Last updated August 2026
This page covers this website (getclientbase.app): the waitlist form, the reviews page, and the client portal at /portal/.
It does not cover the Clientbase macOS app itself, which keeps your client data on your own Mac. The one exception is the client portal — where a Clientbase user chooses to share a project with their own client, the details of that project are sent to this server so the client can see them. That is described under "The client portal" below.
Leander Schuldt is the controller for data processed through this site. Contact: leander@getclientbase.app.
Waitlist signups. If you join the waitlist, we store the email address you enter, so we can notify you when Clientbase launches. Nothing else is collected in that form. You'll receive one confirmation email right after signing up.
Reviews. If you submit a review, we store your license key (used once, server-side, only to confirm you're an actual customer — it is never shown publicly), your star rating, your review text, and your display choice (your name, an alias, or anonymous). Only the rating, review text and display choice are ever shown publicly.
Client portal accounts. If a Clientbase user gives you access to the portal, we store your display name, a username derived from it, and a hash of your password — never the password itself. If you add an email address, we store it and a record of whether you confirmed it. If you upload a profile picture or fill in billing details (company, address, postcode, city, country, phone, VAT ID), we store those too. You can view and change all of it under Account in the portal.
Project data in the portal. For each project shared with you, we store its name, status, deadline, expected delivery date, progress, the list of work steps, revision dates, the freelancer's status notes, any links you post, the review links they send you, your answers to those, tracked time where the project is billed hourly, and the invoice PDF where one is published.
Portal messages. Messages exchanged between you and the freelancer through the portal are stored on this server so both sides can read the thread.
Portal activity log. To let the freelancer see who has been in and to notice attempted break-ins, we record sign-ins, failed sign-ins, sign-outs, password changes, added and confirmed email addresses, sent messages, opened invoices, delivered material and answers to review versions — each with a timestamp, the IP address the request came from, and the browser identification string. This log is deleted automatically after 180 days.
Server logs. Like any web server, ours automatically logs standard technical data (IP address, browser type, timestamp) for security and stability. This is not linked to your waitlist or review submissions.
This site and the data above are hosted on a server provided by IONOS SE, located in Germany.
To actually send you email — the waitlist confirmation, and your license key if you buy Clientbase — we use Resend as our email delivery provider. Your email address is passed to them for that purpose only; they don't use it for anything else. Payments (once Clientbase is on sale) are handled by Paddle, who act as the merchant of record and receive the billing details you enter at checkout.
Both are processors acting on our instructions under data processing agreements. Where they process data outside the EU, that transfer is covered by the EU Standard Contractual Clauses.
Two parties are involved. The Clientbase user — the freelancer you hired — decides which of your projects appear in the portal and what they contain; they are the controller for that data. We provide and run the software and the server on their instructions, as their processor.
Anything you enter yourself in the portal — your email address, profile picture, billing details, messages, links, answers and the notes you pin to a video — is visible to that freelancer. That is the point of the portal, and it is worth being aware of before you type something you would not send them directly.
If you want your portal data corrected or removed, the fastest route is to ask the freelancer directly, since they control it. You can also write to us at the address below and we will pass it on and act on their instruction.
A freelancer can create a link that lets someone watch one cut and comment on it without an account — a colleague, a manager, anyone whose opinion is wanted once. If you opened this page through such a link, this section is about you.
You are asked for a name. Type whatever you want to be called; nothing checks it, and it is stored only so the freelancer can tell whose note is whose. Your name is kept with each note you leave, and your IP address is recorded with the request in our server logs, as with every request to any website. The name you typed is also remembered in your own browser so the link does not ask again — that stays on your device and you can clear it by clearing site data.
Anyone holding the link sees the video, everyone's notes, and nothing else: no other project, no other version, and no download. The link stops working four days after it was made, or sooner if the freelancer withdraws it. Your notes belong to the project and stay with it after the link expires — ask the freelancer if you want one removed.
The client portal sets one cookie. When you sign in, we store a session identifier in a cookie so you stay signed in. It is strictly necessary for the portal to work, contains no personal data itself, is not readable by scripts, is only sent over an encrypted connection, and expires after 30 days or when you sign out. It is not used for tracking or analytics of any kind.
The rest of the website uses no cookies. We use Cloudflare Web Analytics on the public pages to see basic visit counts and referrers — it doesn't use cookies or any persistent identifiers, doesn't track you across sites, and doesn't collect personal data. See Cloudflare's Web Analytics page for details. Analytics is deliberately not loaded on the portal at all.
Waitlist signups and reviews are processed on the basis of your consent (Art. 6(1)(a) GDPR) — given by submitting the form. Server logs and Cloudflare Web Analytics are processed on the basis of legitimate interest in keeping the site secure, running, and understanding how it's used (Art. 6(1)(f) GDPR).
Portal data is processed to perform the contract between you and the freelancer you hired (Art. 6(1)(b) GDPR), and on our side on their documented instruction as their processor (Art. 28 GDPR). Notes left through a review link, and the name chosen for them, rest on the legitimate interest of the freelancer and the person reviewing in getting the cut right (Art. 6(1)(f) GDPR). The session cookie is strictly necessary for a service you requested, so it needs no consent under § 25(2) TTDSG. The activity log rests on the legitimate interest in keeping accounts secure and detecting misuse (Art. 6(1)(f) GDPR). Email notifications are sent only if you switch them on yourself.
Waitlist emails are kept until launch or until you ask us to remove them, whichever is first. Reviews are kept for as long as they stay published.
Portal accounts and their data are kept for as long as the freelancer keeps the access open. When they revoke it, the account, its messages, its projects and any invoice PDF are deleted immediately and together. Withdrawing a single project from the portal deletes that project's data on its own. The activity log is deleted after 180 days, sign-in sessions after 30 days, and password reset links after two hours. Review links stop working after four days; the notes left through one stay with the project until the project's data is deleted. You can ask for anything to be deleted at any time — see Your rights below.
Under GDPR you have the right to access, correct, delete, or export the data we hold about you, and to object to or restrict its processing. To exercise any of these, email leander@getclientbase.app. You also have the right to lodge a complaint with your local data protection supervisory authority.
If this policy changes in a meaningful way, this page will be updated and the date above will change.