Privacy Policy
How we collect, use, and protect your personal information
1. Data Protection at a Glance
The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.
Data Collection on this Website
Who is responsible for the data collection on this website?
Data processing on this website is carried out by the website operator. You can find the contact details of the website operator in the section "Information about the Responsible Party" in this data protection declaration.
How do we collect your data?
On the one hand, your data is collected by you providing it to us. This can be, for example, data that you enter in a contact form. Other data is collected automatically or after your consent when visiting the website by our IT systems. This is mainly technical data (e.g. Internet browser, operating system or time of page view). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipient and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time.
Third-party Analytics and Tools
When visiting this website, your surfing behavior can be statistically evaluated. This is done primarily with so-called analysis programs. Detailed information about these analysis programs can be found in the following privacy policy.
2. Use of Firebase Services
Our website and mobile application use Google Firebase, a platform provided by Google LLC, to support essential functionality and enhance user experience. The following Firebase services are integrated into our system:
Firebase Hosting
We use Firebase Hosting to serve our website content securely and efficiently via Google's global CDN (Content Delivery Network). When you access our website, Firebase automatically logs standard request information, such as IP address, request type, browser type, and operating system, to ensure performance and security.
Cloud Firestore
We use Cloud Firestore as a cloud-hosted, NoSQL database to store and retrieve user-related and application-specific data in real-time. All data stored in Firestore is protected through Firebase security rules. We do not store personally identifiable information unless explicitly stated.
Firebase Authentication (Anonymous)
We use Firebase Authentication to manage user sessions anonymously. This means we do not collect any personal identifiers such as name, email, or phone number. Anonymous authentication allows users to access app features without revealing their identity. Firebase may assign a unique, random ID to each session, but this ID cannot be linked to a specific individual.
Firebase App Check
To protect our app and backend resources from abuse (e.g., spoofing or unauthorized access), we use Firebase App Check. App Check verifies that requests come from our genuine app by validating device integrity. No personally identifiable information is collected during this process.
Firebase Functions
We use Cloud Functions for Firebase to run backend code in response to events triggered by our app (e.g., authentication, database changes). These functions run in a secure environment and are subject to Google’s infrastructure security and compliance standards.
Google Analytics for Firebase
We use Google Analytics to collect aggregated and anonymized data about how users interact with our app and website. This includes data such as:
- Pages visited and time spent
- Device and browser type
- General location (e.g., country-level based on IP)
- Events and actions (e.g., button taps, screen transitions)
We use this data solely to understand usage patterns and improve the service. IP anonymization is enabled, and we do not use Analytics to track individual users.
Data Handling and Compliance
All Firebase services are provided by Google LLC. Data may be processed and stored on servers located globally. Google complies with major data protection regulations, including the GDPR. For more information on Firebase privacy practices, see:
https://firebase.google.com/support/privacy
3. General Notes and Mandatory Information
Privacy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done. We would like to point out that data transmission on the Internet (e.g. when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
Information about the Responsible Party
See the imprint for the responsible party. The responsible body is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses or similar).
Storage Duration
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be deleted once these reasons no longer apply.
General Information on the Legal Basis for Data Processing on this Website
If you have consented to data processing, we process your personal data on the basis of Art. 6 (1) a GDPR or Art. 9 (2) a GDPR, if special categories of data are processed according to Art. 9 (1) GDPR. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 (1) a GDPR. If you have consented to the storage of cookies or to the access to information in your terminal device (e.g. via device fingerprinting), the data processing is additionally carried out on the basis of Section 25 (1) TTDSG. The consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6 para. 1 lit. c GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6 para. 1 lit. f GDPR. Information about the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Note on Data Transfer to the USA and other countries
Among other things, we use tools from companies based in the USA or other countries that are not secure under data protection law. If these tools are active, your personal data may be transferred to these third countries and processed there. We would like to point out that no level of data protection comparable to that in the EU can be guaranteed in these countries. For example, US companies are obliged to hand over personal data to security authorities without you as a data subject being able to take legal action against this. Therefore, it cannot be ruled out that U.S. authorities (e.g. intelligence agencies) may process, evaluate and permanently store your data located on U.S. servers for monitoring purposes. We have no influence on these processing activities.
Withdrawal of your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 ABS. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING IS FOR THE PURPOSE OF ASSERTING, EXERCISING OR DEFENDING LEGAL CLAIMS (OBJECTION UNDER ARTICLE 21(1) GDPR). IF YOUR PERSONAL DATA ARE PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ARTICLE 21 (2) GDPR).
Right of Appeal to the Competent Supervisory Authority
In the event of breaches of the GDPR, data subjects shall have a right of appeal to a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged breach. The right of appeal is without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, Deletion and Correction
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient and the purpose of data processing and, if necessary, a right to correction or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time. The right to restriction of processing exists in the following cases: If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data. If the processing of your personal data happened/is happening unlawfully, you can request the restriction of data processing instead of deletion. If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request restriction of the processing of your personal data instead of erasure. If you have lodged an objection pursuant to Art. 21 (1) GDPR, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data. If you have restricted the processing of your personal data, this data may - apart from being stored - only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a Member State.
SSL and TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data Collection on this Website
Cookies
Our Internet pages use so-called "cookies". Cookies are small text files and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser. In some cases, cookies from third-party companies may also be stored on your device when you enter our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services). Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies are used to evaluate user behavior or display advertising. Cookies that are necessary to carry out the electronic communication process, to provide certain functions that you have requested (e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6 (1) lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); the consent can be revoked at any time. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited. Insofar as cookies are used by third-party companies or for analysis purposes, we will inform you separately about this within the framework of this data protection declaration and, if necessary, request your consent.
5. Request by E-Mail, Phone or Fax
If you contact us by e-mail, telephone or fax, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent. The processing of this data is based on Art. 6 (1) lit. b GDPR, if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the requests sent to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if this has been requested; the consent can be revoked at any time. The data you send to us via contact requests will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular legal retention periods - remain unaffected.
6. Use of Mixpanel Analytics
We use Mixpanel to collect insights on how users interact with our website and mobile app, enabling us to improve functionality and user experience. Mixpanel operates as a first-party analytics provider, meaning data sent to Mixpanel is controlled by us—you decide what’s collected (mixpanel.com).
What Mixpanel Collects
Mixpanel may collect information such as:
- Device and browser details
- General location (city, region, country, not precise GPS)
- Usage metrics (pages viewed, time spent, feature interactions)
- Event IDs and Mixpanel-generated user IDs
- App version, operating system, and session data (mixpanel.com)
This data is aggregated to identify patterns and does not include personal identifiable information (PII) unless explicitly added by your implementation (mixpanel.com).
Consent & Opt-Out
Mixpanel is compliant with GDPR, CCPA, HIPAA, and similar regulations. It does not collect personal data unless users opt in, and supports opt-out methods within its SDKs for JavaScript, iOS, and Android (docs.mixpanel.com). We ensure you can withdraw consent and disable tracking at any time.
Storage & Retention
Data may be processed in the U.S., Europe, or India depending on your data residency settings (docs.mixpanel.com).
Events are retained for up to 5 years by default
Mixpanel provides APIs for data access/export or deletion to support GDPR subject rights (docs.mixpanel.com).
Security & Compliance
Mixpanel uses end-to-end encryption (TLS in transit, encryption at rest), is SOC-2 Type II certified, and offers strong role-based access controls (mixpanel.com). Customers retain full control over what data is sent, preventing collection of unnecessary or sensitive information (mixpanel.com).
International Data Transfers
Mixpanel supports EU and India data residency. For users outside those regions, transfers are protected by encryption, Standard Contractual Clauses, and other data-transfer safeguards (mixpanel.com).
No Session Replay or Sensitive Data Capture
By default, Mixpanel does not perform session replay, nor does it collect granular location, passwords, contact lists, or health/financial data (mixpanel.com). While Mixpanel offers an Autotrack feature, it can be configured to redact sensitive inputs or disabled entirely to prevent unintended data capture.
7. Use of Sentry
We use Sentry, an application monitoring service provided by Functional Software, Inc. (“Sentry”), to help identify, diagnose, and fix errors, performance issues, and crashes in our website and applications.
Data You Provide & Service Data
Sentry collects data that our site or app sends, such as error reports, stack traces, logs, and diagnostic metadata. We control what is included. If you input personal information (e.g., via logs or user actions), that data may be included unless we configure scrubbing or exclusion.
Sentry does not require personal data to operate its service; however, data sent depends on our implementation. Customers can use Sentry’s SDKs and data-scrubbing tools to exclude sensitive or personally identifiable information before transmission—including via a filtering layer or SDK configuration.
Data Scrubbing & Minimization
We employ Sentry’s data-scrubbing features to redact or remove sensitive data (e.g., IPs, usernames, credentials) from error reports. We can also route reports through a proxy to clean them before sending.
International Data Transfers & Residency
Sentry offers data hosting in the EU, allowing us to localize data storage to meet European data-protection requirements. Transfers to the U.S. are covered under robust frameworks, including the EU–U.S. Data Privacy Framework, the UK and Swiss extensions, or Standard Contractual Clauses.
Compliance with Regulations
Sentry is GDPR and CCPA compliant. Their Data Processing Addendum prohibits selling or sharing personal data, and specifies the legal basis and data handling responsibilities.
Data Security & Retention
Sentry applies technical and organizational safeguards to protect data. Details are available in their privacy and trust documentation. Data retention and deletion policies are configurable per account and aligned with regulatory obligations.
Your Rights
If personal data is included in error reports, you may exercise your data protection rights (e.g., access, portability, rectification, deletion). For such requests, you may contact us or the customer organization that controls that data instance. For privacy policy questions, you can also reach out to Sentry via the contact info in their privacy documentation.