Volltreffer
Back to home
Privacy

Privacy Policy

Your data belongs to you. This privacy policy describes the planned, data-minimizing processing for website and app.

1. Controller

Tobias Oitzinger, Lorenz-Mandl-Gasse 21, 1160 Vienna, Austria.

Privacy inquiries: [email protected].

2. General Information

The protection of your personal data is of particular importance to us. We process your data exclusively on the basis of legal regulations (GDPR, TKG 2003).

We collect and process personal data only to the extent technically necessary to provide our service "Volltreffer" (website and mobile app).

  • No advertising trackers
  • No sale of personal data
  • Data-minimizing processing

4. Processed Data

4.1 Account and Profile Data

The following personal data is processed when using the service (this data is required for using the service):

  • Name (if provided)
  • Email address (including Apple Private Relay if applicable)
  • Username
  • Group memberships
  • Predictions, bonus answers and points
  • Last login

4.2 Authentication (Apple / Google Sign-In)

We use Google Sign-In and Sign in with Apple for authentication.

Authentication is performed server-side by verifying the ID token. No tracking by these providers takes place within our application.

The privacy policies of the respective providers also apply: Apple: https://www.apple.com/legal/privacy/, Google: https://policies.google.com/privacy.

The providers do not receive information about usage within the application.

The following data is processed:

  • Email address
  • Name (optional, depending on the provider)
  • Unique user ID provided by the provider

4.3 Technical Data and Server Log Files

Server log files are automatically deleted after a maximum of 30 days.

The following data is automatically collected during use:

  • IP address (full). Purpose: system security, error analysis, abuse prevention. Processing is based on our legitimate interest in ensuring technical operation and IT security.
  • Time of request. Purpose: system security, error analysis, abuse prevention
  • Requested resources. Purpose: system security, error analysis, abuse prevention
  • User agent (browser/device). Purpose: system security, error analysis, abuse prevention

4.4 Game-Related Data

The following data is stored as part of the prediction game:

  • Submitted predictions and bonus predictions
  • Timestamps of submissions
  • Rankings and points

4.5 Visibility Within the Game

Visibility of data from section 4.4 (game-related data):

  • Administrators of a game can view all relevant game data
  • Participants only see data relevant to the game
  • Email addresses are not visible to other participants

4.6 Email Communication

No marketing emails are sent.

Email delivery logs are deleted after a maximum of 30 days.

Emails are sent via Apple iCloud Mail.

Your email address is used for:

  • Authentication
  • Verification (e.g. login)
  • System-related notifications (e.g. reminders)

4.7 Push Notifications (Apple APNs)

Push notifications are used in the mobile app. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

A device-specific push token is processed.

Delivery is handled via Apple Push Notification Service (APNs).

The following information may be communicated via push notifications:

  • Game reminders
  • Game events
  • Live Activities

4.8 Cookies

Only technically necessary cookies are used (legal basis: Art. 6(1)(f) GDPR).

No tracking or advertising cookies are used:

  • vt_locale (language setting, 1 year)
  • vt_theme (display preference, 1 year)

5 Hosting and Infrastructure

5.1 Server Hosting

The application is hosted on a server in Germany:

  • Provider: Hostbrr (VPS)

5.2 Cloudflare

We use Cloudflare to secure and deliver the website and API.

Cloudflare may transfer data to third countries (in particular the USA).

Legal basis: legitimate interest (Art. 6(1)(f) GDPR) to ensure security, performance and protection against attacks.

The following data may be processed:

  • IP address
  • Connection data
  • Security-related information

5.3 Error Monitoring (Laravel Nightwatch)

We use Laravel Nightwatch for monitoring and error analysis (hosting within the European Union).

Technical data may be processed (no profiling takes place):

  • Error messages (purpose: stability and security of the service)
  • Request data (purpose: stability and security of the service)
  • IP address (purpose: stability and security of the service)

6. Recipients of Data

Your data is not shared for advertising purposes.

However, processing is carried out by the following categories of service providers (processors). Where required, data processing agreements in accordance with Art. 28 GDPR have been concluded:

  • Hosting providers (server operation)
  • Cloudflare (security and network services, in particular protection against attacks such as DDoS)
  • Apple (push notifications, email delivery, login)
  • Google (login)
  • Laravel Nightwatch (error analysis)

7. Third-Country Transfers

Some services process data outside the EU.

Transfers are carried out on the basis of standard contractual clauses (Art. 46 GDPR) and, where applicable, the EU-US Data Privacy Framework.

  • Cloudflare
  • Apple
  • Google

8. Data Retention

Data is permanently deleted after account deletion.

Exceptions apply to data temporarily stored in backups for technical reasons (max. 30 days).

  • Account data: until account deletion
  • Server logs: 30 days
  • Backups: up to 30 days
  • Email data: up to 30 days

9. Your Rights

You have the following rights under GDPR (you may withdraw consent at any time):

  • Access to your stored data
  • Rectification of inaccurate data
  • Erasure of your data
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Right not to be subject to automated decision-making (Art. 22 GDPR), where applicable
  • You also have the right to lodge a complaint with the supervisory authority: Austrian Data Protection Authority
    https://www.dsb.gv.at

10. Data Security

We implement technical and organizational measures to protect your data, in particular:

  • Encrypted data transmission (HTTPS)
  • Access restrictions
  • Minimized data storage

11. Changes to This Privacy Policy

This privacy policy may be updated if necessary.

Last updated: April 2026