We are pleased that you are interested in PackShare (hereinafter “the Service”). Protecting your personal data is important to us. Below we inform you in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) about the processing of your data.
Note: PackShare operates under German law. This English version is a translation of the legally binding German privacy policy for your convenience.
1. Controller
The controller within the meaning of the GDPR is:
Philip SchererAlfred-Nägele-Str. 13A
76646 Bruchsal, Germany
E-mail: [email protected]
A data protection officer is not required by law and has therefore not been appointed. For questions about data protection, please contact us at the address above.
2. Your Rights
You have the following rights against us:
- Access (Art. 15 GDPR) to the data stored about you;
- Rectification (Art. 16 GDPR) of inaccurate data;
- Erasure (Art. 17 GDPR), unless statutory retention obligations apply;
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Objection to processing based on legitimate interests (Art. 21 GDPR);
- Withdrawal of a given consent with effect for the future (Art. 7(3) GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the supervisory authority of your habitual residence or the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Königstraße 10a, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de.
3. Hosting
We host the Service with Railway (Railway Corp.). The application and database are operated in a data centre within the European Union (Amsterdam region, Netherlands). The hosting provider processes the data on our behalf under a data processing agreement (Art. 28 GDPR). The legal basis is our legitimate interest in the secure and efficient provision of the Service (Art. 6(1)(f) GDPR) as well as the performance of the contract (Art. 6(1)(b) GDPR).
4. Access to the Website (Server Log Files)
When you access the Service, information technically required to display the page is automatically transmitted to the server. This includes in particular the IP address, date and time of the request, the resource accessed, the browser type and operating system. This data is processed to ensure smooth operation and security. The legal basis is Art. 6(1)(f) GDPR. We do not store or process these log data separately ourselves; they are generated exclusively at the hosting provider Railway (Railway Corp.) and are subject to its own retention practices under the data processing agreement concluded with us (see Section 3).
5. Cookies
We use only a single technically necessary cookie for authentication (session cookie). It stores your session so that you remain logged in and contains no tracking or advertising information. This cookie is required for the operation of the Service; the legal basis is § 25(2) No. 2 TDDDG in conjunction with Art. 6(1)(b)/(f) GDPR. No consent is required for this. We do not use analytics, marketing or tracking cookies.
6. Registration and Sign-In (Google Login)
Sign-in is handled via Google’s single-sign-on service (“Sign in with Google”, OAuth). When you sign in, Google transmits to us the data required to create your account — typically your name, e-mail address and profile picture as well as a unique user identifier. We store this data to maintain your account and to authenticate you. The legal basis is the performance of the usage contract (Art. 6(1)(b) GDPR).
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. During the sign-in process, data may be transferred to Google LLC in the USA. Google is certified under the EU–US Data Privacy Framework; the transfer is additionally based on the standard contractual clauses of the European Commission. You can find Google’s privacy policy at https://policies.google.com/privacy.
7. Use of the Service (Contractual and Content Data)
To provide the Service, we process the data that you and the members of your group enter. This includes in particular:
- Groups, group names and invite codes;
- your memberships and roles (organizer/member) in groups;
- packing list entries with quantities, claimed items and the responsible person;
- your personal packing lists (“Personal Items”) and packing templates; these are visible only to you and are not displayed to other members — including the organizer;
- Arrival and departure time windows, if you provide them.
This data is processed solely to provide the organisational functions within your group. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). Content you share in a group is visible to the other members of that group — please do not enter particularly sensitive or unnecessary personal data in free-text fields.
8. Payment Processing
If you take out a paid Premium subscription, payment is processed via the external payment service provider Stripe. The data required for payment (e.g. name, e-mail address, payment details) is entered directly with the payment service provider; we ourselves store nocomplete payment data such as credit card numbers. We receive from the payment service provider only the information necessary for contract and invoice processing (e.g. payment status, subscription term). The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). You can find the payment service provider’s privacy policy at https://stripe.com/privacy.
9. Contact by E-mail
If you contact us by e-mail, we process the data you provide in order to handle your enquiry. The legal basis is our legitimate interest in responding to your enquiry (Art. 6(1)(f) GDPR) or the initiation or performance of a contract (Art. 6(1)(b) GDPR).
10. Retention Period and Erasure
We store your personal data only for as long as is necessary for the purposes stated above. You can request deletion of your account and the associated data at any time; upon deletion of your account your personal data will be removed, unless statutory retention obligations (e.g. commercial and tax-law obligations for invoice data, generally up to 10 years) preclude this.
11. Data Security
Transmission is encrypted via TLS (https). We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access.
12. Changes to This Privacy Policy
We update this privacy policy whenever changes to the Service or the legal situation require it. The version published on this page is always the current one.