Last updated: [insert publish date] • Draft prepared August 3, 2026
Privacy Policy
YesOpens — yesopens.com
1. Introduction
This Privacy Policy explains how Localesto Sp. z o.o., with its registered office in Warsaw (ul. Szczęsna 26, 02-454 Warszawa, Poland), entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0001200212, NIP: 5223350892, REGON: 543003699, share capital PLN 5,000.00, represented by its Management Board (“Localesto,” “we,” “us,” or “our”) collects, uses, and protects personal data of users (“you,” “User”) of the YesOpens website and platform available at yesopens.com (the “Service”). We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law, in particular the Personal Data Protection Act.
2. Data Controller
The data controller responsible for your personal data is:
- Localesto Sp. z o.o.
- ul. Szczęsna 26, 02-454 Warszawa, Poland
- KRS: 0001200212 • NIP: 5223350892 • REGON: 543003699
- E-mail: info@localesto.com • Phone: [PHONE NUMBER – to be inserted]
For any questions, requests, or complaints about the processing of your personal data, contact us at info@localesto.com or by mail to the above address.
3. What Personal Data We Collect
- Account data: name, e-mail address, password (stored in hashed form), company name, business address, and tax/VAT number — collected when you register or request an invoice.
- Billing data: billing address and payment details, processed through our third-party payment processor. We do not store full payment card numbers on our own servers.
- Google Business Profile data: if you connect a Google Business Profile (or other Google account) to YesOpens, we access — with your explicit authorization through Google's OAuth process — data such as your business listing information, reviews, ratings, questions and answers, performance insights, posts, and photos, solely to provide the Service's rank tracking, audit, review management, content publishing, and reporting features.
- Usage and device data: IP address, browser type, device identifiers, pages visited, referral source, and similar log data, collected through cookies and similar technologies.
- Communications: information you provide when contacting us via the contact form, e-mail, or support/chat tools.
4. How We Use Google User Data (Limited Use Disclosure)
YesOpens's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google Business Profile data only to provide and improve the local-SEO features you request (rank tracking, audits, review and post management, reporting, and statistics).
- We do not sell Google user data.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless: (i) we have your affirmative consent for a specific message or support request; (ii) it is necessary for security purposes such as investigating abuse; (iii) it is necessary to comply with applicable law; or (iv) the data has been aggregated and anonymized.
- You may revoke YesOpens's access to your Google account at any time via your Google Account security settings (myaccount.google.com/permissions) or from within your YesOpens account settings.
5. Legal Basis and Purposes of Processing
We process your data on the following legal bases under Article 6(1) GDPR:
- Performance of a contract (Art. 6(1)(b)): to create and manage your account, provide the Service, process payments, and respond to support requests.
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, and other statutory obligations.
- Legitimate interest (Art. 6(1)(f)): to secure the Service, prevent fraud, analyze and improve our website and product, and pursue or defend legal claims.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing communications, and connecting your Google account.
6. Cookies
Our website uses cookies and similar technologies to operate the Service, remember your preferences, and analyze traffic. Non-essential cookies are only set with your consent, given through the cookie banner shown on your first visit, and you may withdraw that consent at any time through your browser settings. We recommend publishing a separate Cookie Policy listing each cookie, its provider, purpose, and duration — see the recommendations note at the end of this document.
7. Recipients of Data / Subprocessors
We share personal data with:
- Hosting and infrastructure providers necessary to operate the Service.
- Payment processors that handle billing on our behalf (e.g., Stripe or Paddle) — we do not directly store full payment card data.
- Analytics, e-mail delivery, and customer support/chat tool providers.
- Accounting and legal advisors, as needed to comply with our statutory obligations.
- Tax authorities and other public bodies, where required by law.
We share only the minimum data necessary and require these parties to protect it under written agreements consistent with the GDPR.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area, we ensure an adequate level of protection through mechanisms recognized under the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses, before any such transfer takes place.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy: for the duration of your account and use of the Service, plus the period required to comply with statutory retention obligations (e.g., tax and accounting records) or to establish, exercise, or defend legal claims. Where processing is based on consent, we retain the data until you withdraw that consent.
10. Your Rights
Under the GDPR, you have the right to: access your data (Art. 15); rectify inaccurate data (Art. 16); request erasure (Art. 17); restrict processing (Art. 18); receive your data in a portable format (Art. 20); object to processing based on legitimate interest (Art. 21); and withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, or with the supervisory authority of your own EU member state. To exercise these rights, contact us at info@localesto.com.
11. Security
We apply appropriate technical and organizational measures — including encryption in transit, access controls, and staff training — to protect personal data against unauthorized access, loss, or misuse.
12. Children
The Service is not directed at individuals under the age of 16, and we do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new “last updated” date, and for material changes we will provide additional notice (e.g., by e-mail) at least 7 days in advance.
14. Contact
Localesto Sp. z o.o., ul. Szczęsna 26, 02-454 Warszawa, Poland. E-mail: info@localesto.com.
Drafting notes (remove before publishing): insert a contact phone number once confirmed; confirm the exact payment processor and hosting/analytics subprocessors used; confirm whether a stand-alone Cookie Policy will be published; confirm the minimum age threshold if different from 16 under Polish law.