Privacy Policy
1. Controller
wecorn GbR
Rochusstraße 61
52062 Aachen, Germany
Email: mail@wecorn.de
2. Data we collect
We collect and process the following personal data:
- Account data: email, username, display name, date of birth (Art. 6(1)(b) GDPR — contract performance)
- Location data: GPS coordinates only at the moment of a check-in (Art. 6(1)(a) GDPR — consent)
- Usage data: check-in history, reviews, event attendance, friend connections (Art. 6(1)(b) GDPR)
3. Location data
Your location is recorded only at the moment of a check-in — never in the background. Location data verifies that you are physically at the kiosk (60 m radius). Raw GPS coordinates are deleted after 90 days; kiosk statistics use only aggregated, anonymized data.
4. Data storage
Your data is stored on servers in the EU (Frankfurt am Main). We use Supabase as our backend provider, which also hosts in the EU. A data-processing agreement (Art. 28 GDPR) is in place with Supabase Inc. Server location: EU (Frankfurt am Main). Data does not leave the EU under regular operation.
4a. Third-country transfers and international recipients
wecorn uses certain services provided by companies outside the EU/EEA. For these transfers we rely on the EU Commission's Standard Contractual Clauses (SCC) per Art. 46(2)(c) GDPR.
- Apple Inc. (Cupertino, USA) — Apple Push Notification Service (APNs) for delivering push notifications. We transmit device tokens only, no message content.
- Expo / EAS (San Francisco, USA) — over-the-air mobile-app updates. We transmit app-version info and download logs.
- Mapbox, Inc. (Washington DC, USA) — walking-route directions and map tiles. We transmit start/destination/waypoint coordinates per request. No persistent profile is created.
- Netlify, Inc. (San Francisco, USA) — hosting of wecorn.de and admin.wecorn.de via EU edge nodes (Frankfurt). Status: SCC + Data Privacy Framework certified.
You can disable push notifications at any time in your iOS device settings.
4b. Data processors
We use the following processors (Art. 28 GDPR):
- Supabase Inc. (backend + database, EU hosting Frankfurt) — DPA in place, EU Standard Contractual Clauses (Art. 46 GDPR).
- Netlify, Inc. (hosting of marketing site + admin tool, EU CDN) — SCC.
A full list of processors is available on request at mail@wecorn.de.
5. Your rights
Under the GDPR you have the following rights:
- Right to access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
To exercise these rights, contact mail@wecorn.de. You also have the right to lodge a complaint with a supervisory authority — the competent authority is:
Landesbeauftragte für Datenschutz und Informationsfreiheit
Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Web: www.ldi.nrw.de
5a. Retention periods
We retain personal data only as long as necessary for the respective purpose or until statutory retention periods expire. In detail:
| Data category | Retention | Legal basis |
|---|---|---|
| Account and profile data (email, username, display name, DOB) | Until account deletion; then 30-day backup retention | Art. 6(1)(b) GDPR |
| Profile picture and kiosk photos | Until account deletion; photos of third-party kiosks remain (Art. 17(3)(e)) | Art. 6(1)(b) GDPR |
| Location data (GPS at check-in) | Raw coordinates 90 days; then anonymized to kiosk-ID + timestamp | Art. 6(1)(a) GDPR |
| Reviews, ratings, comments | Until account deletion or moderation decision | Art. 6(1)(b) GDPR |
| Friend connections | Until termination by user or account deletion of either side | Art. 6(1)(b) GDPR |
| Push tokens | Until logout, app uninstall, or account deletion | Art. 6(1)(a) GDPR |
| Reports / moderation (UGC) | 12 months audit trail; then reporter-ID pseudonymized | Art. 6(1)(c) + (f) GDPR |
| Deletion audit log (account deletion) | 24 months; then anonymized | Art. 6(1)(c) GDPR |
| Server access logs (Netlify) | 30 days | Art. 6(1)(f) GDPR |
6. Account deletion
You can delete your account at any time in the app's profile settings under “Konto endgültig löschen” (Permanently delete account). Deletion is immediate and irreversible: reviews, check-ins, badges, friend connections, profile picture, and all other personal data are removed.
Kiosk photos you have uploaded for third-party kiosks remain (legitimate interest of third parties per Art. 17(3)(e) GDPR).
7. Cookies
wecorn.de uses only strictly necessary cookies (session, security). No tracking cookies, analytics cookies, or advertising cookies are used.
8. Age restriction
wecorn is intended for users aged 17 and over. We ask for the date of birth at registration to verify this. Accounts of users under 17 will be deleted upon discovery.
9. Code of conduct and zero-tolerance clause
Insulting, sexual, discriminatory, or violence-glorifying content is not allowed on wecorn and leads to immediate removal and potentially account suspension. Content reported by three or more users independently is automatically hidden pending manual review. Review is completed within 24 hours.
Users can report content directly in the app (flag icon on reviews and profiles) and block other users. Blocks are bidirectional and effective immediately.
10. Processors and record of processing activities
A full list of our data processors and the record of processing activities per Art. 30 GDPR is available on request at mail@wecorn.de.
11. Contact
For privacy questions, contact mail@wecorn.de.