Parat.io

Datenschutzerklärung

Version: 0.1-draft · Stand: [DATUM]

warning

Entwurf — noch nicht juristisch geprüft

Dieses Dokument ist ein Platzhalter-Entwurf. Betreiberangaben, Kontaktdaten und Aufsichtsbehörde enthalten noch [PLATZHALTER], und die rechtliche Formulierung muss von einem Datenschutz­anwalt geprüft werden, bevor das Dokument rechtsgültig ist.

Wie parat.io deine personenbezogenen Daten gemäß DSGVO verarbeitet.

1. Controller

The data controller under Art. 4(7) GDPR for parat.io is:

[CONTROLLER NAME] · [LEGAL FORM]
[CONTROLLER ADDRESS]
Email: [CONTROLLER EMAIL]

No Data Protection Officer has been appointed because the size and nature of processing does not trigger the obligation under Art. 37 GDPR / §38 BDSG.

2. Summary

  • Parat.io is a sport event calendar. You can keep a private calendar of your own events and discover public events other users publish.
  • We do not sell your personal data and we do not share it with advertisers.
  • Core processing legal basis for a logged-in account is the contract concluded at sign-up (Art. 6(1)(b) GDPR).
  • Main processors are Google (Firebase) and Vercel. Both are US-based; we rely on their Standard Contractual Clauses for transfers.

3. Data we process, why, for how long

Account & profile: email, display name, hashed password (or Google OAuth identifier), UID, role, optional organization / region / timezone / home location / avatar. Basis: Art. 6(1)(b). Retained while your account exists; erased within 30 days of account deletion (tax-law retention may apply).

Events: title, date range, location (name + coordinates + geohash), optional images. Basis: Art. 6(1)(b) for personal events, Art. 6(1)(a) (consent) for publicly-published events. Retained until you delete the event or the account.

Social features: groups, follow / block relationships, activity feed entries, RSVPs, invitations (invited email + token). Basis: Art. 6(1)(b) + 6(1)(f). Erased / anonymized within 30 days of account deletion.

Server logs: IP address, User-Agent, requested URL, status code, timestamp. Basis: Art. 6(1)(f) operational security. Retention: Vercel default (up to 30 days).

Search & geocoding queries: the location strings you type are forwarded to a geocoding provider (Nominatim by default, Google Maps if configured). We do not store your individual queries.

We do NOT collect: payment data (the service is free), biometric data, Art. 9 special-category data, or data from users under 16.

4. Cookies & local storage

See the separate Cookie Policy. We do not currently use analytics, tracking, or advertising cookies. Before any such cookie is set, a consent banner will allow you to reject non-essential cookies with a single click.

5. Processors (Art. 28 GDPR)

  • Google LLC / Google Cloud (Firebase) — database, auth, storage — USA
  • Vercel Inc. — hosting, serverless functions, logs — USA
  • Google Maps / Places API — optional geocoding — USA
  • OpenStreetMap / Nominatim — geocoding fallback (primary) — EU
  • CARTO — map tile CDN — USA

Ad pixels (e.g. Meta Pixel) are not currently loaded and will only be loaded after your consent via a cookie banner.

6. External links to Google Maps

The app provides external links (“Open in Google Maps”) to maps.google.com with rel="noopener noreferrer". Clicking a link opens Google Maps in a new tab; from that point Google's own privacy policy applies. We do not embed or load Google Maps content inside parat.io.

7. International transfers

Transfers to US processors (Google, Vercel) rely on Standard Contractual Clauses as published by the European Commission, and where applicable the EU-U.S. Data Privacy Framework certifications. A copy of the relevant SCCs can be requested at [CONTROLLER EMAIL].

8. Your rights (Art. 15–22 GDPR)

  • Access (Art. 15) — request a copy of your data
  • Rectification (Art. 16) — most fields are editable in your profile
  • Erasure (Art. 17) — trigger account deletion in your profile
  • Restriction (Art. 18)
  • Portability (Art. 20) — one-click JSON export in your profile
  • Objection (Art. 21)
  • Withdrawal of consent (Art. 7(3))

To exercise any right, email [CONTROLLER EMAIL]. You also have the right to lodge a complaint with a supervisory authority (Art. 77), for us typically [SUPERVISORY AUTHORITY].

9. Children

The service is not intended for users under 16. We do not knowingly collect personal data from children below that age.

10. Security

TLS in transit, encryption at rest (Firestore, Storage), per-user security rules, short-lived Firebase tokens, token-based secret URLs for calendar subscriptions. Personal-data breaches posing a risk to your rights will be reported to the supervisory authority within 72 hours (Art. 33) and to you directly where required (Art. 34).

11. Changes

We will update this document as the service evolves. Material changes affecting registered users will be announced in-app and/or by email at least 30 days before they take effect.

12. Contact

Questions about this Privacy Policy? Email [CONTROLLER EMAIL] or write to the postal address in §1.