1. At a glance
We process data when you open the portal, use an account, submit an enquiry or review, or manage content and contracts as a provider. The data concerned depends on the functions you use.
We do not use advertising cookies and do not integrate Google Analytics, Google Ads or Matomo on the public pages. External services are used only where required for a function and are described below.
2. Controller
The controller responsible for processing personal data on the platform is:
- Address
- bitbox – Agentur für digitale Medien GmbH & Co. KG
Stresemannstraße 6
21335 Lüneburg - Represented by
- Komplementär-bitbox GmbH, diese vertreten durch den Geschäftsführer Frank Dalock
- Commercial register
- HRA 1866
Amtsgericht Lüneburg - Contact
- +49 4131 789900-9
- VAT ID
- DE205681801
3. Hosting and technical delivery
The platform is hosted in Germany by the service provider named below. In particular, server requests, IP addresses, technical metadata and the content, account and communication data stored in the platform are processed there.
The service is used to provide a secure, stable and efficient platform pursuant to Art. 6(1)(b) and (f) GDPR. A data processing agreement is in place with the provider.
- Address
- terralink networks GmbH
Wendenstraße 375
20537 Hamburg - Website
- terralink.de
4. Server logs
Each request involves technically necessary information. This may include the IP address, time, requested URL, amount of data transferred, referrer, browser, operating system and user agent. We use this information for delivery, troubleshooting, abuse prevention and system security.
Processing is based on Art. 6(1)(f) GDPR. Logs are deleted or anonymised when no longer needed for these purposes, unless a security incident or legal obligation requires longer retention.
6. Accounts, login and provider workspace
For registration and login, we process names, email address, account assignments, roles, permissions and security-related session data. Passwords are not stored in the portal; login is handled through the self-hosted Stayful account service.
The provider workspace additionally processes business, team, billing, contract and content data. Security-relevant actions may be recorded with time, account, IP address and user agent in an audit log. Processing is required for contract performance, access control and security under Art. 6(1)(b) and (f) GDPR.
7. Contact and booking enquiries
When you send an enquiry from a listing, we process your name, email address, optional telephone number and travel dates, message, listing assignment and IP address. The IP address is used to limit automated or abusive submissions.
The enquiry is made available to the provider identified in the listing and may be announced by email. Processing is based on Art. 6(1)(b) GDPR where the enquiry concerns steps prior to a contract, and otherwise on Art. 6(1)(f) GDPR. Data is retained for as long as necessary to handle the enquiry, prevent abuse or meet legal obligations.
8. Reviews and reactions
For reviews, we process the supplied name, email address, star rating, text, optional images and technical verification attributes. The email address is not displayed publicly. Votes on whether a review is helpful are protected against duplicate voting using the IP address.
Processing supports publication of authentic reviews, moderation and prevention of manipulation pursuant to Art. 6(1)(b) and (f) GDPR. Published content remains available until deleted or until the purpose of publication ends; verification and blocking data may be required for longer to prevent abuse.
9. Reach and performance statistics
For public listings, the platform counts page views per day and only in aggregated form. The user agent is checked immediately to identify automated requests but is not stored with the view counter. No visitor profile is created.
Providers receive aggregate view and enquiry counts. Processing is based on our legitimate interest in privacy-conscious functional statistics under Art. 6(1)(f) GDPR.
10. OpenStreetMap maps
When an interactive map is displayed, your browser loads map tiles from servers operated by the OpenStreetMap Foundation. In particular, your IP address, browser information, referrer and requested map area are transmitted. Servers may also be located in the United Kingdom or other countries.
Maps provide geographical context for regional offers and load only after your voluntary consent. The subsequent data transfer is based on Art. 6(1)(a) GDPR. You can withdraw consent for future transfers using “Cookie settings” in the footer. Geocoding of an address entered by a provider is performed server-side; the visitor’s location is not collected for this purpose.
11. Weather information
Where the portal enables its weather module, our server retrieves information from MET Norway for a fixed configured location. The device location of a visitor is not requested and the visitor’s IP address is not transmitted to the weather service.
The retrieval supplies regional information and is based on Art. 6(1)(f) GDPR.
12. Payments through Stripe
When a provider subscribes to a paid plan, payment is handled by Stripe. Contract, billing, contact and payment data is transmitted for this purpose. Full card details are processed directly by Stripe and are not stored on our servers.
Processing is based on Art. 6(1)(b) GDPR. Stripe may also process data under its own responsibility to meet legal obligations and prevent fraud. According to Stripe, appropriate safeguards are used for transfers outside the European Economic Area.
13. Email communication
System messages, confirmations, enquiries and replies may be sent through our hosting provider’s mail servers. Sender and recipient address, subject, content and technical delivery data are processed. Depending on the reason for the message, processing is generally based on Art. 6(1)(b) or (f) GDPR.
14. External links and videos
Providers may add links to external websites or YouTube videos. The portal does not load these videos automatically. The external provider’s privacy terms apply only after you open such a link.
15. Optional error diagnostics
If error diagnostics are enabled in the operating environment, our server sends error details and context data to Sentry (Functional Software, Inc.) when technical failures occur. This may include the URL, request method, request, portal and user identifiers, and performance data. Authorisation and cookie headers are removed before transmission.
Processing serves to identify and resolve faults and to secure the platform on the basis of Art. 6(1)(f) GDPR. Sentry may process data in the United States and identifies the EU-US Data Privacy Framework and Standard Contractual Clauses as safeguards.
16. Legal bases, recipients and retention
Depending on the operation, we process data for contract performance or pre-contractual communication (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), on the basis of consent (Art. 6(1)(a) GDPR), or for legitimate interests (Art. 6(1)(f) GDPR).
Recipients receive data only where required for their task. They may include the selected provider, hosting and mail providers, payment providers and legally authorised bodies. Processors are bound by contract.
Data is deleted when the purpose ends and no statutory retention, evidence or security requirement applies. Contract and billing records may in particular be subject to commercial and tax retention periods.
17. Your rights
Subject to the statutory conditions, you may request access, rectification, erasure, restriction of processing and data portability. You may withdraw consent at any time with effect for the future.
Where processing is based on Art. 6(1)(f) GDPR, you may object on grounds relating to your particular situation. Contacting the address above is sufficient to exercise your rights. We may request proof of identity before disclosing personal data.
18. Right to lodge a complaint
You may lodge a complaint with a data protection authority. The State Commissioner for Data Protection of Lower Saxony is in particular responsible for the controller’s registered office.
19. Security and changes
Transmission between your browser and the portal is protected by TLS. We use technical and organisational measures to protect data against loss, alteration and unauthorised access.
We update this notice when functions, service providers or legal requirements change. The version published on this page applies.