Privacy Policy
Last updated: 5 July 2026
1. Introduction
1.1. This Privacy Policy explains how we collect, use, store, and share personal data when you use The Script (thescript.app) and related services (the "Service").
1.2. In this Privacy Policy, "we", "us", and "our" refer to Individual Entrepreneur Andrii Iskra, registered in Ukraine, operating the Service under the name "Script" ("Script").
1.3. We respect your privacy and are committed to protecting your personal data. This Privacy Policy is designed to help you understand what personal data we process, why we process it, and what rights you have.
1.4. This Privacy Policy applies to: (a) business owners and their team members who register for and use the Service ("Customers"); and (b) visitors to our website.
1.5. Two roles. Script processes personal data in two distinct capacities: (a) As a data controller — for personal data of our Customers (for example, account and billing data). This Privacy Policy governs that processing. (b) As a data processor — for personal data that Customers collect about their own contacts and leads through the Service. That processing is governed by our Data Processing Agreement, not this Privacy Policy.
1.6. If you have any questions about this Privacy Policy or how we handle your personal data, contact us at privacy@thescript.app.
2. Personal Data We Collect
2.1. We collect the following categories of personal data about our Customers:
(a) Account data. When you register for the Service, we collect your name, email address, company name, and — where you register using email and password — your password (stored in encrypted form). Where you register using Google, we receive your name, email address, and profile identifier from Google (see Section 2.2).
(b) Payment data. When you subscribe to a paid plan, payments are processed by our payment provider, monobank (JSC "Universal Bank"). We do not collect or store full payment card details. We receive only the transaction status, amount, and a transaction identifier. Card data is handled by monobank in accordance with its own privacy policy.
(c) Communications data. When you contact our support, we collect the content of your messages and any information you choose to provide.
(d) Technical data. When you use the Service, we automatically collect technical data such as your IP address, browser type, device information, and server log data. This data is used to operate and secure the Service.
(e) Usage data. We collect data about how you interact with the Service — such as features used, actions taken, session duration, and onboarding progress — to understand product usage and improve the Service. This usage data is collected and stored on our own servers; we do not use third-party analytics providers for this purpose.
2.2. Data from Google Sign-In. If you choose to sign in using Google, Google shares with us your name, email address, and a unique account identifier, in accordance with the permissions you grant. We do not receive your Google password. Your use of Google Sign-In is also subject to Google's privacy policy.
2.3. We do not intentionally collect special categories of personal data (such as data revealing health, religion, or political opinions) about our Customers. We ask that you do not provide such data except where strictly necessary and lawful.
3. How and Why We Use Your Personal Data
3.1. We use your personal data for the purposes set out below. For each purpose, we rely on one or more legal bases under the General Data Protection Regulation (GDPR) and applicable law.
(a) To provide the Service. We use your account data to create and manage your account, authenticate you, provide access to the Service, and enable its features. Legal basis: performance of a contract.
(b) To process payments. We use your payment data to process subscriptions, manage billing, and prevent fraudulent transactions. Legal basis: performance of a contract; compliance with a legal obligation.
(c) To provide support. We use your communications data to respond to your requests, resolve issues, and provide customer support. Legal basis: performance of a contract; our legitimate interest in supporting our Customers.
(d) To secure and operate the Service. We use technical data to maintain the security, integrity, and reliability of the Service, detect and prevent abuse, and diagnose technical problems. Legal basis: our legitimate interest in operating a secure and reliable service; compliance with a legal obligation.
(e) To improve the Service. We use usage data to understand how the Service is used, identify problems, and develop new features and improvements. Legal basis: our legitimate interest in improving our product.
(f) To communicate with you. We use your account data to send you service-related messages (such as security alerts, billing notices, and changes to the Service). Where permitted, we may also send you product updates and marketing communications; you can opt out of marketing communications at any time. Legal basis: performance of a contract (service messages); consent or legitimate interest (marketing).
(g) To comply with legal obligations. We may process your personal data where necessary to comply with applicable laws, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims. Legal basis: compliance with a legal obligation; our legitimate interest in protecting our rights.
3.2. Where we rely on consent as the legal basis, you have the right to withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
3.3. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms, and we do not use your data in ways where your interests override ours.
4. Sharing Your Personal Data (Sub-processors)
4.1. We do not sell your personal data. We share personal data only with the service providers ("sub-processors") that help us operate the Service, and only to the extent necessary for them to perform their functions.
4.2. We currently use the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Server infrastructure and hosting | Data center: Germany (EU). Provider: USA |
| Cloudflare, Inc. | Media storage and content delivery (CDN); DNS; DDoS protection | Global |
| monobank (JSC "Universal Bank") | Payment processing | Ukraine |
| Meta Platforms, Inc. | Instagram and Facebook messaging channels | USA / EU |
| Resend | Transactional email delivery | USA |
4.3. Each sub-processor is engaged under a data processing agreement (or, in the case of our banking partner, under applicable banking confidentiality obligations) that requires them to protect personal data in accordance with applicable law.
4.4. We may engage additional or replacement sub-processors as the Service evolves. Where required, we will update this list and, for Customers, provide notice of material changes in accordance with our Data Processing Agreement.
4.5. We may also disclose personal data where necessary to comply with a legal obligation, respond to lawful requests from public authorities, or protect our rights, as described in Section 3.1(g).
4A. Communication Channels
4A.1. The Service connects with third-party messaging platforms so that Customers can receive and respond to messages from their contacts. Data (such as messages, phone numbers, usernames, profile names, and attachments) enters the Service through these channels:
- Instagram and Facebook — the Service integrates with these platforms through Meta's official APIs to allow Customers to receive and respond to messages. Meta acts as a processor for data handled through these integrations.
- Telegram — messages are received through Telegram's protocols.
- WhatsApp — messages are received through WhatsApp's protocols.
4A.2. Once data enters the Service through any channel, we process and store it as described in this Privacy Policy and our Data Processing Agreement. Your use of each messaging platform is also governed by that platform's own terms and privacy policy.
4A.3. Customers are responsible for ensuring they have a lawful basis to communicate with their contacts through these channels and for obtaining any consent required by applicable law.
5. International Data Transfers
5.1. Your personal data is stored on servers located in Germany (European Union). Where possible, we keep data within the EU.
5.2. Some of our sub-processors are located outside the European Economic Area (EEA), primarily in the United States. When we transfer personal data outside the EEA, we rely on appropriate safeguards required under the GDPR, which may include: (a) the EU–U.S. Data Privacy Framework (where the recipient is certified); (b) the European Commission's Standard Contractual Clauses (SCCs); or (c) other lawful transfer mechanisms.
5.3. The main transfers outside the EEA relate to:
- email delivery (United States);
- messaging-channel integrations (United States / EU).
5.4. You may request more information about the safeguards we apply to international transfers by contacting us at privacy@thescript.app.
6. Data Retention and Deletion
6.1. We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, or as required to comply with legal obligations.
6.2. Active accounts. While your account and company are active, we retain your data to provide the Service.
6.3. Customer-controlled deletion. (a) Channels. When you delete a channel, you choose whether to delete or archive its chats. Archived chats remain available and can be cleared separately at any time. (b) Company deletion. When you delete a company, it enters a 30-day recovery period during which data is preserved and deletion can be reversed. After 30 days, all associated data is permanently deleted automatically. To delete immediately, contact us at privacy@thescript.app. (c) User account deletion. When you delete your user account, the same 30-day recovery period applies, after which the account is permanently deleted. For immediate deletion, contact us.
6.4. Retention following non-payment. If a subscription is not renewed, all company data — including messages, contacts, and media files — is permanently deleted 90 days after non-payment. After deletion, only the company's name and administrator accounts remain, for up to 360 days, after which the company is permanently deleted. You may exercise your right to delete data at any point during these periods.
6.5. Sub-processor retention. Where data has been transmitted to a sub-processor, deletion is subject to that provider's own retention practices.
6.6. Backups. Backup copies may persist for a limited period after deletion, after which they are securely erased.
7. Your Privacy Rights
7.1. Under the GDPR and applicable law, you have the following rights in relation to your personal data:
(a) Right of access — to obtain confirmation of whether we process your personal data and to receive a copy of it.
(b) Right to rectification — to have inaccurate or incomplete personal data corrected. Much of your account and profile data can be corrected directly within the Service.
(c) Right to erasure ("right to be forgotten") — to request deletion of your personal data. You can delete most data directly within the Service (see Section 6), or request deletion by contacting us.
(d) Right to restriction of processing — to request that we limit the processing of your personal data in certain circumstances.
(e) Right to data portability — to receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller. You can import and export your data within the Service.
(f) Right to object — to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing purposes.
(g) Right to withdraw consent — where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing.
7.2. How to exercise your rights. You can exercise many of these rights directly within the Service. For any request that cannot be completed in-account, contact us at privacy@thescript.app. We will respond within the time limits required by applicable law (generally within one month).
7.3. We do not charge a fee for exercising your rights, unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting on a request.
7.4. Complaints. If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with a data protection supervisory authority. In Ukraine, this is the Ukrainian Parliament Commissioner for Human Rights (Ombudsman). If you are in the EEA, you may also contact your local supervisory authority.
8. Security
8.1. We take appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, loss, or destruction.
8.2. These measures include: (a) Data in transit is encrypted using industry-standard TLS/SSL. (b) Data is stored on servers located in the European Union (Germany). (c) Access to production systems is strictly limited to authorized personnel and protected by two-factor authentication (2FA). (d) Customer data is logically isolated, so that one Customer cannot access another Customer's data.
8.3. We restrict access to personal data to those who need it to operate, support, or improve the Service.
8.4. No method of transmission or storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. We encourage you to use a strong, unique password and to keep your account credentials confidential.
8.5. In the event of a personal data breach affecting your data, we will notify you and, where required, the relevant supervisory authority, in accordance with applicable law.
9. Cookies and Similar Technologies
9.1. We use cookies and similar technologies to operate the Service, keep you signed in, remember your preferences, and understand how the Service is used.
9.2. We use only cookies necessary for the functioning of the Service and our own usage analytics. We do not use third-party advertising cookies.
9.3. You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.
10. Children's Privacy
10.1. The Service is intended for businesses and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children.
10.2. If we become aware that we have collected personal data from a child, we will take steps to delete it.
11. Changes to This Privacy Policy
11.1. We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you through the Service or by email.
11.2. Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
12. Contact Us
12.1. If you have any questions, requests, or concerns about this Privacy Policy or how we handle your personal data, contact us at:
Individual Entrepreneur Andrii Iskra Email: privacy@thescript.app Ukraine