EuRoots App — Privacy Policy

Last Updated: June 2026

Thank you for your interest in our mobile application EuRoots (hereinafter referred to as the "App"). Protecting your personal data is a major priority for us. Below, we provide detailed information about the processing of your personal data and your rights when using our App.

The processing of personal data is carried out in strict accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Table of Contents

  1. Data Controller
  2. Details on Integrated Services and Functionalities
  3. Collection and Processing of Personal Data
  4. Data Retention and Erasure
  5. Sharing Data with Third Parties (Data Processors)
  6. International Data Transfers
  7. Your Rights as a Data Subject

1. Data Controller

The data controller responsible for data processing under the GDPR is:

Arbi Kodraj
Sternstraße 9
53111 Bonn
Germany

Email Address: info@euroots.de
Website: https://www.euroots.de


2. Details on Integrated Services and Functionalities

Camera Access (Barcode Scanner)

To fully support the features of the App, the App requests permissions when first launched or before using specific features.


3. Collection and Processing of Personal Data

a) Provision of the App Without Registration (Guest Mode)

If you use the App without creating a user account, we only process the technical data strictly necessary to operate and query product data: * The barcode scanned or entered by you. * IP address of the requesting device (only stored in encrypted form). This occurs exclusively to prevent and combat abuse and to secure our API infrastructure. * Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in system security, stability, and functionality of our server infrastructure).

b) Provision of the App With Registration and Authentication (User Account)

You have the option to register within the App to unlock additional features (such as higher scan limits, user profiles, or content synchronization).

To maximize your privacy: * We exclusively support native Apple Sign-In for registration and authentication. Other authentication methods (such as Google Sign-In or direct email/password registration) are not offered or supported. * Only email addresses are stored in our database. We do not capture or store passwords or other personal identity profiles. * Anonymization Recommendation: Apple offers the "Hide My Email" feature during the Apple Sign-In process. We recommend using this feature. In this case, Apple transmits a randomly generated, unique relay email address to us instead of your actual personal email address, preventing us from learning your identity.

When creating an account, the following data is stored in our database: * Email address (your personal email address or the anonymized relay email address provided by Apple) * Unique system-internal user identifier (UUID) * Subscription tier classification (e.g., free, lite, pro) * Usage statistics to enforce scan quotas (scans performed in the current period, total scans, period start date) * Registration and modification timestamps * Legal Basis: Art. 6 (1) (b) GDPR (performance of a contract to provide and manage your user account and associated App features) and Art. 6 (1) (f) GDPR (legitimate interest in enforcing terms of service and quotas to prevent server overload).


4. Data Retention and Erasure

We process and store personal data only for the period necessary to achieve the storage purpose or as required by statutory retention periods.


5. Sharing Data with Third Parties (Data Processors)

To operate and provide our App, we use specialized service providers. Data Processing Addendums (DPAs) pursuant to Art. 28 GDPR have been concluded with these service providers.

a) Hetzner (Backend Server Hosting)

b) Supabase (Database & Authentication)

c) Sentry (Error Analysis & Crash Reporting)


6. International Data Transfers

The primary backend server, database, and crash reporting infrastructure (Sentry) of the App are located within the European Union (EU). Some of the auxiliary service providers mentioned above are based in or process metadata in countries outside the European Union (EU) or European Economic Area (EEA)—specifically in the USA and Singapore (Supabase).

To ensure an adequate level of data protection, we have concluded Data Processing Addendums and, where required, current Standard Contractual Clauses (SCCs) of the European Commission with all external service providers.


7. Your Rights as a Data Subject

As a data subject under the General Data Protection Regulation (GDPR), you have the following rights, provided the legal prerequisites are met:

Asserting Your Rights: To exercise your rights, you can contact us informally at any time, e.g., by email. Please ensure clear identification of your identity is possible.

If you believe that the processing of your personal data violates data protection law, you also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State or federal state of your habitual residence, place of work, or place of the alleged infringement.