Privacy Policy (Draft, TODO: Legal counsel)
Effective date: March 19, 2026
This policy describes how NXT Event (“we”, “us”) processes personal data when you use the website, progressive web app, or native app builds.
Controller
The controller responsible for processing under this description is Hendrik Staack, operating as an individual entrepreneur (Einzelunternehmer). Business address: [TODO: Business Address]. Registration identifiers: [TODO: registration identifiers].
Scope
This policy applies to the NXT Event web experience (including the installable PWA) and to native applications distributed through the Apple App Store and Google Play when those builds connect to the same services described here.
Categories of personal data
Depending on how you use NXT Event, we process the following categories of data:
| Category | Examples |
|---|---|
| Account and profile | Email address, authentication identifiers, profile fields stored in Supabase. |
| Usage and technical data | IP address, device and browser characteristics, request metadata, and product analytics signals collected by our hosting and analytics providers. |
| Payment-related data | Payment transaction metadata processed by Stripe. We do not store full payment card numbers on our own servers. |
| Push notifications | Device tokens and delivery identifiers processed through Google Firebase Cloud Messaging for notifications you opt into. |
| Preferences | Language, theme, event filter preferences, and similar settings stored in cookies as described on the Cookie Policy page. |
Purposes and legal bases
We process data for the purposes below. The precise legal basis under GDPR must be confirmed with counsel [TODO: jurisdiction].
| Purpose | Legal basis |
|---|---|
| Provide the service, display events, operate accounts | [TODO: jurisdiction — e.g. contract / legitimate interests] |
| Authentication and security | [TODO: jurisdiction] |
| Payments for paid features or tickets | [TODO: jurisdiction — typically contract] |
| Traffic measurement and product improvement | [TODO: jurisdiction — consent and/or legitimate interests] |
| Push notifications you enable | [TODO: jurisdiction — typically consent] |
Recipients and processors
We use specialized providers to host the service, authenticate users, process payments, deliver analytics, send push notifications, and distribute mobile apps. Their privacy policies apply in addition to this overview:
| Processor | Privacy policy |
|---|---|
| Supabase (database and authentication) | Vendor privacy policy (Opens in new tab) |
| Stripe (payments) | Vendor privacy policy (Opens in new tab) |
| Vercel (hosting and Web Analytics / Speed Insights) | Vendor privacy policy (Opens in new tab) |
| Google Firebase (Cloud Messaging for push) | Vendor privacy policy (Opens in new tab) |
| Apple (App Store distribution and platform services) | Vendor privacy policy (Opens in new tab) |
| Google (Play Store distribution and platform services) | Vendor privacy policy (Opens in new tab) |
International transfers
Providers may process data in multiple regions. Document the primary regions for Supabase, Vercel, Stripe, and Firebase once environments are fixed [TODO: Infrastructure region].
Retention
Retention periods depend on the type of data and legal requirements. Concrete durations for accounts, logs, analytics, marketing attribution, and push tokens must be set with product and legal [TODO: retention].
Your rights
Where applicable law grants you rights over your personal data, you may contact us to exercise them, including:
- Access to the personal data we hold about you
- Rectification of inaccurate data
- Erasure (“right to be forgotten”) where conditions are met
- Restriction of processing
- Objection to certain processing
- Data portability where applicable
- Complaint to a supervisory authority
To exercise your rights, contact us:
Use the Contact link in the site footer. It opens our contact form in a new tab.
Security
We use HTTPS for data in transit, access controls for production systems, and established providers that implement industry-standard safeguards. Payment card data is handled by Stripe; we do not store full card numbers on our infrastructure.
Children
The service is not directed at children below the age we will define with legal counsel [TODO: minors].
Account deletion
Self-service account deletion in the app is planned (coming soon) [TODO: account deletion]. Until it ships, request deletion using the contact channel above.
Cookies and similar technologies
See our Cookie Policy for categories, purposes, and how to adjust preferences where available.
Legal notice
Statutory provider details and contact information for the service are published in our Legal notice.
Terms of service
Rules for using the service, including acceptable use and liability, are set out in our Terms of service.
Changes
We update this policy when our processing changes. The effective date at the top reflects the latest version. Material changes are communicated through the product where appropriate.