Esta página solo está disponible en inglés.
No tracking
No analytics tools, no ads.
No third parties
We only process data on your instructions.
Hosted in Germany
Servers and operations in Germany.
1. Controller
The controller for data processing on this website and in drinklist.app (web and app) is:
iqmeta GmbHAm Sonnenhang 24
71111 Waldenbuch
Germany
Email: support@drinklist.app
Represented by the managing director Otto Neff. Further details can be found in the imprint.
2. Summary
- We only process personal data as far as necessary for the website and drinklist.app.
- We use no analytics or tracking tools, no ad networks and no social media plugins.
- Fonts, images and scripts are loaded exclusively from our own server.
- We never sell data and only share it where required for the service (e.g. with a payment provider you choose).
3. Hosting and server log files
The website and drinklist.app run on servers of Hetzner Online GmbH in its Nuremberg data centre, Germany; emails are sent via our own mail server. When you visit, the server processes technically necessary data: IP address, date and time, requested address, referrer, browser and operating system, and the status code.
The purpose is secure and stable operation, defence against attacks and error analysis. The legal basis is Art. 6(1)(f) GDPR. Log files are deleted after 30 days at the latest unless they are needed longer to investigate a security incident.
Reach measurement: In addition, we record every page view of the website, the app and the management console in a separate overview: time, page requested, domain, referrer, language, IP address as well as browser and device type. This shows us how many people use our services, where they come from and which pages are in demand. Without your consent we neither store nor read anything on your device for this: to count visitors rather than page views, our server computes a checksum (hash) of the IP address, browser identifier, domain and a random daily key. The key is newly generated every day and discarded afterwards, so the checksum changes daily and cannot be traced back to you. Only if you consent in the notice do we additionally set the cookie dl_visitor (see below) so that returning visits count as one visitor. If you sign in to the app, we attribute that day's page views to your user account. We use no tracking pixel and no third-party services for this; the data never leaves our servers. The legal basis is our legitimate interest in needs-based design and secure operation (Art. 6(1)(f) GDPR). Individual page views are deleted after 12 months at the latest; you may object to this processing at any time (Art. 21 GDPR).
4. Cookies
We use strictly necessary cookies and – only with your consent – one cookie for visitor counting. No consent is required for the necessary ones (§ 25(2) no. 2 TDDDG); we still inform you transparently with a notice on your first visit.
- cookie_notice – remembers that you have read the cookie notice. Duration: 12 months.
- currency – remembers your currency choice (EUR or CHF) when you change it in the header. The value is kept only in your browser's local storage and is never sent to us; you can delete it at any time in your browser settings.
- drinklist.app session cookies – keep you signed in and protect forms against misuse. They are deleted when you sign out or the session expires.
- dl_visitor – only with your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR): a random identifier for our own visitor count, without a name and never shared. Duration: 12 months. If you decline in the notice, the cookie is deleted; you can change your choice there at any time.
We do not set tracking or marketing cookies or third-party cookies. You can delete cookies in your browser at any time; however, signing in to drinklist.app does not work without session cookies.
5. Contact by email
When you write to us, we process your information to handle your request. The legal basis is Art. 6(1)(b) GDPR (contract or pre-contractual request) or Art. 6(1)(f) GDPR (general enquiries). We delete the data once the request has been completed and no retention obligations apply.
6. Using drinklist.app
6.1 Registration and user account
For registration we process your email address, optionally your first and last name, and your password. Passwords and PINs are only stored encrypted. We log sign-ins, failed attempts and security-relevant actions to protect your account. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for the security log.
6.2 Sign-in with Google, Apple or Microsoft
If you sign in via one of these providers, we receive your verified email address and an identifier from them. The provider's privacy policy applies to processing on their side. The legal basis is Art. 6(1)(b) GDPR.
6.3 Club members' data (data processing on behalf)
Organisations such as clubs or companies manage their members' accounts, bookings, settlements and payments in drinklist.app. For this data the respective organisation is the controller under the GDPR; iqmeta GmbH processes it as a processor under Art. 28 GDPR based on the data processing agreement. Members should first contact their organisation with questions about their data.
6.4 Emails from drinklist.app
We send emails that are needed for using the service – such as confirmations, invitations, account statements, reminders, messages from the organisation and invoices. We do not send newsletters or advertising without your explicit consent.
7. Payments
Organisations pay subscription invoices online via Stripe (Stripe Payments Europe, Ltd., Ireland), PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg) or SumUp (SumUp Payments Limited, Ireland). Organisations can also use these providers for payments from their members. We transmit the data required for the payment (e.g. amount, currency, reference, email address) to the chosen provider. Payment details such as card numbers are entered only with the provider; we do not store them.
The legal basis is Art. 6(1)(b) GDPR. The providers also process data under their own responsibility and may transfer it to third countries; their privacy notices and appropriate safeguards such as EU standard contractual clauses apply.
8. Recipients
Personal data is only received by parties that need it to provide the service: our hosting provider Hetzner Online GmbH (data centre in Nuremberg, Germany) as processor, the payment or sign-in services you choose, and authorities where we are legally obliged.
9. Retention
We store personal data as long as your user account exists or as required for the contract. After an erasure request we anonymise your user account. Accounting-relevant data such as invoices and bookings are retained according to statutory periods (generally up to 10 years, § 147 AO, § 257 HGB).
Organisations that were only created to try out the service and have not been used for at least six months (no plan, no invoice, no payments; criteria in § 9 of the terms) are deleted after notice by email to the owner and administrators: the organisation is locked no earlier than 30 days after the notice and deleted permanently 30 days later. User logins without an organisation and without an account that have not been used for six months are deleted 30 days after a notice by email. Clicking “Keep” in the email or any use prevents the deletion. Legal basis: Art. 6(1)(b) and (f) GDPR, principles of data minimisation and storage limitation (Art. 5(1)(c) and (e) GDPR).
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You can withdraw consent at any time with effect for the future. Please write to support@drinklist.app.
You can remove your email address yourself at any time: for a single list in the app (“Leave this list”), for an invitation via the “Decline invitation” link in the invitation email, and everywhere on the page Remove email address (confirmation via a link sent to the address). The address is then deleted from lists, invitations and contacts, and a login with this address is deleted; accounts with names, bookings and balances remain in the lists without sign-in by email (retention obligations of the clubs). If an address was on our list for information letters, it remains stored there solely as a block notice so that we never write to it again.
You may also lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
11. Data security
All connections are encrypted via TLS. Credentials, secrets and payment provider access data are stored encrypted; access and changes are logged. Our data is automatically checked for consistency every day and backed up regularly.
12. Changes
We update this privacy policy when the law or our services change. The version published here applies.