Privacy Policy
This privacy policy informs you about the processing of personal data pursuant to GDPR (General Data Protection Regulation / Datenschutz-Grundverordnung / DSGVO).
1. Data Controller
Pautsch Digital UG (haftungsbeschränkt), Im Biengarten 14, 63456 Hanau — Email: privacy [at] sportbuddies.de
2. What Data We Process
Session data: we create an anonymous account before you sign in, so you can browse events without registering. It is carried by a signed JWT in an HttpOnly cookie.
Account data on sign-in, depending on the method you choose: via Google (name, email address, profile picture), via Apple (email address; Apple does not send us a name), or via a one-time code we email you (email address).
Content you create yourself: profile details (name, city, sports, description, profile picture) plus events, groups and chat messages.
Technical access data in server logs: IP address, timestamp, requested address, status code and user agent.
Pseudonymous usage events — see section 7.
3. Legal Basis
Anonymous session cookies: legitimate interest pursuant to Art. 6(1)(f) GDPR (technically necessary).
Account data from signing in via Google, Apple or an email code: consent pursuant to Art. 6(1)(a) GDPR.
Profile and content data you create in the app: performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
Pseudonymous usage analytics and technical access data: legitimate interest pursuant to Art. 6(1)(f) GDPR — we need to be able to tell whether the platform works technically, how it is used, and whether it is economically viable. You may object to this processing under Art. 21 GDPR; section 7 explains how.
4. Retention Period
Access token: 15 minutes. Refresh token: 7 days. Account, profile and content data: until the account is deleted. Anonymous accounts that have done nothing for 30 days are deleted automatically.
Server logs: overwritten on a rolling basis and capped at 30 MB per service — typically a few days. They are not archived and not shipped to any long-term store.
Usage events: the direct user ID is removed automatically after 90 days at the latest. The event itself is retained indefinitely in pseudonymous form (section 7).
5. Your Rights
You have the rights under Art. 15–22 GDPR: access, rectification, erasure, restriction of processing, data portability and objection. Contact privacy [at] sportbuddies.de. We respond within one month.
On erasure, plainly: there is currently no button with which you can delete your own account — we carry out the deletion on your request. This removes your account, profile and content data. The pseudonymous usage events remain, but lose any link to you, because we also delete the only table through which the pseudonym could be resolved (section 7).
In response to an access request we can produce your account, profile and content data, plus the usage events associated with your pseudonym. Server logs are usually gone by then, given how quickly they are overwritten.
You also have the right to lodge a complaint with a data protection supervisory authority.
6. Cookies
access_token: HttpOnly, Secure, SameSite=Lax — signed JWT for the current session, expires after 15 minutes.
refresh_token: HttpOnly, Secure, SameSite=Lax, Path=/api/auth/refresh — automatic token renewal, expires after 7 days.
oauth2_auth_request and redirect_after: short-lived helper cookies (3 minutes each), set only during a sign-in that is in progress, so that you land back on the page you came from.
These cookies are technically necessary and cannot be disabled. We set no cookies for analytics or advertising.
7. Usage Analytics
We measure usage of the platform ourselves, on our own servers. No third-party analytics service is involved, no tracking script, no session recording and no ad network.
The measurement happens on the server, not in your browser: nothing is stored on your device and nothing is read from it for this purpose. That is why § 25 TDDDG does not apply — and why there is no cookie banner here.
What is recorded is that something happened: that an event was created, that someone joined or left, that a group was founded, that a message was sent, or that an account was active on a given day — each with a timestamp and a city and sport identifier. We do not store message contents, profile text, email addresses or IP addresses in these records.
Instead of your user ID, each event carries a pseudonym computed with a secret server key (HMAC-SHA256), which cannot be reversed without that key. We additionally keep the direct user ID for at most 90 days so that incidents can be investigated; after that it is removed automatically. The pseudonymous events are retained indefinitely, because year-on-year comparisons and usage trends cannot be reconstructed after the fact.
Objection under Art. 21 GDPR: write to privacy [at] sportbuddies.de with the subject "Objection to usage analytics". No reason is required. We will then stop evaluating your usage and delete the entry through which your events could be attributed to you.
8. Recipients and Processors
Hosting: Hetzner Online GmbH, Germany. The application and the database run on servers in German data centres.
Email delivery: Scaleway, France (Transactional Email). Transmitted are the recipient address and the content of the message concerned — welcome email, sign-in code and notifications.
Backups: encrypted database backups on a Hetzner Storage Box. The backup is encrypted on our own server before it is transferred; we alone hold the key, and the storage provider cannot read the contents.
Third-party sign-in: Google and Apple learn that you are signing in with us and send us the account data listed in section 2. Those providers are responsible for their own processing.
Operational monitoring: so that a missed nightly maintenance job is noticed, our server reports to Healthchecks.io that a job has started or finished. No user data is transmitted.
Beyond this we do not pass on personal data. We do not sell data, run no advertising business, and make no automated decisions within the meaning of Art. 22 GDPR.