Privacy

Privacy Policy

How we process personal data in our apps and on our websites.

State: January 2026

Back to Home

1. Controller / Responsible Entity

The controller responsible for data processing pursuant to Art. 4 No. 7 GDPR is:

Haukel GbR
Marc Hauck & Jan Kellermann
Am Bärenbach 11
74541 Vellberg
Germany

Phone: +49 ...
Email: [email protected]

2. Scope

This Privacy Policy applies to our websites and to our mobile apps (for example LaunchX). Where features differ between platforms, the relevant section applies only to the platform named in it.

3. Hosting & Server Log Files (Websites)

Our websites run on our own server at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We have concluded a Data Processing Agreement (AV-Vertrag) with the provider pursuant to Art. 28 GDPR.

When you visit our websites, the web server automatically records data in server log files (IP address, time of request, browser info) for security purposes (e.g., DDoS protection). Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in the security and stability of the service).

4. Local Storage & No Web Tracking (Websites)

On our websites we do not use tracking cookies, third-party analytics, or advertising scripts. We use technically essential browser storage (Local Storage, Session Storage) solely to provide the functionality you requested (e.g., maintaining your login session or saving interface preferences).

Legal Basis: Strictly necessary storage requires no consent (§ 25 Abs. 2 No. 2 TDDDG); associated processing is based on our legitimate interest in a functioning service (Art. 6(1)(f) GDPR).

5. Usage Analytics (Apps)

In our apps we process pseudonymous usage and diagnostics data only if you have enabled analytics (opt-in). For this we use analytics and crash-reporting tools (such as Google Firebase). On iOS, we ask for your permission via App Tracking Transparency before any tracking takes place.

Legal Basis: Your consent (Art. 6(1)(a) GDPR, § 25 Abs. 1 TDDDG). You can withdraw your consent at any time in the app settings with effect for the future.

6. Push Notifications (Apps)

If you enable notifications, we process a device push token (via Apple Push Notification service or Firebase Cloud Messaging) in order to send you the reminders and updates you requested (e.g., launch reminders). You can disable notifications at any time in the app or device settings.

Legal Basis: Your consent and the performance of the requested service (Art. 6(1)(a) and (b) GDPR).

7. Location (Apps)

If you grant location access, your location is used to provide location-based features (such as visibility, weather and overpass calculations). Processing happens on your device or transiently for the requested calculation; we do not build movement profiles.

Legal Basis: Your consent (Art. 6(1)(a) GDPR). You can revoke location access at any time in your device settings.

8. Account & Sign-In

If you create an account, we process the data required for registration and login. You may sign in using Sign in with Apple or Google Sign-In; in that case the respective provider transmits the identifiers needed to authenticate you.

Legal Basis: Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR).

9. Payment & Subscriptions

Purchases and subscriptions made through an app store are processed by Apple or Google; subscription status may be managed via a subscription provider (such as RevenueCat). We do not receive your full payment data.

For direct purchases on our websites, we transmit your payment data solely for payment processing to our payment service provider (e.g., Stripe, PayPal, or bank transfer). Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR).

10. External Services

Google Fonts (Local Hosting): Our websites use fonts that are installed locally on our server. No connection to Google servers is established during page load.

11. Storage Duration

We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention periods. Server log files are kept for a short period for security and then deleted or anonymized. Contract and payment data is retained in line with statutory commercial and tax obligations (generally 6 to 10 years, § 257 HGB, § 147 AO).

12. International Data Transfers

Some providers (e.g., Apple, Google/Firebase, payment and subscription providers) may process data in third countries outside the EU/EEA, in particular the USA. Such transfers only take place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses (SCC) or, where applicable, an adequacy decision (such as the EU-US Data Privacy Framework).

13. Your Rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object (Art. 21 GDPR). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR). To exercise these rights, contact us at [email protected].

Right to lodge a complaint (Art. 77 GDPR):
The authority competent for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.