Privacy Policy
vsMars is designed to be readable without consenting to anything. This policy explains the small amount of data we do collect, why, and your rights over it.
Who we are
vsMars (“we”, “us”) is operated by the vsMars team. The data controller for the purposes of the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act is identified on our imprint page.
What we collect — and what we don't
We deliberately collect as little data as possible. We do not use Google Analytics, Facebook Pixel, third-party advertising trackers, or fingerprinting libraries. We do not sell your data. We do not place tracking cookies on your device for advertising.
1. Analytics (Plausible, self-hosted)
We run a self-hosted instance of Plausible Analytics. Plausible is cookieless: it does not store any data on your device and does not assign you a persistent identifier. It records:
- URL of the page you viewed
- Referrer (where you came from), if any
- Browser and OS family (from the User-Agent header)
- Country and region (derived from your IP — the IP itself is hashed and not stored)
- Device type (mobile / tablet / desktop)
We use this data in aggregate to understand which pages are popular, which categories need more content, and whether the site works on the devices people actually use. Legal basis (GDPR Art. 6(1)(f)): legitimate interest in operating and improving the service.
2. Product analytics (PostHog, self-hosted)
For specific product features (Compare tray usage, search query patterns, comparison page A/B variants) we use a self-hosted instance of PostHog. PostHog assigns a per-browser anonymous ID, stored in localStorage. We do not link this ID to any personally identifying data. You can clear it by clearing your browser's site data for versusmars.com.
3. Account data (if you create an account)
Creating an account is optional and only needed to submit reviews, suggest spec corrections, or save comparison lists. We collect: email address, display name (optional), and a hashed password. We never store your password in plaintext. Legal basis: contract (GDPR Art. 6(1)(b)).
4. Affiliate redirects
When you click an outbound “View on Amazon” or similar button, we record an anonymous click event (which product, which merchant, which page it was clicked from) so we can attribute conversions and detect broken links. The retailer you land on then sets their own cookies according to their privacy policy. We have no control over those.
5. Newsletter (optional)
If you subscribe to our newsletter, we share your email address with our transactional email provider (Resend, EU region) for the sole purpose of delivering newsletters. You can unsubscribe in one click from any newsletter. Legal basis: consent (GDPR Art. 6(1)(a)).
Cookies
For browsing without an account, vsMars sets no cookies. With an account, we set a single first-party authentication cookie (HTTP-only, SameSite=Lax) so you stay logged in. See our cookies policy for details.
Where data is processed
Our servers are hosted in Falkenstein (Germany) and Helsinki (Finland) on Hetzner Cloud and Hetzner Storage Box. All processing of EU data takes place inside the EU. Our content delivery network (Bunny CDN) operates globally for static assets only and does not see any personal data.
Retention
- Analytics (Plausible): aggregated, retained indefinitely. No individual data points.
- Product analytics (PostHog): 90 days, then purged.
- Affiliate click logs: 13 months (for refund reconciliation), then aggregated and purged.
- Account data: retained until you delete your account. Deletion takes effect within 30 days.
Your rights (GDPR)
If you are in the EU, UK, or another GDPR-equivalent jurisdiction, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Have your data erased (“right to be forgotten”)
- Restrict or object to processing
- Request a portable copy of your data
- Lodge a complaint with your local data protection authority
Email privacy@versusmars.com to exercise any of these rights. We aim to respond within 30 days.
Changes to this policy
Material changes will be announced on the homepage and via newsletter at least 30 days before they take effect. Non-material changes (clarifications, typos, address updates) are made silently with a bumped “Last updated” date above.