This website requires JavaScript to run properly.

Privacy Policy

How Webfolio collects, uses, and protects personal data for the curated directory, accounts, digests, newsletter, and checkout.

This Privacy Policy explains how webfolio.to (“Webfolio”, “we”, “us”) collects, uses, and protects personal data when you use our curated tool directory, website features (including search and on-site comparisons), newsletter and email digests, accounts, tool submissions and claims, dashboards, and optional paid placements (the “Service”).

Data controller

The data controller for the purposes of the General Data Protection Regulation (GDPR) is:

Entreprise Individuelle (EI) – DA SILVA AVELAR William
Trade name: Webfolio
SIRET: 831 461 363 00028
Address: 10 rue de Penthièvre, 75008 Paris, France
Email: contact@webfolio.to

Personal data is hosted on infrastructure provided by Scaleway (France/EU).

Scope

This Privacy Policy applies to personal data we process when you:

  • Visit or browse our website and directory
  • Subscribe to our newsletter or email digests
  • Create and use an account or dashboard
  • Submit a tool for listing or claim a tool profile
  • Purchase optional placements via checkout (Stripe)
  • Contact support or correspond with us

It does not govern third-party sites or tools you open from our directory; their privacy practices are described on those sites.

Data we collect

Account & identity

  • Email address
  • Name (if you provide it)
  • Credentials and session data needed to secure your account

Newsletter & digests

  • Email address
  • Subscription status, source of signup (e.g. page or flow), timestamp, and related metadata (such as IP address or browser user agent where collected to evidence consent)
  • Locale or language where you provide it

Submissions, claims & listings

  • Information you provide about a tool (name, URL, description, category, pricing and fit-related fields, contact email, etc.)
  • Records of moderation, approval status, and communications about your submission or claim

Checkout & billing

Payments for paid placements are processed by Stripe. We receive limited billing data (such as payment status, amount, currency, and identifiers needed to fulfil your order). We do not store full card numbers on our servers.

Usage & technical data

  • IP address and approximate location derived from it
  • Browser type, device type, and similar technical data
  • Pages viewed, actions taken on the site, and timestamps
  • Server and application logs for security and reliability

Public & editorial directory data

Information displayed on public tool and category pages (including structured fields such as fit-oriented scores, momentum-style signals, and comparison context) is generally not personal data about visitors, but may include business contact details or founder-provided information that identifies individuals when submitted as part of a listing.

How we use data

We use personal data to:

  • Operate and improve the directory and website features
  • Authenticate accounts and secure the Service
  • Review, publish, or reject submissions and manage claims
  • Send newsletters and digests you have signed up for
  • Process and document paid placements
  • Provide support and respond to requests
  • Analyse usage in aggregate to improve the product
  • Detect abuse, fraud, and security incidents
  • Comply with legal obligations

Email communications

We use email in connection with the Service. The main types sent through our delivery providers are described below; other correspondence may occur outside those systems.

  • Transactional emails, such as account verification, login, password reset, submission or claim updates, billing or placement-related messages, and support replies.
  • Optional newsletters or email digests, where you have subscribed or otherwise requested to receive them.

We do not purchase, rent, scrape, or use third-party email lists for newsletter or digest sending.

Newsletter and digest subscribers are collected through Webfolio-owned signup flows, including forms on webfolio.to, account settings, submission or claim flows where a user explicitly opts in, and related first-party product pages. Where required, subscription is based on consent. We record subscription status and related metadata such as the signup source, timestamp, and technical information needed to maintain evidence of consent and protect against abuse.

Digest frequency depends on what you subscribe to (for example daily or weekly digests). We describe what you are signing up for at the point of subscription.

Newsletter and digest emails include an unsubscribe link. You may unsubscribe at any time using the link in the email or by contacting contact@webfolio.to. Transactional or service-critical emails may still be sent where necessary to operate the Service, secure your account, respond to your requests, or fulfil a transaction.

We use email delivery providers, including Mailgun, to send and manage transactional, newsletter, and digest email. These providers may process email addresses, message metadata, delivery events, bounces, complaints, and unsubscribe or suppression data on our behalf.

We maintain suppression records where needed to respect unsubscribe requests, complaints, and delivery failures for newsletter and digest sending.

We process personal data on the following legal bases under GDPR, as applicable:

  • Contract: providing the Service you request (accounts, submissions, checkout)
  • Legitimate interests: securing the platform, improving the product, analytics that do not require consent, and limited marketing to existing users where permitted
  • Consent: newsletter and similar emails where required, and non-essential cookies as described in our Cookie Policy
  • Legal obligation: where the law requires processing

Data sharing

We share personal data with service providers who process it on our instructions (“processors”), including:

  • Hosting and infrastructure providers
  • Payment processing: Stripe
  • Email delivery: Mailgun (transactional, newsletter, and digest email)
  • Security: Cloudflare (including Turnstile where used)
  • Error monitoring (e.g. Sentry) where enabled
  • Support or chat tools (e.g. Crisp) where enabled
  • Analytics or ads measurement (e.g. Google) only where you consent

We do not sell your personal data.

We only engage processors that provide sufficient guarantees. Each processor listed above processes personal data on our instructions under a data processing agreement meeting GDPR Article 28 requirements.

Automated processing & scores

Webfolio publishes structured information about tools (such as fit-style scores, momentum-style signals, and comparison-oriented groupings) using editorial rules, data you and founders provide, and automated calculations on our systems. This processing supports discovery and comparison on the site.

We may use AI-assisted tools to help draft editorial articles and tool listing content, including optional AI prefill when you submit a tool. Directory listings are subject to human review before publication. Automated scores and momentum-style signals use editorial rules and data you provide, not generative authoring of published descriptions. If we introduce new automated or AI-assisted features that materially affect your personal data, we will update this Policy as needed.

Data retention

We retain personal data only as long as necessary for the purposes described in this Policy. Specific periods or criteria include:

  • Account data: deleted or anonymised within 30 days after account closure, except where a legal hold, unresolved dispute, or security investigation requires longer retention.
  • Billing and tax records: 10 years from the end of the financial year, as required by the French Commercial Code (Code de commerce).
  • Newsletter and digest data: until you unsubscribe; inactive subscribers may be purged after 3 years without engagement.
  • Security and application logs: up to 6 months, unless needed longer for incident investigation or legal obligations.
  • Submissions, listings, and moderation records: for the duration the listing is published and a reasonable period thereafter to operate the directory, defend claims, and maintain an audit trail of moderation decisions.

Security

We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit where standard, and monitoring.

No system is completely secure; we cannot guarantee absolute security.

Your rights

Under GDPR, you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure in certain cases
  • Restrict or object to certain processing
  • Data portability where applicable
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact contact@webfolio.to. You can unsubscribe from newsletter or digest emails using the link in each message. Where processing is based on consent (newsletter, non-essential cookies), you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal; see our Cookie Policy and the Withdrawal & refunds section of our Terms for purchase-related withdrawal rights.

Cookies

We use essential cookies to run the site and optional cookies for analytics, ads measurement, or support where you consent. See our Cookie Policy and the “Cookie settings” link in the footer to update preferences.

International transfers

Some processors may process data outside the European Economic Area. Where required, we use appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-U.S. Data Privacy Framework.

  • Stripe (payments): may process data in the EU and United States, using SCCs and/or the EU-U.S. Data Privacy Framework as applicable.
  • Mailgun (email): United States, using SCCs.
  • Google (Analytics/Ads, consent-gated): United States, using SCCs and/or the EU-U.S. Data Privacy Framework as applicable.
  • Cloudflare (security, CDN, Turnstile): global edge network, using SCCs.
  • Sentry (error monitoring) and Crisp (support chat): United States, using SCCs; loaded only with your consent where required.

Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email where appropriate.

Contact

For privacy questions or requests, contact contact@webfolio.to.

Last updated: May 21st, 2026