Privacy Policy
Last updated: 31 August 2026
Preamble
This privacy policy explains which personal data we process, for what purposes and to what extent. It covers the crewcase.app website and the “Crewcase” iOS app.
Controller
Konrad von Bruchhausen Libellenweg 8 14532 Stahnsdorf, Germany
- hallo@crewcase.app
Overview of processing
Types of data processed
- Master data (e.g. display name in the app).
- Contact data (email address).
- Content data (trips, packing lists, messages, photos, documents in the app).
- Usage data (page views, time on page).
- Meta, communication and procedural data (IP addresses, timestamps, identifiers).
- Log data (server log files).
Categories of data subjects
- Users of the website and the app.
- Communication partners (for email enquiries).
Purposes of processing
- Provision of the online offering and the app.
- Performance of the user agreement (syncing app content between devices and within a crew).
- Communication and answering enquiries.
- Notification about the app launch (waiting list).
- Reach measurement.
- Security measures.
We run no online marketing, use no advertising networks and currently maintain no profiles on social networks.
Relevant legal bases
- Consent (Art. 6(1)(a) GDPR): the data subject has given consent for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR): processing is necessary for the performance of a contract or pre-contractual measures.
- Legal obligation (Art. 6(1)(c) GDPR): processing is necessary to comply with a legal obligation.
- Legitimate interests (Art. 6(1)(f) GDPR): processing is necessary to safeguard legitimate interests, provided the interests and fundamental rights of the data subject do not override them.
In addition to the GDPR, national data protection rules apply, in Germany in particular the Federal Data Protection Act (BDSG).
Security measures
We take appropriate technical and organisational measures, in line with the state of the art, to ensure a level of protection appropriate to the risk. These include safeguarding the confidentiality, integrity and availability of data through access control, as well as procedures for handling data subject rights, for deleting data and for responding to data protection incidents.
Transport encryption: all connections to the website and from the app are encrypted with TLS (recognisable by “https://” in the address bar).
Separation of user data: in the app, access rules at database level ensure that nobody can read other users’ content. What this does not cover is described under “No end-to-end encryption”.
International data transfers
Where we transfer data to a third country outside the EU or EEA, or use services that do so, this takes place in accordance with the legal requirements.
Two services are concerned:
- Cloudflare (delivery of the website): the parent company is based in the USA. Cloudflare, Inc. states that it is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses are additionally in place.
- Supabase (syncing app content): the data itself is held in Frankfurt am Main. The provider, however, is based in Singapore, and some sub-processors are US companies. There is no adequacy decision by the European Commission for Singapore, so the transfer is based on the Commission’s Standard Contractual Clauses.
Further information on third-country transfers and applicable adequacy decisions is provided by the European Commission at commission.europa.eu.
General information on storage and deletion
We delete personal data as soon as the underlying consent is withdrawn or no further legal basis for processing exists, in particular when the purpose ceases to apply. Exceptions apply where statutory retention obligations, or the establishment, exercise or defence of legal claims, require longer retention.
Where several periods are stated for the same data, the longest applies.
Rights of data subjects
- Right to object: you have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6(1)(e) or (f) GDPR.
- Right to withdraw consent: you may withdraw consent you have given at any time.
- Right of access: you may request confirmation as to whether and which data we process, and receive a copy of that data.
- Right to rectification: you may request the correction of inaccurate data or the completion of your data.
- Right to erasure and restriction of processing: you may request that your data be deleted, or alternatively that processing be restricted. In the app you can do this without asking: see “Storage and deletion in the app”.
- Right to data portability: you may receive the data concerning you in a structured, commonly used and machine-readable format. The app offers the export itself; the same section has the details.
- Right to lodge a complaint: you have the right to complain to a supervisory authority, in particular in the Member State of your residence or place of work.
Provision of the online offering and web hosting
To deliver the website, we process visitors’ IP addresses. This is technically necessary in order to transmit the content to the browser.
- Types of data processed: usage data, meta and communication data, log data.
- Purposes: provision of the online offering, IT infrastructure, security measures.
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
Server log files: access is logged. Logs may include the address requested, date and time, volume of data transferred, browser type and version, operating system, referrer URL and IP address. They serve the security and stability of the server. Log file information is stored for a maximum of 30 days and then deleted or anonymised; data whose retention is required as evidence is exempt until the incident in question has been resolved.
netcup: provision of storage space and computing capacity. Provider: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). Privacy policy · Data processing agreement.
Cloudflare: the website is delivered via Cloudflare’s content delivery network and security services. The provider for Europe is Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich; the parent company is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.
Cloudflare sits in front of our server. All requests to this website and to the waiting list endpoint therefore pass through Cloudflare’s servers first. In doing so, IP address, the address requested, time and scope of the request as well as browser and operating system details are processed, in order to speed up delivery and to fend off attacks. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). Basis for third-country transfers: Data Privacy Framework and Standard Contractual Clauses; a data processing agreement under Art. 28 GDPR is in place. Cloudflare’s privacy policy.
Storage on your device
This website sets no cookies and embeds no advertising or tracking services. There is therefore no consent banner.
One single piece of information is stored locally in your browser: if you switch the language manually, the website remembers that choice (in what is called local storage), so that the automatic language switch does not override your decision in future. This storage is strictly necessary for the function you explicitly requested (§ 25(2)(2) TDDDG); it contains nothing but the code “de” or “en” and is not transmitted to us. You can delete it at any time via your browser settings.
Blog
We publish articles on this website. There is no comment function; for readers, only the information under “Provision of the online offering and web hosting” applies.
Contact and enquiry management
If you contact us by email, we process your details to the extent necessary to answer your enquiry. We do not use a contact form.
- Types of data processed: contact data, content data, meta and communication data.
- Data subjects: communication partners.
- Purposes: communication, answering enquiries.
- Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
- Deletion: your enquiry remains stored until the purpose ceases to apply, you request deletion, or statutory retention periods expire.
Waiting list for the app launch
You can ask to be notified with your email address as soon as Crewcase is available in the App Store.
How it works: after submitting, you receive an email containing a confirmation link (double opt-in). Only once you click that link do we add you to the list. This ensures that nobody can sign up using somebody else’s address. The sign-up procedure is logged so that its proper course can be demonstrated.
Data stored: your email address, whether you are waiting for the iPhone or the Android version, the language of the page you signed up on, and the time and status of confirmation.
Recipients: for storage and delivery we use Brevo, a service of Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany (Berlin-Charlottenburg District Court, HRB 133191). Processing takes place on servers in Germany. A data processing agreement under Art. 28 GDPR is in place with Brevo. Details can be found in Brevo’s privacy policy. Your entry is additionally stored in our own content system, which runs on the server named under “Provision of the online offering and web hosting”.
- Legal basis: consent (Art. 6(1)(a) GDPR); legitimate interests for logging the sign-up procedure (Art. 6(1)(f) GDPR).
- Withdrawal: you can withdraw your consent at any time. Every email contains an unsubscribe link; alternatively an informal message to hallo@crewcase.app is enough. The lawfulness of processing carried out up to the withdrawal remains unaffected.
- Storage period: we store your address until you unsubscribe or the purpose no longer applies, at the latest twelve months after the launch of the app. We then delete the entry from the waiting list and from Brevo.
Reach measurement with Matomo
We use the web analytics software Matomo to understand how this website is used.
Matomo runs without cookies and on a server we operate ourselves; the data is not passed on to third parties. Returning visits are recognised via an anonymised short-term value that changes every 24 hours. Your IP address is shortened before analysis so that it can no longer be clearly assigned to you.
- Types of data processed: usage data, meta and communication data.
- Purposes: reach measurement.
- Security measures: shortening of the IP address.
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR). As no information is stored on or read from your device, consent under § 25 TDDDG is not required.
- Objection: you may object to this measurement at any time; an informal message to the address above is enough.
The Crewcase app (iOS)
This section concerns not the website but the “Crewcase” iOS app.
The app shows no advertising and uses no analytics or tracking tool. Your content lives on your device first; packing needs no connection. So that your trips are available on more than one device and can be shared with others, the app syncs them with a server we operate.
Account
The app creates an anonymous account on first launch. We ask you for nothing; it consists of a random identifier. Once you share a trip we additionally offer “Sign in with Apple”, so your trips survive a change of device. That sign-in is optional; without it every feature remains available to you.
What data the app processes
- Content you enter: trip names, dates, packing list entries, people and crew (name, avatar, emoji or photo), notes, messages and any photos or documents added. These are stored on your device and on our server. This also applies to entries you mark as private: private means other travellers cannot see them, not that they stay on the device.
- Crew sharing: when you share a trip with others, the relevant trip data is made accessible to the people you invite.
- Connection data: syncing produces technical data, in particular IP address, time and the function called.
- No location access: Crewcase requests no location permission. The “don’t forget” reminder works purely from the departure date you entered. When you add a photo from your library, the app reads the coordinates stored inside that photo to suggest which trip it belongs to; this happens on your device, and the coordinates are not transmitted to us.
- Weather (optional): for the weather display, coordinates of the destination are sent to Apple WeatherKit. Apple’s terms apply; we receive no personal data in the process.
- Purchases (Crewcase+): subscriptions and purchases are handled entirely through the Apple App Store. We receive no payment data, only the unlock status via Apple’s StoreKit.
Syncing via Supabase
We use the Supabase platform for syncing. The provider is Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513.
Data is stored in the eu-central-1 (Frankfurt am Main) region; the underlying infrastructure is provided by Amazon Web Services. Supabase in turn uses sub-processors, including Amazon Web Services and Cloudflare.
- Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR). Without this sync, packing together and use across several devices are not possible.
- Third-country transfer: see “International data transfers”. A data processing agreement under Art. 28 GDPR is in place with the provider. Details are set out in the Data Processing Addendum and the Transfer Impact Assessment.
No end-to-end encryption
Transmission is encrypted, and the access rules on the server keep different users’ data strictly separate. Your content is, however, not end-to-end encrypted there: we as the operator could technically view it. This architecture protects users from each other, not from us. Please therefore do not store content in Crewcase that is particularly sensitive to you.
Notifications
Crewcase can send notifications, for example packing reminders. You grant permission in the iOS settings and can withdraw it there at any time.
Storage period and deletion in the app
Your data remains stored until you delete it in the app or remove the app from your devices. You can delete trips, people and content at any time directly in the app; deleted content is removed from the server as well.
Deleting your account: in the “More” tab, under “About”, you can delete your account and all associated data yourself, without any detour. Beforehand the app shows you what will disappear and what will remain: trips in which you are the only account are deleted; in shared trips ownership passes to another crew member and your place remains as an ordinary participant without an account — with name and check marks, so that the others’ list does not fall apart. A message to the address above of course still works too.
Taking your data with you: in the same place (“Your data”), you can export all your content as a file — as JSON for machine processing and additionally as a PDF to read (Art. 20 GDPR).
Retention on the server: so that a device that has been offline for a while can catch up on what changed, the server keeps a change history. It is deleted after 90 days. Markers for deleted entries — they make sure a deleted item disappears on the other devices too — are deleted after 30 days.
Changes and updates
We adapt this privacy policy as soon as changes to our processing make this necessary. Should a change require action on your part, such as consent, we will inform you separately.
Addresses and contact details of companies may change over time; please check them before making contact.
Definitions
- Master data: information needed to identify and manage user accounts and profiles, such as names and identifiers.
- Content data: information created when producing and editing content, such as texts, images and files together with related details.
- Contact data: details that make communication possible, in particular email addresses.
- Meta, communication and procedural data: details about how data is processed and transmitted, such as IP addresses, timestamps and identifiers.
- Usage data: details of how an offering is used, such as page views, time on page and devices used.
- Personal data: any information relating to an identified or identifiable natural person.
- Log data: records of events in a system, such as timestamps, IP addresses and error messages.
- Reach measurement: evaluation of visitor flows to an online offering in order to see which content is used.
- Controller: the body that decides on the purposes and means of processing personal data.
- Processing: any handling of personal data, from collection and storage through to deletion.