1. Data controller
Tobias ZillmannLeienfelsstraße 25
81243 München
Germany
E-Mail: info@get-on.app
2. Hosting, service delivery, and server logs
When you access the website or the app connects to our servers, we process data including your IP address, date and time, the address or resource requested, HTTP method, status code, amount of data transferred, referrer, browser or app version, operating system, and device information. We process this data to deliver the service, analyze errors, and prevent attacks and misuse.
We do not permanently store IP addresses internally. They may only be included temporarily in technical server or HTTP logs, or processed temporarily for IP-based rate limiting to protect against attacks and abuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable, and error-free provision of the service. Where processing is necessary to provide contractually agreed features, Article 6(1)(b) GDPR also applies.
Our hosting provider is Render Services, Inc., 525 Brannan St, San Francisco, CA 94131, USA. The application is hosted in Render's Frankfurt (EU Central), Germany region. Application and HTTP logs available in the Render dashboard are retained for seven days under the Hobby plan we use. Data is retained for longer only where necessary to investigate a specific security incident, pursue legal claims, or comply with legal obligations.
To protect our website and API against automated or abusive requests, we use IP-based rate limiting at all endpoints. The IP address is processed temporarily to enforce a limit of 60 requests per minute per IP address. It is not stored in the campaign tracking entry. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our services.
3. Registration, sign-in, and user account
For registration and sign-in, we process your email address, a time-limited verification code in hashed form, authentication and token information, and the time and technical details of requests. This is necessary to establish, secure, and perform the user agreement (Article 6(1)(b) GDPR).
Depending on the information you provide, your profile may include your display name, date of birth, gender, phone number, place of residence, occupation, profile text, relationship status, interests, languages, and profile pictures. Required information is identified in the app. We process optional profile information under Article 6(1)(b) GDPR to provide the profile features you request. You can change or remove this information in the app.
We use IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, as our email service provider to deliver sign-in codes. This involves processing the recipient address, message content, and technical delivery data. Processing is carried out on our behalf under a data processing agreement pursuant to Article 28 GDPR.
4. Location, search, and MeetUps
When you use location features, we process geographic coordinates, search radius, search terms, and selected filters to find MeetUps near you and calculate distances. When you create or use a MeetUp, we process data including its title, description, image, location, date, time, category, language, visibility, participant status, join requests, and association with your account.
Processing is necessary to provide the features you request under Article 6(1)(b) GDPR. You can revoke the device's location permission at any time in your operating system settings. This does not automatically delete location and search data already sent to the server.
Depending on visibility settings, MeetUp content, the specified meeting point, and profile information are shown to other users. Do not share sensitive data in public content or content visible to larger groups of users.
5. Chats and community features
For chats, we process messages, timestamps, senders, chat and MeetUp associations, memberships, and join, leave, and removal events. Content is intended for the relevant chat participants. As soon as the last user leaves a chat, we delete the chat, including all chat messages and membership data, as well as the associated MeetUp from our servers. The legal basis is Article 6(1)(b) GDPR.
For ratings, bug and feature suggestions, and reports about users or MeetUps, we process the submitted information, the reporting user, the affected content or user, the reason, description, processing status, and timestamps. If you request that we contact you, we use your contact details for that purpose. The legal bases are Article 6(1)(b) and (f) GDPR. Our legitimate interests are improving the service, protecting the community, investigating violations, and establishing, exercising, or defending legal claims.
6. Push notifications and Firebase
If you enable push notifications, we process an installation or device identifier, your selected app language, the notification content, and technical delivery data. We use Google's Firebase Cloud Messaging for this purpose. You can revoke the device permission at any time in your operating system settings.
Processing is necessary to provide the notification feature you enabled (Article 6(1)(b) GDPR). Where consent is obtained, the legal basis is Article 6(1)(a) GDPR. You may withdraw consent at any time with effect for the future.
The provider in the EEA is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by affiliated companies in third countries, particularly the United States, cannot be ruled out. Google states that it relies on applicable adequacy decisions and standard contractual clauses for transfers. Firebase privacy information
7. Image search via Pixabay
When you use the integrated image search, our server sends your search term, selected language, and requested results page to Pixabay. The app does not send your IP address directly to Pixabay; however, when selected preview images are retrieved from Pixabay, Pixabay may receive your IP address and technical request data. Processing is necessary to provide the requested image search under Article 6(1)(b) GDPR.
The provider is Canva Germany GmbH, Pappelallee 78/79, 10437 Berlin, Germany. For more information, see Pixabay's privacy information. Pixabay privacy information
8. Cookies and local storage
The website uses only technically necessary session and security cookies, in particular session and CSRF cookies. The selected language is stored in the URL and does not require a language cookie. The cookies support sign-in and protection against forged requests. The legal basis for storage on or access to the user's device is section 25(2) no. 2 TDDDG; the subsequent processing is based on Article 6(1)(b) or (f) GDPR.
On the campaign landing pages, we use server-side campaign tracking to measure visits from campaign links and clicks on the App Store or Google Play links. For this purpose, we process the requested URL, any UTM campaign parameters contained in the URL, the selected language, the time of the visit and, where applicable, the time and destination of a store click. The tracking entry is associated with the visitor's current session. Reloads within five minutes use the same entry and are not counted again. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are campaign measurement and reliable attribution of store clicks.
We do not use analytics, marketing or tracking cookies. The session cookie is technically necessary for the session-based deduplication described above. Session cookies are generally deleted at the end of the session or according to their technical validity period. You can delete or block cookies in your browser; necessary functions may then be restricted.
9. Recipients and transfers to third countries
Within our organization, access is limited to people who need it for operations, support, or moderation. Hosting, email, push notification, IT, storage, and support providers may also receive data as processors. We also disclose data where required by law or necessary to pursue legal claims.
Transfers outside the European Economic Area take place only under the conditions of Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision or EU standard contractual clauses, supplemented by additional safeguards where necessary. You may request a copy of the applicable safeguards using the privacy contact details above.
10. Retention and account deletion
Email verification codes are valid for ten minutes and become invalid afterward. Application and HTTP logs available in the Render dashboard are retained for seven days under the Hobby plan we use.
Personal account and profile data is generally retained for as long as the user account exists. When you delete your profile, data including profile details, profile pictures, search and location history, device identifiers, ratings, join requests, sessions, and active authentication information is deleted or permanently anonymized.
Chat messages remain after profile deletion only while other participants remain in the relevant chat. As soon as the last user leaves, the chat, all chat messages, membership data, and the associated MeetUp are deleted. Other created MeetUps and report records relating to content that remains available are retained so that shared content remains accessible and reports can be reviewed. The association of this content with the deleted profile and all identifying profile data is removed. An internal UUID may persist solely as an anonymized technical identifier to maintain data integrity. It contains no information about the former identity and must not enable the deleted person to be reidentified, either by itself or in combination with logs or other tables.
Beyond this, we retain data only where statutory retention obligations apply or where it is needed to establish, exercise, or defend legal claims.
11. Requirement to provide data
Without the account and feature data identified as required, we cannot provide your account or the requested feature. You are not legally or contractually required to provide optional profile information.
12. Automated decision-making
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Article 22 GDPR. Search and location information is used to display suitable or nearby MeetUps.
13. Your rights
Subject to the statutory requirements, you have the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR), and objection (Article 21 GDPR). Under Article 7(3) GDPR, you may withdraw consent at any time with effect for the future; this does not affect the lawfulness of processing carried out before withdrawal.
Where we process data on the basis of legitimate interests, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without stating particular grounds; we do not currently engage in direct marketing.
To exercise your rights, email info@get-on.app.
14. Right to lodge a complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, your workplace, or the place of the alleged infringement.
15. Data security and changes
We take appropriate technical and organizational measures to protect personal data, in particular against loss, manipulation, and unauthorized access. These measures are continually developed in line with the state of the art and the level of risk.
We update this privacy policy when features, service providers, or legal requirements change. The current version is available on this page.