Legal Notice & Privacy
This page has not been filled in yet. Before launch, name, address, email, responsible must be set through the environment variables IMPRINT_NAME, IMPRINT_ADDRESS, IMPRINT_EMAIL and IMPRINT_RESPONSIBLE.
Provider identification under § 5 DDG
- Operator
- Address
- —
- Responsible for content under § 18 (2) MStV
Responsibility for content
Event data comes from the venues themselves. They enter their own programme and are responsible for it. We do not review entries in advance, but we do follow up on notices — see Report.
Privacy
In short: an e-mail address to sign in, what you saved, who you follow. No tracking, no advertising identifiers, no third parties in your browser.
What we store
- Your e-mail address — it is the only way to sign you in.
- Optionally a display name.
- Saved dates and the venues you follow.
- A hashed IP address and a coarse browser family, for 30 days, solely against abuse.
What we do not store
No real name, no address, no date of birth, no phone number, no payment details, no location, no full user agent, no referrer and no third-party identifier. There is no advertising profile because there is no purpose that would need one.
There are no passwords
Signing in works with a six-digit code by e-mail. We store no passwords, so no password list can be stolen. Codes are stored hashed, are valid for ten minutes, and only in the window that requested them.
Saved dates are the most sensitive thing here
A record of who goes where and when is a profile of interests. In a scene whose clubs are also queer spaces, political spaces and safer spaces, that can be particularly worth protecting. So saved dates are never shown per person — not even to the venue. A venue sees a number, never a list. There is no "your friends are going". Who you follow is visible to nobody but you.
There is one exception, and it is a narrow one: a moderator can see the saved dates and followed accounts of a single account while investigating a report. That is only possible by deliberately opening that one account — never from a list, never sorted by it, never exported — and every one of those views is logged, with its purpose. After twelve months the rows are reduced to a count anyway.
Statistics
We count page views with a self-hosted Umami instance — no cookies, no per-person identifier, IP addresses hashed and discarded. That is why there is no cookie banner here: there is nothing to consent to.
Images
Uploaded images are re-encoded on the server. The original metadata disappears with it — including the GPS coordinates a phone photo carries.
For how long
- sign-in codes: 24 hours
- hashed IP addresses: 30 days
- expired sessions: 30 days
- accounts with no activity and no e-mail address: 12 months
- saved dates older than 12 months are reduced to a count and the rows deleted
Your rights
Access (Art. 15) and erasure (Art. 17) are buttons, not a support ticket: in your account. Deleting removes the data from the database immediately. It disappears from the backups within seven days — that belongs to the truth, or the deletion promise would be false.