Privacy policy

Privacy policy pursuant to Art. 13 GDPR for the website and the Steigerpass app.

This is a translation for your convenience. The German version is legally binding.

1. Controller

The controller within the meaning of the GDPR is:

Tony Schirmacher-Richter
Augustusburger Str. 400, 09127 Chemnitz, Germany
Email: contact@schiri.consulting

2. This website

No trackers, no cookies, no third-party requests. This website loads all resources – including fonts – from our own server. When you visit it, the web server processes technically necessary connection data (IP address, time, requested page) to provide and secure the service (Art. 6(1)(f) GDPR). These logs are deleted after 14 days at the latest.

Links to external maps (OpenStreetMap) only open after you click them – the privacy policy of the respective provider then applies.

Interactive map (stations page): On the stations page you can optionally load an interactive map. The map software (Leaflet) is hosted on our own server. Only when you click “Load map” are map tiles loaded from OpenStreetMap (OpenStreetMap Foundation, United Kingdom); your IP address is transmitted to their servers in the process (Art. 6(1)(a) GDPR – consent by clicking). No such connection is made before the click.

3. The Steigerpass app

Account

When you register, we process your email address, display name and a password (stored as a salted hash). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

In addition, we store the time of your last activity on your account (updated at most once a day) and, for each calendar month, only whether your account was active in that month – without times of day or individual usage events. This lets us roughly evaluate how many accounts actually use the service, for example as the number of active accounts per month (legitimate interest in developing the service, Art. 6(1)(f) GDPR). For the period before 27 September 2026, we derived these monthly records once from data already stored (e.g. registration, check-ins). Both are deleted together with your account.

Email confirmation

To confirm your email address, we send a one-time, time-limited code to the address you provided. This serves the security of your account and fraud prevention (legitimate interest, Art. 6(1)(f) GDPR). The emails are sent via the service provider Brevo (Sendinblue SAS, France) as a processor within the EU.

Sign-in with Google (optional)

If you sign in with Google, we receive your Google account ID, your email address and your name from Google in order to create or link your Steigerpass account (performance of a contract, Art. 6(1)(b) GDPR). No other Google data is retrieved. Whether you use this sign-in method is up to you.

Location data – only at the moment of stamping

The app transmits your location to our server only during an active check-in (and when you submit a station using “My location”, see below): coordinates, GPS accuracy and the operating system’s mock-location flag. This data is stored per stamp in order to verify the stamp and detect misuse (e.g. faked positions) (performance of a contract and legitimate interest in fraud prevention, Art. 6(1)(b) and (f) GDPR). It remains stored until your account is deleted and is removed with it. There is no continuous tracking; no movement profiles are created and location data is not passed on to third parties.

Wish list

If you add stations to your wish list, we store this selection (station and time) with your account so that it is available on all your devices (performance of a contract, Art. 6(1)(b) GDPR). The wish list is only visible to you and is deleted with your account.

Tour suggestions, hiking year and “On this day”

The app calculates tour suggestions on your device. If the app happens to know your location anyway (e.g. on the home screen), it remembers an approximate location rounded to about 1 km on the device only in order to suggest nearby stations – it is not transmitted to us. The “Your hiking year” review and the “On this day” memories are calculated from the check-ins already stored; no additional data is collected for them.

Weekend tip (Android, can be switched off)

By default, the app checks in the background on Fridays whether a station suits the coming weekend and shows at most one notification per week on your device. On Android 13 and later this only happens once you allow the app to show notifications. You can switch the tip off at any time in your profile (legitimate interest in suggesting suitable hiking destinations, Art. 6(1)(f) GDPR; you can object at any time by switching it off). To do so, it fetches the weather forecast for all stations from our server and makes the choice itself – neither your location nor a selection of stations leaves your device. Our server obtains the forecast of the German Weather Service (DWD) via the free service Bright Sky and only queries it with the coordinates of the stations; Bright Sky receives no data about you. No push service is used.

Map in the app

The app’s map view loads map tiles from OpenStreetMap (OpenStreetMap Foundation, United Kingdom); your IP address and the map section viewed are transmitted to their servers in the process (legitimate interest in displaying the map, Art. 6(1)(f) GDPR). Photos of individual stations are partly loaded from Wikimedia. Neither provider receives any account or location data from the app.

Station and photo submissions

You can suggest new stations and submit photos (optional). Submitted content is stored, reviewed by us before any publication and only shown to other users after approval (performance of a contract, Art. 6(1)(b) GDPR). The app shrinks photos before uploading and removes metadata such as the location where they were taken. If you set the location of a new station using “My location” and do not move the map afterwards, the app additionally transmits the GPS accuracy, time and the operating system’s mock-location flag for this position; if the station is approved, we use this to credit you with the stamp – checked like a check-in (performance of a contract and legitimate interest in fraud prevention, Art. 6(1)(b) and (f) GDPR). This data is deleted together with your account. If you delete your account, approved submissions remain part of the station collection – but without any reference to you (anonymised).

Rights to submitted photos: Before submitting a photo, you confirm in the app that you took it yourself and that any recognisable people shown agree to its publication. You grant us a simple (non-exclusive), free-of-charge right, unlimited in time and territory, to show the photo in the app and on steigerpass.de as the station’s picture and to resize or crop it for that purpose. We credit the photo with your display name (performance of a contract, Art. 6(1)(b) GDPR). If you delete your account, the photo remains; the credit then only reads “Steigerpass-Community”. If you would like an approved photo removed, simply send an email to the address above.

Feedback

We store messages sent via the feedback form (including an optional contact email address) in order to handle your request (legitimate interest, Art. 6(1)(f) GDPR). You can also send feedback without an account and without contact details.

Error reports

If the app crashes or an unexpected error occurs, it sends an anonymous error report to our server: error type, error message and technical trace (stack trace), app version, platform, approximate operating system version and language. The report contains no reference to your account; email addresses, sign-in tokens and coordinates are masked before sending and again on the server. We use the reports exclusively to find and fix bugs (legitimate interest in a working app, Art. 6(1)(f) GDPR) and delete them automatically after 30 days. No third-party services are used.

Social features

Your display name, your check-ins and badges are visible to confirmed hiking friends in the feed; your display name may appear in leaderboards and as “summit sponsor” (Gipfelpate). You control who follows you through your friends list.

Health insurance export

An activity certificate is generated only at your explicit request and passed on by you yourself (Art. 6(1)(a) GDPR – consent by action). We do not transmit any data to health insurers automatically.

4. Retention & deletion

You can delete your account completely at any time in the app (Profile → Delete account permanently) or request deletion by email – even without the app installed. Step-by-step instructions are available at Delete account & data. Deletion irrevocably removes your account, check-ins (including the location data stored with them), badges, wish list, hiking-friend connections, greetings and your feedback (Art. 17 GDPR). Approved station submissions remain in anonymised form (see above).

5. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR), as well as the right to lodge a complaint with a supervisory authority – in Saxony: the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte).

6. Hosting

The website and the app server are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre within the EU. A data processing agreement (Art. 28 GDPR) is in place with Hetzner.