Skip to content
Twinpage

Privacy Policy

Effective 1 October 2026

Ziad Antar, trading as Twinpage, United Arab Emirates runs Twinpage. This policy explains what personal data we handle, why, and what your choices are.

For your account, billing and our website, we are the controller of your personal data. For data about visitors to your website that the snippet handles, you (our customer) are the controller and we are your processor: we handle it only to run your tests, under our Data Processing Agreement. Visitors with questions about that data should contact the website they visited.

What we collect

  • Your account: your email address, account identifiers, and, if you sign in with Google, the name (and profile picture link) Google shares. Your password is held by our authentication provider; we do not store it in our own database.
  • Billing: a Paddle customer ID, your subscription ID and your subscription status (plan, renewal date, whether it is cancelled). If you upgrade, you enter your name, address and card details in Paddle's checkout; they never reach our servers.
  • Your projects and experiments: project names, your website's domain, site keys, how each experiment is set up and, when a site other than yours sends our snippet's requests, the address of the latest such site (shown to you on the Install tab for up to 7 days; it is deleted with the project).
  • Results: counts only, such as how many sessions saw each version and how many converted, and how many sessions your account used each month. We do not keep a record of individual visitors.
  • Product usage: which account actions you take (for example creating a project or starting an experiment), linked to your account's user id, with a few labels such as whether it is your first project or experiment, your sign-in method and your plan. Never your email, your visitors' data, or names or URLs.
  • Visual editor: the editor runs only in a browser tab you open from your dashboard while signed in, and stores nothing in that browser. When you save, it sends us your edits: the element selectors it builds, the values you type into its fields (styles, image and link URLs, alt text, positions and replacement text). It reads the page in your browser to show you previews, but sends us no other page content (no HTML, screenshots or form input) and nothing about your site's visitors. Like any request, our servers see the requesting site's address, your IP address and browser details.
  • Custom JavaScript: if you turn it on for a project, we store the code you write with your experiment, and keep a change log for each switch change, save and start: which member acted, when, and the code's fingerprint (SHA-256 hash) and length, never the code itself. When a visitor's browser requests the code, we read nothing from the request, and store and log nothing about the visitor. What your code does on your site is your processing.
  • Technical data: our hosting provider keeps standard request logs (such as IP address, browser details, the address requested and the time) to run and secure the Service, for the period that provider sets.
  • Website visits: pages viewed, referrer, approximate location (country, region, city), device, operating system and browser type. Vercel counts visits without cookies, using a short-lived identifier derived from the request that it discards after 24 hours.
  • Waitlist: if you leave your email in the waitlist form on our website, your email address and nothing else.

Visitors to your website

When you install the Twinpage snippet, it stores in each visitor's browser a random visitor ID, the version they were assigned, whether they saw and converted in each experiment, and, if an experiment uses targeting, their device type, traffic source and whether they visited before. It sends us your site key and the snippet's version when a page loads, and for each view or conversion the experiment, the version, the metric (for an extra metric) and whether it was a view or a conversion. The visitor ID stays in the browser and is not sent to us. We keep only counts. We do not store visitors' IP addresses or browser details in our database; our hosting provider's request logs see them, as for any website. If you use custom JavaScript, the visitor's browser also requests that code from us. If you turn on the Google Analytics 4 setting for a project, the snippet also passes the experiment and the version a visitor was shown to your own Google Analytics, through the Google tag or Google Tag Manager on your website; Twinpage does not receive or send that data. The Snippet privacy and consent page has the details, including how to load the snippet only after a visitor consents.

Cookies

When you sign in, we use cookies that keep you signed in. They are needed for the dashboard to work. We do not use advertising or analytics cookies on this website. We measure visits on our public pages (home, pricing, guides, legal pages, sign-in and sign-up) with Vercel Web Analytics. It does not use cookies and we do not use it on the dashboard. If you choose a light or dark theme in the dashboard, your browser remembers it in local storage; nothing is sent to us. The snippet uses browser storage, not cookies.

Why we use your data

To provide the Service and manage your account (to perform our contract with you), to keep the Service secure and prevent abuse (our legitimate interests), to understand how the website is used (our legitimate interests), to understand which features are used and improve the Service (our legitimate interests), and to keep the billing records the law requires (a legal obligation). If you join the waitlist, we use your email address only to tell you when Twinpage opens (your consent).

Who we share it with

We use these providers to run Twinpage. They handle data on our behalf, except Paddle, which is the seller of record (see its entry), and Google and Apple sign-in:

  • Supabase: database and sign-in. Our production database is in the EU (Frankfurt). If you choose Google or Apple sign-in, they tell us your email address (Google also your name).
  • Vercel: website hosting and visit measurement. We run our servers in the EU (Frankfurt) region.
  • Paddle: payments, billing and tax. Paddle is the seller of record for a paid Twinpage plan (Starter or Growth): it sells you the subscription, adds any sales tax or VAT at checkout, and is an independent controller of the payment and tax data it collects there, under its own privacy policy. We send Paddle your email address (so your Paddle customer is always the one for your account's email), your account ID, a signature that proves the account ID is ours, and the plan you chose. Paddle sends us back your customer ID, subscription ID, subscription status, plan and renewal dates; we also read your customer's email from Paddle to check it matches your account, and do not store it.
  • PostHog: product analytics. We send only your account's user id, the name of the action and a few labels (such as whether it is your first project or experiment, your sign-in method and your plan), never your email, your visitors' data, or names or URLs.
  • Zoho: the emails we send you, such as sign-up confirmation, password reset and test alerts.
  • Google and Apple: if you choose to sign in with them, they confirm your identity to us under their own privacy policies.
  • Loops (Loops, Inc.): the waitlist. It holds the email addresses left in the waitlist form on our website and sends the email that tells you Twinpage has opened.

Twinpage is operated from the United Arab Emirates. Our database and servers are in the EU (Frankfurt, Germany). When we access them from the UAE, and when providers outside the EU or UK handle data (such as Loops, in the United States), we rely on the safeguards the law requires, such as the European Commission's standard contractual clauses and the UK addendum. Write to us for a copy of the relevant safeguards. We do not sell your data and we do not show advertising.

How long we keep it

We keep your account data while your account exists. Results are kept while their experiment exists; deleting an experiment deletes its results. When you delete your account, on the Account page or by asking us, we delete your account data: your sign-in, projects, experiments and results, and we cancel any subscription and ask our analytics provider to erase your analytics profile. We may keep billing records for as long as the law requires, and our providers' backups clear on their own schedules. Paddle keeps its own payment and tax records as the seller of record. The custom JavaScript change log is kept while your account exists and deleted with it. We keep waitlist email addresses until Twinpage opens, or 24 months after you join, whichever comes first, and delete them 12 months after launch if you have not signed up. To be removed from the waitlist sooner, write to hello@twinpage.app. Every waitlist email has an unsubscribe link, and you can withdraw your consent at any time.

Your rights

Depending on where you live, you can ask us for a copy of your data, to correct it, to delete it, to restrict how we use it, or to receive it in a portable format. You can object at any time to our use of your data based on our legitimate interests (security, understanding how our website and features are used); we will stop unless we have compelling grounds or need it for legal claims. Where we rely on your consent (the waitlist), you can withdraw it at any time; this does not affect what we did before. You can complain to the data protection authority where you live or work. To use these rights, write to hello@twinpage.app; we answer within one month. You can delete your account yourself on the Account page (or ask us, if your account has more than one member). You need to give us an email address to have an account; without it we can't provide the Service. We do not make decisions about you based solely on automated processing.

Security

We use encrypted connections and per-account access controls in our database. No system is perfectly secure, so we cannot guarantee it.

Children

Twinpage is a business tool and is not directed at children.

Changes to this policy

If we change this policy in a material way, we will tell you by email or in the dashboard before the change applies.

Contact

Ziad Antar, trading as Twinpage, United Arab Emirates, hello@twinpage.app.