1. CONTROLLER and CONTACT
Controller: RattleStork UG (haftungsbeschränkt), Sternstraße 23, 39104 Magdeburg, Germany.
Email: rattlestork[at]gmail.com · Contact form: rattlestork.org/contact
Data protection officer: currently not appointed (not legally required).
Supervisory authority: State Commissioner for Data Protection of Saxony-Anhalt.
2. WHAT DATA DO WE COLLECT?
Information you provide
- Account data (email, username, password).
- Profile and UGC (texts, images, preferences, messages, matches, reports).
- Support (requests, attachments, diagnostic data).
- Billing metadata (plan, renewal status, transaction IDs; no full card numbers are stored with us).
Automatically collected information
- Log and usage data (timestamps, pages/screens, feature usage, crashes/errors).
- Device data (identifiers, OS, app version, language, network).
- Location (approximate IP-based; precise only with app permission).
- Cookies/SDKs according to the Cookie Policy.
3. SPECIAL CATEGORIES (SENSITIVE DATA)
Our services may allow you to share information about health, sexual orientation, or family planning. We do not require this information. If you voluntarily disclose it, we process it only with explicit consent (Art. 9(2)(a) GDPR) to provide the services (matching, messaging, safety/moderation) and to fulfill legal obligations. You can withdraw consent at any time in the Settings; processing remains lawful until withdrawal.
4. HOW DO WE PROCESS YOUR DATA?
- Provision: accounts, profiles, matching, messaging, moderation, support.
- Improvement and security: troubleshooting, analytics (with consent), anti-spam/fraud, abuse prevention.
- Communication: service emails, transactional messages, push (opt-out in device settings).
- Compliance: tax/accounting, consumer law,DSA, government requests.
- Marketing only with consent; can be withdrawn at any time.
5. LEGAL BASES (GDPR/UK GDPR/CANADA)
- Contract (Art. 6(1)(b)): providing requested core features.
- Consent (Art. 6(1)(a)): non-essential cookies/SDKs, marketing, special categories (Art. 9(2)(a)).
- Legal obligation (Art. 6(1)(c)): tax, consumer law, DSA, retention.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, product-related analytics with safeguards.
Canada: processing with explicit or implied consent; withdrawal possible at any time.
6. PAYMENTS and SUBSCRIPTIONS
Purchases/subscriptions via the Apple App Store, Google Play, or web payment providers. No full card numbers are stored with us. We receive limited billing metadata (plan, status, transaction IDs) to manage access. Prices/plans are in the app or on the subscription page.
9. GOOGLE-APIs and ANALYTICS
Use of Google APIs in accordance with the Google API Services User Data Policy (including Limited-Use). Google Analytics: Opt-out, e.g., via the browser add-on, the NAI opt-out, and mobile options.
10. NOTICE-AND-ACTION (EU-DSA)
Reports of suspected illegal content via the contact form or in-app reporting. We review, take appropriate action, and notify according to legal requirements.
11. HOW LONG DO WE RETAIN DATA?
Stored until the purpose is fulfilled or the account is active; thereafter deleted or anonymized, unless longer legal periods apply (e.g., tax/accounting). Typical: operational logs/analytics 90–365 days; security logs as required. Deletion requests in the Settings.
12. HOW DO WE PROTECT DATA?
Appropriate technical and organizational measures (transport encryption, access controls, backups). However, no electronic transmission or storage can be absolutely secure.
13. CHILDREN and MINORS
Services for adults 18+. We do not knowingly collect data from anyone under 18. If you become aware of such data, please contact us to request deletion.
14. YOUR PRIVACY RIGHTS
Depending on where you live (EEA/UK/CH/Canada/US states): rights to access, rectify, erase, restrict, object, data portability, and withdraw consent. You can exercise these via Settings, Contact form or rattlestork[at]gmail.com. You also have the right to lodge a complaint with your supervisory authority.
15. US STATE PRIVACY NOTICES
Residents of certain US states have specific rights (notice/access, correction, deletion, copy, opt-out of targeted advertising/"sale"/profiling). We do not sell or share personal data for cross-context behavioral advertising.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Contact, IP, email, account name | YES |
| B. Customer records (CA) | Name, contact, billing metadata | YES |
| C. Protected characteristics | Provided by you | YES |
| D. Commercial information | Transactions/purchases | NO (via stores/providers; metadata YES) |
| E. Biometrics | Fingerprint/voice prints | NO |
| F. Internet/network | Browsing, usage | YES |
| G. Geolocation | Device location | YES (with permission/IP) |
| H. Audio/visual | Images/recordings for support | NO (UGC provided by you) |
| I. Professional | Job/application | NO (except application) |
| J. Education | Student records | NO |
| K. Inferences | Profiles/characteristics | NO (security indicators only) |
| L. Sensitive data | Health/sexual orientation (UGC) | YES (only with explicit consent) |
Exercising US state rights
Requests via Settings, Contact form or email to rattlestork[at]gmail.com. Identity verification as required by law; authorized agents may act (proof required). If a request is denied: appeal by email; you may also contact the Attorney General.
16. INTERNATIONAL TRANSFERS
For transfers outside the EEA/UK/CH, we use appropriate safeguards (EU standard contractual clauses/UK IDTA) and conduct transfer impact assessments. Copies are available on request (with redactions).
17. DO-NOT-TRACK
Due to the lack of an accepted industry standard, we currently do not respond to DNT signals. If a standard emerges, we will update this notice.
18. UPDATES TO THIS NOTICE
Changes will be dated above; significant updates may be highlighted in the app or otherwise. Please check regularly.
19. CONTACT
RattleStork UG (haftungsbeschränkt)
Sternstraße 23, 39104 Magdeburg, Germany
Email: rattlestork[at]gmail.com
Contact and reports: rattlestork.org/contact
8. SOCIAL LOGINS
When you register/login via social networks we receive profile data according to your settings with the provider; used only for account/login. Please review the privacy notices of the respective provider.