Privacy Policy
This privacy policy informs you about the processing of personal data pursuant to GDPR (General Data Protection Regulation / Datenschutz-Grundverordnung / DSGVO).
1. Data Controller
Pautsch Digital UG (haftungsbeschränkt), Im Biengarten 14, 63456 Hanau — Email: datenschutz [at] sportbuddies.de
2. What Data We Process
Session data: we create an anonymous account before you sign in, so you can browse events without registering. It is carried by a signed JWT in an HttpOnly cookie.
Account data on sign-in, depending on the method you choose: via Google (name, email address, profile picture), via Apple (email address; Apple does not send us a name), or via a one-time code we email you (email address).
Content you create yourself: profile details (name, city, sports, description, profile picture) plus events, groups and chat messages. For chat messages, please see section 5: messages in group and event chats stay in the thread when an account is deleted, without your name.
Technical access data in server logs: IP address, timestamp, requested address, status code and user agent.
Pseudonymous usage events — see section 7.
3. Legal Basis
Anonymous session cookies: legitimate interest pursuant to Art. 6(1)(f) GDPR (technically necessary).
Account data from signing in via Google, Apple or an email code: consent pursuant to Art. 6(1)(a) GDPR.
Profile and content data you create in the app: performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
Pseudonymous usage analytics and technical access data: legitimate interest pursuant to Art. 6(1)(f) GDPR — we need to be able to tell whether the platform works technically, how it is used, and whether it is economically viable. You may object to this processing under Art. 21 GDPR; section 7 explains how.
4. Retention Period
Access token: 15 minutes. Refresh token: 7 days. Account, profile and content data: until the account is deleted. Anonymous accounts that have done nothing for 30 days are deleted automatically.
Server logs: overwritten on a rolling basis and capped at 30 MB per service — typically a few days. They are not archived and not shipped to any long-term store.
Usage events: the direct user ID is removed automatically after 90 days at the latest. The event itself is retained indefinitely in pseudonymous form (section 7).
5. Your Rights
You have the rights under Art. 15–22 GDPR: access, rectification, erasure, restriction of processing, data portability and objection. Contact datenschutz [at] sportbuddies.de. We respond within one month.
On erasure, plainly: you can delete your account yourself, in the app — in your profile under “Delete account”. It takes effect immediately and cannot be undone; there is no waiting period and no way back. We will of course still carry it out for you on request to datenschutz [at] sportbuddies.de.
This removes your account and profile data, your buddy relationships, your direct messages, and your RSVPs, XP, awards and ladder entries. Two things are not removed, and we name them explicitly: past events you organised remain, without your name, because other people's points and results hang off them — and your messages in group and event chats remain in the thread, without your name, so the conversation stays intelligible to everyone else in it. The text of those messages is therefore not deleted. If you want specific message content removed, write to datenschutz [at] sportbuddies.de and we will do it by hand.
The pseudonymous usage events remain, but lose any link to you, because we also delete the only table through which the pseudonym could be resolved (section 7).
In response to an access request we can produce your account, profile and content data, plus the usage events associated with your pseudonym. Server logs are usually gone by then, given how quickly they are overwritten.
You also have the right to lodge a complaint with a data protection supervisory authority.
6. Cookies
access_token: HttpOnly, Secure, SameSite=Lax — signed JWT for the current session, expires after 15 minutes.
refresh_token: HttpOnly, Secure, SameSite=Lax, Path=/api/auth/refresh — automatic token renewal, expires after 7 days.
oauth2_auth_request and redirect_after: short-lived helper cookies (3 minutes each), set only during a sign-in that is in progress, so that you land back on the page you came from.
These cookies are technically necessary and cannot be disabled. We set no cookies for analytics or advertising.
7. Usage Analytics
We measure usage of the platform ourselves, on our own servers. No third-party analytics service is involved, no tracking script, no session recording and no ad network.
The measurement happens on the server, not in your browser: nothing is stored on your device and nothing is read from it for this purpose. That is why § 25 TDDDG does not apply — and why there is no cookie banner here.
What is recorded is that something happened: that an event was created, that someone joined or left, that a group was founded, that a message was sent, or that an account was active on a given day — each with a timestamp and a city and sport identifier. We do not store message contents, profile text, email addresses or IP addresses in these records.
Instead of your user ID, each event carries a pseudonym computed with a secret server key (HMAC-SHA256), which cannot be reversed without that key. We additionally keep the direct user ID for at most 90 days so that incidents can be investigated; after that it is removed automatically. The pseudonymous events are retained indefinitely, because year-on-year comparisons and usage trends cannot be reconstructed after the fact.
Separately from this, we count how many people were active on a given day and in a given month. That count needs no identifier at all: we increment a counter at the moment your account becomes active for the first time on a day, and store only the number — not who was counted. What ends up stored is a statement like “4,711 accounts were active on 27 August”.
Objection under Art. 21 GDPR: while signed in you can switch the person-level analysis off yourself at any time, under “Settings → Privacy”. Without an account, an email to datenschutz [at] sportbuddies.de with the subject “Objection to usage analytics” is enough; no reason is required.
What the objection does: from then on your events carry no pseudonym, no user ID and no session or record identifier — only a timestamp, city, sport and plan. We remove the same details from the events already recorded and delete the entry through which those events could be attributed to you. Your usage history can no longer be reassembled. The anonymous count described above continues, because it contains nothing about you to object to. You can withdraw the objection at any time; the attribution entry is then created again, but the removed details do not come back.
8. Recipients and Processors
Hosting: Hetzner Online GmbH, Germany. The application and the database run on servers in German data centres.
Email delivery: Scaleway, France (Transactional Email). Transmitted are the recipient address and the content of the message concerned — welcome email, sign-in code and notifications.
Backups: encrypted database backups on a Hetzner Storage Box. The backup is encrypted on our own server before it is transferred; we alone hold the key, and the storage provider cannot read the contents.
Third-party sign-in: Google and Apple learn that you are signing in with us and send us the account data listed in section 2. Those providers are responsible for their own processing.
Operational monitoring: so that a missed nightly maintenance job is noticed, our server reports to Healthchecks.io that a job has started or finished. No user data is transmitted.
Beyond this we do not pass on personal data. We do not sell data, run no advertising business, and make no automated decisions within the meaning of Art. 22 GDPR.