Updated: 26 September 2026
Privacy notice
Draft. Operator details, retention periods and contractual terms still need completion and review. The placeholders are not complete legal information.
Responsible operator
[Operator to be added][Business address to be added]
[Contact email to be added]
Data we process
For your account: name, email, a password hash, sessions and any connected sign-in providers. For collaboration: teams, memberships, roles and invitations. OmaFahrt stores the family details, trips, statements and payment evidence you enter. Upload only what is needed; you can redact unrelated details on bank evidence first.
Purposes and legal bases
Account management and requested features serve contractual performance (GDPR Article 6(1)(b)). Security and administrative logs support the legitimate interest in secure operation (f). Statutory invoice retention relies on legal obligations (c). Optional marketing emails require separate, withdrawable consent (a). No marketing emails are currently sent.
Recipients and collaboration
Team members see data according to their permissions. Platform administrators can access records for support and administration; access is logged. The hosted service stores data in the platform's PostgreSQL database. Account verification, password reset and invitation emails are delivered through the configured email service. Sign-in with Google, Apple and Instagram is currently unavailable. Public checkout is disabled. Hosting, email and other processors, storage locations and any international transfer safeguards still need to be specified in this draft. Mailpit is used only in local development; Stripe test mode sends necessary test billing data to Stripe.
Cookies and preferences
The application uses essential session cookies for sign-in. Your chosen language is remembered in a preference cookie for one year. Your theme preference is stored in your browser. There are no advertising pixels or embedded Instagram content. Fonts and illustrations are served locally.
Optional visitor analytics
When visitor analytics are enabled, Matomo loads only after your explicit consent. It measures visits to the public landing and legal pages only. Private account, team and tool pages, URL parameters, forms, user IDs and referrer URLs are excluded. Connecting to the analytics server necessarily transmits your IP address and browser information. Analytics cookies and additional browser-feature detection are disabled.
Your choice is stored for 180 days in this browser only. This is the lifetime of your choice, not the retention period for analytics data. Optional analytics rely on your consent (GDPR Article 6(1)(a), and TDDDG Section 25(1) where applicable). Withdraw it for future activity using “Disable analytics” at the bottom of the page. Requests already submitted may still complete. All features remain available without analytics. Do Not Track and Global Privacy Control are respected. The operator and processing arrangements still need to be specified in this draft.
Matomo masks IP addresses before storage and also uses the masked address for location lookup. A daily cleanup limited to Kramklar normally removes raw visit records after 180 to 181 days; missed runs can delay this. Aggregate reports remain. Encrypted backups may contain older raw records until rotated out of the 21 most recent successful backups; this is not a fixed 21-day expiry.
Retention and deletion
Anonymous demo access ends after 24 hours. Hourly cleanup normally removes expired, solely anonymous-owned demo accounts and their sample records within about 25 hours; service interruptions can delay this. Registration discards the demo samples, so your private team starts without them. Security logs and backups have separate retention periods that still need to be specified.
You can delete your account and solely owned teams in account settings. Shared teams may first require ownership transfer; records shared with other members remain. Security logs and invoice records subject to statutory retention may be excepted. Binding production retention periods for invoices, logs and backups still need to be set.
Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. You can withdraw consent for the future. Data export and marketing preferences are available in your account. You may complain to a competent data protection authority. Requests: [Privacy contact to be added]