Vorratsmanager

Privacy policy

Placeholder — replace before launch. The highlighted values below are examples and must be replaced with your real details before this site goes public.

1. Controller

The controller responsible for data processing on this platform is: Max Mustermann, Musterstraße 1, 12345 Musterstadt, Germany, email: kontakt@vorratsmanager.de.

2. General principles

We process personal data only to the extent necessary to provide a functional application together with our content and services. The legal bases are in particular Art. 6(1)(b) GDPR (contract/user account), (f) (legitimate interest in secure operation), (c) (legal obligations) and, where applicable, (a) (consent).

3. Hosting and server log files

The application runs on servers of our hosting provider Hetzner Online GmbH, Germany. Data is stored exclusively on servers in the EU/Germany.

When the site is accessed, the server automatically collects access data (IP address, date and time, page requested, amount of data transferred, browser type/version, operating system). This serves delivery, stability and security (Art. 6(1)(f) GDPR). Log data is deleted or anonymised after 7 days.

4. Cookies and local storage

We use technically necessary cookies or comparable storage techniques to keep you signed in (session/authentication token) and to store settings such as the colour scheme. These are required for operation (Art. 6(1)(f) GDPR and § 25(2) TDDDG). We do not use tracking or advertising cookies.

For offline use, the app mirrors your inventory data locally on your device (browser: IndexedDB; app: SQLite). This data stays on your device and is only transmitted to the server to synchronise with your account.

5. User account and content data

For registration we process your email address, username and a password (stored only as a cryptographic hash). To use the service you enter content data yourself, such as stocks, storage locations, shopping lists, recipes, meal plans, preparedness details and optional household members. This processing is for the performance of the contract (Art. 6(1)(b) GDPR).

In a shared household, the content data you enter is visible to the other members of that household. If you upload images (e.g. product photos), they are stored on our server.

6. Email delivery

For transactional emails (registration confirmation, invitations, password reset, expiry reminders) we use an email provider (e.g. Postmark / Brevo / own mail server). This processes your email address and the respective message content (Art. 6(1)(b) and (f) GDPR).

7. Payment processing

For paid plans we offer two options. If you pay by bank transfer, we process the payment/reference details you provide in order to match the incoming payment.

For online payment we use the payment provider Stripe Payments Europe, Ltd., Ireland (card, Apple Pay, Google Pay, and PayPal where applicable). You enter your payment data (e.g. card details) directly with Stripe; we do not receive it, only a confirmation of the payment status. Stripe may also transfer data to the USA (safeguarded by EU standard contractual clauses). The legal basis is Art. 6(1)(b) GDPR; tax/commercial retention obligations follow from (c).

8. AI features

If you use optional AI features, the inputs required for them (e.g. free text, ingredient or product details) are transmitted to our AI provider Anthropic, PBC, USA and processed there to generate the response. Transmission only takes place when you actively trigger an AI feature (Art. 6(1)(b) GDPR). Do not enter particularly sensitive personal data into AI features. The transfer to the USA is safeguarded by EU standard contractual clauses.

9. Push notifications

With your consent we send push notifications (e.g. expiry reminders). For this we store a device- or browser-specific push token. You can revoke notifications at any time in your device/browser settings or in the app (Art. 6(1)(a) GDPR).

10. Error monitoring

If enabled, we use Sentry to capture technical errors in order to improve stability and security. This may process technical data (error message, affected function, possibly a truncated IP) (Art. 6(1)(f) GDPR). Without an active configuration, no such transmission takes place.

11. Retention period

We store personal data for as long as your account exists or as long as it is necessary to fulfil the purpose. After you delete your account, your data is deleted unless statutory retention obligations (e.g. for payment records) apply.

12. Your rights

Under the GDPR you have the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

13. Right to complain

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or the place of the alleged infringement (Art. 77 GDPR). The competent authority is, for example, the supervisory authority of your federal state.

14. Changes to this policy

We update this privacy policy whenever changes to our processing make it necessary. The version published on this page applies in each case.