Privacy Policy
Last updated: 9 June 2026
1. Introduction
ContractMaker (contractmaker.app) is operated by Yassine Rajallah, a sole proprietor under German law (“ContractMaker,” “we,” “us,” or “our”). This Privacy Policy explains how we handle information when you use our document generation tool and website (the “Service”).
Our core privacy promise: the documents you create are assembled entirely in your browser. The details you type into the generator — party names, scope, prices, dates, and any other contract content — are processed on your own device and are never transmitted to, seen by, or stored on our servers.
2. How document generation works
When you use the ContractMaker generator:
- You select a base template and fill in plain-language fields.
- The fields are merged into the template locally, in your browser, using client-side code.
- You download, copy, or print the finished document directly from your device.
- We do not receive a copy of your inputs or your generated document, and we cannot retrieve them.
3. Information we process vs. information we store
What we process but never store
- Document content: the information you enter into the generator, processed only in your browser and never sent to us.
- Generated documents: created on your device; we keep no copy.
What we may store
- Analytics: aggregated, privacy-friendly usage data such as page views and feature usage (no document content).
- Support communications: your email address and message if you contact us.
- Account information (only if and when accounts are offered): email, name, and an encrypted password.
- Billing data (only if and when paid plans are offered): transaction history and subscription status, handled by our payment processor.
The Service is currently free and does not require an account. Account and billing data are processed only if you choose to register or purchase once such features are available.
4. Legal basis for processing (GDPR)
- Legitimate interests: to operate, secure, and improve the Service.
- Contract: to provide a paid plan you subscribe to (if applicable).
- Legal obligations: to keep tax and accounting records.
- Consent: for optional analytics cookies and marketing communications.
5. Your privacy rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing or withdraw consent. To exercise any right, email contact@contractmaker.app.
6. Data retention
- Document content & generated documents: never stored (processed in your browser only).
- Analytics: aggregated and anonymized; retained no longer than necessary.
- Support tickets: up to 2 years.
- Billing records (if applicable): 7 years, as required by German tax law.
7. Third-party services
We rely on a small number of carefully selected providers:
- Hosting & CDN: serves the website and static assets.
- Analytics: aggregated usage only, no document content.
- Payment processor (if and when paid plans launch): handles billing securely and is PCI-DSS compliant; we never see full card numbers.
8. Data security
- Encryption: TLS for data in transit.
- Minimal data: because document content never leaves your browser, there is nothing for us to lose.
- Incident response: breach notification within 72 hours where required.
9. International transfers
Your data is primarily processed within the European Union. Where any processing occurs outside the EU, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Cookies and tracking
We use minimal cookies: essential cookies for basic site function, and optional analytics cookies (only with consent where required). You can control cookies through your browser settings.
11. Children’s privacy
ContractMaker is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us and we will delete it.
12. California privacy rights
California residents have rights under the CCPA, including to know what personal information we collect, to request deletion, and to opt out of any “sale” of data. We do not sell personal data, and you will not be discriminated against for exercising your rights.
13. Supervisory authority
You have the right to lodge a complaint with your local data protection authority. For our establishment, that is the Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin, Germany.
14. Changes to this policy
We may update this policy to reflect legal requirements, new features, or security improvements. Material changes will be notified via the website or, where you have an account, by email before they take effect.
15. Contact us
Questions or requests about your privacy:
Email: contact@contractmaker.app
Operator: Yassine Rajallah, Berlin, Germany
By using ContractMaker, you acknowledge that you have read and understood this Privacy Policy.