Frametap
Pricing

Privacy Policy

Last updated · October 2026

Frametap is operated by MB DJUMP (company code 307521980, Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania), the controller of the personal data described here. Anything about this page reaches us at start@djump.io. We have not appointed a data protection officer: the GDPR requires one only where a company's core activities consist of regular and systematic monitoring of people on a large scale, or of large-scale processing of special categories of data (Art. 37), and ours do not. This page explains what we do with the information you give us — in the app, and on this website.

What we collect and why

In the app we hold the account details you register with: your email address, your sign-in credentials and your shop name. If you sign in with Google or Apple instead, they tell us the email address and name on that account and nothing else — never your password — and Apple lets you hide the address behind a relay it forwards from. When you are signed in, the surveys you create sync to our servers so they are on every device signed in to your account: project name and site address, window labels and specifications, and the photos you attach. On this website, the contact form hands your name, email address and message — with the page language and your IP address, which helps us tell people from spam bots — to our own inbox as a single email, through our mail provider; it is not added to a mailing list and not kept in a database. The product-updates sign-up worked the same way and closed when the app shipped on both stores. To have such a message deleted, write to start@djump.io.

If you arrive through an advertisement or a campaign link, the page address carries campaign tags — utm_source, utm_campaign and the like, a ref name, or Google's click id, gclid. Nothing is stored on your device for them. If you then create an account on this website, the tags are saved with the account, together with the page you signed up on and the time, so we can tell which campaigns bring shops that actually use Frametap. They are not passed on with your account to Google or anyone else, and they go when the account goes. When you tap a store badge, the campaign tags travel with the link to Google Play, or just the campaign name to the App Store, so the store's own statistics can count installs per campaign.

To find out whether the pricing page actually works, we record a short list of steps taken on this website: that a pricing page was opened, which plan was picked, that a free trial was started, and that a payment was started, completed or could not be started, with the kind of error the page showed — together with the language of the page. These steps need no cookie and no visitor identifier, so nobody is followed from one visit to the next. On your device the site keeps only what something you did needs: your choice of light or dark theme and, while you are signed in, your sign-in session, both in your browser's local storage; while a Google or Apple sign-in is under way, a note in that tab that you started it; and a cookie named NEXT_LOCALE that remembers your language until you close the browser, if you pick one other than your browser's. None of them is used to follow you, which is why there is no consent banner. While you are signed in, the step is kept against your account id, so that a trial which became a subscription can be told apart from one which did not; signed out, it is only a number. Delete your account and these entries stop pointing at you.

The app keeps a similar short list, but only once you are signed in: that the app was opened and on which plan, that a project was created, that a window was added and which one it was in that project, that a PDF was exported, that a project was deleted — and, if you choose to tell us, why — and that a limit of the free plan was reached. When the app is opened and when you sign in, it also notes your device's region setting — the country code from its language and region settings, such as DE, not your location. It also notes how the app itself is doing: whether a sync with your account worked and, if not, the kind of error and its code; how a purchase or a restore in the app ended — bought, cancelled, failed, with the store's error code; and, when the app runs into an error it did not expect, the kind of error and the line of our code where it happened. Never the survey itself: no project names, no addresses, no measurements, no photos, no email addresses, and no device identifier. It is stored against your account in our own database, is shared with nobody, and exists for one purpose: to understand where people stop, so the next version fixes the right thing. Delete your account and these entries stop pointing at you as well.

During the free trial and just after it, we send up to three plain emails to the address the account was registered with: four days before the trial ends, on the day it ends, and a week later — to say what changes on the free plan, what Frametap Pro costs and where it is switched on, and to ask one question. They advertise our own product, so we tell you about them when you sign up and in every one of them, and you can say no at any time, free of charge: tick “Don't send me these emails” when you sign up, use the one-click unsubscribe link at the bottom of any of them, or reply STOP — no further one is then sent. Each is sent once, to the account owner only, and only if that account has been signed into. If you signed up in Polish, or with a .pl address, we send them only if you ticked the box agreeing to them. An account whose sign-up did not show this notice gets only a short reminder four days before the trial ends — no price, nothing to buy.

Frametap Pro can be bought on this website or inside the app. On the website the payment is handled by Stripe, who take the card details — we never see them — and issue the invoice. Inside the app the subscription is sold by Apple or Google, who are the sellers of record: they take the payment, charge the VAT of your country and tell us only that a subscription exists, which plan it is and when it runs to. That last part reaches us through RevenueCat, Inc. (United States), our processor for store receipts, which for this purpose holds your shop's account identifier and the purchase record — no name, no email address, no card. It is covered by a data processing agreement with the European Commission's standard contractual clauses.

Your account, your surveys and your photos are stored in the EU, in an Amazon Web Services data centre in Paris, and this website's forms run in Paris too. Photos are kept in a private bucket that is never served over a public URL. Here are the companies that run Frametap for us, with the safeguard that applies when personal data reaches them outside the EU. Supabase Pte. Ltd., Singapore (database, file storage and sign-in; its servers for Frametap are the Paris ones): the European Commission's standard contractual clauses, which are part of Supabase's data processing agreement. In the United States, Vercel Inc. (hosting of this website), Resend — Plus Five Five, Inc. (delivery of the emails we send), Google (Google Workspace, where our mailbox and your messages to us are kept) and Stripe (payments on this website): each is certified under the EU–US Data Privacy Framework, for which the European Commission has found the protection adequate, and their data processing terms add standard contractual clauses. RevenueCat, Inc., USA (store receipts, described above): standard contractual clauses. Each receives only what its job needs. Write to start@djump.io for a copy of the standard contractual clauses. We never sell your details or share them with marketing partners, and if you object to our emails — with the link in any of them or by replying STOP — we stop writing to you, except for what you ask for yourself, such as a password reset link.

At a glance: purpose, legal basis, retention

The same, kind by kind: why we hold it, the article of the GDPR that allows it, how long it is kept and who else receives it.

Account

What
Email address, password (kept only as a hash), shop name, sign-up language and, when you sign up in the app, the device's region setting; with Google or Apple sign-in, the name and email address on that account.
Why
To give your shop an account, sign you in and keep its surveys together.
Legal basis
Contract — Art. 6(1)(b) GDPR.
How long
Until you delete the account.
Who else
Supabase Pte. Ltd. (Singapore; servers in Paris). Resend, for sign-in and password emails. Google or Apple, if you sign in with them.

Surveys, photos and quotes

What
Project names and site addresses, window labels and specifications, quotes, photos, and any client details you type in.
Why
To sync them between your shop's devices and keep a copy in the cloud.
Legal basis
Contract — Art. 6(1)(b) GDPR. For your clients' details we act on your behalf — see below.
How long
A survey until you delete it or the account; photo files until the account is deleted.
Who else
Supabase Pte. Ltd. (Singapore; servers in Paris).

Sign-in security log

What
When you signed in or changed your account, from which IP address, and which account it was.
Why
To keep accounts secure and look into misuse.
Legal basis
Legitimate interest in secure accounts — Art. 6(1)(f) GDPR.
How long
As long as Supabase keeps its sign-in logs — on our plan, about 7 days.
Who else
Supabase Pte. Ltd. (Singapore; servers in Paris).

Usage steps on the website and in the app

What
The steps described above, the page language or the app's plan, the device's region setting (a country code, not a location), your account id while you are signed in, and a reason for deleting a project if you give one.
Why
To see where people stop, so the next version fixes the right thing.
Legal basis
Legitimate interest in improving Frametap — Art. 6(1)(f) GDPR.
How long
Linked to you until you delete the account; after that only as counts that point at nobody.
Who else
Supabase Pte. Ltd. (Singapore; servers in Paris).

Campaign tags

What
utm parameters, ref, Google's gclid click id, the page you signed up on and the time.
Why
To know which campaigns bring shops that actually use Frametap.
Legal basis
Legitimate interest in advertising that works — Art. 6(1)(f) GDPR.
How long
Until you delete the account.
Who else
Nobody, with your account. A store badge passes the campaign tags to Google Play, or the campaign name to the App Store.

Trial emails

What
The account email, the shop name, the trial dates, which emails were sent, and whether you objected or consented at sign-up.
Why
To tell you when the trial ends, what changes and what Pro costs.
Legal basis
Emails to our own customers about our own product. EU law allows them without separate consent if you were told about them at sign-up and can object at any time (Art. 13(2) Directive 2002/58/EC; in Germany § 7(3) UWG, in Lithuania Art. 81 of the Law on Electronic Communications — where these rules apply, Art. 6(1) GDPR does not apply separately, CJEU C‑654/23). For accounts signed up in Polish or with a .pl address: your consent — Art. 6(1)(a) GDPR, which you can withdraw at any time. Object or withdraw: the link at the bottom of any of these emails, or reply STOP.
How long
The record of what was sent stays until the account is deleted.
Who else
Resend (delivery). Your replies reach our Google Workspace mailbox.

Payments on this website

What
Company name, billing name and address, VAT number, email address, the subscription and its invoices, and your confirmation at checkout that you buy as a business. Card details go to Stripe only.
Why
To take payment and issue invoices.
Legal basis
Contract — Art. 6(1)(b) GDPR; keeping invoices is a legal obligation — Art. 6(1)(c) GDPR.
How long
Invoices and payment records 10 years — Lithuanian Law on Financial Accounting (Art. 10) with the Chief Archivist's index of retention periods (item 3.15); the subscription status until the account is deleted.
Who else
Stripe, which also handles some of it as a controller in its own right, for fraud prevention and its own legal duties.

In-app purchases

What
Your shop's account id, the plan, its dates and the store receipt — no name, email address or card.
Why
To switch Pro on for a subscription bought in the App Store or on Google Play.
Legal basis
Contract — Art. 6(1)(b) GDPR.
How long
Ours until the account is deleted; RevenueCat's until we have it deleted.
Who else
RevenueCat (United States). Apple or Google sell the subscription as controllers in their own right.

Contact form

What
Name, email address, message, topic, page language and IP address.
Why
To answer you; the IP address helps us tell people from spam bots.
Legal basis
Legitimate interest in answering — Art. 6(1)(f) GDPR; for a question about buying, steps before a contract — Art. 6(1)(b) GDPR.
How long
In our mailbox as long as the conversation needs it; deleted at once if you ask.
Who else
Vercel, Resend, Google Workspace.

Server logs

What
IP address, browser, the page or service called and the time.
Why
To deliver the website and the app's sync and keep them running and secure.
Legal basis
Legitimate interest in a working, secure service — Art. 6(1)(f) GDPR.
How long
As long as the hosting providers keep their logs — on our plans, up to about 7 days.
Who else
Vercel, Supabase.

Your clients' data

The surveys your shop keeps often hold other people's data: your clients' names, their site addresses, photos of their homes. For that data your shop is the controller — you decide what goes in and why — and MB DJUMP is your processor: we store it, sync it between your devices and keep it safe, on your instructions and for no purpose of our own. We look at it only when your shop asks us to fix a problem and lets us, and only for that; we never use it to write to you or to anyone else. It is stored on Supabase's servers in Paris — Supabase Pte. Ltd., Singapore, which uses Amazon Web Services there, is our sub-processor for it, under the standard contractual clauses. If you email us survey content for support, it also reaches our Google Workspace mailbox. If your shop needs a data processing agreement under Art. 28 GDPR, write to start@djump.io.

What stays after you delete your account

Deleting the account removes the account itself, your shop's surveys, photos and quotes, its campaign tags and the record of trial emails, and the usage steps stop pointing at you. A few things stay, and we would rather say so: invoices and payment records for purchases on this website stay with us and with Stripe for the 10 years accounting law requires; sign-in security log entries stay until Supabase clears its logs, on our plan after about 7 days; a copy of the deleted data stays in Supabase's daily backups for up to about 7 days and disappears as they are overwritten; RevenueCat's purchase record, which names no one, is deleted with the account — if that ever fails, ask and we will have it deleted; emails you sent us stay in our mailbox until we delete them; the email provider keeps its delivery log for its own short period; and if the deletion needed a person — a photo that could not be removed, a Sign in with Apple that could not be revoked — an internal note with your shop's random id, never a name or an address, stays for up to 90 days so we can finish the job. Deleting the account cancels a subscription bought on this website at once; one bought in the App Store or on Google Play has to be cancelled in that store.

Your rights

Under the GDPR you have the right to:

  • see the data we hold about you and get a copy of it;
  • have data that is wrong corrected;
  • have your data deleted — most of it you can delete yourself in the app;
  • have its use restricted while a question about it is being settled;
  • receive the data you gave us in a common machine-readable format, or have it sent to another provider;
  • withdraw a consent you gave us at any time, without affecting what was done before it was withdrawn;
  • object to any use based on our legitimate interest — and to the trial emails at any time, without giving a reason.

To use any of them, write to start@djump.io from the address on the account; we answer within a month. To use Frametap you have to give us an email address and a password, or sign in with Google or Apple — without them there is no account. Nothing about you is decided by automated means.

If you think we handle your data unlawfully, you can complain to Lithuania's State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, vdai.lrv.lt) or to the data protection authority of the country you live or work in.

Questions about this policy or your data? Email start@djump.io.