Privacy Policy

Version: 0.1-draft · Effective date: August 17, 2026

How parat.io handles your personal data under the GDPR.

1. Controller

The data controller under Art. 4(7) GDPR for parat.io is:

Jochen Leinberger · Einzelunternehmer (sole proprietor)
Germany
Email: hello@parat.io

No Data Protection Officer has been appointed because the size and nature of processing does not trigger the obligation under Art. 37 GDPR / §38 BDSG.

2. Summary

  • Parat.io is a sport event calendar. You can keep a private calendar of your own events and discover public events other users publish.
  • We do not sell your personal data and we do not share it with advertisers.
  • Core processing legal basis for a logged-in account is the contract concluded at sign-up (Art. 6(1)(b) GDPR).
  • Your data is stored in the EU (Google Firebase, region europe-west4 / EU multi-region). Hosting runs on Vercel, a US company; Standard Contractual Clauses apply to residual transfers (see section 7).

3. Data we process, why, for how long

Account & profile: email, display name, hashed password (or Google OAuth identifier), UID, role, optional organization / region / timezone / home location / avatar. Basis: Art. 6(1)(b). Retained while your account exists; erased immediately when you delete your account.

Events: title, date range, location (name + coordinates + geohash), optional images. Basis: Art. 6(1)(b) for personal events, Art. 6(1)(a) (consent) for publicly-published events. Retained until you delete the event or the account.

Social features: invitations (invited email + token), participation records, and the host name shown on events you joined. Basis: Art. 6(1)(b) + 6(1)(f). Invitations expire after 30 days and are then deleted automatically. On account deletion your social records are erased immediately and your name on other users' joined events is anonymized.

Server logs: IP address, User-Agent, requested URL, status code, timestamp. Basis: Art. 6(1)(f) operational security. Retention: Vercel default (up to 30 days).

Reach measurement (Vercel Web Analytics): to understand which pages are used, we count page views with Vercel Web Analytics. It sets no cookie and stores nothing on your device; the script and the beacon are served from our own domain. Vercel derives a visitor hash from your IP address and browser signature that is valid for a single day and cannot be linked across days or sites, and records the page path, referrer, country, and device class — no user IDs, no profiles, no cross-site tracking. Basis: Art. 6(1)(f), our legitimate interest in understanding how the service is used. You may object at any time by emailing hello@parat.io.

Search & geocoding queries: the location strings you type are resolved through our own server, which forwards only the text of your query to a geocoding service (Photon by Komoot; Nominatim as fallback; Google Places only if explicitly configured). Your IP address is not passed on, and we do not store your individual queries.

Calendar subscriptions (iCal): if you subscribe to your personal calendar feed in a calendar app (Apple, Google, …), that provider polls the feed and keeps a copy of your calendar under your account with them. The feed URL contains a secret token that you can rotate at any time in your settings.

AI assistant connections (MCP): you can connect an AI assistant of your choice (e.g. Claude, ChatGPT) to your parat.io calendar. This is entirely user-initiated: your events are then shared with that assistant inside your own account with the AI provider. Access is scope-limited (read-only by default), tokens expire after 90 days, and you can revoke a connection at any time in your settings. Basis: Art. 6(1)(b).

Race planner & Suunto: the race planner keeps your GPX track and pacing plan locally in your browser. If you connect your Suunto account, OAuth tokens are stored in an encrypted cookie (rp_session, ~180 days) — not in a server database — and routes you export are uploaded to your own Suunto account. Basis: Art. 6(1)(b).

We do NOT collect: payment data (the service is free), biometric data, Art. 9 special-category data, or data from users under 16.

4. Cookies & local storage

See the separate Cookie Policy. We use no tracking or advertising cookies, and our reach measurement (section 3) is cookieless. Before any non-essential cookie is ever set, a consent banner will allow you to reject it with a single click.

5. Processors (Art. 28 GDPR)

  • Google Ireland Ltd. / Google LLC (Firebase) — database, authentication, file storage — data stored in the EU (europe-west4 / EU multi-region)
  • Vercel Inc. — hosting, serverless functions, logs, rate limiting, cookieless reach measurement (Web Analytics) — USA
  • MapTiler AG — map tiles — Switzerland (EU adequacy decision)
  • Komoot GmbH (Photon) / OpenStreetMap Foundation (Nominatim) — geocoding via our server-side proxy (query text only, no IP) — Germany / UK
  • Google Maps / Places API — geocoding, only if explicitly configured — USA

Some recipients act on your own initiative and are not our processors: your calendar provider (iCal subscription), your AI assistant provider (MCP connection), and Suunto (route export to your Suunto account). Each of them processes your data within your own account relationship with that provider.

Ad pixels (e.g. Meta Pixel) are not currently loaded and will only be loaded after your consent via a cookie banner.

6. External links to Google Maps

The app provides external links (“Open in Google Maps”) to maps.google.com with rel="noopener noreferrer". Clicking a link opens Google Maps in a new tab; from that point Google's own privacy policy applies. We do not embed or load Google Maps content inside parat.io.

7. International transfers

Your data is stored in the EU (see section 5). Google's and Vercel's parent companies are US-based; residual transfers (for example support access) rely on Standard Contractual Clauses as published by the European Commission and, where applicable, EU-U.S. Data Privacy Framework certifications. MapTiler processes tile requests in Switzerland, which holds an EU adequacy decision. A copy of the relevant SCCs can be requested at hello@parat.io.

8. Your rights (Art. 15–22 GDPR)

  • Access (Art. 15) — request a copy of your data
  • Rectification (Art. 16) — most fields are editable in your profile
  • Erasure (Art. 17) — trigger account deletion in your profile
  • Restriction (Art. 18)
  • Portability (Art. 20) — one-click JSON export in your profile
  • Objection (Art. 21)
  • Withdrawal of consent (Art. 7(3))

To exercise any right, email hello@parat.io. You also have the right to lodge a complaint with a supervisory authority (Art. 77) — the authority responsible for your place of residence, your place of work, or the place of the alleged infringement.

9. Children

The service is not intended for users under 16. We do not knowingly collect personal data from children below that age.

10. Security

TLS in transit, encryption at rest (Firestore, Storage), per-user security rules, short-lived Firebase tokens, token-based secret URLs for calendar subscriptions, daily backups with point-in-time recovery, and automatic time-to-live deletion of expired invitations and access tokens. Personal-data breaches posing a risk to your rights will be reported to the supervisory authority within 72 hours (Art. 33) and to you directly where required (Art. 34).

11. Changes

We will update this document as the service evolves. Material changes affecting registered users will be announced in-app and/or by email at least 30 days before they take effect.

12. Contact

Questions about this Privacy Policy? Email hello@parat.io.