1. CONTROLLER and CONTACT
Data controller: RattleStork UG (haftungsbeschränkt), Sternstraße 23, 39104 Magdeburg, Germany.
Email: rattlestork[at]gmail.com · Contact form: rattlestork.org/contact
Data protection officer: currently not appointed (not legally required).
Supervisory authority: State Commissioner for Data Protection Saxony-Anhalt.
2. WHAT DATA DO WE COLLECT?
Information you provide
- Account data (Email, username, password).
- Profile and UGC (texts, images, preferences, messages, matches, reports).
- Support (inquiries, attachments, diagnostic data).
- Billing metadata (plan, renewal status, transaction IDs; no full card numbers are stored with us).
Automatically collected information
- Log and usage data (timestamps, pages/screens, feature usage, crashes/errors).
- Device data (identifiers, OS, app version, language, network).
- Location (approximate, IP-based; precise only with app permission).
- Cookies/SDKs according to the Cookie Policy.
3. SPECIAL CATEGORIES (SENSITIVE DATA)
Our services may allow you to share information about health, sexual orientation, or family planning. We do not require these details. If you voluntarily disclose them, we process them only with explicit consent (Art. 9 para. 2 lit. a GDPR) to provide the services (matching, messaging, safety/moderation) and to fulfill legal obligations. Withdrawal is possible at any time in the Settings; until withdrawal, processing remains lawful.
4. HOW DO WE PROCESS YOUR DATA?
- Service delivery: Account, profiles, matching, messaging, moderation, support.
- Improvement and security: troubleshooting, analytics (with consent), anti-spam/fraud, abuse prevention.
- Communications: service emails, transactional messages, push (opt-out in device settings).
- Compliance: tax/accounting, consumer law,DSA, requests from authorities.
- Marketing only with consent; withdrawal at any time.
5. LEGAL BASES (GDPR/UK GDPR/CANADA)
- Contract (Art. 6(1)(b)): provision of requested core functions.
- Consent (Art. 6(1)(a)): non-essential cookies/SDKs, marketing, special categories (Art. 9(2)(a)).
- Legal obligation (Art. 6(1)(c)): tax, consumer law, DSA, retention.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, product-related analytics with safeguards.
Canada: Processing based on express or implied consent; withdrawal possible at any time.
6. PAYMENTS and SUBSCRIPTIONS
Purchases/subscriptions via the Apple App Store, Google Play, or web payment providers. No full card numbers are stored with us. We receive limited billing metadata (plan, status, transaction IDs) to manage access. Prices/plans are shown in the app or on the subscription page.
9. GOOGLE-APIs and ANALYTICS
Use of Google APIs in accordance with the Google API Services User Data Policy (including Limited-Use). Google Analytics: Opt-out, e.g. via the Browser add-on, NAI opt-out and mobile choices.
10. Notice-and-Action (EU-DSA)
Reports of allegedly unlawful content via the contact form or in-app reporting. We review, act appropriately, and notify as required by law.
11. HOW LONG DO WE RETAIN DATA?
Stored until the purpose is fulfilled or account activity ends; then deleted or anonymized, unless longer legal retention periods apply (e.g., tax/accounting). Typical: server logs/analytics 90–365 days; security logs as required. Deletion requests via the Settings.
12. HOW DO WE PROTECT DATA?
Appropriate technical and organizational measures (transport encryption, access controls, backups). However, no electronic transmission or storage can be completely secure.
13. CHILDREN and MINORS
Adult services 18+. No intentional collection of data from people under 18. If you become aware of such data, please contact us for deletion.
14. YOUR PRIVACY RIGHTS
Depending on your residence (EEA/UK/CH/Canada/US states): rights to access, rectification, deletion, restriction, objection, data portability, and withdrawal of consent. Exercise via the Settings, contact form or rattlestork[at]gmail.com. Right to lodge a complaint with your supervisory authority.
15. US STATE PRIVACY NOTICES
Residents of certain US states have specific rights (notice/access, rectification, deletion, copy, opt-out from targeted advertising/'sale'/profiling). We do not sell/share personal data for cross-context behavioral advertising.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Contact, IP, email, account name | YES |
| B. Customer data (CA) | Name, contact, billing metadata | YES |
| C. Protected characteristics | Provided by you | YES |
| D. Commercial information | Transactions/purchases | NO (via stores/providers; metadata YES) |
| E. Biometrics | Fingerprint/voiceprints | NO |
| F. Internet/network | Browsing, usage | YES |
| G. Geolocation | Device location | YES (with permission/IP) |
| H. Audio/visual | Images/recordings for support | NO (UGC by you) |
| I. Professional | Job/application | NO (except application) |
| J. Education | Student records | NO |
| K. Inferences | Profiles/attributes | NO (only security indicators) |
| L. Sensitive data | Health/sexual orientation (UGC) | YES (only with explicit consent) |
Exercising U.S. state rights
Requests via Settings, Contact form or email to rattlestork[at]gmail.com. Identity verification in accordance with law; authorized representatives possible (proof required). If denied: appeal by email; also contact the public prosecutor's office.
16. INTERNATIONAL TRANSFERS
For transfers outside the EEA/UK/CH we use appropriate safeguards (EU standard contractual clauses/UK IDTA) and carry out transfer impact assessments. Copies available on request (with redactions).
17. Do-Not-Track
In the absence of an accepted industry standard, we do not currently respond to DNT signals. If a standard is established, we will update this notice.
18. UPDATES TO THIS NOTICE
Changes will be dated at the top; material updates may be highlighted in the app or elsewhere. Please check regularly.
19. CONTACT
RattleStork UG (limited liability)
Sternstraße 23, 39104 Magdeburg, Germany
E-mail: rattlestork[at]gmail.com
Contact and notices: rattlestork.org/contact
8. Social Logins
When registering/logging in via social networks, we receive profile data according to your settings with the provider; use is limited to account/login. Please refer to the privacy notices of the respective provider.