Privacy Policy
Last updated: April 2026
MrRooT ("we", "us", "our") operates the digital signage platform at mrroot.eu. This Privacy Policy explains how we collect, use, and protect your personal data when you use our website and services.
1. Data We Collect
We collect information you provide directly: name, email address, venue name, and phone number when you contact us or sign up. For our signage service, we collect device telemetry data (online/offline status, memory usage, WiFi signal strength, screen model) from deployed player devices. We do not collect personal data from your venue's customers or visitors.
2. How We Use Your Data
We use your contact information to respond to inquiries, set up your account, and provide support. Device telemetry is used to monitor screen health, diagnose issues, and ensure uptime. We may send you service-related emails (account updates, maintenance notices). We never sell your data to third parties.
3. Data Storage & Security
Your data is stored on Supabase (EU Frankfurt region) and our Hetzner server (Falkenstein, Germany). All data stays within the EU. We use TLS encryption for all data in transit and encrypt sensitive data at rest. Access to production systems is restricted to authorized personnel.
4. Third-Party Services
We use Supabase for authentication and database services, Hetzner for hosting, Cloudflare for DNS and CDN, and Let's Encrypt for SSL certificates. Each provider has their own privacy policy. We do not share your data with advertisers or analytics companies.
5. Cookies
Our website uses only essential cookies required for authentication and language preferences. We do not use tracking cookies, analytics cookies, or third-party advertising cookies. No consent banner is needed because we only use strictly necessary cookies.
6. Your Rights (GDPR)
Under GDPR, you have the right to: access your personal data, correct inaccurate data, request deletion of your data, restrict processing, data portability, and object to processing. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Data Retention
We retain your account data for as long as your subscription is active, plus 30 days after cancellation. Device telemetry data is retained for 90 days. Contact form submissions are retained for 12 months. You can request earlier deletion at any time.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice on our website. Your continued use of our services after changes take effect constitutes acceptance of the updated policy.
9. Contact Us
For privacy-related questions or to exercise your GDPR rights, contact: MrRooT — [email protected] — Prague, Czech Republic.