Privacy Policy
The wording on this page is under legal review.
This policy explains how Eluvaris processes personal data under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for the processing of your personal data is:
Tim Gansczyk, Richard-Sorge-Straße 53, 10249 Berlin, Germany.
Email: tim.gansczyk@gmail.com.
2. Data we process
- Account identity: your email address and the sign-in provider you use (Google or a one-time email link).
- Profile: display name, gender, date of birth (from which age is derived), a short bio, social links, and photographs you upload.
- Membership records: your country, number, contribution status, Murph date, and the confirmations that make up your verification.
- Payment data: handled by our payment provider (Stripe). We receive confirmation of payment and the amount; we do not receive or store your full card details.
- Technical data: your IP address, used to rate-limit public pages and prevent abuse and enumeration of members.
3. Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR): operating your membership, your profile, payment, and verification.
- Legitimate interests (Art. 6(1)(f) GDPR): security, rate-limiting, and preventing abuse of the public surfaces.
- Legal obligation (Art. 6(1)(c) GDPR): retaining billing records for statutory tax and commercial periods.
- Consent (Art. 6(1)(a) GDPR) where we ask for it; you may withdraw consent at any time with effect for the future.
4. Cookies
We use only essential cookies: an authentication cookie that keeps you signed in, and a cookie set by our payment provider during checkout. We do not use advertising or cross-site tracking cookies, and we do not build advertising profiles.
5. Processors
We use the following processors, each under a data-processing agreement:
- Stripe: Payments and tax calculation.
- Supabase: Database, authentication, and file storage.
- Vercel: Application hosting.
- Google: Authentication when you choose Sign in with Google.
Where a processor transfers data outside the European Economic Area, the transfer is safeguarded by the European Commission’s Standard Contractual Clauses or an adequacy decision.
6. Retention
We keep your account data for as long as your account exists. When you close your account we delete your profile and photographs; your number is retired and not reused. Billing records are kept for the statutory retention periods under German tax and commercial law.
7. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time. To exercise any of these, contact us at the address above. You also have the right to lodge a complaint with a supervisory authority; for our location this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
8. Contact
For any privacy question or request, contact tim.gansczyk@gmail.com.