⚠️ Draft with placeholder operator details — not legally valid yet. Fill in the real operator identity in apps/web/src/lib/legal-operator.ts before inviting real users.

Privacy Policy

Last updated: 13/09/2026 — the German version is the legally authoritative one; this is provided for convenience.

1. Controller

The controller responsible for Kiste under the GDPR is:

[Dein Name oder Firmenname — Platzhalter]
[Straße, Hausnummer, PLZ, Ort — Platzhalter]
Email: [Kontakt-E-Mail für rechtliche Anfragen — Platzhalter]

2. A note on roles

Kiste is a tool organisations (NPOs, collectives) use to manage their own inventory, contacts, and loans. For data an organisation itself enters into Kiste (e.g. names of borrowers in contacts, team member names), that organisation is the data controller — we act as a processor. For data collected to operate the platform itself (account, login, server logs), we are the controller under this notice.

3. What data we collect

  • At signup: name, email address, a hashed password (the plaintext password is never stored).
  • In use: inventory data, locations, contacts, loans, events, and any uploaded photos your organisation creates.
  • Automatically: technical server logs (IP address, timestamp, requested page) to keep the service running; not analysed in a way linked to your account.
  • Cookies: a session cookie for login (strictly necessary, not tracking) and a cookie storing your language preference (English/German).

4. Purpose and legal basis

Processing occurs to provide the contractually agreed service (GDPR Art. 6(1)(b)) and to maintain the security and functioning of the platform (GDPR Art. 6(1)(f), legitimate interest).

5. Recipients and subprocessors

We use the following service providers, each under a DPA or standard contractual clauses:

  • netcup GmbH (Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany) — server hosting, data located in Germany.
  • wint.global GmbH (In der Steele 35, 40599 Düsseldorf, Germany) — transactional email (invites, password resets).
  • Functional Software, Inc. (Sentry) — error/crash tracking to fix technical issues; processed in Sentry's EU/Germany region.
  • Cloudflare, Inc. — storage of uploaded photos and encrypted database backups (Cloudflare R2); transfers outside the EU covered by EU Standard Contractual Clauses.

We do not share data with any other third party except where legally required.

6. Retention

Account data is kept for as long as your account exists. Database backups are created automatically and auto-deleted after 15 days (off-site) / 5 days (local to the server). After account or organisation deletion, associated data is removed subject to statutory retention periods.

7. Your rights

  • Access to your stored data (GDPR Art. 15)
  • Rectification of inaccurate data (GDPR Art. 16)
  • Erasure (GDPR Art. 17)
  • Restriction of processing (GDPR Art. 18)
  • Data portability (GDPR Art. 20)
  • Objection to processing (GDPR Art. 21)
  • Lodging a complaint with a data protection authority

To exercise these rights, contact [Kontakt-E-Mail für rechtliche Anfragen — Platzhalter]. You can also manage your account directly in Settings.

8. Changes to this policy

We update this policy when our data processing changes. The current version is always available on this page.