Privacy Policy
Last updated: 13 July 2026
What we collect
- Email address — your account identity. Sign-in is by magic link; there are no passwords. Optional passkeys store a public key, never biometrics.
- Payment reference — your card is held by Stripe. We store only a customer reference plus the card brand and last four digits. We never see or store the card number.
- Commitments — the place, schedule, and stake you set. Place details come from a venue search; your search text (and, if you grant location, your approximate position for nearby suggestions) is forwarded through our server to Mapbox.
- Check-in location — checking in requires your browser-reported position. We store the reported coordinates and their distance to the venue for each check-in, as proof the occurrence was kept. Location is read only when you have the app open during a check-in window — never in the background.
- Charges — missed occurrences and the resulting stake charges (amount, outcome, Stripe payment reference) are recorded as billing history.
What we don't do
- We don't sell your data.
- We don't run analytics, tracking cookies, or advertising pixels.
- We don't read your location outside an open check-in window.
Legal bases (GDPR Art. 6)
- Contract — running your account, commitments, check-ins, and charging forfeited stakes: that is the product you signed up for.
- Legitimate interests — keeping the service secure and preventing abuse, including audit logs of support actions.
- Legal obligation — retaining billing records required by tax law.
Third-party processors
- Hetzner — hosting and database. Germany (EU).
- Stripe — payments and card storage. USA.
- Resend — delivery of transactional email: sign-in links and codes, account-deletion notices, and the notice sent when all your commitments are paused (sent from EU infrastructure; Resend is a US company).
- Mapbox — venue search and geocoding. USA.
These processors act on our behalf and receive only what their function needs. US transfers rely on the EU Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework.
Retention and deletion
We keep your data as long as your account exists. You can delete your account yourself, from the account page on the site or in the app. Deletion executes as soon as nothing is owed: check-in windows already inside their 23-hour lock still run their course, and any resulting charge is settled first. Until it executes, the deletion can be cancelled.
On execution we erase all personal data: your email address, sessions and passkeys, check-in locations, place history, and your stored card (the customer record at our payment processor is deleted). What remains are anonymized charge and outcome records — amounts, timestamps, and the payment processor's transaction reference, with no link to you — retained because tax and commercial law require it (Art. 6(1)(c) GDPR).
Cookies
Session cookie only — required to keep you signed in. Nothing else is set.
Your rights (GDPR)
Access, correction, deletion, portability, and objection. Deletion is self-serve (see above); for everything else email us and we act within 30 days. You can also lodge a complaint with a supervisory authority; for us that is the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI).
Contact
Controller: Johannes Nanninga — full details in the Impressum.