Privacy Policy
1. Controller
Adrian Schäfer
Werneuchener Straße 33, 13055 Berlin, Germany
E-mail: adrian.schaefer87@gmail.com
2. What this app fundamentally does not do
There are no user accounts and no registration. Neither your name nor your e-mail address is collected. There is no cross-device tracking, no reach measurement and no advertising analysis, and no cookies are set for analytics or advertising. The only success measurement is an anonymous attribution of purchases to a marketing channel, with no personal reference (see section 4a).
3. Accessing the website (server log files)
When the site is accessed, the web server automatically logs access data: IP address, time, the address requested, the amount of data transferred, browser type and referrer. This data is technically necessary to deliver the page and to detect malfunctions and attacks.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, trouble-free operation).
4. Storage in your browser
The app stores a few values in your browser's local storage (localStorage). They do not leave your device on their own and serve solely the service you requested:
- Credit code — your anonymous access code (
CG-XXXX-XXXX-XXXX). It is also your recovery code; without it, purchased credits would be lost. - Language — the interface language you chose.
- Invite code — only if you arrived via an invitation link, so the reward credit can be attributed later.
- Source tag — only if you arrived via a marketing link with
?src=(e.g. from a flyer): a short channel label (such as "hostel-kreuzberg"). It contains nothing about you personally; see section 4a.
The credit code, language and invite code are necessary for the service you expressly requested; storing them requires no consent under Section 25(2)(2) TDDDG (German Telecommunications Digital Services Data Protection Act). For the source tag, see section 4a. You can delete all values at any time via your browser settings — deleting the credit code, however, loses access to any existing credits.
4a. Source / channel attribution
If you reach us via a marketing link with a suffix such as
?src=hostel-kreuzberg, the app remembers this short channel label. If
you later buy credits, the label is linked once to your anonymous credit
code so that we can evaluate which channel (e.g. which flyer) leads to
purchases. No personal data, no IP address and no cross-device profile
is stored; the evaluation is only aggregated over anonymous identifiers.
The legal basis for this success measurement is Art. 6(1)(f) GDPR (legitimate interest in assessing our advertising). The tag is only set if you arrive via such a link; you can delete it in your browser at any time and object to this evaluation under Art. 21 GDPR.
5. Map display (Google Maps)
The map is loaded via the Google Maps JavaScript API from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Your IP address is transmitted to Google in the process; a transfer to the USA cannot be ruled out. Google is certified under the EU-US Data Privacy Framework.
Without this integration, the app's core function — the map — could not be shown. The legal basis is Art. 6(1)(b) and (f) GDPR. If Google Maps cannot be loaded, the app automatically uses the free map alternative OpenStreetMap/Leaflet.
Further information: Google's privacy policy.
6. Fonts and program libraries
Fonts and the Leaflet map library are served from our own server. No connection is made to Google Fonts, a content delivery network or any other third party, and no IP address is transmitted to third parties.
6a. Map tiles of the fallback map
If Google Maps cannot be loaded, the app uses the free map alternative OpenStreetMap/Leaflet. Its map images are loaded from CARTO (CARTO Inc.); your IP address is transmitted to CARTO in that case. This only happens in this fallback, not in normal operation.
7. Creating a tour
When you create a tour, the map section you chose, the search radius and your preferences (selected categories and the optional free text) are sent to our server and passed from there to the following services:
- Google Places API (Google Ireland Limited) — to find places in the chosen area.
- Google Gemini (Google Ireland Limited) — to write the audio-guide texts.
These calls are made by our server, not by your browser. Your IP address is not transmitted — only the map section and your preferences. Please do not enter any personal data in the free-text field.
The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract).
8. Audio guide
For speech output, the respective tour text is sent to a speech service — depending on the setting, to OpenAI (OpenAI Ireland Ltd., with processing in the USA) or to Google Cloud Text-to-Speech. This too happens server-side; your IP address is not transmitted. Alternatively, your browser's own speech output can be used, in which case the text does not leave your device.
9. Saving and sharing a tour
If you save and share a tour, it becomes publicly accessible and appears in the gallery. The tour name, places, texts and the time are stored. In addition, a hash of your IP address formed with a secret key is stored so that abusive content can be removed. The IP address cannot be reconstructed from this value. The legal basis is Art. 6(1)(f) GDPR.
10. Payments
Purchases are processed via Stripe (Stripe Payments Europe Ltd., Dublin, Ireland). You enter your payment data directly with Stripe — it never reaches our server. From Stripe we only receive the information that a particular payment was made, the amount, and a session identifier.
The legal basis is Art. 6(1)(b) GDPR. Stripe's privacy policy applies.
11. Referral programme
If you share an invitation link and a purchase is made through it, we store — to prevent abuse — a card fingerprint provided by Stripe: an identifier that recognises the same payment card without containing the card number. This prevents anyone from gaining credits through repeated self-invitations. We can neither reconstruct the card from it nor identify you as a person.
The legal basis is Art. 6(1)(f) GDPR (protection against abusive use).
12. Location
The app requests your location in order to centre the map on your surroundings. The request is made exclusively via your browser and only with your consent in the browser dialog. Your location is not transmitted to us and not stored — it is only used locally to move the map.
13. Retention periods
- Server log files: deleted after 7 days at the latest.
- Saved tours: until you request their deletion or we remove them.
- Credit accounts and purchase records: as long as credits exist or as long as commercial and tax retention obligations require.
- Caches for place data and texts: contain no personal data.
14. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21 GDPR). To exercise them, contact the e-mail address given above.
Please note: as we cannot identify you without an account, we generally need your access code or the link of the relevant tour in order to provide information.
You also have the right to lodge a complaint with a supervisory authority, for example the Berlin Commissioner for Data Protection and Freedom of Information.