Privacy Policy
Last Updated: January 31, 2025
Version: 1.0
---
Table of Contents
1. Introduction
4. Purposes and Legal Bases for Processing
5. Blockchain and Immutability
6. Recipients and Data Sharing
7. International Data Transfers
8. Cookies and Tracking Technologies
10. Your Rights
11. Right to Lodge a Complaint
13. Changes to This Privacy Policy
14. Contact
---
Introduction
This Privacy Policy explains how we collect, use, and protect your personal data when you use our decentralized autonomous organization (DAO) application and website.
We take the protection of your personal data very seriously and handle your personal data confidentially and in accordance with legal data protection regulations and this Privacy Policy.
---
Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
MüritzPhone
Hohe Straße 2
17207 Röbel/Müritz
Germany
Email: mueritzphone@gmail.com
Phone: 039931 148019
Owner: Max Brych
---
Personal Data We Collect
3.1 Data You Provide Directly
Wallet Address (Public Key):
- Your Ethereum/Base wallet address is collected when you connect your wallet to our application
- Important: Wallet addresses are considered personal data under GDPR, even though they are pseudonymous
- Participation in DAO votes
- Proposal creation
- NFT ownership (HomeTownVotingNFT)
- Display name
- Email address (if you subscribe to updates)
- Profile picture
- IP address
- Browser type and version
- Operating system
- Device type and model
- Screen resolution
- Language settings
- Time zone
- Pages visited
- Interactions with smart contracts
- Application usage patterns
- Session duration
- Referring URL
- Wallet address (public key)
- Transaction history with our smart contracts
- NFT ownership and transfers
- Participation in governance votes
- Smart contract interactions
- Transaction hashes
- GPS coordinates (when you grant location permission)
- Used for map features and location-based content
- Only collected when actively using the feature
- City or region-based location information
- Derived from IP address
- For weather data and regional context
- Map interactions
- Searched places
- Route queries
- Location requests for weather information
- Request timestamps
- Weather preferences
- Processing is necessary to enable your participation in the DAO
- Voting may reveal political opinions (special category of personal data)
- We use MACI (Minimal Anti-Collusion Infrastructure) for encrypted voting
- Only the fact of your participation is public, your voting choice remains private
- Art. 6(1)(a) GDPR (consent) - You expressly consent to permanent storage on the blockchain
- Art. 6(1)(b) GDPR (contract performance) - Technically necessary for DAO operation
- You expressly consent when you grant location permissions
- You can revoke consent at any time in device settings
- Our legitimate interest: Improve our services, ensure functionality
- Your interests: We use pseudonymized data and no behavioral advertising
- When you accept analytics cookies
- Our legitimate interest: Platform security and protection of all users
- Necessary to prevent abuse and comply with legal obligations
- Art. 6(1)(a) GDPR (consent) - for newsletters and marketing
- Art. 6(1)(b) GDPR (contract performance) - for essential service updates
- Your wallet address (public key)
- NFT ownership and transfers
- Participation in governance votes (not your voting choice)
- Proposal creation
- Smart contract interactions
- Transaction hashes
- ✅ Publicly accessible via blockchain explorers
- ✅ Globally retrievable
- ✅ Permanent and immutable
- ✅ Cannot be deleted or modified
- ✅ Remains on the blockchain indefinitely
- Your voting choice is encrypted before being transmitted to the blockchain
- Only the coordinator can decrypt votes to calculate results
- Results are verified using zero-knowledge proofs
- Your specific voting choice is never publicly revealed
- Only the fact that you voted is visible via your wallet address
- Prevents vote buying and coercion
- Protects political opinions (special category of personal data)
- Enables verifiable but private voting
- Immutable and permanent
- Publicly accessible
- Cannot be deleted
- Minimal: Only wallet addresses and encrypted votes
- Modifiable and deletable
- Private and access-controlled
- GDPR-compliant deletion possible
- Contains: Profile information, email addresses, preferences
- We can delete off-chain data (profile, email)
- We CANNOT delete blockchain data (wallet address, transactions)
- This is a technical limitation, not a legal exception
- We inform you transparently about this before first use
- Blockchain data cannot be corrected
- Corrections can be added as new transactions, but old data remains visible
- Art. 17(3)(e) GDPR: Archiving purposes in the public interest
- The blockchain serves as a public, decentralized archive for governance
- Account information (email, authentication credentials)
- Profile information
- Session information
- Content you upload
- We have entered into a Data Processing Agreement (DPA) with Supabase
- Includes EU Standard Contractual Clauses
- All your data remains in the EU
- NOT transferred to third countries (for Supabase services)
- SOC 2 Type 2 certified
- AES-256 encryption at rest
- TLS encryption in transit
- Daily encrypted backups
- Amazon Web Services (AWS) - Cloud hosting (EU Frankfurt)
- Stripe - Payment processing (if applicable)
- More at: https://supabase.com/privacy
- IP addresses
- Browser information
- Request data and server logs
- Performance metrics
- Data Processing Agreement (DPA) executed
- EU Standard Contractual Clauses for data transfers
- Data may be processed worldwide
- Protected by EU-US Data Privacy Framework (DPF)
- ISO 27001:2022 certified
- SOC 2 Type 2 attested
- TLS encryption
- DDoS protection
- Hobby Plan: 1 hour
- Pro Plan: 1 day
- Configurable depending on plan
- Amazon Web Services (AWS)
- Microsoft Azure
- Google Cloud Platform (GCP)
- Full list: https://security.vercel.com/
- Wallet addresses
- Transaction data
- Smart contract interactions
- IP addresses
- Device information
- Usage analytics (via Client ID)
- Standard Contractual Clauses (SCCs)
- thirdweb GDPR/CCPA compliance
- GDPR: 30 days
- CCPA: 45 days
- TLS encryption
- AES-256 encryption for backups
- Private keys are NEVER stored or transmitted
- IP addresses
- Location data (when you grant permission)
- Device and browser information
- Map interactions
- Unique identifiers (API key)
- Google Maps is only loaded after your express consent
- You can revoke consent at any time
- EU-US Data Privacy Framework (Google is certified)
- Google Cloud Data Processing Addendum (CDPA) with SCCs
- NID cookie: User settings, connection to Google network
- More information: https://policies.google.com/technologies/cookies
- You can disable Google Maps in settings
- The app will continue to function without map features
- Location coordinates or city name
- IP address
- Request timestamps
- Device information
- EU-US Data Privacy Framework (Google is certified)
- Google Cloud Data Processing Addendum (CDPA) with SCCs
- Minimal data: Device installation IDs (randomly generated, no unique device identifiers)
- Push tokens (only if you enable push notifications)
- EAS update requests (do NOT contain unique device identifiers)
- Collects only minimal data
- No end-user tracking without your implementation
- GDPR/CCPA compliant
- Amazon AWS (cloud infrastructure)
- Google (cloud infrastructure)
- Cloudflare (CDN)
- Full list: https://expo.dev/privacy/subprocessors
- All on-chain transactions
- Wallet addresses
- Smart contract interactions
- Publicly accessible data
- We have NO control over the blockchain network
- Data is public and immutable
- Nodes are distributed worldwide (international transfer is inherent)
- Anyone can access this data (e.g., via Etherscan, Basescan)
- Art. 6(1)(a) GDPR (consent)
- Art. 6(1)(b) GDPR (contract performance - technically necessary for DAO)
- No cookies
- No cross-site tracking
- Anonymous visitor identification (hash-based)
- Session data automatically deleted after 24 hours
- No personal data collected
- No consent required (no cookies, fully anonymous)
- Requires express consent via cookie banner
- Cookies are only set after consent
- IP anonymization enabled
- No sharing with Google for advertising purposes
- Data processing agreement with Google executed
- Government requests (police, courts)
- Legal obligations
- Protection of our rights or the safety of others
- Vercel Inc. (hosting)
- thirdweb Inc. (Web3 infrastructure)
- Google LLC (Maps, potentially Analytics)
- Expo (mobile platform)
- EU Commission adequacy decision
- Vercel and Google are DPF-certified
- Verification: https://www.dataprivacyframework.gov/list
- EU Commission-approved contractual clauses (2021)
- Executed with all US service providers
- Ensure legally binding level of protection
- Executed with all processors
- Obligate compliance with GDPR standards
- Contain technical and organizational measures
- Supabase Frankfurt (eu-central-1) region
- All data processing occurs in Germany
- Backups remain in the same region
- NO transfer to third countries for Supabase database services
- Nodes are located worldwide (incl. third countries)
- Data is publicly accessible on the entire blockchain
- International transfer is inherent to the technical architecture
- Transfer is technically necessary for DAO participation
- Art. 49(1)(b) GDPR (contract performance)
- Art. 49(1)(a) GDPR (explicit consent)
- Session Cookies: Authentication, session management
- Security Cookies: CSRF protection, security tokens
- Preference Cookies: Language settings, theme (light/dark)
- Cookie Consent Cookie: Stores your cookie preferences
- NO cookies: Vercel Analytics does not use cookies
- Privacy-friendly: Hash-based anonymous visitor identification
- No consent required: Fully anonymous, no tracking
- Analytics Cookies: _ga, _gid, _gat
- NID Cookie: User settings, connection to Google network
- Cookie banner on first visit
- Change settings at any time via: [Link to Cookie Settings]
- Granular control by category (Essential, Analytics, Maps)
- You can block or delete cookies in your browser
- Note that this may affect functionality
- Instructions for common browsers:
- Essential cookies: Website may not function correctly
- Analytics cookies: No impact on functionality
- Google Maps cookies: Map features unavailable
- Wallet connection status (thirdweb)
- App settings and preferences
- Cached data for offline functionality
- Technically necessary for app functionality
- No consent required
- As long as your account is active
- Definition "active": You have logged in or interacted within the last 24 months
- Retention period: 2 years after last activity
- Deletion: Automatic deletion after expiration
- Notification: We send a reminder email 30 days before deletion (if email available)
- Email addresses: As long as account exists or until newsletter unsubscribe
- Profile information: As long as account exists
- Session data: Until logout or after session expiration
- Support requests: 3 years after completion (for legal purposes)
- Wallet addresses
- Transaction hashes
- NFT ownership and transfers
- Vote participation (not voting choice with MACI)
- Smart contract interactions
- Session data: Automatically deleted after 24 hours
- Aggregated statistics: Indefinite (fully anonymized)
- Raw data: 14 months (IP anonymized)
- Aggregated reports: Indefinite (anonymized)
- Hobby Plan: 1 hour
- Pro Plan: 1 day (30 days with Observability Plus)
- Enterprise: 3 days (30 days with Observability Plus)
- Commercial retention obligations: 6-10 years (German law)
- Contract-relevant documents: 6 years after contract end (statute of limitations)
- To receive a copy of your personal data
- To receive information about processing (purposes, categories, recipients, retention)
- Email: mueritzphone@gmail.com
- Subject: "GDPR Access Request"
- Or use the "Export Data" function in app settings
- To have inaccurate personal data corrected
- To have incomplete data completed
- Off-chain data: Can be changed anytime in account settings
- Blockchain data: CANNOT be corrected (technical immutability)
- To request deletion of your personal data
- Use "Delete Account" function in app settings
- Email: mueritzphone@gmail.com
- ✅ Off-chain data: Profile, email, preferences, session data
- ✅ Cookies and LocalStorage
- ✅ Supabase database entries
- ✅ Analytics data (personal)
- ❌ Blockchain data: Wallet address, transactions, NFT ownership, vote participation
- Reason: Technical immutability of the blockchain
- Alternative: We can delete encryption keys to make data inaccessible
- Fulfillment of legal obligations
- Establishment, exercise, or defense of legal claims
- Archiving purposes in the public interest (blockchain)
- To request restriction of processing when:
- Data will be marked and only processed for limited purposes
- Contact: mueritzphone@gmail.com
- To receive your data in a structured, commonly used, machine-readable format
- To transmit this data to another controller
- Off-chain data from our database
- Blockchain data (publicly accessible via block explorers)
- "Export Data" function in app settings
- Email request: mueritzphone@gmail.com
- To object to processing based on legitimate interest (Art. 6(1)(f) GDPR) for reasons arising from your particular situation
- Analytics purposes
- Security processing (unless mandatory)
- Direct marketing: You can ALWAYS object to processing for direct marketing
- To withdraw granted consents at any time
- Blockchain data storage (prevents future interactions, existing data remains)
- Location data for Google Maps (in device settings)
- Analytics cookies
- Newsletter and marketing emails
- Push notifications
- Cookie settings: [Link to Cookie Settings]
- Location permission: Device Settings > App > Permissions
- Newsletter: Unsubscribe link in every email
- App settings: Privacy & Consents
- Not to be subject to a decision based solely on automated processing with legal effect
- Graurheindorfer Str. 153
- 53117 Bonn, Germany
- Phone: +49 (0)228 997799-0
- Fax: +49 (0)228 997799-550
- Email: poststelle@bfdi.bund.de
- Website: https://www.bfdi.bund.de
- Friedrichstr. 219, 10969 Berlin
- Phone: +49 (0)30 13889-0
- Email: mailbox@datenschutz-berlin.de
- Website: https://www.datenschutz-berlin.de
- Promenade 18, 91522 Ansbach
- Phone: +49 (0)981 180093-0
- Email: poststelle@lda.bayern.de
- Website: https://www.lda.bayern.de
- Kavalleriestr. 2-4, 40213 Düsseldorf
- Phone: +49 (0)211 38424-0
- Email: poststelle@ldi.nrw.de
- Website: https://www.ldi.nrw.de
- Email: mueritzphone@gmail.com
- We strive to resolve all privacy concerns promptly and satisfactorily
- In transit: TLS/HTTPS encryption for all data transmissions
- At rest: AES-256 encryption for database and backups
- Wallet security: Private keys are NEVER stored or transmitted
- Role-based access rights
- Multi-factor authentication (MFA) for administrative access
- Principle of least privilege
- Secure API endpoints with authentication
- Firewalls and DDoS protection (Cloudflare, Vercel)
- Intrusion detection systems
- Regular security updates and patches
- Row Level Security (RLS) in Supabase
- Database replication and backups
- Encrypted connections
- Audited and reviewed smart contracts
- Use of OpenZeppelin standard libraries
- Timelock mechanisms for critical governance functions
- Data Protection Officer (if required)
- Documented data protection policies
- Record of Processing Activities (Art. 30 GDPR)
- Regular data protection training
- Confidentiality commitments
- Access rights only for authorized employees
- Data protection incident management
- 72-hour reporting obligation for data breaches (Art. 33 GDPR)
- Notification procedures for affected persons
- Review of all third-party vendors for GDPR compliance
- Data Processing Agreements (DPAs) with all processors
- Regular audits
- Daily encrypted backups (Supabase)
- Backups in the same region (EU)
- Regular recovery testing
- SOC 2 Type 2 (Security, Availability, Confidentiality)
- ISO 27001:2022 (Information Security)
- SOC 2 Type 2 (Security, Confidentiality, Availability)
- ISO 27001, ISO 27017, ISO 27018
- SOC 2/SOC 3
- Various other certifications
- We only collect data necessary for the respective purpose
- No collection "just in case"
- Use of wallet addresses instead of real names
- Hash-based analytics (Vercel)
- MACI for encrypted voting
- Most privacy-friendly settings as default
- Opt-in instead of opt-out for optional data processing
- No pre-selected checkboxes
- Deletable data stored off-chain
- Only the essentials on-chain
- Use hardware wallets for larger amounts
- NEVER share your private keys or seed phrases
- Use secure passwords
- Enable MFA where available
- Use secure, unique passwords
- Log out from unused sessions
- Regularly review your account activity
- Verify URLs before logging in
- We will NEVER ask for your private key
- Be cautious with suspicious emails
- Our processing activities
- Legal requirements
- New technologies or features
- Feedback from supervisory authorities
- We notify you via email (if available) at least 30 days in advance
- We display a prominent notice in the app for 30 days
- We obtain new consent if required (when legal bases change)
- We update the "Last Updated" date above
- No active notification (but you should check regularly)
- Email: mueritzphone@gmail.com
- Or at: [Link to version history]
- Email: mueritzphone@gmail.com
- Subject: "Privacy Inquiry"
- Email: mueritzphone@gmail.com
- Subject: "GDPR Rights: [Type of Right]"
- Email: mueritzphone@gmail.com
- 🇩🇪 Deutsch (legally binding version)
- 🇬🇧 English (translation, not legally binding)
Governance Data:
Optional Profile Data:
3.2 Automatically Collected Data
Technical Data:
Usage Data:
Blockchain Data:
3.3 Location Data (Mobile App)
Precise Location Data:
Approximate Location Data:
Google Maps Data:
3.4 Weather Data
---
Purposes and Legal Bases for Processing
We only process your personal data for specified purposes and based on a lawful legal basis pursuant to Art. 6(1) GDPR:
4.1 DAO Governance and Contract Performance
Purpose: Enable participation in DAO governance (voting, proposals, NFT management)
Processed Data: Wallet address, voting data, NFT ownership, smart contract interactions
Legal Basis: Art. 6(1)(b) GDPR (contract performance)
Additionally: Art. 9(2)(a) GDPR (explicit consent)
4.2 Blockchain Storage
Purpose: Immutable recording of DAO transactions and governance activities
Processed Data: Wallet address, voting participation (not voting choice), NFT transactions
Legal Basis:
Important Notice: Blockchain data cannot be deleted due to technical immutability (see Section 5)
4.3 Location-Based Services
Purpose: Provision of maps, weather information, and location-related community content
Processed Data: GPS coordinates, location preferences, map interactions
Legal Basis: Art. 6(1)(a) GDPR (consent)
4.4 Analytics and Service Improvement
Purpose: Improve user experience, fix bugs, optimize performance
Processed Data: IP address, usage patterns, technical data, device information
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest)
Alternatively: Art. 6(1)(a) GDPR (consent)
4.5 Security and Fraud Prevention
Purpose: Protection against abuse, fraud, security breaches
Processed Data: IP address, transaction patterns, access logs
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest)
4.6 Communication and Support
Purpose: Send important updates, notifications, respond to inquiries
Processed Data: Email address, communication history
Legal Basis:
---
Blockchain and Immutability
5.1 Permanent Data Storage
Important Information: When you interact with our DAO, certain data is permanently stored on the public [Base/Ethereum] blockchain:
Data Stored on the Blockchain:
Characteristics of Blockchain Data:
5.2 Private Voting with MACI
We use MACI (Minimal Anti-Collusion Infrastructure) for privacy-friendly voting:
How MACI Protects Your Privacy:
Benefits:
5.3 On-Chain vs. Off-Chain Data Storage
On-Chain (Blockchain):
Off-Chain (Supabase Database):
5.4 Your Consent
Before Your First Blockchain Interaction:
You will be expressly informed and must consent that:
1. Your wallet address will be permanently stored on the blockchain
2. This data is publicly accessible
3. This data cannot be deleted
4. Voting may reveal political opinions (but MACI protects your voting choice)
You cannot proceed without providing this express consent.
5.5 Limitations on the Right to Erasure
Important: Due to the technical immutability of the blockchain, we cannot fully fulfill the following rights:
Limited Right to Erasure (Art. 17 GDPR):
Limited Right to Rectification (Art. 16 GDPR):
Legal Exceptions:
---
Recipients and Data Sharing
We only share your personal data with the following recipients:
6.1 Infrastructure Service Providers
Supabase Inc. (Database and Backend)
Location: Singapore (headquarters), Data Processing: Germany (Frankfurt, eu-central-1)
Purpose: Database, authentication, file storage, real-time functionality
Processed Data:
Legal Basis: Art. 28 GDPR (data processing agreement)
Data Storage Location: EU (Frankfurt, Germany)
Security:
Sub-processors:
---
Vercel Inc. (Hosting and Infrastructure)
Location: USA (440 N Barranca Ave #4133, Covina, CA 91723)
Purpose: Website hosting, serverless functions, edge network, deployments
Processed Data:
Legal Basis: Art. 28 GDPR (data processing agreement)
Data Storage Location: Primarily USA, global edge network
Security:
Log Retention:
Sub-processors:
---
thirdweb Inc. (Web3 Infrastructure)
Location: USA
Purpose: Wallet connection, blockchain interactions, smart contract calls, analytics
Processed Data:
Legal Basis: Art. 28 GDPR (data processing agreement) and Art. 6(1)(b) (contract performance)
Data Storage Location: USA
International Transfer:
Data Deletion: Customer data deleted upon request:
Security:
Privacy Policy: https://thirdweb.com/privacy
---
6.2 Map Services
Google LLC (Google Maps Platform)
Location: USA (Mountain View, California)
Purpose: Map display, location search, route planning, geolocation
Processed Data:
Legal Basis: Art. 6(1)(a) GDPR (consent)
Data Storage Location: Worldwide (Google data centers, including USA)
International Transfer:
Cookies: Google Maps uses cookies:
You Have Control:
Google Privacy Policy: https://policies.google.com/privacy
---
6.3 Weather Services
Google Cloud Weather API
Location: USA (Google LLC, Mountain View, California)
Purpose: Provision of weather information based on your location
Processed Data:
Legal Basis: Art. 6(1)(a) GDPR (consent)
International Transfer:
Privacy Policy: https://policies.google.com/privacy
---
6.4 Mobile App Services (Expo)
Expo (630 Network, Inc.)
Location: USA
Purpose: Mobile app development platform, OTA updates, push notifications (if used), error reports
Processed Data:
Expo's Privacy-First Approach:
Legal Basis: Art. 28 GDPR (data processing agreement)
Data Storage Location: USA
Sub-processors (Expo):
Privacy Policy: https://expo.dev/privacy
---
6.5 Blockchain Network
Public Blockchain (Base/Ethereum)
Type: Decentralized network with thousands of independent nodes worldwide
Processed Data:
Important:
Legal Basis:
---
6.6 Analytics and Monitoring (if applicable)
Option 1: Vercel Web Analytics (Recommended - privacy-friendly)
Privacy Features:
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest)
---
Option 2: Google Analytics (If used - requires consent)
Purpose: Website analysis, user behavior, traffic sources
Legal Basis: Art. 6(1)(a) GDPR (consent)
Privacy-Friendly Configuration:
---
6.7 Legal Disclosures
We may disclose personal data when legally required:
Legal Basis: Art. 6(1)(c) GDPR (legal obligation)
---
International Data Transfers
7.1 Transfers to Third Countries
Some of our service providers process data outside the European Economic Area (EEA):
USA (United States):
7.2 Safeguards for Data Transfers
We ensure that your data is adequately protected:
1. EU-US Data Privacy Framework (DPF):
2. Standard Contractual Clauses (SCCs):
3. Data Processing Agreements (DPAs):
7.3 Supabase EU Data Residency
Advantage: Your primary application data (profile, email, preferences) remains in the EU:
7.4 Blockchain Data Transfers
Specificity: The blockchain is a global, decentralized network:
Legal Basis:
---
Cookies and Tracking Technologies
8.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help store your preferences and improve website functionality.
8.2 What Cookies Do We Use?
Strictly Necessary Cookies (No Consent Required):
- Purpose: Enable you to log in and securely use the application
- Duration: End of session or until logout
- Provider: Our application (Supabase Auth)
- Legal Basis: Art. 6(1)(b) GDPR (contract performance)
- Purpose: Protection against attacks and abuse
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in security)
---
Functional Cookies (No Consent Required):
- Purpose: Store your preferences
- Duration: 12 months
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in user-friendliness)
- Purpose: Remembers your cookie consent
- Duration: 12 months
- Legal Basis: Art. 6(1)(c) GDPR (legal obligation to store consent)
---
Analytics Cookies (Require Consent):
If using Vercel Analytics (recommended):
If using Google Analytics:
- Purpose: Website usage analysis, traffic measurement
- Duration: _ga: 2 years, _gid: 24 hours
- Provider: Google LLC (USA)
- Legal Basis: Art. 6(1)(a) GDPR (consent)
- Consent required: Yes, via cookie banner
- IP anonymization: Enabled
---
Google Maps Cookies (Require Consent):
- Purpose: Google Maps functionality, abuse detection
- Duration: 6 months
- Provider: Google LLC (USA)
- Legal Basis: Art. 6(1)(a) GDPR (consent)
- Consent required: Yes, before Google Maps is loaded
More information: https://policies.google.com/technologies/cookies
---
8.3 Manage Your Cookie Settings
Grant/Revoke Consent:
Browser Settings:
- Chrome: https://support.google.com/chrome/answer/95647
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
- Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
Impact of Disabling:
8.4 Do Not Track (DNT)
We respect Do-Not-Track signals when you use Vercel Analytics (no cookies). For other tracking technologies, we use a consent-based solution.
8.5 Local Storage (LocalStorage)
We also use browser LocalStorage for:
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in functionality)
---
Data Retention
We only store your personal data as long as necessary for the respective purposes:
9.1 Off-Chain Data (Supabase Database)
Active Accounts:
Inactive Accounts:
Specific Data Types:
9.2 On-Chain Data (Blockchain)
Retention Period: Indefinite / permanent
Reason: Technical immutability of the blockchain
Affected Data:
Important: This data cannot be deleted due to blockchain architecture.
9.3 Analytics Data
Vercel Analytics:
Google Analytics (if used):
9.4 Server Logs
Vercel Server Logs:
Content: IP addresses, request data, error messages
9.5 Cookies
See Section 8.2 for specific cookie retention periods.
9.6 Legal Retention Obligations
We must retain certain data longer if legal requirements mandate:
9.7 Early Deletion
You can request deletion of your data at any time (see Section 10.3 "Right to Erasure").
---
Your Rights
Under GDPR, you have comprehensive rights regarding your personal data:
10.1 Right of Access (Art. 15 GDPR)
You have the right:
How to request access:
Timeline: We respond within 1 month (extendable to 3 months for complexity)
Format: Machine-readable format (JSON, CSV)
10.2 Right to Rectification (Art. 16 GDPR)
You have the right:
Implementation:
- Corrected data can be added as new transaction
- Old data remains visible
10.3 Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
You have the right:
How to delete your data:
What will be deleted:
What CANNOT be deleted:
Exceptions to erasure right:
Confirmation: You will receive a deletion confirmation via email
10.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right:
- You contest the accuracy of data
- Processing is unlawful but you don't want deletion
- We no longer need data but you need it for legal claims
- You have objected (during review)
Implementation:
10.5 Right to Data Portability (Art. 20 GDPR)
You have the right:
Available Data:
Format: JSON, CSV
How to exercise this right:
10.6 Right to Object (Art. 21 GDPR)
You have the right:
Affected:
Exception: We can continue processing if compelling legitimate grounds override
Absolute right to object:
10.7 Right to Withdraw Consent (Art. 7(3) GDPR)
You have the right:
Affected Consents:
How to withdraw:
Important: Withdrawal does not affect the lawfulness of processing before withdrawal.
10.8 Right Not to be Subject to Automated Decision-Making (Art. 22 GDPR)
You have the right:
Note: We do not perform automated individual decisions that legally affect you.
---
Right to Lodge a Complaint
11.1 Right to Complain to a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.
11.2 Competent Supervisory Authorities in Germany
Federal Level:
Federal Commissioner for Data Protection and Freedom of Information (BfDI)
---
State Level:
Depending on your place of residence or our company's location, the respective state data protection authority is responsible.
Examples:
Berlin:
Berlin Commissioner for Data Protection and Freedom of Information
Bavaria:
Bavarian State Office for Data Protection Supervision (BayLDA)
North Rhine-Westphalia:
State Commissioner for Data Protection and Freedom of Information NRW (LDI NRW)
Complete list of all German supervisory authorities:
https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html
11.3 EU-wide Complaint Right
You can also contact the supervisory authority in another EU member state:
List of all European data protection authorities:
https://edpb.europa.eu/about-edpb/about-edpb/members_en
11.4 Direct Contact
Before filing a complaint, feel free to contact us directly:
---
Security Measures
We implement comprehensive technical and organizational measures to protect your data:
12.1 Technical Measures
Encryption:
Access Control:
Network Security:
Database Security:
Smart Contract Security:
12.2 Organizational Measures
Data Protection Governance:
Employee Training:
Incident Response:
Vendor Oversight:
Backups:
12.3 Certifications of Our Service Providers
Supabase:
Vercel:
Google (Maps):
12.4 Privacy by Design
Data Minimization:
Pseudonymization:
Privacy by Default:
Off-Chain Priority:
12.5 What You Can Do
Wallet Security:
Account Security:
Beware of Phishing:
12.6 Reporting Security Incidents
If you discover a security vulnerability or data protection incident:
Contact: mueritzphone@gmail.com
We take all reports seriously and investigate them promptly.
---
Changes to This Privacy Policy
13.1 Updates
We may update this Privacy Policy from time to time to reflect changes in:
13.2 Notification of Material Changes
For material changes:
For minor changes:
13.3 Version History
Previous versions of this Privacy Policy are available upon request:
13.4 Consent to Changes
By continuing to use our services after changes take effect, you agree to the updated Privacy Policy.
---
Contact
14.1 Privacy Inquiries
For general privacy questions:
For exercising your rights (access, deletion, etc.):
For security incidents:
14.2 Response Times
Access requests (Art. 15 GDPR): Within 1 month (extendable to 3 months for complexity)
Deletion requests (Art. 17 GDPR): Within 1 month
Other requests: We strive to respond within 7 business days
14.3 Postal Address
MüritzPhone
Hohe Straße 2
17207 Röbel/Müritz
Germany
14.4 Languages
This Privacy Policy is available in:
In case of discrepancies between versions, the German version shall prevail.
---
Additional Notes
Children
Our services are not directed at persons under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact us immediately.
External Links
Our website may contain links to external websites. We are not responsible for their privacy practices. Please read their privacy policies.
Social Media
If we integrate social media plugins, they are only loaded after your consent (2-click solution). The platforms may collect data according to their privacy policies.
---
This Privacy Policy complies with the requirements of the GDPR (General Data Protection Regulation) and the BDSG (Federal Data Protection Act) in their current versions.
Status: January 31, 2025
Version: 1.0
---
Also available in: Deutsch