Privacy Policy
Last updated: April 2026
1. Controller
Thurn is operated from Switzerland. Operator identity (legal name, registered address, commercial register entry) is published on the imprint page. For data protection inquiries: @EMAIL@.
2. What data we collect
- Letter content: The text you type or upload, used solely to generate and mail your letter.
- Recipient address: Required to address and deliver the letter.
- Sender address: Optional. Printed on the letter if provided.
- Email address: Optional. Used for order confirmation, shipping notification, unsubscribe / data-deletion confirmations, and — only with a separate opt-in — post-delivery follow-up and letter-recovery reminders.
- Payment data: Processed by Stripe. We do not store credit card numbers.
- IP address: Used transiently for rate limiting and fraud prevention. Not stored long-term.
- Referral codes: If you receive a discount code after a completed order, we store the code issuance record (code value, issuing order, redemption state) to prevent double-redemption.
3. Why we process your data — legal bases
- Contract performance (Swiss nDSG Art. 31 para. 2 lit. a; GDPR Art. 6(1)(b)): to generate, print, and mail the letter you ordered, to take payment, and to send transactional notifications (order confirmation, shipping update).
- Legitimate interests (nDSG Art. 31 para. 2 lit. d; GDPR Art. 6(1)(f)): rate limiting, anti-abuse, fraud prevention, diagnostic / security logging. Balanced against your interest in minimal data processing — data is either transient or short-retention.
- Consent (nDSG Art. 6 para. 7; GDPR Art. 6(1)(a)): optional marketing-adjacent emails (post-delivery follow-up, abandoned-letter recovery reminders). Each such email includes a one-click unsubscribe; consent is withdrawable at any time without affecting contract emails.
- Legal obligation (nDSG Art. 31 para. 2 lit. e; GDPR Art. 6(1)(c)): retention of accounting and tax records where required.
4. Data processors (sub-processors)
We share data only with the processors below, each bound by a data-processing agreement:
- Stripe Inc. — Payment processing (US / EU).
- A&O Fischer GmbH & Co. KG (onlinebrief24.de) — Letter printing and mailing for orders routed through OB24 (Germany).
- Pingen AG — Letter printing and mailing for orders routed through Pingen (Switzerland). Used when the dispatch routing rules select Pingen (typically Swiss national / priority mail).
- Hetzner Online GmbH — Server hosting and object storage (Germany / Finland).
- Cloudflare Inc. — Edge delivery, TLS termination, DDoS protection (US / EU).
- smtp2go Pty Ltd — Transactional email delivery, including bounce and complaint handling (Australia, with EU sub-processors).
- Plausible Analytics — Privacy-respecting, cookieless web analytics (self-hosted / EU). Only enabled when the operator has configured a Plausible endpoint; no personal identifiers are sent and no cross-site tracking is performed. See section 7.
5. Data retention
- Letter PDFs: Deleted within 14 days after dispatch.
- Order metadata (addresses, status, timestamps): Retained for 90 days for support, then deleted.
- Email events (bounces, complaints, suppression list): Retained for 180 days so we stop re-sending to addresses that bounced or complained. Required to protect deliverability.
- Inbound webhook events (Stripe, Pingen, OB24 delivery updates): Retained for 90 days for audit and replay-protection.
- Audit logs (admin actions, dispatch decisions, status transitions): Retained for 90 days.
- Payment and accounting records: Retained as required by tax law (typically up to 10 years under Swiss / EU bookkeeping obligations).
- Referral-code issuance records: Retained until the code expires and has been used or voided, then purged on the next retention run.
6. Your rights
You have the right to access, correct, and delete your personal data. The fastest paths are self-service: request a copy of your data or request deletion. Both pages take your email and send a confirmation link. You can also email @EMAIL@ from the address on file. You can unsubscribe from non-transactional emails at any time — every such email carries a one-click unsubscribe link.
You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or with your local EU supervisory authority if you consider that our processing of your data infringes applicable data-protection law.
7. Cookies & analytics
We use only strictly necessary session state (language preference, theme preference) stored client-side. We do not use advertising cookies, cross-site tracking, or consent-banner cookies.
When the operator has configured an analytics endpoint, aggregate traffic analytics are provided by Plausible Analytics — cookieless, no personal identifiers, no cross-site profiling. If analytics are not configured, no analytics requests are sent at all.
8. International data transfers
Most processing occurs within the EEA or Switzerland. Processors based outside the EEA (Stripe Inc. — US; smtp2go — Australia; Cloudflare Inc. — US) rely on Standard Contractual Clauses and, where applicable, supplementary measures to meet Swiss and EU adequacy requirements.
9. Changes
We may update this policy. Material changes will be noted on this page with a new "last updated" date.