Privacy Policy
Protecting your personal data is important to us. Below we inform you in accordance with Art. 13, 14 of the General Data Protection Regulation (GDPR) about the processing of your data when using the Nutze.app platform.
1. Controller
The controller within the meaning of the GDPR is:
Chris Wernsmann
Vennstr. 3
48619 Heek
Germany
Email: hello@nutze.app
2. What data we process and for what purposes
Depending on your use of the platform, we process the following data:
- Account and profile data: name, email address, encrypted password (for classic email sign-in), phone number, profile picture. Purpose: provision of the user account and communication. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
- Listing and booking data: titles, descriptions, photos, prices, item location, chat messages between the parties. Purpose: processing of rental contracts between users. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
- Handover and return protocols: photos of the condition of the items, timestamps and confirmations (digital handshake). Purpose: preservation of evidence and contract processing. Legal basis: legitimate interest in dispute resolution (Art. 6 (1) (f) GDPR) and performance of a contract.
- Payment data: information about processed payments. Note: we do not store full credit card details ourselves. Purpose: payment processing. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
- Booking and payment records subject to statutory retention: booking, invoicing and payment details we must keep beyond the purpose of the contract. Purpose: meeting tax and commercial retention obligations. Legal basis: compliance with a legal obligation (Art. 6 (1) (c) GDPR) in conjunction with § 147 AO and § 24 Abs. 3 PStTG. This retention is why a deleted account is anonymised rather than removed (see section 7).
- Technical usage data (server log files): IP address, browser type, date and time of access. Purpose: security, stability and troubleshooting. Legal basis: legitimate interest (Art. 6 (1) (f) GDPR).
- Push notifications (mobile app): a device token from the push service (Expo push token), the platform (iOS/Android) and the device name, each linked to your account. Purpose: delivering notifications about your bookings and messages. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR). The token is deleted as soon as you turn push notifications off, sign out, or delete your account.
- Device capabilities of the mobile app: the app asks for access to the camera, photo library, location and microphone only when you use a feature that needs it — and you can withdraw any permission in your system settings at any time. The camera is used solely to scan the handover QR codes; nothing it captures is stored or transmitted. From the photo library we take only the images you select yourself. Location is used to show you offers near you, and only for the duration of the search. Microphone and speech recognition serve voice input in search. The conversion to text is performed by your operating system's speech recognition service (Apple or Google), to which the recording may be transmitted for that purpose; the respective provider's privacy terms apply. We receive only the finished text, never the audio recording, and we store no audio data.
3. Storage on your device (TDDDG) and cookieless analytics
We use technically necessary storage technologies (such as local storage in the browser) to keep you logged in and to ensure essential functions of the app (e.g. the booking process).
In the mobile app, local storage is replaced by your operating system's encrypted keychain (iOS Keychain or Android Keystore), which holds your session data and a few display preferences. That data never leaves your device and is removed when you sign out or uninstall the app. The cookieless analytics described below run on the web only — the mobile app contains no analytics, advertising or tracking SDK of any kind.
The storage of this strictly necessary data on your device is based on § 25 (2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). The subsequent processing of the personal data takes place in accordance with Art. 6 (1) (f) GDPR (legitimate interest in providing the app) or Art. 6 (1) (b) GDPR.
For reach measurement we use Vercel Analytics and Speed Insights. These services work cookielessly and collect data (such as page views) only in anonymised form. No user profiles are created across websites.
4. Sign-in via third-party providers (single sign-on)
In addition to classic registration by email, we offer the option of signing in via the services of Google and Apple.
If you choose this option, we are authorised directly by the respective third-party provider and receive certain profile data from them (such as your name and email address) in order to create your Nutze.app account or log you in. The legal basis for this is the performance of a contract (Art. 6 (1) (b) GDPR) or your consent through the active selection of the provider (Art. 6 (1) (a) GDPR).
- The providers are Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and Apple Distribution International Ltd. (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland).
5. Recipients of the data and US data transfer (DPF)
To provide our platform, we use specialised service providers (processors pursuant to Art. 28 GDPR).
Every provider listed below is contractually bound — through a data processing agreement under Art. 28 GDPR — to process your data solely on our instructions and for the stated purpose, and to provide the same level of protection for that data as is described in this privacy policy. Your data is never passed on for the providers' own purposes, sold, or used for advertising.
Important note on data transfer to the USA
Some of our service providers are based in the USA. The European Commission has issued an adequacy decision for the EU-US Data Privacy Framework (DPF). Insofar as our US service providers are certified under the DPF, the transfer of data to the USA is permissible under data protection law.
We use the following service providers:
- Vercel Inc. (USA): hosting of the web application and cookieless reach measurement. (Certified under the EU-US DPF.)
- Supabase Inc. (USA): hosting of the database, user authentication and storage of uploaded images. Supabase uses European data centres, but support access from the USA is possible. (Certified under the EU-US DPF.)
- Resend Inc. (USA): sending of purely transactional system and notification emails (e.g. booking confirmations). (Certified under the EU-US DPF.)
- Upstash Inc. (USA): cache (Redis) for the technical protection (rate limiting) of the platform.
- Functional Software, Inc. ("Sentry", USA): error and stability monitoring to detect and fix technical errors. We operate Sentry in the EU data region (data centre in the EU), so error data is processed within the EU. Session replay is disabled; transmitted error reports are also stripped of personal data (e.g. IP addresses, email addresses, cookies). (Certified under the EU-US DPF.)
Artificial intelligence (content screening and assistive features)
Artificial intelligence assists us in a few places. The only provider used for this is:
- Google Ireland Ltd. / Google LLC (USA) — Gemini (Google AI). A data processing agreement under Art. 28 GDPR is in place, binding Google to the same level of protection promised in this privacy policy. Google processes the transmitted content solely on our instructions and not for its own purposes.
Only what the respective feature needs is transmitted:
- Screening of listings: a listing's title, description and photos are checked automatically before publication for compliance with our terms of use. This serves to detect prohibited or illegal offers and to prevent fraud. Legal basis: legitimate interest in a safe and lawful platform (Art. 6 (1) (f) GDPR).
- Listing assistant: if you use it, the photos you select for a listing are transmitted so that suggestions for a title, description and category can be generated from them. The suggestions are suggestions — you can change or discard them before publishing. Legal basis: consent (Art. 6 (1) (a) GDPR).
- Category suggestion: a listing's title, description and first photo may be transmitted in order to suggest the matching category. Legal basis: consent (Art. 6 (1) (a) GDPR).
- Search: the search text you type may be transmitted in order to derive matching search terms and filters. Legal basis: consent (Art. 6 (1) (a) GDPR).
- Search keywords: a listing's title and description may be transmitted in order to derive additional terms your listing can be found under. Legal basis: consent (Art. 6 (1) (a) GDPR).
Before any content is sent to Google for the first time, the app and the website show you which data is sent to whom, and ask for your decision.
For the four assistive features — listing assistant, category suggestion, search and search keywords — that decision is consent under Art. 6 (1) (a) GDPR: without it nothing is transmitted and the features stay switched off.
Listing screening, by contrast, rests on our legitimate interest (Art. 6 (1) (f) GDPR) — a safety check that could be switched off would not be one. We still follow your decision here: it takes effect as an objection under Art. 21 GDPR, and your listing is then screened by a person instead of an AI. That takes longer, but restricts neither publishing nor any other use of the platform.
Changing or withdrawing your permission: you can change your decision at any time and without giving reasons — in the app under Profile → Account & Security → Artificial intelligence, on the website under Dashboard → Profile → Account & Security → Artificial intelligence. A withdrawal takes effect going forward: from that moment no further content is sent to Google. The lawfulness of processing carried out until then is unaffected.
Uploaded images are converted before being passed on, and GPS coordinates are stripped from the EXIF data in the process.
Not transmitted: chat messages, handover and return records, payment or account data. Your content is not used to train AI models — this is contractually excluded by our use of the paid Google API.
Payment processing via Stripe
For processing payments we use Stripe Payments Europe, Ltd. (Ireland) or its parent company in the USA (certified under the EU-US DPF).
Stripe processes payment information (e.g. credit card details) partly as our processor, but also as an independent controller in order to comply with its own legal obligations (e.g. anti-money-laundering). You can find further information in Stripe's privacy policy: https://stripe.com/privacy.
6. Map services and geocoding
To show you the locations of listings, we embed interactive maps. For data-protection reasons (privacy by design), we host the underlying map tiles (Protomaps/PMTiles) on our own servers. When simply viewing the map, no location data is therefore transmitted to third-party map providers.
However, the following applies to certain additional map functions:
- Map assets: to display fonts and symbols (sprites) on the map (MapLibre), files are loaded from GitHub (protomaps.github.io). For technical reasons, your IP address is transmitted to GitHub (USA) in the process. The same applies when loading fallback tiles via the servers of the OpenStreetMap Foundation.
- Geocoding: when you enter an address in the search field or create a listing, we convert this address into coordinates in the background. This conversion (geocoding) takes place server-side via the interfaces of Geoapify (Geoapify GmbH, Austria/EU) and Nominatim / OpenStreetMap.
The legal basis for this processing is our legitimate interest in a functioning and appealing location search (Art. 6 (1) (f) GDPR) and the performance of a contract (Art. 6 (1) (b) GDPR).
7. Storage period
We only store your data for as long as is necessary for the respective purpose.
Account deletion
You can delete your account yourself at any time — on the web and in the app under Profile → Account & Security. Deletion happens in two stages.
Immediately upon your request: your profile, your listings and your presence in search disappear at once. From that moment your account can no longer be found by anyone else.
Your access remains for 30 days — deliberately so. Deletion is reversible during that period, and you can only reach the reversal if you are still able to sign in. Pressing "Cancel deletion" on the same page restores your account completely. Simply signing in does not cancel the deletion; that button is the only thing that does.
After the 30 days have passed, your account is automatically and permanently anonymised. We do not delete the row in our database — we delete the person in it. Your name is replaced with "Deleted user"; profile picture, phone number, company details, VAT ID, any stored imprint and terms documents, notification preferences and all Stripe identifiers are removed; your addresses are overwritten. Push tokens, favourites, follows and blocks are deleted. Your credentials are made unusable: password and linked Google/Apple accounts are removed, active sessions are ended, and access is permanently locked. From this point recovery is no longer possible.
Why anonymised rather than deleted: a rental always has two sides. If we removed your row entirely, your counterparty would also lose the record of a booking they were party to — including the invoicing and payment data we are required to retain for up to 10 years under § 147 AO and § 24 Abs. 3 PStTG. Those records therefore remain, but can no longer be attributed to an identifiable person.
That is not the end of it. Anonymisation removes the person from the row; what remains of the content has its own deadline, and an automated process checks daily which of those have passed and erases them. Three years after the end of the year in which they were created, message text, review text and listing descriptions are erased (§ 195, § 199 Abs. 1 BGB). Ten years applies to the booking and payment details that matter for tax (§ 147 AO, § 24 Abs. 3 PStTG) — and § 24 Abs. 3 PStTG expressly requires erasure once the period ends. Images sent in chat are removed as soon as the message they belong to no longer exists.
When we refuse a deletion: while you are party to a booking that is not yet completed, cancelled or rejected, we cannot delete your account — the same applies during an open dispute and while there is an unpaid balance on your Stripe account. In those cases we tell you what is still outstanding. If any of these checks cannot be carried out for technical reasons, we refuse as a precaution rather than perform a deletion that would damage an ongoing rental.
Your right to erasure under Art. 17 GDPR remains unaffected; you can contact us at any time at hello@nutze.app. Where we must keep data to meet a statutory retention obligation, Art. 17 (3) (b) GDPR expressly provides an exception to the right to erasure; we then restrict processing of that data to the retention purpose and delete it once the period ends.
8. Data sharing between users
When you request a booking, we pass on your name and the city of the handover location to the respective other contracting party.
Once a booking is confirmed (that is, accepted and onwards), we additionally pass the following data to the other contracting party so that you can arrange the handover and know who you have entered into a contract with:
- the full address of the handover location,
- your phone number, if you have provided one,
- the default address you have on file,
- for commercial accounts, additionally the company name and VAT identification number.
This is strictly necessary for the performance of the rental contract between you (Art. 6 (1) (b) GDPR). Before a booking is confirmed we do not share this data. We never pass your email address to the other contracting party — communication runs through the in-app chat.
9. Your rights
You have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification or erasure (Art. 16 and 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw a given consent (Art. 7 (3) GDPR)
Right to object (Art. 21 GDPR): insofar as we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you can object to the processing at any time.
To exercise your rights, an email to hello@nutze.app is sufficient.
10. Right to complain to a supervisory authority
You also have the right to complain to a data protection supervisory authority. The supervisory authority responsible for our registered office is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2-4
40213 Düsseldorf, Germany
Last updated: September 2026