Deutsch English

Privacy Policy

Last updated: April 2026 · Version 2.0

This Privacy Policy explains, in accordance with Art. 13 and 14 GDPR, how personal data is collected, processed and used when you use the mobile application "Pin Your Plate" (the "App") and the website pinyourplate.app.

1. Controller

The controller within the meaning of Art. 4 No. 7 GDPR is:

Marius Wenk
Arcostraße 48
15831 Mahlow
Germany
E-mail: support@pinyourplate.app
Phone: +49 1578 2045200

A data protection officer is not legally required and has not been appointed.

2. Scope

This Privacy Policy applies to the mobile app "Pin Your Plate" (Android and iOS) as well as to the website pinyourplate.app. For linked third-party offerings, their respective privacy policies apply.

3. Overview of processing activities

Pin Your Plate enables users to save food-related locations ("pins") on a map, add photos and notes, organize gatherings ("meetups") and share content with other users. We process personal data exclusively for the purposes described below.

4. Categories of data, purposes and legal bases

4.1 Account data (upon registration and use)

Purpose: providing the account, authentication, operating social features.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).

4.2 User content

Purpose: core functionality of the App.
Legal basis: Art. 6(1)(b) GDPR.

Important: coordinates of created pins are stored permanently, as they are integral to the functionality. Photos may contain personal metadata (EXIF); we recommend removing sensitive metadata before uploading.

4.3 Location data (device location)

The App accesses the current device location when you grant the corresponding permission. Location is used:

Your live location is not stored permanently nor transmitted to other users. Only the coordinates you explicitly assign to a pin are stored permanently.

Legal basis: Art. 6(1)(a) GDPR (consent by granting the location permission). You can revoke the permission at any time in the system settings of your device.

4.4 Device and technical data

Purpose: stability, debugging, performance optimization, product improvement.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional, error-free product) for purely necessary diagnostics; Art. 6(1)(a) GDPR (consent) for analytics beyond what is technically necessary. Analytics is disabled in debug mode.

Opt-out: you can limit crash reports, performance monitoring and analytics at the device system level via Android/iOS privacy settings (or on iOS via App Tracking Transparency). An in-app opt-out for analytics is planned.

4.5 Purchase and payment data

When you purchase the "Founder Pack" or "Premium Pack", the following data is processed:

The actual payment is processed exclusively via the Apple App Store or Google Play; we do not receive credit card or bank data. Purchase management is handled technically through RevenueCat (see section 5).

Legal basis: Art. 6(1)(b) GDPR (performance of contract), Art. 6(1)(c) GDPR (statutory retention requirements).

4.6 Reports and moderation

When you report content or a user, we store your user ID, the ID of the reported content/user, the reason and optionally a description. This data is stored to process the report and for documentation pursuant to the Digital Services Act (DSA).

Legal basis: Art. 6(1)(c) GDPR (legal obligation under the DSA), Art. 6(1)(f) GDPR (legitimate interest in platform safety).

5. Third-party services used

We use the following processors and services. Data processing agreements under Art. 28 GDPR are in place with all providers. Where data is transferred to third countries (in particular the United States), transfers are based on Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR and/or – for US-certified providers – on the EU-US Data Privacy Framework (Art. 45 GDPR).

ServiceProviderPurposeTransfer
Firebase AuthenticationGoogle Ireland Ltd. (EU) / Google LLC (US)Login, password hash, sessionUS (SCCs + DPF)
Cloud FirestoreGoogle Ireland Ltd. / Google LLCDatabase for pins, profiles, meetupsEU – Region: europe-west4 (Netherlands); administrative access by Google LLC (US) cannot be excluded, based on SCCs + DPF
Firebase StorageGoogle Ireland Ltd. / Google LLCStorage of uploaded photosUS (SCCs + DPF)
Firebase Cloud FunctionsGoogle Ireland Ltd. / Google LLCServer-side logicUS (SCCs + DPF) – default us-central1
Firebase Cloud MessagingGoogle Ireland Ltd. / Google LLCPush notificationsUS (SCCs + DPF)
Firebase AnalyticsGoogle Ireland Ltd. / Google LLCUsage analyticsUS (SCCs + DPF)
Firebase CrashlyticsGoogle Ireland Ltd. / Google LLCCrash reportingUS (SCCs + DPF)
Firebase Performance MonitoringGoogle Ireland Ltd. / Google LLCPerformance measurementUS (SCCs + DPF)
Firebase HostingGoogle Ireland Ltd. / Google LLCWebsite deliveryUS (SCCs + DPF)
Google Sign-InGoogle Ireland Ltd. / Google LLCAuthentication via Google accountUS (SCCs + DPF)
Google Places APIGoogle Ireland Ltd. / Google LLCAutocomplete and place searchUS (SCCs + DPF)
Google Play In-App ReviewGoogle Ireland Ltd. / Google LLCIn-app rating prompt (Android)US (SCCs + DPF)
Apple Sign InApple Distribution International Ltd. (Ireland)Authentication via Apple IDEU / US
Apple App Store In-App PurchaseApple Distribution International Ltd.Purchase processing on iOSEU / US
Apple Push Notification ServiceApple Distribution International Ltd.Push notifications on iOSEU / US
Apple In-App RatingsApple Distribution International Ltd.In-app rating prompt (iOS)EU / US
MapboxMapbox Inc., USMap tiles and renderingUS (SCCs + DPF)
RevenueCatRevenueCat Inc., USIn-app purchase and entitlement managementUS (SCCs)

Provider privacy notices:

6. Visibility of your content

Profiles, pins and meetups may – depending on your settings – be visible to other users of the App. Public profiles and pins can potentially be viewed by all signed-in users. When creating content, be mindful not to share information you do not want to be public.

7. Sharing with third parties

No sharing with third parties other than the processors listed in section 5 takes place. Disclosure to government agencies only occurs when we are legally obliged to do so (e.g., upon court order).

We do not sell personal data.

8. Retention

Data categoryRetention period
Account and profile datafor the duration of your account
Content (pins, photos, meetups)until deleted by you or upon account deletion
Crash and performance dataup to 90 days (Firebase default)
Analytics dataup to 14 months (configured Firebase default)
Push tokensuntil logout or uninstall
Reports and moderation decisionsup to 3 years (DSA documentation)
Purchase receipts and transactionsup to 10 years (tax retention, § 147 AO)
Server logs with IP addressusually max. 30 days

After deletion of your account, personal data is removed from all active systems within 30 days, except for data subject to statutory retention (e.g., invoicing data).

9. Your rights

Under the GDPR, you have the following rights:

You can delete your account at any time in the app settings under "Delete account". Instructions and information on how to request deletion without the app installed are available at pinyourplate.app/delete-account. For any other request, contact support@pinyourplate.app.

10. Right to lodge a complaint

Without prejudice to any other legal remedy, you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or of the alleged infringement.

The supervisory authority for the controller is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg
Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany
www.lda.brandenburg.de

11. No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

12. Minors

Use of the App is permitted for persons aged 16 and over. Persons under 16 may use the App only with verifiable consent of their legal guardians (Art. 8 GDPR). The App is not directed at children. If we become aware that a child has submitted data without the required consent, it will be deleted immediately.

13. Security

Data is encrypted in transit via TLS/HTTPS. On the server side, data is stored in the access-controlled systems of our processors. Internal access to personal data is restricted to the necessary minimum.

14. Push notifications

Push notifications are only sent if you have granted the corresponding system permission. You may revoke the permission at any time in your device settings.

15. Cookies and web storage (website)

The website pinyourplate.app is a purely static information page and does not set tracking cookies. Technically necessary cookies of the hosting provider (Firebase Hosting) may be used temporarily; no consent is required for this under § 25(2)(2) TDDDG.

16. Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy to reflect changes in the law or new features. We will inform you of material changes – where required – within the app or by e-mail. The current version is available at pinyourplate.app/privacy.

17. Contact

For privacy-related questions, contact us at:
E-mail: support@pinyourplate.app