Privacy Policy

1. General information

This Privacy Policy explains how metrik.social processes personal data when you visit our website, use our FitCheck, contact us, purchase a subscription or use our Instagram growth service.

It also provides information about the processing of publicly available Instagram data in connection with our service.

Personal data means any information relating to an identified or identifiable natural person.

2. Controller

The controller responsible for the processing of personal data is:

Tom Tägtmeier
c/o Postflex #10318
Emsdettener Str. 10
48268 Greven
Germany

Telephone: +49 176 84756915
E-mail: hello@metrik.social

3. Provision of personal data

Providing personal data is generally voluntary.

Certain information is, however, required to process a FitCheck or other request, enter into a contract or provide the agreed service. If this information is not provided, we may be unable to process the relevant request or provide the service.

Our paid service is available only to persons aged 18 or older and to legal entities or other organizations capable of entering into a valid contract.

4. Website hosting and delivery

Our website is provided using Framer. The provider is Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands.

Framer may process personal data on our behalf in connection with hosting and delivering our website.

Our internal application, dashboard and database infrastructure is additionally operated on our own server infrastructure located in Germany.

5. Server logs

When our website or technical systems are accessed, the following information may be processed:

IP address,
date and time of access,
requested page or file,
referrer URL,
browser type and version,
operating system,
device information,
technical error and security information, and
amount of data transferred.

Processing is based on Article 6(1)(f) GDPR.

Our legitimate interests are the secure, stable and technically reliable operation of our website and systems and the detection and prevention of misuse and security incidents.

Data is retained only for as long as necessary for these purposes. Longer retention may occur where necessary to investigate a specific security incident or establish, exercise or defend legal claims.

6. Consent management and local storage

We use our own technical consent management implementation based on Google Consent Mode V2.

The consent status selected by the user for categories including Analytics and Marketing is stored locally in the user’s browser. We currently use the browser’s Local Storage for this purpose.

This storage allows the website to remember and apply the user’s consent choice during subsequent visits.

Where storage of or access to information on the user’s device is strictly necessary to provide a function expressly requested by the user or another technically necessary function, Section 25(2) TDDDG applies subject to its statutory requirements.

Non-essential analytics and marketing technologies are used on the basis of consent pursuant to Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR.

Consent may be withdrawn at any time with effect for the future. You may contact us at hello@metrik.social for this purpose. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

7. Google Tag Manager and server-side tag management

We use Google Tag Manager to technically manage and control analytics and marketing tags.

In addition to a web container, we use server-side tag-management infrastructure.

Our server-side tag-management infrastructure is provided through Stape Global, operated by Stape, Inc., USA.

Depending on the relevant consent status, technical events may be processed through this infrastructure and forwarded to the relevant analytics and marketing providers.

Stape may process technical information including IP address, request information, browser and device information and event data processed through the server-side tag-management environment.

Where Stape processes data on our behalf, processing is governed by a data processing agreement.

Because Stape Global is operated by a US company, international data transfers may occur. Where required, appropriate safeguards such as the European Commission’s Standard Contractual Clauses are used.

8. Google Analytics 4

Following the relevant consent, we use Google Analytics 4, provided by Google Ireland Limited.

Google Analytics is used to statistically analyse website usage, measure conversions and improve our website and marketing activities.

The information processed may include:

pages visited,
session timing and duration,
referrer information,
approximate location information,
device, browser and operating-system information,
technical identifiers,
website interactions, and
events defined by us.

Relevant events currently include generate_lead and purchase.

Processing is based on your consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.

We use Google Consent Mode V2 to communicate and apply the relevant consent status.

Google may process data outside the European Economic Area. Where required, transfers are based on an adequacy decision or appropriate safeguards.

9. Meta Pixel and Meta Conversions API

Following marketing consent, we use the Meta Pixel and Meta Conversions API provided by Meta Platforms Ireland Limited.

These technologies are used to measure the effectiveness of advertising on Facebook and Instagram, attribute conversions and, where enabled, optimise advertising campaigns and audiences.

Events processed may include:

PageView when pages are viewed,
Lead following successful submission of the FitCheck form,
InitiateCheckout in connection with beginning a checkout process, and
Purchase following a successful order or payment.

Browser-side and server-side copies of an event may use a shared event ID for deduplication.

Depending on the technical configuration, the following information may additionally be processed:

IP address,
user agent,
page and referrer information,
event time,
fbp and fbc,
device and browser information, and
where enabled and covered by consent, normalized and hashed contact information.

Hashed information may still constitute personal data.

Processing is based on consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.

Depending on the relevant processing, Meta and we may act as independent or joint controllers, or Meta may process certain data on our behalf.

10. LinkedIn Insight Tag

Following marketing consent, we use the LinkedIn Insight Tag provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

The service is used for conversion measurement, reporting on LinkedIn advertising campaigns and, where enabled, creating or evaluating website audiences.

Information processed may include:

visited URL,
referrer URL,
IP address,
device and browser characteristics,
timestamp,
technical identifiers, and
information relating to website interactions.

Where Enhanced Matching is enabled, eligible contact information such as e-mail addresses may additionally be hashed before transmission.

Processing is based on consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.

LinkedIn may process data in the United States. Applicable statutory transfer mechanisms are used for international transfers.

11. OpenAI Ads and conversion measurement

Following marketing consent, we may use OpenAI advertising conversion tools, including the OpenAI Pixel and/or OpenAI Conversions API, to measure advertising interactions and conversions.

Information processed may include:

page views,
lead events,
checkout events,
purchases or orders,
event type and timestamp,
page and referrer information,
device and browser information,
event IDs,
technical identifiers, and
the OpenAI click reference (oppref).

Where matching functionality is enabled, eligible first-party contact information may be normalized and hashed before transmission.

Processing takes place only on the basis of marketing consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.

OpenAI Ireland Ltd. may in particular process EEA data. Depending on the functionality used, OpenAI and we may act as independent controllers or OpenAI may process certain information on our behalf.

12. FitCheck

Prospective customers may submit a FitCheck through our website.

The FitCheck form is integrated directly into our website provided through Framer.

We may process:

name,
e-mail address,
Instagram username,
niche,
target-audience description,
voluntarily provided free-text information,
publicly available information relating to the specified Instagram profile, and
technical submission information.

Processing is carried out to perform the FitCheck requested by the user, communicate the result, contact the user regarding directly relevant next steps and, where applicable, take steps prior to entering into a contract.

The legal basis is Article 6(1)(b) GDPR.

Without a separate legal basis, the e-mail address submitted through the FitCheck is not used for general newsletters, discount campaigns or other marketing unrelated to the FitCheck.

13. Automated FitCheck assessment using the OpenAI API

We use the OpenAI API for parts of the automated initial assessment performed as part of our FitCheck.

Under OpenAI’s current contractual structure, the relevant provider for customers based in the European Economic Area is in particular OpenAI Ireland Ltd.

Depending on the technical process, the Instagram username provided and publicly available or otherwise relevant profile information may be transmitted to the OpenAI API.

The processing is used solely to support and automate the initial FitCheck assessment.

The legal basis is Article 6(1)(b) GDPR.

OpenAI processes relevant API data subject to the contractual data-protection terms applicable to the services used.

The automated FitCheck result is an initial assessment. A negative automated assessment does not technically prevent the person from purchasing the service.

If a prospective customer believes the assessment is incorrect or does not take relevant circumstances into account, they may reply to the relevant e-mail and request human review.

14. Contract, onboarding and service provision

When you purchase a metrik.social service, we process personal data necessary to enter into and administer the contract, process billing, complete onboarding and provide the Instagram growth service.

This may include:

name and contact information,
contractual and billing information,
Instagram username,
niche and target-audience information,
requested regions and languages,
competitor, reference and audience-source accounts,
requested or excluded targeting areas,
follow/unfollow preferences,
access information,
account and login status,
information about interactions performed as part of the service, and
dashboard and performance information.

Processing is generally based on Article 6(1)(b) GDPR.

Where additional information is processed for system security, misuse prevention or the establishment, exercise or defence of legal claims, processing may be based on Article 6(1)(f) GDPR.

15. Instagram credentials and two-factor authentication

Direct access to the Instagram account specified by the customer may be required to provide the agreed growth activities.

Information processed may include:

Instagram username,
password,
two-factor authentication information,
backup codes or login approvals,
login status, and
technical information relating to successful or unsuccessful login attempts.

Processing is carried out solely for setup and provision of the agreed service and is based on Article 6(1)(b) GDPR.

Credentials are stored in encrypted form in an internal database on our own server infrastructure in Germany.

We currently also use Tally BV, Belgium, to collect and operationally process access information. As part of our internal workflows, relevant form information may also be processed through Google Workspace, including Gmail and Google Sheets.

Tally processes form data as our processor. Google may also process personal data on our behalf in connection with the Workspace services used.

Credentials and authentication information are retained only for as long as required for the agreed service, necessary login processes and any technical offboarding that remains to be completed. They are then deleted or permanently made inaccessible unless a legal requirement or specific legal reason requires further retention.

16. Publicly available Instagram data and interaction logs

In connection with organic targeting and performance of the agreed growth service, we process a limited amount of publicly available information relating to other Instagram users.

The information originates primarily from publicly available Instagram profiles and publicly visible follower, engagement and audience structures relating to relevant reference or audience-source accounts.

Our interaction logs may contain:

Instagram username,
type of interaction performed,
date and time of interaction,
relevant reference or audience source, and
where applicable, a technical attribution indicating whether a follow-back occurred.

As part of these interaction logs, we do not intentionally store additional information such as full names, profile biographies, religious beliefs, political opinions, health information or other special categories of personal data.

The processing is used to perform, manage, quality-control and document our organic Instagram growth service and optimise targeting.

The legal basis is Article 6(1)(f) GDPR.

Our legitimate interests are the proper and targeted provision of the service commissioned by our customers, avoiding repeated or unsuitable interactions and assessing the quality of audience sources.

Individual interaction logs are generally retained during active service provision and for 90 days after the service has finally ended.

Personal identifiers are subsequently deleted or anonymized so that they can no longer be attributed to a natural person, unless statutory requirements or specific legal claims require longer retention.

Aggregated performance statistics that no longer constitute personal data may be retained for longer periods.

This section also provides information to persons whose publicly available Instagram information is processed in connection with our service.

Data subjects may exercise their rights by contacting hello@metrik.social.

17. Contact and customer support

If you contact us by e-mail, Instagram or another communication channel, we may process:

your contact information,
the contents of your request,
your Instagram username where applicable,
contractual or account information, and
communication history.

Where communication relates to a current or prospective contract, processing is based on Article 6(1)(b) GDPR.

Other business or general enquiries are processed on the basis of Article 6(1)(f) GDPR and our legitimate interest in responding to and documenting enquiries.

18. Stripe and payment processing

We use Stripe for payment processing, recurring billing and subscription management.

Depending on the customer’s location, payment method and the processing involved, different Stripe group entities may be involved, including Stripe Payments Europe, Limited and Stripe Technology Company, Limited in Ireland and, where applicable, other Stripe entities.

Stripe may process:

name,
e-mail address,
billing information,
payment information,
payment method,
transaction amount and currency,
subscription and invoice status,
fraud-prevention information, and
technical device and connection information.

Processing required to enter into and perform the contract is based on Article 6(1)(b) GDPR.

Where payment and invoice information must be retained in accordance with statutory tax or accounting requirements, processing is based on Article 6(1)(c) GDPR.

Depending on the processing concerned, Stripe may act as our processor or as an independent controller.

19. Recipients and categories of recipients

Personal data may be disclosed in connection with the processing described above to providers and categories of recipients including:

Framer B.V., the Netherlands – website provision and hosting

Tally BV, Belgium – forms, including transmission of account-access information

Google Ireland Limited and affiliated Google companies – Google Analytics, Google Tag Manager, Google Workspace, Gmail and Google Sheets

Stape, Inc., USA – server-side tag management

Meta Platforms Ireland Limited – Instagram, Meta Pixel and Conversions API

LinkedIn Ireland Unlimited Company – LinkedIn Insight Tag and advertising measurement

OpenAI Ireland Ltd. and affiliated OpenAI companies – OpenAI API used for the FitCheck and OpenAI advertising conversion measurement

Stripe group companies – payment processing and subscription management

Personal data may additionally be disclosed to tax advisers, legal advisers, public authorities or other recipients where required by law or necessary to establish, exercise or defend legal claims.

20. International transfers

Some providers or their subprocessors may process personal data outside the European Economic Area.

Where an adequacy decision by the European Commission applies to the relevant third country or certified recipient, transfers may be based on that decision.

Otherwise, where required, we use appropriate safeguards within the meaning of Article 46 GDPR, in particular the European Commission’s Standard Contractual Clauses and, where appropriate, supplementary protective measures.

21. Retention

We retain personal data only for as long as required for the relevant purpose or statutory retention obligations.

In particular:

FitCheck and enquiry data is retained for as long as required to perform the FitCheck, process the enquiry and, where applicable, establish a contractual relationship.

Contractual, billing and payment information is retained in accordance with applicable statutory tax and accounting requirements.

Support and communication records may be retained for the duration of the contractual relationship and beyond where necessary for customer support, documentation or the establishment, exercise or defence of legal claims.

Credentials are retained only for as long as required for the agreed access and provision of the service.

Personal interaction logs are generally deleted or anonymized no later than 90 days after the service has finally ended.

Consent information may be retained for as long as necessary to demonstrate the valid obtaining and administration of consent.

22. Data security

We implement appropriate technical and organisational measures designed to protect personal data against loss, unauthorized access, alteration and disclosure.

Depending on the relevant processing, these measures include encrypted transmission, access controls and encrypted storage of sensitive credentials in our internal database.

Absolute security of electronic data processing cannot technically be guaranteed.

23. Automated decisions

The FitCheck may use automated and rule-based procedures, including the OpenAI API, for its initial assessment.

The automated result does not technically prevent the conclusion of a contract and may be reviewed by a person upon request.

Apart from this process, we do not use the website or contractual processing described in this Privacy Policy to make solely automated decisions that, without meaningful human involvement, produce legal effects concerning a person or similarly significantly affect them.

24. Your rights

Where the applicable statutory requirements are met, you have rights including:

access under Article 15 GDPR,
rectification under Article 16 GDPR,
erasure under Article 17 GDPR,
restriction of processing under Article 18 GDPR,
data portability under Article 20 GDPR, and
withdrawal of consent under Article 7(3) GDPR.
25. Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object to that processing on grounds relating to your particular situation in accordance with Article 21 GDPR.

Where personal data is processed for direct marketing, you may object to that processing at any time without providing reasons relating to your particular situation.

26. Right to lodge a complaint

You have the right to lodge a complaint with a competent data protection supervisory authority.

This may in particular be a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement.

27. Changes to this Privacy Policy

We may update this Privacy Policy where our services, technical systems, service providers or applicable legal requirements change.

Last updated: 10 September 2026

Organic Instagram visibility through manual interaction. No bots, no fake followers, no automated DMs - just structured, transparent growth activity.

Location

metrik · Hamburg, Germany

Social

metrik

metrik