Privacy Policy
1. Privacy at a glance
The following information provides a simple overview of what happens to your personal data when you visit this website or use the Bierblock application. Personal data is any data that can be used to personally identify you.
2. Controller
Christian Jäkl
Nesslbachweg 17
9551 Tschöran
Austria
Email: support@bierblock.app
3. Hosting
Our website and the Bierblock application are hosted on a server in Germany. The server is operated by us. We do not keep access logs in which visitor data such as IP address, browser, operating system or referrer is stored. We process technical operation and error logs exclusively for error analysis and the security of our service (Art. 6(1)(f) GDPR, legitimate interest in secure, error-free operation).
4. Authentication (Clerk)
For registration and login in the Bierblock application, we use Clerk (Clerk, Inc., USA). Clerk enables login via:
- Google account (OAuth)
- Apple account (OAuth)
- Email address
The following data is transmitted to or processed by Clerk:
- Email address
- First and last name
- Profile picture (if provided by the OAuth provider)
- Clerk user ID
Clerk stores this data on servers in the USA. The Clerk Privacy Policy applies. Data transfer to the USA is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR). Legal basis: Art. 6(1)(b) GDPR (contract performance).
To protect against automated registrations (bots, spam), Clerk uses Cloudflare Turnstile as part of its bot protection, a service provided by Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA). The challenge is only shown when a registration attempt is suspected to be a bot. Your IP address, browser characteristics and a challenge token are transmitted to Cloudflare and processed there exclusively for bot mitigation. The Cloudflare Privacy Policy applies. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in defending against abusive requests).
5. Data we store
In our database (PostgreSQL, server in Germany) we store the following personal data:
- User ID, first and last name, email address
- Profile picture URL
- Selected tariff (Demo or subscription), billing model (one-time purchase, monthly, yearly or Founder Edition) and subscription status
- Payment information: Mollie customer ID, subscription ID as well as amount, currency, status and timestamps of payments
- Registration date, plan expiration date, founder status
- Referral data: personal referral code, attribution of referrer and referred user as well as the time the code was redeemed (if you redeem a code)
- Event data: events, items, helper and station configurations, tables, orders, evaluations
- User settings (e.g. display preferences, language)
This data is stored for as long as your account exists. When you delete your account, the deletion is initially scheduled only; you can undo it within 7 days. After that period your personal data is anonymised and the record is deleted (see section 13). Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest).
6. Payment processing (Mollie)
For payment processing, we use Mollie (Mollie B.V., Netherlands). When making a purchase or a recurring payment, you are redirected to Mollie's checkout page. Mollie processes:
- Email address
- Payment information depending on the chosen payment method
- Mollie customer ID and — for recurring payments — Mollie subscription ID
The following payment methods are available: credit and debit card, Apple Pay, Google Pay, PayPal, eps, SEPA bank transfer, SEPA direct debit and Pay by Bank.
We do not store any credit card numbers or bank details. Mollie processes data on servers in the EU. The Mollie Privacy Policy applies. Legal basis: Art. 6(1)(b) GDPR (contract performance).
7. Real-time communication (WebSocket)
For the live update of orders, table status and evaluations during an event, we use WebSocket connections. Event data is transmitted in real time between server and browser or the helpers' devices. No additional personal data is collected beyond what is already listed in section 5.
8. Referral programme
If you recommend Bierblock or redeem a referral code, we store the referral data listed in section 5 (attribution of referrer and referred user as well as the time the code was redeemed). A permanent credit balance or a qualification status is not stored: whether and to what extent a discount applies is determined live at each payment based on the subscription status of the referred account (see Terms § 7). Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in managing the referral programme).
9. Local storage (localStorage)
We store technically necessary data in your browser's localStorage or sessionStorage:
- Theme preference (light/dark mode)
- Language and display settings
- Cache for application features (e.g. helper session, site-plan history, pending event actions)
- A referral code entered but not yet redeemed (until successful login)
- Your consent decision regarding reach measurement (see section 10)
For analysing the use of the Bierblock application, we store a random, pseudonymous identifier (localStorage) and a session identifier (sessionStorage). These are set independently of your website consent, as app analytics is based on contract performance and legitimate interest (see section 10). They contain no name and no directly personally identifiable data; once you sign in, the identifier can be associated with your account.
Technically necessary settings such as theme, language and the referral code you entered can be deleted at any time via your browser settings; the referral code is transmitted to our server after login.
10. Cookies & reach measurement
The Bierblock application uses cookies from Clerk for authentication (session management). These are technically necessary and cannot be disabled without limiting functionality. We use no advertising cookies and no third-party analytics services (e.g. Google Analytics).
Anonymous reach measurement (without consent): When you visit our website, we collect purely anonymous, non-personal counter data (page visited, page title, language). No cookies, no identifiers and no data are stored in your browser, and no personal data is collected — the GDPR does not apply to this processing (Recital 26).
Detailed usage analytics (with consent): To improve our service, we additionally operate our own privacy-friendly, first-party reach measurement ("first-party analytics"): we record page views and clicks on calls to action (e.g. "Get started") and link them to a visit session via a random, pseudonymous identifier. The data is processed on our own servers. To operate lifecycle marketing campaigns, we transmit account lifecycle events (e.g. "subscription started") including your email address and user ID to the backend of our sister product else.events, which is also operated by us; there are no other recipients. A random identifier alone does not establish anonymity: as long as the identifier exists, it is pseudonymous personal data.
The detailed processing takes place only with your consent (Art. 6(1)(a) GDPR; for storing the identifiers on your device, § 165 (3) TKG 2021 applies in Austria and § 25 TDDDG in Germany), which you give via the consent banner on your first visit. Without consent, only the anonymous counter (see above) is collected. You can withdraw your consent at any time with effect for the future via the "Cookie settings" link in the footer; stored analytics identifiers are deleted when you do, and the open page will no longer append analytics parameters to app links or send events. The lawfulness of processing carried out before the withdrawal remains unaffected.
Identifiers and data flow: With your consent, we store a random visit identifier (localStorage, until deletion or withdrawal) and a session identifier (sessionStorage, until the browser is closed) as well as information about the landing page and origin (landing path, referrer, UTM parameters). When you click an app link, these identifiers are passed as URL parameters to the Bierblock application — such parameters are only appended if you consented on the website. Once you sign in to the application, the pseudonymous visit identifier is associated with your account (account linking) so that journey analytics (e.g. from website visit to booking) are possible. Website reach measurement and the analysis of logged-in application usage are separate purposes: for the authenticated use of the app, the legal bases are Art. 6(1)(b) (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in product improvement); the website consent neither replaces nor blocks this app analytics.
Retention: Analytics events are automatically deleted on our servers at the latest 14 months after the event. Identifiers in your browser are removed upon withdrawal or deletion via your browser settings; the visit identifier remains in localStorage until you withdraw or delete it.
11. Your rights (Art. 15–21 GDPR)
You have the right at any time to:
- Access (Art. 15 GDPR) – What data we have stored about you
- Rectification (Art. 16 GDPR) – Correction of inaccurate data
- Erasure (Art. 17 GDPR) – Deletion of your data
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) – Export of your data in a common format
- Objection (Art. 21 GDPR) – Against processing based on legitimate interests
To exercise your rights, contact us at support@bierblock.app.
12. Right of withdrawal
Where the processing of your personal data is based on consent, you have the right to withdraw that consent at any time. The lawfulness of processing carried out before the withdrawal remains unaffected. You can declare your withdrawal by email to support@bierblock.app or via the "Cookie settings" link in the footer.
13. Data deletion
When you delete your account, the deletion is initially scheduled only: the account remains usable for 7 days, and you can undo the deletion within that period. At your explicit request ("delete now") the deletion happens immediately. After the period ends, name, email and profile picture are anonymised and a cleanup process then deletes your event, order and evaluation data. Any existing subscription is cancelled; if a subscription is active, the final deletion may be delayed until the end of the paid term or until the cancellation is completed. Certain records are retained even after that without a direct personal reference, to the extent required by law or based on legitimate interests: payment and accounting data are retained without a user association, and audit log entries are retained in anonymised form for up to 730 days. Data held by third-party providers (Clerk, Mollie, Cloudflare) is handled according to their respective privacy policies; upon request we forward deletion requests.
14. Data security
Communication between your browser and our servers is exclusively encrypted via HTTPS/TLS. Access to our servers is protected by firewalls and SSH keys.
15. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Austria is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna, Austria
www.dsb.gv.at
16. Contact form (website)
You can send us a message via the contact form on our website. We process the details you enter — name, email address and message — as well as the time of submission, in order to answer your request. The transmission is encrypted to our server and forwarded by email to our support inbox (support@bierblock.app). There is no disclosure to third parties.
To protect against automated spam requests, we use technical measures: a honeypot field that is invisible to humans, a server-signed token with a short minimum fill time, a client-side proof-of-work check and a limit on requests per IP address. Your IP address is processed briefly for this purpose. If Cloudflare Turnstile is additionally enabled, your IP address, browser characteristics and a challenge token are transmitted to Cloudflare, Inc. (USA) and processed there exclusively for bot defence; the Cloudflare privacy policy applies. Legal basis: Art. 6(1)(b) GDPR (answering your request) or Art. 6(1)(f) GDPR (legitimate interest in defending against abusive requests).
We store your request and the related correspondence until the matter is finally resolved, and delete it afterwards unless statutory retention obligations apply.
17. Changes
We reserve the right to update this privacy policy to reflect changes in the law or our service. The current version is always available on this page.