Privacy Policy
Last updated: 2026-02-25
1. Data Controller
The controller responsible for data processing on this website is:
Newmatik GmbH
Am Markt 1
55619 Hennweiler, Germany
Email: software@newmatik.com
Phone: +49 6752 16998-0
This policy explains what data we collect when you use gerbtrace.com and the Gerbtrace desktop application (together, the "Service"), and how we handle it.
2. Legal Basis for Processing
We process personal data on the following legal bases under Art. 6 GDPR:
- Contract performance (Art. 6(1)(b)) — account creation, project storage, payment processing, AI-powered BOM enrichment, component pricing lookups, and transactional emails necessary to provide the Service.
- Consent (Art. 6(1)(a)) — where you explicitly agree, such as accepting these terms during registration.
- Legitimate interest (Art. 6(1)(f)) — error monitoring, performance analysis, and security measures to maintain and improve the Service. Our legitimate interest is ensuring the reliability and security of the platform.
3. Data We Collect
3.1 Account Data
When you create an account we store your email address, display name, and avatar (if provided). Authentication is handled by Supabase. If you sign in via a third-party provider (Microsoft, GitHub) we receive only the profile fields you authorize (typically name, email, and avatar).
3.2 Project Data
Gerber files, BOMs, pick-and-place files, and other design data you upload are stored in your browser's local storage (IndexedDB) for free-tier users or in our cloud database (Supabase Storage, EU region eu-central-1) for team features. We do not access, analyze, or share your design files for any purpose other than providing the Service to you.
3.3 Payment Data
Payments are processed by Stripe. We never see or store your full credit card number. We store only your Stripe customer ID and subscription status. Stripe's privacy policy applies to payment processing.
3.4 Consent Records
When you accept our Terms of Service and Privacy Policy, we record your consent including the version accepted, timestamp, IP address, and user agent. This data is retained for legal compliance purposes.
4. AI Processing (Spark AI)
Gerbtrace offers an optional AI-powered BOM enrichment feature called "Spark AI." When you explicitly trigger an AI enrichment run, the following non-personal data is sent to Anthropic (Claude):
- BOM component data: descriptions, component types, packages, quantities, manufacturer part numbers
- Pick-and-place component data: designators, values, packages (up to 1,000 components)
No personally identifiable information is sent to the AI provider. Each AI run is explicitly triggered by the user. Data is processed in the United States. Legal basis: contract performance (Art. 6(1)(b)). Anthropic's data processing practices are governed by their privacy policy.
5. Error Monitoring (Sentry)
We use Sentry for error monitoring and performance analysis:
- Error reports — stack traces, browser type, operating system, and error context. Captured when errors occur.
- Session replay — masked recordings of interactions, with text masked and media blocked. Sampled for 10% of sessions and for sessions in which errors occur.
- Performance traces — page load and navigation timings. Sampled at 20%.
Error context can include route identifiers, browser details and diagnostic messages. A bug report can also include the email address and information you choose to send. Data is processed in the United States. Legal basis: legitimate interest (Art. 6(1)(f)).
6. Component Pricing (Elexess)
When you use the BOM pricing feature, manufacturer part numbers from your BOM are sent to the Elexess API to retrieve component pricing and availability data. No personal data is transmitted. Legal basis: contract performance (Art. 6(1)(b)).
7. Telemetry
On non-production domains only, we collect basic telemetry: hostname, page path, referrer, and IP address. This data is stored in our database and used to understand usage patterns. It is not collected on gerbtrace.com, localhost, or newmatik.com subdomains. Legal basis: legitimate interest (Art. 6(1)(f)).
Support (Help Scout)
Support is opened explicitly from the help menu. The Help Scout support widget loads when requested; it does not load automatically or show a floating launcher. After accepted account terms, your signed-in email and available profile name can identify your support request. Include only the project information you choose to share with support.
8. Email Delivery
Transactional emails (account confirmation, password reset, team invitations) are delivered via Resend. Your email address is shared with Resend solely for the purpose of delivering these emails. Legal basis: contract performance (Art. 6(1)(b)).
9. How We Use Your Data
- To provide, maintain, and improve the Service.
- To authenticate you and manage your account and team.
- To process payments for Pro and Team plans.
- To send transactional emails (account confirmation, password reset, team invitations).
- To provide AI-powered BOM enrichment when you request it.
- To look up component pricing and availability when you request it.
- To diagnose and fix technical problems.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
10. Cookies and Local Storage
We use the following client-side storage mechanisms:
- Authentication storage — Supabase session tokens and sign-in recovery state in localStorage. These are needed to keep you signed in.
- localStorage — team selection, viewer preferences, application settings, sidebar layout, cookie consent preference.
- sessionStorage — telemetry deduplication flag, consent flow state.
- IndexedDB — personal project data (Gerber files, BOMs and documents), cached team projects, and account-scoped pending team edits via Dexie.js. Browser storage limits or clearing site data can remove these local copies.
We do not use advertising or tracking cookies.
11. Data Storage and Security
Account and team data are stored in Supabase Cloud (EU region, eu-central-1). All data is encrypted in transit (TLS) and at rest. We follow industry-standard security practices including role-based access control, row-level security policies, secret management, and regular dependency updates.
12. Sub-processors
We use the following third-party services to provide the Service:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase | Authentication, database, file storage | Account data, project data, files | EU (eu-central-1) |
| Stripe | Payment processing | Payment details, subscription status | US |
| Sentry | Error monitoring, session replay | Error reports, masked session recordings | US |
| Cloudflare | Web hosting, CDN, DNS | HTTP requests, IP addresses | Global |
| Anthropic | AI BOM enrichment (Spark AI) | BOM/PnP component data (no PII) | US |
| Elexess | Component pricing lookup | Manufacturer part numbers | EU (Germany) |
| Resend | Transactional email delivery | Email addresses, email content | US |
| Help Scout | Support requests via the optional widget | Email, available profile name, and information you choose to send | US |
| GitHub | OAuth authentication, desktop releases | OAuth profile data | US |
| Microsoft | OAuth authentication (Entra ID) | OAuth profile data | US |
13. International Data Transfers
Some of our sub-processors are located in the United States. These transfers are safeguarded by the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) as adopted by the European Commission. You can request copies of the relevant safeguards by contacting us.
14. Data Retention
- Account data — retained while your account is active. Deleted within 30 days of account deletion.
- Project data — retained while the associated team and project exist.
- Payment records — retained for 10 years as required by German tax law (§ 147 AO).
- Consent records — retained for the duration of the business relationship plus 3 years (statute of limitations).
- Error logs (Sentry) — retained for 90 days.
- Telemetry data — retained indefinitely in anonymized form.
15. Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access (Art. 15) — obtain a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate personal data.
- Right to erasure (Art. 17) — request deletion of your personal data.
- Right to restriction (Art. 18) — restrict processing of your personal data.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format. You can export your data from your profile page.
- Right to object (Art. 21) — object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at software@newmatik.com.
16. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority for our registered office is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Postfach 30 40
55020 Mainz, Germany
www.datenschutz.rlp.de
17. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email or an in-app notice. Where required, we will ask for your renewed consent. Continued use of the Service after changes constitutes acceptance.
18. Contact
For privacy-related questions, contact us at software@newmatik.com.