Privacy Policy for the App "Meteo!" (Version 1.5)

I. General

1. Legal Basis for Processing Data

Personal data is processed in accordance with the GDPR. It is only processed after the user has given consent for this by accepting this privacy policy. The only exception is the case where processing of data is legally allowed without the user given consent. This can for example be the case when the processing is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

2. Maximum Storage Time and Data Deletion

Any user related data is deleted shortly after the purpose for storage does not apply anymore. Data is also deleted in case a legal obligated storage period exceeds except when further storage is necessary by another legal obligation or for the performance of a contract in which the user is a participant.

3. Owner and Data Controller

Leif Both

Moritzstraße 37

44807 Bochum

Germany

Phone: +49 15206596155

E-Mail: leif.both@leifhacks-apps.com

II. Required Permissions

The app requires some permissions to work properly.

1. Internet Connection

A core functionality of the app is to request data via the internet. This requires the corresponding permission for internet connectivity.

2. In-App Purchases

The app offers the possibility to purchase a premium version of the app with additional functionalities. For this, it requires the corresponding permission for in-app purchases.

3. Push Notifications

The user is able to create a support ticket via the app. In order to be notified via push notifications in case of a response to the ticket, the user can grant the corresponding permission for push notifications. If the permission is not granted, no notification is sent to the user's device.

4. Request Location (Optional)

In order to determine the location automatically (see below) the user needs to grant the app the permission to request the device’s location. A request appears before the first usage of this feature.

III. On-Device Storage

1. Data Processing

1.1. Current Location

The current location is stored on the device to be able to send it to the app server for retrieving new alerts when necessary.

1.2. Location History

The last entered locations are stored on the device to enable quick switching for the user.

2. Legal Basis for Processing Data

The processing of the data described above is a legitimate interest of the data controller and this interest is not overridden by the rights, interests or freedoms of the user.

3. Purpose of Data Processing

Storing data on the device is required so it is available permanently (e.g. after restarting the device). This is mandatory for the app to work.

4. Storage Time

All processed data is stored as long as the app is installed or the user manually removes the data via the device's storage settings.

5. Possibilities for Objection and Data Removal

Any processed data stored on the device can be removed anytime via the device's storage settings or by uninstalling the app.

IV. Storage on the App Server

1. Data Processing

The processed data is sent to the “Meteo!” Server. The locations name, altitude as well as FCM token and language are stored for future requests or Push notifications.

2. Legal Basis for Processing Data

The processing of the data described above is a legitimate interest of the data controller and this interest is not overridden by the rights, interests or freedoms of the user.

3. Purpose of Data Processing

Forwarding above mentioned data to the “Meteo!” Server is necessary to provide the basic functionalities of the app like fetching weather alerts or sending push notifications.

4. Storage Time

The collected data is stored as long as the app is installed. No later than 30 days after uninstallation, all the above data will be deleted from the server.

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory to provide the basic functionalities of the app. There is no possibility for objection despite deinstallation of the app which results in the removal of any stored data related to the user.

V. Fetch Weather Alerts

The app provides weather alerts for a given location.

1. Data Processing

The requests are send to external services (see below). The providers of these services store basic information like IP address or device info for each request.

1.1. Determine Location

Location data can either be determined manually by the user or automatically via the device’s location functions.

The Google Geocoding API is used to determine location details (i.e. zip code, name/coordinates of the city or county, current altitude) for the given location input (see below). Fur further information about Google Geocoding & Privacy please refer to: https://developers.google.com/maps/terms

1.1.1. Automatic Determination of the Location

The automatic determination of the location uses the device’s location functionalities (i.e. GPS, WiFi, Bluetooth or the mobile network). The user has to grant permission for this first.

1.1.1. Manual Determination of the Location

Alternatively the user can determine the location manually by entering a city or county name. The device’s location functions are not used in this case. Thus, the user can fully determine the processed location data.

1.2. Fetch Weather Alerts

The processed data is sent to the “Meteo!” Server. The locations name, altitude as well as FCM token and language are stored for future requests or Push notifications.

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

Location determination and forwarding above mentioned data to the “Meteo!” Server is necessary to provide the basic functionalities of the app like fetching weather alerts or sending push notifications.

4. Storage Time

After at most 30 days after deinstallation all data is deleted from the server. Further information on the storage time can be found on respective privacy pages.

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory to provide the basic functionalities of the app. The user can decide how the location data is determined. However, there is no possibility for objection despite deinstallation of the app which results in the removal of any stored data related to the user.

VI. In-App Purchases

1. Data Processing

In the scope of in-app purchases the Google Play Store (for the Android app) or App Store (for the iOS app) are processing data. This covers especially data related to electronic payment. The data is processed locally by the app and stored on the device.

Further information on Google resp. Apple and privacy can be found here:

https://policies.google.com/privacy

https://www.apple.com/legal/privacy/

Purchase details are furthermore sent to the app server. This includes purchase id, product id, status and date of purchase but no data related to electronic payment

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

Processing of above mentioned data is responsible to verify in-app purchases as well as the determination which contents have been bought in order to provide them adequately to the customer.

4. Storage Time

Further information on the storage time can be found on the Privacy Page of Google resp. Apple:

https://policies.google.com/privacy

https://www.apple.com/legal/privacy/

The data stored on the app server is deleted in case they are not necessary for the initial purpose anymore.

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory. Thus, there is no possibility for objection.

VII. Push Notifications

Push notifications are used to inform the user about answers to support tickets. The app provides moreover weather alerts for a given location. These alerts can either be fetched or be received via Push notifications.

1. Data Processing

1.1. Firebase Cloud Messaging Token

After the app’s installation a random token is generated which is uniquely identifies the current installation of the app. This token is necessary to receive push notifications or to associate other data with the device.

1.2. Processing by Google Firebase

Push notifications are send by the app's Server to the Google Firebase servers in order to forward them to the associated device. Firebase is used as a transmitter only and cannot make any conclusions about the user. For further information about Google Firebase & Privacy please refer to:

https://policies.google.com/privacy

1.3. Processing on the app server

Token, device language and operating system (Android/iOS) as well as settings for push notifications (e.g. time of desired notifications) are sent to the server and stored so that notifications can be delivered as desired.

2. Legal Basis for Processing Data

Above mentioned personal data is only processed after the user has given consent.

3. Purpose of Data Processing

Processing of above mentioned data is required to deliver push messages correctly.

4. Storage Time

Further information on the storage time can be found on the Privacy Page of Google:

https://policies.google.com/privacy

5. Possibilities for Objection and Data Removal

The user can deny the permission to send notifications.

VIII. Support Tickets

1. Data Processing

Support tickets created by the user as well as the message history are stored on the app server. In addition, device related data is stored in case permission for this is granted by the user. This includes the used Firebase Cloud Messaging Token or purchase information. This data is not stored together with other user related data like mail address or user name.

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

The temporary storage of support tickets is required to allow replying to the requests. Device related data is required to identify potential errors and bugs. They are NOT used for marketing purposes.

4. Storage Time

The data is deleted in case they are not necessary for the initial purpose anymore.

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory. Thus, there is no possibility for objection.

IX. User Interactions

1. Data Processing

Some user interactions are processed on the app server. This contains information about consent to this privacy policy, onboarding activities or pricing page accesses. Besides the Firebase Cloud Messaging Token no personal data is processed and stored for this purpose.

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

The processing and storage of the data described above is necessary to securely prove the purchase of in-app products or the consent of the user.

4. Storage Time

The data is deleted in case they are not necessary for the initial purpose anymore.

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory. Thus, there is no possibility for objection.

X. Google AdMob

1. Data Processing

The free version of this app uses Google AdMob (https://admob.google.com/intl/de/home/) to display non-personalized advertisements.

Further information on Google and privacy can be found here:
https://policies.google.com/privacy

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

The Usage of Google AdMob to display ads is necessary to provide the app at no charge.

4. Storage Time

Further information on the storage time can be found on the Privacy Page of Google:

https://policies.google.com/privacy

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory. Thus, there is no possibility for objection.

XI. Logs

1. Data Processing

The app server stores anonymized data about access into log files. The following data is logged:

- Date and time of the access
- On requesting this privacy policy in the browser: used browser and OS, used device
- Used IP

This data is not stored together with other user related data. The user’s IP is anonymized for long term storage.

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

The temporary storage of the full IP address for the current session is mandatory in order to deliver the requested data to the user’s device.

The log files are stored in order to ensure the functionality of the server. They are used to identify potential errors and bugs, for optimization purposes and to ensure the security of the IT system. They are NOT used for marketing purposes.

4. Storage Time

The data is deleted in case they are not necessary for the initial purpose anymore. In case of session data this is the case after the session has ended. Log files are deleted after 14 days at the latest.

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory. Thus, there is no possibility for objection.

XII. Server Provider

1. Data Processing

The app server is hosted by Netcup GmbH. The server is located in Germany. Netcup may store data about server accesses.

More information about Netcup and privacy can be found here:

https://www.netcup.de/kontakt/datenschutzerklaerung.php

2. Legal Basis for Processing Data

Processing of data is a legitimate interest of the data controller and this interest is not overridden by rights, interests or freedom of the user.

3. Purpose of Data Processing

Information on the purpose of data processing can be found on Netcup's privacy page:

https://www.netcup.de/kontakt/datenschutzerklaerung.php

4. Storage Time

You can find information about the duration of storage on Netcup's privacy page:

https://www.netcup.de/kontakt/datenschutzerklaerung.php

5. Possibilities for Objection and Data Removal

The processing of above mentioned data is mandatory. Thus, there is no possibility for objection.