Privacy Policy
1. Data Controller
Roadex UG (haftungsbeschränkt)
represented by Managing Director Robin Mühlhoff
Biemser Weg 47
32052 Herford, Germany
Email: support@schatzbox.app
2. Overview
From your visit to this website we process personal data only to the extent technically necessary and for a pseudonymous audience measurement that we run on our own server (section 8). No usage profiles are created, there is no cross-device tracking, and no data is shared for advertising purposes. Separate from this is content that finders of a treasure have given us with their explicit consent and that we publish here. See section 10.
3. Hosting and Server Log Files
This website is hosted on a dedicated server in a German data centre operated by our infrastructure provider (netcup GmbH, Nuremberg), which acts as a processor under Art. 28 GDPR strictly on our instructions. Each access automatically stores the following data in server log files:
- IP address of the requesting device
- Date and time of access
- Requested URL
- Amount of data transferred
- HTTP status code
- Browser type and version (User-Agent)
- Operating system
Processing is based on Art. 6 (1) (f) GDPR (legitimate interest in ensuring reliable operation and security). Log files are deleted automatically after 14 days at the latest, sooner when traffic is high, because older entries are then displaced earlier. Security records of automatically repelled attack and scan attempts are kept for up to five weeks. This data is not combined with any other data sources.
For backups we use Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, as a further processor under Art. 28 GDPR. The backups are encrypted and held in a data centre in Germany. Server log files are excluded from the backup. The periods above therefore apply without qualification. What is backed up is the other data named in this policy. Backup copies are overwritten automatically, normally after six months. At the backup provider they may persist for a further ten days in that provider’s own system snapshots. Until then they may still contain data that has already been deleted in live operation.
4. SSL/TLS Encryption
This site uses SSL/TLS encryption for security. You can recognize an encrypted connection by “https://” in your browser’s address bar. While the encryption is active, third parties cannot read the data you transmit to us.
5. Fonts
This website uses self-hosted fonts. No external services (such as Google Fonts) are used. Loading fonts does not involve any data transfer to third parties.
6. Map Display
We generate the map previews of treasures (the rough region of the current one, the find location of the most recently found one, the search areas of past ones) and of the locations of sponsors, organizations and places ourselves, while the site is being built, from free OpenStreetMap data on our own server, and deliver them from there as ordinary image files of this website. Viewing a map does not transmit any data to third parties.
7. Cookies and Local Storage
This website uses no tracking, analytics, or advertising cookies. It sets no cookies at all. The audience measurement described in section 8 stores nothing on your device either. The exception is two purely functional markers in your browser's local storage, each set only by an active decision of yours: schatzbox-lang-suggest remembers that you dismissed the notice about the other language version, and roadex-analytics-opt-out remembers (if you set it) your objection to the audience measurement. Neither contains any identifier of you, neither is used for any other purpose, and both remain until you clear your browser data. You can remove them at any time in your browser settings, but note: deleting roadex-analytics-opt-out also removes your objection, and the audience measurement starts again in that browser. The objection only ever applies in the browser and on the device where you set it.
Legal basis: Art. 6 (1) (f) GDPR and § 25 (2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). Storing information on your device and accessing information already stored there are permitted without consent as far as they are strictly necessary to provide the service you have explicitly requested. This applies to both markers: without the stored entry neither the language notice can be dismissed for good nor your objection honoured for good, and that same entry is read on every page you open in order to act on your choice.
8. Audience Measurement: OpenPanel and Visitor Count
We want to understand how our website is used so that we can improve it. For that we use OpenPanel, analytics software that we run on our own server in Germany. No data is passed to third parties and none is transferred to third countries. We do not use services such as Google Analytics.
Two counts, one section: OpenPanel measures how the website is used as a whole. Alongside it we count ourselves how many people have seen the page of a treasure, a sponsor, an organization or a place (visitor count, see below). Together, the two are what this policy calls the audience measurement. What this section says about your device, the legal basis and your objection applies to both. What each of the two processes is described in its own paragraph.
For the audience measurement we store nothing on your device (no cookies, no local storage, no session storage) and we read nothing stored there. The only exception is an objection marker you have set yourself (see below). We therefore need no consent for it and show you no cookie banner.
What OpenPanel processes: when you open a page, your browser transmits certain information to our server for technical reasons. From it we evaluate: the page requested (including any parameters in the address, e.g. campaign parameters), where the visit came from, duration and extent of the visit (session-based, 30-minute window), device type, operating system and browser, and the approximate location (country, region, city). We receive the origin of a visit as your browser transmits it. For moves within this website we limit it to the bare domain name. How much an external website you came from transmits is that website’s own decision. Clicks on links leading away from here are not recorded. For the audience measurement your IP address is processed only briefly in memory (to determine the approximate location and to form a technical counting value) and is never stored. That value is derived from IP address, browser identifier and a secret key that is rotated daily. Re-identification is therefore technically limited to at most two consecutive days. No usage profiles are created and there is no cross-device tracking.
Visitor count: when you open the page of a treasure, a sponsor, an organization or a place, your browser tells our server which page that is (type and number of the page), once per opening. Reloading the same page reports nothing. From your IP address, your browser identifier, the calendar day and a secret key the server derives a check value from which neither the IP address nor the browser identifier can be recovered. Only that check value is stored. It ensures that the same browser counts as a visitor of the same page at most once a day, and it is deleted after three days at the latest. As a safeguard against manipulation we also count only a fixed number of different browsers per address and day as visitors. For that the server keeps check values of address and browser identifier in memory for about a day at most, from which neither can be recovered either. What remains are two plain figures per page and day without any personal reference, visitors and views, which we keep permanently. Your IP address is not stored for the visitor count, and known search-engine programs are not counted. Why: sponsors, places and organizations want to know how many people have seen their page.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in the statistical evaluation of usage in order to improve content, technology and services to meet actual needs and to ensure the stability of what we offer. For the visitor count it also lies in being able to tell sponsors, places and organizations how many people have seen their page, because the sponsors fund the treasures and the operation. Your protected interests do not outweigh this, because the evaluation is purely statistical, no profiles are built, no data reaches third parties, and nothing is stored on your device.
Retention: the pseudonymous statistical data of OpenPanel is deleted automatically after 14 months, the check value of the visitor count after three days at the latest, the in-memory check values of the manipulation safeguard after about a day at most. The daily figures of the visitor count contain no personal reference and are kept permanently. For the encrypted backup copies the periods in section 3 apply.
Your right to object: you can object to the audience measurement at any time. The button below does that immediately and without giving reasons, independently of the statutory right to object under Art. 21 (1) GDPR, which requires grounds relating to your particular situation. The objection applies to OpenPanel and to the visitor count alike. Your objection takes effect immediately and you can withdraw it there at any time. To honour it we store a technical marker in your browser, solely in order to respect your wish permanently (§ 25 (2) No. 2 TDDDG).
9. Contact Form and Content Reports
When you write to us (through the contact form or directly by email to support@schatzbox.app), we process your message in our own self-hosted ticket system (Zammad, on a server of our own in Germany). It is not passed on to any third party. Through the form that is name, email address, optionally company, message and timestamp. By email it is whatever your mail contains. Both routes end up in the same request and are treated the same from there on.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest in responding to inquiries).
You automatically receive a short acknowledgement of receipt for every message sent through the contact form, at the email address you provided. It repeats your message as a copy. It is sent by the ticket system itself, through our own mail server with no third parties involved. It is the same acknowledgement you get when you write to support@schatzbox.app directly. It is stored as part of your request and deleted together with it. There is no separate send queue for it any more.
We delete your enquiry 12 months after we have closed it, whether it came through the form or by email. While an enquiry is still being dealt with it stays, which is exactly what we keep it for. Excepted is correspondence we are required to retain under commercial or tax law, for instance when an enquiry turns into a contract. The statutory periods apply then.
To protect against automated abuse (spam), the contact form uses a captcha called Cap, which we run on a server of our own. It is not another company’s service. Your browser solves a cryptographic puzzle in the background. No cookies are set, nothing is stored on your device and no usage behaviour is analysed. The only thing processed is your IP address, so that a single connection cannot request an unlimited number of puzzles. The security check starts as soon as you select the first field of the form. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in protection against spam).
Using the report flag on the finder card of a found treasure, you can tell us about a published display name or finder photo that you consider unlawful. Your name, your email address, your description, the treasure concerned and the time are transmitted to our server and processed there. Name and email address are mandatory: Article 16(4) and (5) of the Digital Services Act oblige us to confirm receipt of your report and to inform you of our decision on it. Without an address we cannot. The legal basis is Art. 6 (1) (c) GDPR (compliance with a legal obligation). The report form uses the same captcha as the contact form.
We delete decided reports after six months, and any still-open report after twelve months at the latest. The two emails to you (the acknowledgement of receipt and the decision) go through a send queue on our own server: the contents sit there encrypted and are deleted as soon as the message has been delivered or has permanently failed. After that, your email address, the subject and the timestamps remain stored, among other things: 14 days after a successful delivery, at most 365 days after a permanent failure, in that case together with the technical error message of the last delivery attempt.
10. Publication of a Finder's Display Name and Photo
Whoever finds a treasure can choose a display name and upload a photo in the app's winner form. Both are published on that treasure's page on this website and remain visible there permanently. If someone chooses "Anonymous finder" and uploads no photo, nothing about them is published.
We review the display name and the photo before they are published. Until they are approved they do not appear here. If we do not approve them, or remove them again later, we inform the person concerned and explain why, provided we still have an email address for them. We delete that address 36 months after the find. Display names and photos that we refuse do not appear publicly and are deleted at the latest 12 months after the find, or without delay if we only refuse them later.
The legal basis is consent (Art. 6(1)(a) GDPR), given explicitly and voluntarily in the winner form. It can be withdrawn at any time with effect for the future. An informal message to support@schatzbox.app is enough, and we will then remove the display name and the photo. This does not affect the lawfulness of processing carried out before the withdrawal.
The remaining details from the winner form (full name, postal address, email address and phone number) are not published. They serve solely to hand over the prize.
11. No Data Sharing
Your personal data will not be shared with, sold to, or used for advertising by third parties. Transfer only occurs if legally required. Processors under Art. 28 GDPR, who act strictly on our instructions, are not third parties in this sense. Section 3 names them. The contact form’s spam protection, too, runs on a server we operate ourselves (see section 9). The publication described in section 10 is not sharing with a third party: it happens on our own website and only with explicit consent.
12. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR): You can request information about whether and which personal data we process about you.
- Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate data or the completion of incomplete data.
- Right to erasure (Art. 17 GDPR): You can request the deletion of your data, provided no legal retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR): Under certain conditions, you can request the restriction of the processing of your data.
- Right to data portability (Art. 20 GDPR): You can request that we provide your data in a commonly used, machine-readable format.
- Right to withdraw consent (Art. 7(3) GDPR): You can withdraw any consent you have given (for example for publishing your display name or photo) at any time with effect for the future. The lawfulness of processing carried out before the withdrawal is not affected.
- Right to object (Art. 21 GDPR): set out in full in the paragraph below this list.
Right to object under Art. 21 GDPR: Where we process your data on the basis of a legitimate interest (Art. 6 (1) (f) GDPR, this concerns sections 3, 7, 8 and 9), you may object at any time on grounds relating to your particular situation. An informal message to support@schatzbox.app is enough. Independently of that, you can object to the audience measurement without giving reasons, using the button in section 8.
Whether you have to provide data: you are under no legal or contractual obligation to provide us with data. Without the technically necessary connection data (section 3) this website cannot be delivered to you, however, and without the details in the contact form (section 9) we cannot deal with your request.
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
To exercise your rights, contact: support@schatzbox.app
13. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de
14. Changes
We reserve the right to update this privacy policy to comply with current legal requirements or to reflect changes to our services.
15. From here on: the Schatzbox app
Sections 1 to 14 describe this website. What follows is the privacy policy of the Schatzbox app. Its sections are marked “App ·” and numbered separately from 1 to 12. None of it applies to your visit to this website: it describes what the app does on your device, and it also names switches that exist only there. Three topics might look as though they contradict each other, but they do not. The map display: this website generates its maps itself from OpenStreetMap data (section 6), while the app talks to Mapbox (app section 4). Usage counting: this website’s audience measurement (section 8) and the app’s (app section 12) both count pseudonymously, but they run separately and each has its own switch. The server log files: they record your browser’s requests to this website (section 3) and the app’s requests to api.schatzbox.app (app section 10). The server is the same one (it serves this website and forwards the app’s requests at the same time), which is why the fields recorded are essentially the same and the maximum period of 14 days applies to the access logs in both sections.
App · 1. Responsible Party
Roadex UG (haftungsbeschränkt)
represented by Managing Director Robin Mühlhoff
Biemser Weg 47
32052 Herford, Germany
Email: support@schatzbox.app
App · 2. Data Collected
Schatzbox only collects the data described in this policy. For operation, that is:
- Pseudonymous device ID (random UUID), stored regardless of whether you allowed notifications. It is used to persist your settings (language, radius, objection to usage statistics), to deliver push notifications (if you allowed them), to enable the pseudonymous counts described in app section 12 and, if you tick the box in the app's contact form, to attach its first eight characters to your message.
- Location data only with explicit user consent (for map display and radius notifications)
- Finder data (name, address, email, phone): only if you have found a treasure and submitted the winner form. It is used to hand over the prize. Your display name and an optional photo are published only with your explicit, voluntary consent (Art. 6(1)(a) GDPR), and only after we have looked at them and approved them.
- Report data (name, email address, description): only if you report a published display name or finder photo to us. It is used to handle your report and to send you the reply the law requires.
- Technical access data for every request the app makes to our server (IP address, time, endpoint called, status code, program identifier). Details in app section 10.
Legal basis for the device ID: Art. 6(1)(f) GDPR (legitimate interest in a functional, personalised app). For attaching it to a contact request it is your consent. The ID is pseudonymous (no person behind it) and is reset on the device when you uninstall the app. The identifier stored on the server can additionally be deleted on request (see app section 11).
Finder data in detail. The legal basis is Art. 6(1)(b) GDPR, in the alternative Art. 6(1)(f) GDPR (our interest in fulfilling the obligation from the public promise of reward and in avoiding a double payout), for the retention Art. 6(1)(c) GDPR. Your contact details are stored encrypted. The only recipients are the operator, the server and mail server the operator runs in Germany, and, for shipping physical prizes, the delivery company commissioned for it (postal or parcel service), which receives your name and address for the delivery. In addition there are the technical processors for hosting and data backup named in app section 10. There are no other recipients.
The name you entered, your address and your phone number are deleted 12 months after the find, the email address after 36 months: the longer period because we must still be able to reach you if there is a safety problem with a prize, and because statutory limitation periods are running. The city, the display name we have approved and an approved photo are stored permanently. The display name also remains if you chose a variant containing your name. It is visible on the treasure page once we have approved it, because the treasure pages are kept as a record. We delete them at any time on your request (app section 11). Display names and photos that we refuse do not appear publicly and are deleted at the latest 12 months after the find, or without delay if we only refuse them later. Until we have decided, the entry stays stored and does not appear publicly. Where retention obligations under tax or commercial law apply, the relevant records remain stored in the accounts until those periods expire.
App · 3. Device-Bound Settings and App Updates
The app stores your settings pseudonymously on your device. As far as your settings are concerned, this is permitted without consent under § 25 (2) No. 2 TDDDG: without storing them, the app could not restore them on the next start. There are no user accounts. Uninstalling and reinstalling the app resets all settings.
App updates. Separately from your settings, the app updates itself: on start-up it asks the update service of its app framework Expo (Expo, San Francisco, USA) whether a newer version of the program code is available, and stores a downloaded version on your device. For technical reasons this transmits, among other things, your IP address, the app's version and platform, the identifiers of the running and of the embedded version, and a permanent installation identifier (a random identifier generated on first start and stored on your device). It is not the device ID from app section 2 but an identifier of the framework itself, and it disappears when you uninstall the app. There is no switch for it: without this request the app could no longer receive bug fixes. Storing it on your device is therefore permitted without consent under § 25 (2) No. 2 TDDDG. Legal basis for the transmission: Art. 6(1)(f) GDPR (legitimate interest in fixing a fault before it causes harm). For the transfer to the USA, Expo relies on the EU Standard Contractual Clauses.
App · 4. Map service (Mapbox) and place lookup
To display maps (the search area of the current treasure and the locations of sponsors, organizations and places), Schatzbox uses the map service Mapbox by Mapbox Inc., 740 15th Street NW, Washington, D.C. 20005, USA. Once a map is actually loaded, your IP address is transmitted to Mapbox in the USA for technical reasons. Without it, the map material cannot be delivered. In addition, the Mapbox map SDK periodically transmits location and usage data (telemetry) and accesses information on your device in order to do so. This data is not anonymous, and we have no influence on how Mapbox processes it further.
You have a say in when that happens: under “Settings” → “Offline map” you decide whether the map of the current search area is pre-loaded onto your device (always, only over a connection without a data limit, or not at all) and whether the satellite imagery comes with it. The app asks the first time you open it. Either way, missing tiles are loaded when you open a map. A map cannot be displayed without any transmission to Mapbox at all.
Objecting to the telemetry: Mapbox prescribes its own way of doing this, and we are contractually forbidden from switching it off on your behalf. Every map carries a small ⓘ that opens a notice from Mapbox. That is where the switch for Mapbox telemetry sits. Every other ⓘ in the app belongs to Schatzbox and only explains what is shown in its place, in the searcher display, in the map legend or next to a section heading, for instance. None of them contains a switch. The switch described in app section 12 does not reach the Mapbox telemetry either. It turns off our own usage statistics only.
Place lookup via your operating system. When you set up the notification radius, your operating system's place lookup service is also involved: Google's on Android, Apple's on iOS. This happens in two cases: if you choose “use my position”, the place name for the coordinates found is looked up so that you see a place rather than numbers. If you type in a place, we ask Mapbox first. If Mapbox does not answer or finds nothing, the place name you entered goes to your operating system's service. In both cases the data concerned leaves your device and is processed by Google or Apple. We have no influence on how they process it further, and it may involve a transfer to third countries. If you do not set up a radius, none of this happens.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a clear presentation of the search and location areas). For the transfer to the USA, Mapbox relies on the EU Standard Contractual Clauses. More information: https://www.mapbox.com/legal/privacy
App · 5. Push notifications
If you allow notifications, your device generates a technical push identifier (push token) used to deliver notifications. This involves the push service of the app framework Expo (Expo, San Francisco, USA) and, depending on your device, Google's Firebase Cloud Messaging (Android) or Apple's Push Notification Service (iOS). The technical push identifier, the title and text of the notification, and a small technical payload (what kind of notification it is and which treasure it relates to) are transmitted to these services. A notification cannot be delivered otherwise. Our automatic notifications contain no name and nothing you entered. In a broadcast written by hand, the operator determines the text. An individual person cannot be identified from the push identifier itself.
So that the app can show you your notifications, our server keeps the delivered notifications per device: title, text, the treasure they relate to, and whether you have read them. They are deleted automatically after 18 months, and additionally when the device record is deleted (app section 11).
You can disable notifications at any time in the app or device settings. Legal basis: Art. 6(1)(a) GDPR (consent by enabling notifications). For the transfer to the USA, the providers rely on the EU Standard Contractual Clauses.
App · 6. Active searcher display
The treasure page shows the minimum number of people currently searching. For this, the app (only while it is open and your device is inside the search area) periodically reports to the server that a device is active in the search area. Only the pseudonymous device identifier is stored, together with the relevant treasure and the timestamp. What is expressly NOT stored are precise location coordinates. Only whether the device is inside the search area is answered.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a live display of search activity as a mere count). This presence data is pseudonymous: it contains no name and no contact details, but it is tied to a device via the device identifier.
Storage period: The entries are deleted as soon as the hunt is over. When a treasure is found, we compute in the same operation what is displayed (the total number of searchers on its page and the breakdown in the admin area), and then delete the device-linked entries. All that remains are those plain numbers with no reference to any device. If a hunt is cancelled, retracted or a find is revoked, the entries are deleted as well and no number remains at all. While a hunt is running we delete your entries on request at any time (app section 11). Afterwards nothing is left to delete, because no reference to your device remains.
App · 7. Contact form and content reports
When you write to us (through the contact form or directly by email to support@schatzbox.app), we process your message in our own self-hosted ticket system (Zammad, on a server of our own in Germany) in order to answer your request. Through the form that is your name, email address, optionally your company, your message and the time. By email it is whatever your mail contains. Both routes end up in the same request and are treated the same from there on.
The app's contact form has a tick box for app and device details, and it is not ticked by default. If you tick it, we attach these details to your message, as far as your device knows them: the app version, the date of the running app bundle, your operating system and its version, your device model and the first eight characters of your pseudonymous device ID. Before you send, the info symbol next to the box shows you what your device would attach. We use these details only to reproduce a technical problem.
To protect against automated abuse (spam), the form uses a captcha called Cap, which we run on a server of our own. It is not another company's service. Your device solves a computational puzzle in the background. No cookies are set, nothing is stored on your device, and your behaviour is not analysed. The only thing processed is your IP address, so that a single connection cannot request an unlimited number of puzzles. The check starts as soon as you select the first field of the form. If you do not use the form, nothing is triggered.
You automatically receive a short acknowledgement of receipt for every message sent through the contact form, at the email address you provided. It confirms receipt and repeats your message as a copy. The message itself is read and answered by a person. It is sent by the ticket system itself, through our own mail server and without third parties. It is the same acknowledgement you get when you write to support@schatzbox.app directly. It is stored as part of your request and deleted together with it. There is no separate intermediate storage for sending it any more.
We delete your request 12 months after we have closed it, whether it came through the form or by email. While a request is still being dealt with it stays, which is exactly what we keep it for. Excepted is correspondence we are required to retain under commercial or tax law, for instance when a request turns into a contract. The statutory periods apply then. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in answering requests and in protection against spam). Where it concerns entering into or performing a contract, additionally Art. 6(1)(b) GDPR.
The app and device details are also in the acknowledgement that goes to the email address you entered. We keep them as part of your request and delete them with it. The legal basis is your consent (Art. 6(1)(a) GDPR and § 25 (1) TDDDG), which you give by ticking the box. You can withdraw this consent at any time by replying to the acknowledgement or writing to support@schatzbox.app. Because the details sit inside your request, we then delete the whole request. What was processed before the withdrawal remains lawful.
Reports about published content: using the report flag on the finder card of a found treasure, you can tell us about a published display name or finder photo that you consider unlawful. Your name, your email address, your description, the treasure concerned and the time are transmitted to our server and processed there. Name and email address are mandatory: Article 16(4) and (5) of the Digital Services Act oblige us to confirm receipt of your report and to inform you of our decision on it. Without an address we cannot. The legal basis is Art. 6(1)(c) GDPR (compliance with a legal obligation). The form uses the same captcha as above.
We delete decided reports after six months, and any still-open report after twelve months at the latest. The two emails to you go through the same send queue as our other messages.
App · 8. Confirmation email after a find
After you successfully find a treasure you automatically receive a confirmation email at the address you provided. It restates the details you entered (for verification), lists your prizes, and explains what happens next.
All outbound mail is sent through our own mail server. No external sending service is involved.
The content of every outgoing message is encrypted (AES-256-GCM) while queued for send and is deleted as soon as the message has been delivered or has permanently failed. After that, what remains includes your email address, the subject and the timestamps: 14 days after a successful delivery, and at most 365 days after a permanent failure, in that case together with the technical error message of the last delivery attempt.
If we do not approve your display name or your photo, or remove them again later, you receive a second email telling you so and explaining why. The same sending and storage rules as above apply to it.
Legal basis: Art. 6(1)(b) GDPR, in the alternative Art. 6(1)(f) GDPR (our interest in fulfilling the obligation from the public promise of reward). A public promise of reward is a unilateral legal act, not a contract.
App · 9. Crash reports
So we can detect and fix crashes and errors in the app quickly, Schatzbox uses self-hosted crash reporting (GlitchTip). It runs exclusively on our own servers in Germany. No external crash service is used, and the reports go to no third party. Your data never leaves the operator's area of responsibility. The same processors for hosting and data backup apply as named in app section 10, acting solely on our instructions.
When the app crashes or reports an error, technical diagnostic information is transmitted, e.g. the error message and technical trace (stack trace), the app version, and operating-system/device information (e.g. OS version, device model). This is exclusively technical data, not content you entered.
Not transmitted: any data you entered (e.g. name, address, email, phone) or any identifier that could identify your device or you personally. Your IP address is not stored in the crash report. There is no behavioural tracking and no sharing with third parties.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable, secure app). You can object to this processing at any time at support@schatzbox.app.
App · 10. Server, hosting and logs
Our server sits in a German data centre operated by our infrastructure provider (netcup GmbH, Nuremberg), which acts as a processor under Art. 28 GDPR exclusively on our instructions. For data backups we additionally use Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, as a further processor under Art. 28 GDPR. The backups are encrypted and are likewise held in a data centre in Germany. Server log files are excluded from the backups. The periods below therefore apply without restriction. The other data named in this policy is backed up. Backup copies are overwritten automatically, as a rule after six months. At the backup provider they may additionally persist for up to ten days in its own system backups. Until then they may still contain data that has already been deleted in live operation.
Every request the app makes to our server (api.schatzbox.app) is logged there automatically, as on any web server. Stored are your device's IP address, date and time, the endpoint called (the requested address: it can contain the pseudonymous device identifier, for example when your notification list is fetched), the HTTP status code of the response, the amount of data transferred and your device's program identifier (user agent: it names the app version and the operating system in use, including its version). The content you enter (form data or a find code, for instance) is not logged.
This also applies to the transmission of crash reports (app section 9): the report itself contains no IP address, but the request that transmits it appears in this log like any other.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). The legitimate interest lies in ensuring undisturbed operation and in detecting and repelling attacks: without these logs, neither faults could be traced nor automated attacks detected and blocked.
The logs are deleted automatically after 14 days at the latest, sooner when traffic is high, because older entries are then displaced earlier. Security records of automatically repelled attack and scan attempts are kept for up to five weeks. This data is not combined with any other data source.
App · 11. Data deletion and your rights
You have the right at any time to access, rectification, erasure and restriction of processing, as well as a right to object (Art. 15–21 GDPR). An informal message to support@schatzbox.app is sufficient for access or deletion. You can withdraw any consent you have given us (for example for publishing your display name or photo, or for device details attached to a contact request) at any time with effect for the future (Art. 7(3) GDPR). An informal message to support@schatzbox.app is enough for this as well. The lawfulness of processing carried out before the withdrawal is not affected.
Finder data (name, address, email, phone, photo), contact requests and reports about published content are deleted upon request, unless statutory retention obligations prevent this. The pseudonymous device identifier and your settings are reset on the device when you uninstall the app. On the server it is removed automatically once notifications can no longer be delivered to the device and it has been inactive for more than 180 days. As long as delivery is possible the record is kept, because it carries the notifications you switched on. Immediate deletion is possible on request at any time. It also covers your presence data from app section 6. Anonymous daily statistics figures contain no personal reference and are exempt from this.
You also have the right to lodge a complaint with a data protection supervisory authority (responsible for us: the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia).
App · 12. Usage statistics and sponsor funding
Schatzbox is a project for a good cause and only works thanks to sponsors. They fund the treasures and ongoing operations. To attract sponsors we need to show how many people actively use Schatzbox. Without that information we couldn't win sponsors and the project couldn't exist. Pseudonymous usage statistics additionally help us understand how the app is used so we can improve it. Everyone involved benefits from this: more valuable treasures, more donations to charities, a better project.
That's why we record three things, all three without any details about you as a person (no names, no contact details) and without profiling, all three switched off together via a toggle in the app:
- Daily count: Once per day we store a pseudonymous device ID (no person behind it) plus the date, only the information “your app was active today”, with no IP address and no behavioural data.
- Usage statistics: which screens are opened and which features are used. We record the screen pattern (e.g. “treasure detail”), never secret find codes or your inputs. For the app's public content we additionally record which content was displayed: e.g. which treasure (its public number), which sponsor, which organisation or which place. We also record which features are used (e.g. map opened, which FAQ question was expanded, the type of a tapped notification, never its content) and, when you open an external link provided by us, its target (only the domain of the target site, e.g. “example.com”, or the kind of link, such as e-mail or maps app, never the full address). In addition: app version, device model and operating-system version, the session-based usage duration and the approximate origin (down to city level). This runs on OpenPanel, analytics software on our own server in Germany. The app stores nothing on your device for this and reads no identifiers (no advertising IDs, no device IDs, no install referrer). Your IP address is never stored. It is only processed transiently to determine the approximate origin and to compute a pseudonymous counting value that changes every day. Recognition is technically limited to at most two consecutive days (as a rule it ends with the change of day).
- Visitor count: how often the page of a treasure, a sponsor, an organisation or a place was opened. When you open one, the app sends the pseudonymous device ID to our server. There it is combined with the date and the page you opened into a check value from which the device ID cannot be read back. Only that check value is stored. It makes sure the same device counts a given page at most once per day, and it is deleted after three days at the latest. What remains is a plain number per page and day with no personal reference. Why: sponsors, places and organisations want to know how many people have seen their page.
- For all three: NO sharing with third parties (no Google Analytics, no Firebase, no ad networks: this is about the statistics), NO profiling and NO automated decisions (Art. 22 GDPR), NO session replay. For the DELIVERY of notifications see app section 5, where Firebase is involved.
This is not full tracking, but two pseudonymous counts plus pseudonymous statistics (no names, no profiles), to know how many people use the app and which areas help them, not to follow individual persons.
Retention: The device-linked daily activity is automatically deleted after 90 days. Only anonymous daily figures (plain numbers, no device link) are kept for long-term statistics: how many installations there were on a day and how many devices were active on that day, and, because this cannot be recalculated later, how many devices were active in the 7 days and in the 30 days up to and including that day. Usage-statistics events are automatically deleted after 14 months. The check values of the visitor count are deleted after three days at the latest. The daily per-page numbers derived from them carry no personal reference and are kept indefinitely.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the app and in its sponsor funding).
Your right to object (Art. 21 GDPR): You can object to all three at any time, in the app under “More” → “Legal” → “Privacy Policy”, via the switch that turns all three off together. After your objection, the existing device-linked daily-count data is deleted immediately. The anonymous daily figures remain. Usage-statistics events cannot technically be linked to any device. They therefore cannot be selectively deleted, but no new ones are recorded after your objection and old ones expire automatically. The same applies to the check values of the visitor count: they contain no identifier. They could only be recomputed, not looked up. No new ones are added after your objection, and the existing ones expire on their own within three days. You can undo the objection at any time.
This switch only concerns our own statistics. It does not turn off the telemetry of the map service Mapbox. App section 4 explains how to object to that.
Crash reporting (app section 9) is separate and independent.