Skip to content
Norly

Legal

Privacy Policy

Last updated: July 17, 2026

This policy explains how Norly, operated by Vladimir Pitenin (“Norly”, “we”, “us”), handles personal data on norly.co and app.norly.co. For privacy inquiries, use the contact form. We've tried to write this the way we'd want to read it: short sections, plain words, no surprises.

1. The three hats we wear

  • To website visitors and leads — when you browse norly.co, request a checkup, or write to us, we decide how that data is used: we're the data controller.
  • To our customers (venue owners and their teams using the app) — we're the controller of your account data.
  • To our customers' guests — when you leave feedback or contact details through a venue's Norly page, that data belongs to the venue: the venue is the controller, and we process the data on the venue's behalf and instructions. For questions or deletion requests about feedback you left, contact the venue — we'll help them fulfil your request.

2. Information we collect

  • Account information — name, business email, account credentials, company/venue details and settings.
  • Campaign data — content you upload (video messages, images, platform links) and, processed for venues: guest ratings, feedback text, contact details guests submit, and technical events such as QR scans (which code, when).
  • Leads and forms — what you type into our contact, checkup and newsletter forms: email, venue name, message.
  • Usage data — IP addresses, browser and device details, timestamps, pages visited and actions in the app.

3. Payments — handled by Paddle

Purchases are processed by our authorized reseller and Merchant of Record, Paddle.com. Paddle collects your billing details and payment information directly; Norly never receives or stores your card data. We receive from Paddle what we need to run your subscription: who paid, for which plan, and the subscription status. See the Paddle Privacy Policy.

4. Third-party services

We share data only with service providers that help us run Norly, each with its own privacy policy:

  • Bubble.io — application hosting and data storage for app.norly.co.
  • Our email delivery provider — sending campaign emails and account notifications.
  • Paddle.com — payment processing (Merchant of Record).
  • The hosting provider of the norly.co marketing site.
  • Google (Analytics via Google Tag Manager) — usage analytics on the marketing site, loaded only after you consent (see section 6).
  • Authorities — only when the law genuinely requires it.

We don't sell personal data, and we don't use it for third-party advertising.

5. How we use data

  • To provide and enhance the Service — accounts, campaigns, smart pages, analytics, support.
  • To process guest feedback and contacts strictly for the venue that collected them.
  • To send important notifications: billing, service updates, security alerts.
  • To respond to leads, run the free checkup you requested, and send updates you signed up for — you can unsubscribe anytime.
  • To monitor and improve performance using aggregated usage data.

6. Cookies and analytics

The application uses essential cookies for authentication and session management — these are required for the service to work and are always on. The marketing site (norly.co) can additionally use analytics cookies (Google Analytics via Google Tag Manager) to understand how the site is used; this data is pseudonymous and never combined with your account to profile you.

We do not load analytics until you agree. On your first visit a banner asks for your choice: analytics run only if you select “Accept”, and not at all if you select “Decline”. You can change your mind anytime via the “Cookie settings” link in the footer, or by clearing cookies in your browser.

7. Retention

  • Account and venue data — while your account is active, then deleted or anonymized within 90 days of account deletion.
  • Guest data processed for venues — while the venue's account holds it; deleted with the venue's account or on the venue's instruction.
  • Leads and correspondence — up to 24 months after our last contact.
  • Billing records — as long as tax and accounting law requires.

8. Your rights

You may request access to, correction of, or deletion of your personal data via the contact form. We address requests within 30 days. If you're a guest of a venue, we'll route the request to the venue and help them fulfil it.

9. International transfers

Your data may be processed and stored outside your jurisdiction, including in the United States and other regions, in line with our service providers' policies and safeguards.

10. Security

We implement standard industry practices to secure your data, including encryption in transit and role-based access controls, and payment data never touches our systems (see section 3). No system guarantees absolute security; if a breach ever affects your data, we'll notify you and the authorities as the law requires.

11. Minors

The Service is not intended for individuals under 16, and we do not knowingly collect their personal data.

12. EEA / UK / Switzerland

Norly is currently not available to residents of the European Economic Area, the United Kingdom, or Switzerland until we fully implement GDPR compliance measures (see our Terms of Service, section 2).

13. Changes and contact

We may update this policy periodically. Updates are posted here, and significant changes are communicated to customers directly by email or in the app. Questions, requests, complaints: the contact form at norly.co/contact.