Cerez tercihleri
Temel islevsellik icin cerezler kullaniyoruz. Onayinizla, LandedFees'i gelistirmek icin analiz (Google, PostHog) ve pazarlama pikselleri (Meta, LinkedIn) de kullaniyoruz. Onayinizi Ayarlar'dan istediginiz zaman geri cekebilirsiniz. Ayarlar.
Güven
Son güncelleme 24 August 2026
This page is written for the security or procurement reviewer evaluating LandedFees. It covers what we store, where it lives, who processes it, how we authenticate requests, how you can report a problem, and how you can export or delete your data. Everything below is authoritative. If we make a change, the "Last updated" date at the top moves.
/dashboard/settings/sso./dashboard/api-keys.X-RateLimit-Limit/X-RateLimit-Remaining/X-RateLimit-Reset response headers. Higher limits available by request.lc_session). HttpOnly, Secure, SameSite=Lax.The following third parties process customer data on our behalf. The erasure column indicates how we complete a right-to-erasure (GDPR Article 17) request against that processor. "API erasure" means we call a dedicated delete endpoint (durable queue in migration 113). "Cascade delete" means data is removed via the primary database delete. "Manual filing" means we submit a documented request to the processor because they have no self-serve deletion API.
| İşleyici | Amaç | Veri | Bölge | Silme |
|---|---|---|---|---|
| Supabase | Yönetilen Postgres, depolama ve kimlik doğrulama arka ucu. | Hesap kayıtları, hesaplama geçmişi, yüklenen faturalar, şifrelenmiş sırlar. | EU (Frankfurt, eu-central-1). | Kademeli silme |
| Vercel | Uygulama barındırma ve edge ağı. | İstek günlükleri (30 gün saklama), build artifactları. | US + EU edge; primary functions run in iad1 and fra1. | Kademeli silme |
| Dodo Payments | Abonelik faturalandırması, faturalama ve vergi tahsilatı. | Müşteri adı, fatura adresi, ödeme yöntemi referansı, abonelik durumu. | US primary. | API ile silme |
| Brevo | İşlem ve yaşam döngüsü e-postası. | E-posta adresi, gönderi/açılış olayları, şablon değişkenleri. | EU. | API ile silme |
| Resend | Kimlik doğrulama OTP ve makbuz e-posta teslimi. | E-posta adresi, message-id. | US. | API ile silme |
| PostHog | Ürün analitiği (izne bağlı). | Takma adlı distinct-id, olay akışı, özellik kullanımı. | US. | API ile silme |
| Google Analytics 4 | Toplu web analitiği (izne bağlı). | Client-id çerezi, sayfa görüntülemeleri, kampanya parametreleri. | US. | Manuel başvuru |
| Meta Pixel | Pazarlama ölçümü (izne bağlı). | İzne bağlı takma adlı tarayıcı parmak izi. | US. | Manuel başvuru |
| LinkedIn Insight tag | Pazarlama ölçümü (izne bağlı). | İzne bağlı takma adlı tarayıcı parmak izi. | US. | Manuel başvuru |
When the sub-processor list changes we publish the change here and, for logged-in users, notify the address on the account. Consent-gated processors (PostHog, GA4, Meta, LinkedIn) only receive data when the user has opted in via the cookie banner, and are torn down synchronously on revocation (LFQG-111 vendor artifact cleanup).
If you believe you have found a security issue in LandedFees, please email info@growyourbrand.io with reproduction steps, affected URL, and impact. Please do not test against other customers' data.
LandedFees is a pre-funding independent product. We are not SOC 2 audited, and we do not hold ISO 27001, HIPAA, or FedRAMP attestations. We do not plan to pursue these attestations until the product reaches revenue or funding milestones that justify the annual audit spend (a SOC 2 Type II typically runs $30k to $100k per year plus engineering overhead, which would be indefensible at our current scale).
What we can offer today:
Every account holder has an unconditional right to export or delete their data, independent of jurisdiction. The self- serve endpoints:
All security, privacy, procurement, and disclosure correspondence goes to info@growyourbrand.io. Signed by the LandedFees team.