Legal
Privacy Policy
Last updated:
This Privacy Policy explains how Matthias Blank (“we”, “us”), a natural person operating the Vantage Insights service (the “Service”) as a Swiss sole proprietor, processes personal data when you visit or use the Service. It applies in addition to our Terms of Service and is intended to satisfy the transparency requirements of the revised Swiss Federal Act on Data Protection (revFADP) and, where applicable to visitors in the EU/EEA or the UK, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who is responsible (controller)
The data controller for the Service is Matthias Blank, a natural person resident in Switzerland and operating the Service as a sole proprietor. Full operator details are listed in our Impressum. You can reach us at hello@vantage-energies.com for any question or request about your personal data. This address is also the contact point for data-protection matters for users in Switzerland and the EU/EEA.
2. What personal data we process
We process the following categories of personal data:
2.1 Account data
- Email address (required to create an account)
- Display name (optional; shown on comments)
- Hashed password, if you set one (stored using a modern, salted password-hashing algorithm; never in clear text). Accounts can also be used without a password, via emailed single-use sign-in links.
- Third-party sign-in: if you choose “Continue with Google” or “Continue with Microsoft”, we receive your account email address and a provider identifier from that provider. We do not receive your password or your account content. Where the provider does not confirm the address as verified, we verify it ourselves by email before treating it as confirmed.
- Marketing-newsletter opt-in flag and confirmation timestamp
- Account creation date, last sign-in date, email-verification status, ban status (if applicable)
2.2 Subscription & billing data
- Subscription tier (FREE / PAID), plan (monthly / yearly), status, period end
- Stripe customer ID and Stripe subscription ID (no card data ever touches our servers)
- Invoice history (held by Stripe; we hold only the metadata above)
2.3 Usage & telemetry data
If you accept analytics cookies, we generate a random anonymous identifier (UUID) stored in the vantage_anon_id cookie and use it to attribute the following events to a pseudonymous visitor:
- Page views on
/insights/*pages - Article and chart impressions
- Email-newsletter signups and email-confirmation events
- Signup, sign-in, and upgrade-to-Pro funnel steps
The cookie itself carries no name, email, or other identifying information. We may join it to your account once you sign in, so that we can understand whether free-tier visitors eventually convert to paying subscribers. If you decline analytics cookies, none of the events above are recorded.
We also use PostHog, a product-analytics service, to understand how the Service is used and to improve it. If you accept analytics cookies, it processes the usage events above along with page-interaction data and session replay; any text you type is always masked. Signed-in activity is attributed to your account. If you decline analytics cookies, PostHog is never loaded.
2.4 Community & content data
- Comments you post on articles
- Community posts and replies
- Newsletter email captures (with double-opt-in confirmation)
2.5 Technical logs
Our hosting provider retains short-term technical logs: IP address, user agent, request URL, and response status. These logs are retained for a maximum of 30 days and used only to operate, secure, and debug the Service.
3. Why we process it (purposes and legal bases)
Under the revFADP we rely on legitimate contractual and operational grounds; under the GDPR the applicable legal bases are listed alongside each purpose:
- Provide the Service: account creation, sign-in, subscription management, content delivery. GDPR Art. 6(1)(b), contract performance.
- Process payments via Stripe. We receive the subscription metadata, Stripe handles card data. GDPR Art. 6(1)(b), contract performance.
- Send transactional emails: email verification, password reset, magic sign-in link, payment-failed notifications. GDPR Art. 6(1)(b), contract performance.
- Send the newsletter, only after explicit double-opt-in. You can unsubscribe with one click from every email. GDPR Art. 6(1)(a), consent.
- Analytics & product improvement: pseudonymous usage metrics, only if you accept analytics cookies. GDPR Art. 6(1)(a), consent.
- Security & abuse prevention: short-term technical logs, rate limits, ban enforcement. GDPR Art. 6(1)(f), legitimate interest in keeping the Service available and free of abuse.
- Legal compliance: bookkeeping, tax records, response to lawful requests. GDPR Art. 6(1)(c), legal obligation.
4. Cookies & similar technologies
We use the smallest possible set of cookies, split into two categories:
- Strictly necessary: the session cookie (keeps you signed in), the cookie-consent record (
vantage_cookie_consent), and the CSRF token. These are set without consent because the Service cannot function without them. - Analytics (optional): the anonymous-visitor cookie (
vantage_anon_id), Vercel Analytics and Vercel Speed Insights, and the PostHog analytics cookie (ph_*, which stores the random visitor identifier and session state), all enabled only after you click “Accept analytics” in the cookie banner. You can withdraw consent at any time using the “Cookie preferences” link in the footer.
We do not use third-party advertising cookies, retargeting pixels, social plug-ins, or behavioural-profiling trackers.
5. Sub-processors and recipients
We use a small number of service providers (“sub-processors”) to operate the Service. Each one only processes the personal data needed for its specific function, under a data-processing agreement (DPA) where required:
- Vercel Inc. (United States) provides application hosting and edge delivery (always active, strictly necessary), plus Vercel Analytics and Vercel Speed Insights for pageview and Web-Vitals metrics (active only after you click “Accept analytics” in the cookie banner). Primary processing region: Frankfurt (eu-central). DPA in place; transfers covered by Standard Contractual Clauses.
- Neon, Inc. (United States) runs the managed PostgreSQL database for account, subscription, and content data. Primary processing region: Frankfurt (eu-central). DPA in place; SCCs apply.
- Stripe Payments Europe, Ltd. (Ireland) handles payment processing, card tokenisation, the customer portal, and invoicing. Your card data is sent directly to Stripe and never stored on our servers. DPA in place.
- Resend, Inc. (United States) delivers transactional and newsletter email. We share your email address, display name, and the message content. DPA in place; SCCs apply.
- PostHog, Inc. (United States) provides product analytics, including session replay, active only after you accept analytics cookies. Receives the usage data described in section 2.3 and, for signed-in users, the account identifier and email address. GDPR Art. 6(1)(a), consent. DPA in place; transfers covered by Standard Contractual Clauses.
- Functional Software, Inc. (Sentry) (United States) provides application error and performance monitoring. Receives diagnostic event data which can include your IP address and the URL path where an error occurred; we scrub email addresses, tokens, and request cookies before transmission. GDPR Art. 6(1)(f), legitimate interest in a secure, working Service. DPA in place; SCCs apply.
- Upstash, Inc. (United States) provides Redis-backed rate limiting to protect sign-in and public endpoints from abuse. Receives your IP address as a short-lived rate-limit key. GDPR Art. 6(1)(f), legitimate interest in security and abuse prevention. DPA in place; SCCs apply.
- Cloudflare, Inc. (United States) supplies bot protection (Turnstile) on the sign-in, sign-up, and newsletter forms. Receives your IP address and browser/device signals to distinguish humans from automated abuse. GDPR Art. 6(1)(f), legitimate interest in security and abuse prevention. DPA in place; SCCs apply.
- Google Ireland Limited (Ireland) provides the optional “Sign in with Google” authentication. Used only if you choose it; Google then confirms your identity to us and shares your verified email address and a provider identifier. Google acts as an independent controller for its own sign-in service; see Google’s privacy policy. GDPR Art. 6(1)(b), contract performance (providing the sign-in method you chose).
- Microsoft Ireland Operations Limited (Ireland) provides the optional “Sign in with Microsoft” authentication. Used only if you choose it; Microsoft then confirms your identity to us and shares your account email address and a provider identifier. Microsoft acts as an independent controller for its own sign-in service; see Microsoft's privacy statement. GDPR Art. 6(1)(b), contract performance (providing the sign-in method you chose).
We do not sell personal data and we do not share it with third parties for their own marketing purposes.
6. International transfers
Some of our sub-processors are established outside Switzerland and the EEA, in particular in the United States. In those cases we rely on (i) the relevant adequacy decisions issued by the Swiss Federal Council and the European Commission, where they apply, and (ii) Standard Contractual Clauses with appropriate supplementary measures. A copy of the safeguards in place is available on request from hello@vantage-energies.com.
7. How long we keep your data
- Account data: kept for as long as your account is active. If you delete your account, we erase it within 30 days, except for what we must keep for tax or legal reasons (see below).
- Billing and invoice metadata: 10 years, as required by Swiss tax and bookkeeping rules.
- Telemetry events: 24 months, then deleted or fully anonymised.
- Newsletter signups: until you unsubscribe; an unsubscribe record is kept so we don’t accidentally re-add you.
- Technical logs: up to 30 days.
8. Your rights
You have the following rights regarding your personal data:
- Access: a copy of the personal data we hold about you (revFADP / Art. 15 GDPR).
- Rectification: correction of inaccurate or incomplete data (revFADP / Art. 16 GDPR).
- Erasure: deletion of your data, subject to legal retention duties (revFADP / Art. 17 GDPR).
- Restriction: limit processing while a dispute is resolved (Art. 18 GDPR).
- Data portability: a structured export of the data you provided to us (revFADP / Art. 20 GDPR).
- Withdraw consent: at any time, with effect for the future, for processing based on your consent (newsletter, analytics).
- Object: to processing based on our legitimate interests (Art. 21 GDPR).
To exercise any of these rights, email hello@vantage-energies.com. We answer within 30 days. You can unsubscribe from the newsletter via the one-click link in every email.
If you believe our processing infringes data-protection law, you have the right to complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, if you are in the EU/EEA, to your local data-protection authority.
9. Security
We protect personal data through technical and organisational measures: TLS in transit, encryption at rest, salted password hashing, role separation between application code and database, least-privilege secrets management, and a documented incident-response procedure. No system is perfectly secure; if we ever become aware of a breach that creates a high risk to your rights, we will notify the relevant authority and you directly where the law requires it.
10. Automated decision-making
We do not use automated decision-making (in the sense of Art. 22 GDPR) that produces legal or similarly significant effects for you.
11. Children
The Service is intended for users aged 16 or older. We do not knowingly process personal data of children under 16. If you believe a minor has created an account, please contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves or as the law changes. Material changes will be announced by email to subscribers and by a prominent notice on this page. The “last updated” date at the top of this page always reflects the current effective version.
13. Contact
Privacy questions, rights requests, and notices of any kind: hello@vantage-energies.com.