Privacy policy
Last updated: 11 October 2026
1. Controller
The controller responsible for processing personal data on the website moodz.io and in the application app.moodz.io is:
Alaeddin Abdellaoui4310 Rheinfelden
Switzerland
Email: support@moodz.io
Please send questions about data protection and requests about your rights to this address.
2. General information
This privacy policy covers the website moodz.io and the application app.moodz.io (together “Moodz”). It explains which personal data we process, for what purposes, on what basis, to whom we pass it, how long we keep it and what rights you have.
It follows the Swiss Federal Act on Data Protection (FADP) and, where you are in the European Union or the European Economic Area, the General Data Protection Regulation (GDPR). Where the FADP speaks of “processing” and “personal data”, the same is meant as under the GDPR.
The website and the application are transmitted only over encrypted connections (HTTPS).
3. Legal bases
Where the GDPR applies, we base processing on the following grounds, which we name for each purpose:
- Contract and pre-contractual steps (Art. 6(1)(b) GDPR): where we need data to provide Moodz to you or to answer your request;
- Legal obligation (Art. 6(1)(c) GDPR): where a law obliges us to process or disclose data;
- Legitimate interests (Art. 6(1)(f) GDPR): where processing is needed to run Moodz securely and without errors, and your interests do not override ours.
We base no processing on consent.
Under the FADP we process personal data in line with the principles of Art. 6 FADP: lawfully, in good faith, proportionately and only for the stated purpose. Where the FADP requires a justification, we rely on the contract with you or on our overriding interest (Art. 31 FADP).
4. Hosting and server log files
The website and the application are hosted by Vercel; the application runs on servers in Frankfurt am Main. With every request Vercel processes technically necessary data: your IP address, date and time, the address requested, the status code, and your browser and operating system. Without these data the pages cannot be delivered.
The application also logs every request to its interface with the time, address, result, duration, a request number and the identifiers of your account and of your studio or house. This lets us investigate problems you report to us.
The purpose is delivering the website and the application and running them securely (Art. 6(1)(f) GDPR). Vercel keeps these logs only briefly, under its retention periods.
5. Audience measurement
On the website we count page views with Vercel Web Analytics. It sets no cookies and stores nothing in your browser. It records the page viewed, the referring page, country and region, browser, operating system and device type. To count visits, Vercel derives a hash from the request, which is discarded after 24 hours. We see only aggregated numbers, never individual visitors.
The purpose is to understand which pages are read, so that we can improve the website (Art. 6(1)(f) GDPR). We use no audience measurement in the application.
6. Contacting us and the request form
Request form
When you request access or a demo through the form, we process what you enter: name, studio or company, role, email address, phone number, whether you are a studio or a design house, your message and the language of the page. Name, studio or company, email address and the kind are required; without them we cannot answer. Role, phone number and message are optional.
We use the details to answer your request and, if you would like to use Moodz, to set up your account (Art. 6(1)(b) GDPR). The request is stored in our database at Supabase (Frankfurt am Main) and emailed through Resend to support@moodz.io. You receive no confirmation email.
To prevent abuse we limit the number of requests per sender. For this we store a hash of your IP address, not the address itself, for one day at most (Art. 6(1)(f) GDPR).
Requests by email
When you write to support@moodz.io, we process your email address and the content of your message to answer you (Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR).
7. Accounts in the application
The application is used by interior design studios and furniture houses and their staff. Accounts are by invitation only.
For your account we process your name, email address, password (stored only as a hash), role, language and, if you set one up, your second factor. When you sign in, the sign-in service (Supabase Auth) stores your sessions and sign-in events with IP address and browser. We need your name and email address; without them no account is possible.
The basis is the contract with you or with your studio or house (Art. 6(1)(b) GDPR). Where you use Moodz as their employee, it is their and our legitimate interest in providing the agreed service and protecting the accounts (Art. 6(1)(f) GDPR).
8. Content of studios and houses
Studios and houses store projects, orders, messages, images and documents in Moodz, including the names and addresses of their clients and their own company details. The studio or house is the controller of this content; we process it only on its behalf and on its instructions (processing on behalf, Art. 28 GDPR, Art. 9 FADP). Please direct questions about it to the studio or house first.
9. Change history
We record who changed what and when, for example sent an order or invited a member. This lets studios and houses follow their work and lets us investigate misuse (Art. 6(1)(b) and (f) GDPR).
10. Sending emails
We send only the emails that belong to the service: invitations, password resets and messages about orders and connections. They are sent through Resend. Each email is recorded with its recipient and content in our database, so that it is delivered reliably and sent again after an error (Art. 6(1)(b) and (f) GDPR). We send no marketing emails or newsletters.
11. Error monitoring
When an unexpected error occurs in the application, we send an error report to Sentry: the error, the time, the address called, the request number and the identifiers of your account and of your studio or house, but not your IP address or the content of the request. Sentry stores the reports in its EU region in Frankfurt am Main. The purpose is finding and fixing errors (Art. 6(1)(f) GDPR).
12. Protection against automated access
When you sign in to the application or reset your password, Cloudflare Turnstile checks that a person is sending the form. For this Cloudflare processes your IP address and technical features of your browser. The purpose is protecting accounts from automated attacks (Art. 6(1)(f) GDPR). The website does not use Turnstile.
13. Cookies and local storage
The website sets no cookies and stores nothing in your browser.
The application sets only the cookies that signing in technically needs:
__Host-moodz_tokenkeeps you signed in for images and downloads while the session lasts;__Host-moodz_act_asremembers which studio or house a platform administrator is working in.
In your browser's storage (localStorage) the application keeps your sign-in session and your settings: language, appearance, the collapsed navigation and the order you last chose. None of it serves advertising or tracking across other websites, so we do not ask for consent. You can delete cookies and stored data in your browser at any time; you then need to sign in again.
14. Recipients and processors
We pass personal data only to service providers that process it on our behalf and with whom we have data processing agreements:
- Vercel Inc., USA: hosting of the website and the application (servers in Frankfurt am Main), logs, the website's audience measurement;
- Supabase Inc., USA: database, sign-in and file storage (servers in Frankfurt am Main);
- Resend, USA: sending the emails;
- Functional Software Inc. (Sentry), USA: error reports (EU region, Frankfurt am Main);
- Cloudflare Inc., USA: Turnstile, which protects sign-in from automated access;
- a monitoring service that regularly checks that the application is reachable; it receives no data about you.
Studios and houses see the data they share with each other: for example, a house sees the orders a studio sends it and the studio's company details. Authorities receive data only where a law obliges us (Art. 6(1)(c) GDPR).
15. Transfers to other countries
Our database and the application run in Frankfurt am Main (Germany). Several providers are based in the USA and may access or process data there. Where a provider is certified under the EU-US Data Privacy Framework and its Swiss counterpart (the Swiss-US Data Privacy Framework), the transfer relies on the adequacy decisions of the European Commission and the Swiss Federal Council. Otherwise it relies on the European Commission's standard contractual clauses, with the amendments Switzerland requires (Art. 46(2)(c) GDPR, Art. 16(2)(d) FADP).
16. Retention
We keep personal data only as long as the purpose requires or a law prescribes:
- Account and content: as long as the account, or the studio or house, exists on Moodz. When a studio or house is archived, its data is kept until it is restored or deleted on request.
- Change history and sent emails: as long as the studio's or house's data exists, until deleted on request.
- Requests from the form and by email: until deleted on request.
- Hashes against misuse of the form: one day at most.
- Logs at Vercel and error reports at Sentry: under these providers' short retention periods.
17. Your rights
You have the right
- of access to the data we process about you (Art. 15 GDPR, Art. 25 FADP);
- to have incorrect data rectified (Art. 16 GDPR, Art. 32 FADP);
- to have your data erased (Art. 17 GDPR, Art. 32 FADP);
- to restriction of processing (Art. 18 GDPR);
- to receive the data you provided to us in a common electronic format, or to have it transmitted (Art. 20 GDPR, Art. 28 FADP);
- to object to processing based on our legitimate interest (Art. 21 GDPR, Art. 30(2)(b) FADP).
You could withdraw any consent you gave us at any time (Art. 7(3) GDPR); at present, however, no processing is based on consent.
Write to support@moodz.io. For content a studio or house has stored in Moodz, we pass your request on to them.
18. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch; in the EU with the authority of the country where you live or work or where the alleged infringement took place, in Germany with the data protection authority of your federal state (Art. 77 GDPR).
19. No automated decision-making
We make no automated individual decisions (Art. 22 GDPR, Art. 21 FADP) and create no profiles.
20. Changes to this policy
We update this policy when Moodz or the law changes. The version published here applies.
Last updated: 11 October 2026
See also the legal notice.