feat: Swiss-compliant launch — Impressum/AGB/Contact, support panel, DSG exports, cookie banner
All checks were successful
Deploy to Production / deploy (push) Successful in 57s
All checks were successful
Deploy to Production / deploy (push) Successful in 57s
Legal (Swiss minimum, no individual named): - Impressum page (UWG Art. 3 lit. s) — provider, contact via support panel, no email required, jurisdiction = Switzerland - AGB page — subscription terms, payment, cancellation, suspension on payment fail, 14-day money-back, AI-processing-per-tier disclosure, Swiss law + Swiss venue, modeled after typical Schweizer SaaS terms - Privacy: Stripe added as subprocessor with full data-flow disclosure Support panel replaces email contact entirely: - @bmm/db: support_status enum + support_tickets + support_messages tables, migration applied to prod DB - @bmm/api: support routes (user create/list/view/reply, admin list/view/reply /set-status), public /v1/contact for logged-out visitors with per-IP rate limit of 3 submissions/day to prevent spam-flood - Web: /settings/support (list + new), /settings/support/[id] (conversation), /admin/support, /admin/support/[id] - Public /contact form with email collection for guest tickets Data rights (DSG Art. 25 / GDPR Art. 15+20): - /v1/account/export returns user-scoped JSON of profile, org, servers, builds, audit, support tickets and messages — excludes hashes, encrypted secrets, other-user data - /settings/account: download button + deletion-via-ticket workflow Production-readiness gaps closed: - org.suspended now blocks /v1/servers POST and /v1/servers/preview (402); webhook flagged this state but enforcement was missing - Cookie banner: minimal, essential-cookies-only disclosure (Swiss DSG + GDPR compliant without dark-pattern consent UI), mounts on both layouts Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
129
apps/web/app/(marketing)/agb/page.tsx
Normal file
129
apps/web/app/(marketing)/agb/page.tsx
Normal file
@@ -0,0 +1,129 @@
|
||||
import { pageMetadata } from '@/lib/seo';
|
||||
import Link from 'next/link';
|
||||
|
||||
export const metadata = pageMetadata({
|
||||
title: 'AGB',
|
||||
description:
|
||||
'Allgemeine Geschäftsbedingungen für die Nutzung von BuildMyMCPServer (Schweiz).',
|
||||
path: '/agb',
|
||||
});
|
||||
|
||||
const SECTIONS: Array<{ h: string; p: string[] }> = [
|
||||
{
|
||||
h: '1. Geltungsbereich',
|
||||
p: [
|
||||
'Diese AGB regeln die Nutzung der über buildmymcpserver.com bereitgestellten Dienste durch natürliche und juristische Personen ("Kund:in"). Mit Erstellung eines Accounts oder Abschluss eines kostenpflichtigen Abonnements bestätigt die Kund:in, diese AGB gelesen, verstanden und akzeptiert zu haben.',
|
||||
'Abweichende Bedingungen der Kund:in gelten nur, wenn schriftlich bestätigt.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '2. Vertragsgegenstand',
|
||||
p: [
|
||||
'BuildMyMCPServer ist ein Software-as-a-Service-Angebot zur Generierung und zum Betrieb von Model-Context-Protocol-Servern (MCP-Server). Der Funktionsumfang ergibt sich aus dem jeweils gewählten Tarif gemäss Pricing-Seite.',
|
||||
'Wir liefern den Service "as-is" mit angestrebter Verfügbarkeit gemäss tariflicher SLA (Hobby/Pro: keine SLA; Team: 99.9% monatlich; Enterprise: vertraglich vereinbart).',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '3. Account und Sicherheit',
|
||||
p: [
|
||||
'Die Kund:in ist verpflichtet, Zugangsdaten vertraulich zu behandeln. Bei Verdacht auf unberechtigten Zugriff sind wir unverzüglich über das Support-Panel zu informieren.',
|
||||
'Wir behalten uns vor, Accounts bei schwerwiegenden Verstössen gegen diese AGB oder geltendes Recht zu suspendieren.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '4. Tarife und Bezahlung',
|
||||
p: [
|
||||
'Bezahlung erfolgt im Voraus über unseren Zahlungsdienstleister Stripe Payments Europe Ltd. (Irland). Akzeptierte Zahlungsmethoden umfassen Kreditkarte und SEPA-Lastschrift.',
|
||||
'Monatliche Tarife werden monatlich, Jahres-Tarife jährlich abgerechnet. Bei Jahres-Tarif werden zwei Monate gratis gewährt.',
|
||||
'Preise verstehen sich vorbehältlich gesetzlicher Mehrwertsteuer. Die anwendbare MwSt. wird durch Stripe Tax automatisch nach Sitz der Kund:in berechnet und ausgewiesen.',
|
||||
'Nutzungs-Overage (Tool-Calls über das tarifliche Kontingent hinaus) wird zu €0.02 / 1000 Calls am Folgemonat in Rechnung gestellt.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '5. Laufzeit, Kündigung und Rückerstattung',
|
||||
p: [
|
||||
'Monats-Abos verlängern sich automatisch um einen Monat, Jahres-Abos um ein Jahr. Eine Kündigung ist jederzeit über das Kundenportal (Stripe) zur nächsten Periode möglich.',
|
||||
'Bereits gezahlte Beträge werden bei Kündigung nicht anteilig rückerstattet; der Service bleibt bis Periodenende aktiv.',
|
||||
'Wir gewähren eine 14-tägige Geld-zurück-Garantie ab Erst-Buchung (nicht bei Verlängerungen). Anfragen über das Support-Panel.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '6. Aussetzung bei Zahlungsverzug',
|
||||
p: [
|
||||
'Bei fehlgeschlagener Zahlung versucht Stripe automatisch Nachzahlungen. Nach drei erfolglosen Versuchen wird der Account in den "suspended"-Status versetzt: Bestehende MCP-Server laufen weiter, jedoch können keine neuen Server angelegt oder Builds gestartet werden.',
|
||||
'Nach erfolgreicher Aktualisierung der Zahlungsmethode wird der Account automatisch reaktiviert.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '7. Daten der Kund:in',
|
||||
p: [
|
||||
'Die Kund:in behält alle Rechte an ihren Inhalten (Prompts, Konfigurationen, Secrets, generierter Code). Wir nutzen diese ausschliesslich zur Erbringung des Dienstes.',
|
||||
'Eine Datenexport-Funktion ist über das Einstellungsmenü verfügbar und entspricht Art. 25 Schweizer Datenschutzgesetz (DSG) sowie Art. 15 DSGVO.',
|
||||
'Details zur Datenverarbeitung siehe unsere Datenschutzerklärung.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '8. KI-Verarbeitung',
|
||||
p: [
|
||||
'Zur Spec-Generierung übermitteln wir Prompt-Texte an unsere KI-Anbieter: Hobby-Tarif → Zhipu AI (China); Pro/Team/Enterprise → Anthropic (USA). Vor Versand keiner sensiblen Daten gilt: Die Kund:in ist verantwortlich, welche Informationen sie in Prompts einfügt.',
|
||||
'Der generierte Code wird statisch auf gefährliche Patterns (eval, child_process, Prompt-Injection-Marker) geprüft, jedoch nicht funktional verifiziert. Die Kund:in prüft den Code vor Produktivnutzung selbst.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '9. Haftung',
|
||||
p: [
|
||||
'Wir haften nur für Schäden, die auf vorsätzlichem oder grob fahrlässigem Verhalten beruhen. Die Haftung für leichte Fahrlässigkeit, Mangelfolgeschäden, entgangenen Gewinn und Drittansprüche ist im gesetzlich zulässigen Umfang ausgeschlossen.',
|
||||
'Wir haften nicht für Inhalte oder Verhalten von Drittanbietern (Anthropic, Zhipu, Stripe, Hetzner u.a.), an die personenbezogene Daten gemäss Datenschutzerklärung übermittelt werden.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '10. Änderungen',
|
||||
p: [
|
||||
'Wir behalten uns vor, diese AGB sowie Preise mit Wirkung für die Zukunft anzupassen. Änderungen werden mindestens 30 Tage vor Inkrafttreten per E-Mail oder im Dashboard angekündigt. Bei Preisanhebung steht der Kund:in ein ausserordentliches Kündigungsrecht zum Wirkungsdatum zu.',
|
||||
],
|
||||
},
|
||||
{
|
||||
h: '11. Anwendbares Recht und Gerichtsstand',
|
||||
p: [
|
||||
'Es gilt schweizerisches Recht unter Ausschluss kollisionsrechtlicher Bestimmungen sowie des UN-Kaufrechts. Ausschliesslicher Gerichtsstand ist der Sitz des Anbieters; zwingende Verbraucher-Gerichtsstände bleiben vorbehalten.',
|
||||
],
|
||||
},
|
||||
];
|
||||
|
||||
export default function Agb() {
|
||||
return (
|
||||
<div className="mx-auto max-w-3xl px-6 py-16">
|
||||
<header className="mb-12">
|
||||
<div className="text-[11px] uppercase tracking-[0.16em] text-[--color-fg-subtle]">
|
||||
Allgemeine Geschäftsbedingungen
|
||||
</div>
|
||||
<h1 className="mt-2 text-[32px] font-semibold tracking-tight">AGB</h1>
|
||||
<p className="mt-3 text-[14px] leading-relaxed text-[--color-fg-muted]">
|
||||
Stand: 2026-05-25. Bei Fragen zur Auslegung erreichst du uns über das{' '}
|
||||
<Link href="/contact" className="text-[--color-accent] underline">
|
||||
Support-Panel
|
||||
</Link>
|
||||
.
|
||||
</p>
|
||||
</header>
|
||||
|
||||
<div className="space-y-9">
|
||||
{SECTIONS.map((s) => (
|
||||
<section key={s.h}>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">{s.h}</h2>
|
||||
<div className="mt-2 space-y-2">
|
||||
{s.p.map((p) => (
|
||||
<p
|
||||
key={p.slice(0, 32)}
|
||||
className="text-[13.5px] leading-relaxed text-[--color-fg-muted]"
|
||||
>
|
||||
{p}
|
||||
</p>
|
||||
))}
|
||||
</div>
|
||||
</section>
|
||||
))}
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
133
apps/web/app/(marketing)/contact/page.tsx
Normal file
133
apps/web/app/(marketing)/contact/page.tsx
Normal file
@@ -0,0 +1,133 @@
|
||||
'use client';
|
||||
|
||||
import { Input, Label, Textarea } from '@/components/input';
|
||||
import { Button } from '@/components/ui/button';
|
||||
import { apiFetch } from '@/lib/api';
|
||||
import Link from 'next/link';
|
||||
import { useState } from 'react';
|
||||
|
||||
export default function ContactPage() {
|
||||
const [email, setEmail] = useState('');
|
||||
const [subject, setSubject] = useState('');
|
||||
const [body, setBody] = useState('');
|
||||
const [state, setState] = useState<'idle' | 'sending' | 'sent' | 'error'>('idle');
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
setState('sending');
|
||||
setError(null);
|
||||
try {
|
||||
await apiFetch('/v1/contact', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify({ email, subject, body }),
|
||||
});
|
||||
setState('sent');
|
||||
} catch (err) {
|
||||
setState('error');
|
||||
const detail = (err as { detail?: { detail?: string; error?: string } }).detail;
|
||||
setError(detail?.detail ?? detail?.error ?? (err as Error).message);
|
||||
}
|
||||
}
|
||||
|
||||
if (state === 'sent') {
|
||||
return (
|
||||
<div className="mx-auto max-w-2xl px-6 py-16">
|
||||
<div className="panel p-6 text-center">
|
||||
<h1 className="text-[20px] font-semibold tracking-tight">Message received</h1>
|
||||
<p className="mt-2 text-[13.5px] text-[--color-fg-muted]">
|
||||
Thank you — we got your message. We'll reply to{' '}
|
||||
<span className="text-[--color-fg]">{email}</span> within one business day.
|
||||
</p>
|
||||
<p className="mt-4 text-[12px] text-[--color-fg-subtle]">
|
||||
<Link href="/" className="hover:text-[--color-fg]">
|
||||
← Back to home
|
||||
</Link>
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="mx-auto max-w-2xl px-6 py-14">
|
||||
<header className="mb-8">
|
||||
<div className="text-[11px] uppercase tracking-[0.16em] text-[--color-fg-subtle]">
|
||||
Contact
|
||||
</div>
|
||||
<h1 className="mt-2 text-[28px] font-semibold tracking-tight">Talk to us</h1>
|
||||
<p className="mt-3 text-[14px] leading-relaxed text-[--color-fg-muted]">
|
||||
We don't do public email — every conversation runs through our internal support
|
||||
panel so nothing gets lost. Already have an account?{' '}
|
||||
<Link href="/settings/support" className="text-[--color-accent] hover:underline">
|
||||
Open a ticket from inside
|
||||
</Link>
|
||||
.
|
||||
</p>
|
||||
</header>
|
||||
|
||||
<form onSubmit={submit} className="panel space-y-4 p-5">
|
||||
<div className="space-y-1.5">
|
||||
<Label htmlFor="contact-email">Your email</Label>
|
||||
<Input
|
||||
id="contact-email"
|
||||
type="email"
|
||||
required
|
||||
value={email}
|
||||
onChange={(e) => setEmail(e.target.value)}
|
||||
placeholder="you@company.com"
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="space-y-1.5">
|
||||
<Label htmlFor="contact-subject">Subject</Label>
|
||||
<Input
|
||||
id="contact-subject"
|
||||
required
|
||||
minLength={3}
|
||||
maxLength={200}
|
||||
value={subject}
|
||||
onChange={(e) => setSubject(e.target.value)}
|
||||
placeholder="Briefly — what's this about?"
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="space-y-1.5">
|
||||
<Label htmlFor="contact-body" hint={`${body.length} / 10000`}>
|
||||
Message
|
||||
</Label>
|
||||
<Textarea
|
||||
id="contact-body"
|
||||
required
|
||||
rows={7}
|
||||
minLength={10}
|
||||
maxLength={10_000}
|
||||
value={body}
|
||||
onChange={(e) => setBody(e.target.value)}
|
||||
placeholder="Tell us what's going on. We answer within one business day."
|
||||
/>
|
||||
</div>
|
||||
|
||||
{error && <p className="text-[12.5px] text-[--color-danger]">{error}</p>}
|
||||
|
||||
<div className="flex items-center justify-between pt-1">
|
||||
<p className="text-[11px] text-[--color-fg-subtle]">
|
||||
Submitting creates a support ticket — see{' '}
|
||||
<Link href="/privacy" className="hover:text-[--color-fg]">
|
||||
privacy
|
||||
</Link>
|
||||
.
|
||||
</p>
|
||||
<Button
|
||||
variant="primary"
|
||||
size="md"
|
||||
type="submit"
|
||||
disabled={state === 'sending' || !email || subject.length < 3 || body.length < 10}
|
||||
>
|
||||
{state === 'sending' ? 'Sending…' : 'Send'}
|
||||
</Button>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
95
apps/web/app/(marketing)/impressum/page.tsx
Normal file
95
apps/web/app/(marketing)/impressum/page.tsx
Normal file
@@ -0,0 +1,95 @@
|
||||
import { pageMetadata } from '@/lib/seo';
|
||||
import Link from 'next/link';
|
||||
|
||||
export const metadata = pageMetadata({
|
||||
title: 'Impressum',
|
||||
description: 'Legal information for BuildMyMCPServer (Switzerland).',
|
||||
path: '/impressum',
|
||||
});
|
||||
|
||||
export default function Impressum() {
|
||||
return (
|
||||
<div className="mx-auto max-w-3xl px-6 py-16">
|
||||
<header className="mb-10">
|
||||
<div className="text-[11px] uppercase tracking-[0.16em] text-[--color-fg-subtle]">
|
||||
Impressum
|
||||
</div>
|
||||
<h1 className="mt-2 text-[32px] font-semibold tracking-tight">Impressum</h1>
|
||||
<p className="mt-3 text-[14px] leading-relaxed text-[--color-fg-muted]">
|
||||
Angaben gemäss UWG Art. 3 Abs. 1 lit. s (Schweiz).
|
||||
</p>
|
||||
</header>
|
||||
|
||||
<div className="space-y-8">
|
||||
<section>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">Anbieter</h2>
|
||||
<div className="mt-2 text-[13.5px] leading-relaxed text-[--color-fg-muted]">
|
||||
<p>BuildMyMCPServer</p>
|
||||
<p>Schweiz</p>
|
||||
<p className="mt-2 text-[12px] text-[--color-fg-subtle]">
|
||||
Postanschrift auf Anfrage über das Support-Panel.
|
||||
</p>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">Kontakt</h2>
|
||||
<p className="mt-2 text-[13.5px] leading-relaxed text-[--color-fg-muted]">
|
||||
Sämtliche Kontaktanfragen laufen über unser integriertes Support-Panel — ohne
|
||||
Account erreichbar unter{' '}
|
||||
<Link href="/contact" className="text-[--color-accent] underline">
|
||||
/contact
|
||||
</Link>
|
||||
. Eingeloggte Nutzer:innen verwenden{' '}
|
||||
<Link href="/settings/support" className="text-[--color-accent] underline">
|
||||
/settings/support
|
||||
</Link>
|
||||
. Wir antworten in der Regel innerhalb von einem Werktag.
|
||||
</p>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">Mehrwertsteuer</h2>
|
||||
<p className="mt-2 text-[13.5px] leading-relaxed text-[--color-fg-muted]">
|
||||
UID-Nummer wird im ausgestellten Beleg geführt. Bei steuerrechtlichen Anfragen
|
||||
kontaktiere uns über das Support-Panel.
|
||||
</p>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">Haftungsausschluss</h2>
|
||||
<p className="mt-2 text-[13.5px] leading-relaxed text-[--color-fg-muted]">
|
||||
Inhalte dieser Webseite werden mit grösstmöglicher Sorgfalt erstellt. Für Richtigkeit,
|
||||
Vollständigkeit und Aktualität wird jedoch keine Gewähr übernommen. Für Inhalte
|
||||
externer Links sind ausschliesslich deren Betreiber verantwortlich.
|
||||
</p>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">Anwendbares Recht</h2>
|
||||
<p className="mt-2 text-[13.5px] leading-relaxed text-[--color-fg-muted]">
|
||||
Es gilt schweizerisches Recht unter Ausschluss kollisionsrechtlicher Bestimmungen.
|
||||
Gerichtsstand ist der Sitz des Anbieters.
|
||||
</p>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
<h2 className="text-[16px] font-semibold tracking-tight">Weiterführend</h2>
|
||||
<p className="mt-2 text-[13.5px] leading-relaxed text-[--color-fg-muted]">
|
||||
<Link href="/privacy" className="text-[--color-accent] underline">
|
||||
Datenschutzerklärung
|
||||
</Link>{' '}
|
||||
·{' '}
|
||||
<Link href="/agb" className="text-[--color-accent] underline">
|
||||
AGB
|
||||
</Link>{' '}
|
||||
·{' '}
|
||||
<Link href="/security" className="text-[--color-accent] underline">
|
||||
Security
|
||||
</Link>
|
||||
</p>
|
||||
</section>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -1,3 +1,4 @@
|
||||
import { CookieBanner } from '@/components/cookie-banner';
|
||||
import { Logo } from '@/components/logo';
|
||||
import { MarketingAuthButtons } from '@/components/marketing-auth-buttons';
|
||||
import { MarketingMobileMenu } from '@/components/marketing-mobile-menu';
|
||||
@@ -48,12 +49,21 @@ export default function MarketingLayout({ children }: { children: React.ReactNod
|
||||
<Link href="/docs" className="transition-colors hover:text-[--color-fg]">
|
||||
Docs
|
||||
</Link>
|
||||
<Link href="/contact" className="transition-colors hover:text-[--color-fg]">
|
||||
Contact
|
||||
</Link>
|
||||
<Link href="/security" className="transition-colors hover:text-[--color-fg]">
|
||||
Security
|
||||
</Link>
|
||||
<Link href="/privacy" className="transition-colors hover:text-[--color-fg]">
|
||||
Privacy
|
||||
</Link>
|
||||
<Link href="/agb" className="transition-colors hover:text-[--color-fg]">
|
||||
AGB
|
||||
</Link>
|
||||
<Link href="/impressum" className="transition-colors hover:text-[--color-fg]">
|
||||
Impressum
|
||||
</Link>
|
||||
<Link href="/terms" className="transition-colors hover:text-[--color-fg]">
|
||||
Terms
|
||||
</Link>
|
||||
@@ -61,6 +71,7 @@ export default function MarketingLayout({ children }: { children: React.ReactNod
|
||||
<div>© {new Date().getFullYear()} BuildMyMCPServer</div>
|
||||
</div>
|
||||
</footer>
|
||||
<CookieBanner />
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -38,10 +38,10 @@ const SECTIONS = [
|
||||
p: [
|
||||
"Anthropic, USA (Claude AI — used for prompt analysis and code generation on Pro / Team / Enterprise tiers). Only the prompt text and resulting spec are sent. Anthropic's data-retention policy applies.",
|
||||
'Zhipu AI, China (GLM model — used for prompt analysis on the free Hobby tier only). Only the prompt text and resulting spec are sent. Upgrade to a paid tier to keep all AI processing within Anthropic (US).',
|
||||
'Hetzner, Germany (compute).',
|
||||
'Stripe Payments Europe Ltd., Ireland (billing, invoicing, payment processing, automatic VAT). Stripe receives: email, billing address, payment method details. Card numbers are tokenised by Stripe and never reach our servers. Stripe is GDPR-compliant and Swiss-DSG-aligned via the EU-Swiss adequacy decision.',
|
||||
'Hetzner, Germany (compute, Postgres, Redis, runner containers).',
|
||||
'Backblaze, EU (encrypted backups).',
|
||||
'Stripe, Ireland (billing).',
|
||||
'Cloudflare (DNS + DDoS protection).',
|
||||
'Cloudflare (DNS + DDoS protection + TLS termination).',
|
||||
],
|
||||
},
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user