Privacy Policy
Information on data protection in accordance with Art. 13 GDPR
1. Controller
Sebastian Hoffmann & Florian Westmeier GbR
Spessartstraße 1
64572 Büttelborn, Germany
Email: info@angelsshare.io
2. General information on data processing
We process personal data only to the extent necessary to provide our website and app, to fulfill contractual obligations, and to safeguard legitimate interests. The legal bases are in particular Art. 6(1)(a), (b), and (f) GDPR.
Data will only be shared with third parties where this is necessary for operating our services or performing contractual obligations.
3. Collection and storage of personal data
When using our website or app, we collect personal data that you actively provide (e.g., during registration or authentication) as well as technically necessary information automatically transmitted by your device (e.g., IP address, device information, access time).
When creating an account, we store the data you provide (email address, name if applicable, payment information) to set up and manage your user account.
4. Authentication and account management
Login is performed via email and one-time password (OTP). Personal data such as email address, name, and associated account IDs are stored to enable access, prevent misuse, and facilitate payment functions. Processing is carried out under Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in protecting account access).
5. Audience measurement with Umami
We use Umami to collect aggregated website statistics, such as page views, referring pages, browser and device types. The reviewed tracker uses no analytics cookies or local storage and creates no personal profiles. Its purpose is to improve the technical operation and content of this website. The legal basis is Article 6(1)(f) GDPR, based on our interest in understanding use of our website.
Hosting: IONOS SE; server location: DE. We operate a self-hosted Umami instance. The hosting provider processes data on our behalf under Article 28 GDPR.
6. Payment processing via Stripe
We use the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, for payments, subscriptions, and payouts.
Stripe processes personal data (name, email, payment information) to handle transactions. Processing is carried out under Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure payment processing). Further information: https://stripe.com/privacy
7. Hosting and infrastructure
Our website runs on a cloud server provided by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, located in a data centre in Berlin. A data processing agreement under Art. 28 GDPR is in place with IONOS. The backend runs on Amazon Web Services (AWS).
Data may be transferred to third countries (e.g., the USA). Transfers are based on Standard Contractual Clauses under Art. 46 GDPR to ensure an adequate level of data protection.
8. Social media presence
We maintain online presences on Instagram and Facebook to communicate with users and share information about our products. When visiting these pages, the privacy policies of the respective operators (Meta Platforms Ireland Ltd.) apply. We do not use any tracking pixels on our own website.
9. Your rights
Right to access stored data (Art. 15 GDPR)
Right to rectification of inaccurate data (Art. 16 GDPR)
Right to erasure ('right to be forgotten', Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object to certain processing activities (Art. 21 GDPR)
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
10. Retention period
Personal data will only be stored for as long as necessary to fulfill the respective purposes or as required by statutory retention obligations. After that, the data will be deleted or anonymized.
11. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy as necessary to reflect changes in legal requirements or new features of our services.
12. Cookies for age confirmation and language
ageVerified stores the value true for one year after successful age confirmation. Your year of birth is not stored in the cookie. The cookie prevents the age prompt from appearing on every page visit.
NEXT_LOCALE stores de or en for one year after you explicitly choose a language using the language switcher. This preference applies to the homepage. Other pages use the language specified by their URL. Simply visiting a page does not set this cookie.
Both cookies apply to this website, use SameSite=Lax and are not used for advertising. Storage and access serve the requested functions under Section 25(2)(2) TDDDG; associated processing relies on Art. 6(1)(f) GDPR. You can delete these cookies in your browser settings. The age prompt will then appear again and your saved language preference will be removed.
