limited Use
mastroHQ's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. International transfers
Some providers process data outside Switzerland or the EU/EEA. Where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner) and additional technical measures.
8. How long we keep it
- Account & Customer Data: for as long as your account is active, then deleted or anonymised within a reasonable period after termination (typically 30 days for export, then deletion), subject to your instructions in the DPA.
- Billing & tax records: retained for the periods required by Swiss law (generally up to 10 years).
- Marketing data: until you withdraw consent or unsubscribe.
- Logs & analytics: retained for a limited period for security and improvement.
9. How we protect data
We use technical and organisational measures including encryption in transit, access controls, multi-tenant isolation enforced at the database level (row-level security), least-privilege service credentials, and encryption of stored integration credentials. No system is completely secure, but we work to protect your data and to notify you of material breaches as required by law.
10. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your local authority.
To exercise your rights, contact privacy@mastrohq.com. If your request concerns data held on behalf of one of our business customers (where you are an End Client), we will refer you to that customer as the controller.
11. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or in-app. The “last updated” date above shows the current version.
13. Contact
Dreamer Studios [GmbH] (trading as Elev8labs), [Registered address, Basel-Stadt, Switzerland]. Privacy enquiries: privacy@mastrohq.com.