Who we are
Stevin.AI ("Stevin") is an AI platform operated by WPOT B.V., a company registered in the Netherlands. We help marketing teams and agencies detect campaign issues earlier than regular reporting does.
What data we collect
- Account data: name, business email, organization, role within your team.
- Campaign and analytics data: only through OAuth integrations that you initiate (Google Ads, Meta, GA4, etc.). We receive read-only access to campaign metrics, no payment or billing information.
- Platform usage data: page visits, feature usage, timestamps, to improve the service and detect abuse.
- Technical data: IP address, browser type, device type for security and debugging.
- Website and lead context: when you submit a contact or demo form, we store the form details with limited context such as landing page, referrer, UTM parameters, campaign clicks and recently visited pages. We use this to follow up properly and understand which content and campaigns create qualified leads.
Why we use it
- To give you access to the platform and connected data.
- To generate signals, alerts and recommendations for your campaigns.
- To detect and resolve security incidents.
- To improve the service based on anonymous usage patterns.
- To qualify website requests and follow up with the right context.
We do not sell personal data. We do not share your campaign data with other Stevin customers. Strict tenant isolation applies per organization.
Retention
We retain account data for as long as you have an active account, plus 12 months after termination for administrative and tax obligations. Campaign data is deleted within 30 days after a platform is disconnected or the service is cancelled.
Subprocessors
We use a limited set of subprocessors, all under a data processing agreement:
- Supabase (database hosting, EU region): platform data storage.
- AWS (EU region): application infrastructure.
- Vercel (EU region): front-end hosting.
- Resend (EU region): transactional email.
- Anthropic / OpenAI: for AI features only, with stripped or anonymous prompts where possible; no personal data goes into training datasets.
OAuth integrations (such as Google Ads, Meta, Pinterest, LinkedIn) run directly between you and the platform. We only receive the tokens you authorize.
Your rights
Under GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your data. Send a request to privacy@stevin.ai. We respond within 30 days.
Not satisfied? You can lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
Cookies
On stevin.ai we use necessary cookies for basic functions such as session, language preference and security. Without consent, we do not load Microsoft Clarity and we do not grant Google or advertising platforms permission to use analytics or advertising cookies.
If you choose statistics, we use Google Analytics and Microsoft Clarity to analyze page views, interactions, scroll behavior, clicks, heatmaps and session recordings. If you choose marketing, we use Google Ads and Meta for campaign and conversion measurement. Where relevant, form data is only sent in hashed form for enhanced conversion measurement.
You can choose between necessary, statistics, marketing or accept all through the cookie settings. We do not sell personal data.
Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production data is restricted to specifically authorized employees, with logging and periodic audits.
Changes
We may amend this privacy policy. For material changes we notify active users at least 14 days before the change takes effect.