EuRoots App — Privacy Policy
Last Updated: June 2026
Thank you for your interest in our mobile application EuRoots (hereinafter referred to as the "App"). Protecting your personal data is a major priority for us. Below, we provide detailed information about the processing of your personal data and your rights when using our App.
The processing of personal data is carried out in strict accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Table of Contents
- Data Controller
- Details on Integrated Services and Functionalities
- Collection and Processing of Personal Data
- Data Retention and Erasure
- Sharing Data with Third Parties (Data Processors)
- International Data Transfers
- Your Rights as a Data Subject
1. Data Controller
The data controller responsible for data processing under the GDPR is:
Arbi Kodraj
Sternstraße 9
53111 Bonn
Germany
Email Address: info@euroots.de
Website: https://www.euroots.de
2. Details on Integrated Services and Functionalities
Camera Access (Barcode Scanner)
To fully support the features of the App, the App requests permissions when first launched or before using specific features.
- Purpose: The App requires access to your device's camera to scan product barcodes (EAN/GTIN) in order to provide the App's core services.
- How it works: Image processing and barcode detection take place entirely locally on your mobile device. Photos, live camera feeds, or video streams are never transmitted to our servers or to third parties.
- Transmission: Only the result of the scan—the numerical barcode string (e.g.,
4000582289652)—is sent to our servers as text to retrieve origin information from the database.
- Legal Basis: Art. 6 (1) (b) GDPR (performance of a contract to provide App functionalities), Art. 6 (1) (f) GDPR (legitimate interest in the technical functionality of the App).
3. Collection and Processing of Personal Data
a) Provision of the App Without Registration (Guest Mode)
If you use the App without creating a user account, we only process the technical data strictly necessary to operate and query product data:
* The barcode scanned or entered by you.
* IP address of the requesting device (only stored in encrypted form). This occurs exclusively to prevent and combat abuse and to secure our API infrastructure.
* Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in system security, stability, and functionality of our server infrastructure).
b) Provision of the App With Registration and Authentication (User Account)
You have the option to register within the App to unlock additional features (such as higher scan limits, user profiles, or content synchronization).
To maximize your privacy:
* We exclusively support native Apple Sign-In for registration and authentication. Other authentication methods (such as Google Sign-In or direct email/password registration) are not offered or supported.
* Only email addresses are stored in our database. We do not capture or store passwords or other personal identity profiles.
* Anonymization Recommendation: Apple offers the "Hide My Email" feature during the Apple Sign-In process. We recommend using this feature. In this case, Apple transmits a randomly generated, unique relay email address to us instead of your actual personal email address, preventing us from learning your identity.
When creating an account, the following data is stored in our database:
* Email address (your personal email address or the anonymized relay email address provided by Apple)
* Unique system-internal user identifier (UUID)
* Subscription tier classification (e.g., free, lite, pro)
* Usage statistics to enforce scan quotas (scans performed in the current period, total scans, period start date)
* Registration and modification timestamps
* Legal Basis: Art. 6 (1) (b) GDPR (performance of a contract to provide and manage your user account and associated App features) and Art. 6 (1) (f) GDPR (legitimate interest in enforcing terms of service and quotas to prevent server overload).
4. Data Retention and Erasure
We process and store personal data only for the period necessary to achieve the storage purpose or as required by statutory retention periods.
- Guest Data: Technical server logs (such as encrypted IP addresses) are deleted or permanently anonymized after 7 days at the latest.
- Registered Users: Data linked to your user account (email address, ID, quotas) remains stored as long as your user account is active.
- Account Deletion: You can have your user account and all associated personal data (email address and usage statistics) deleted at any time. Please contact us at the address above or use the deletion feature in the App settings. Upon deletion, your data will be erased immediately unless statutory retention obligations prevent deletion.
5. Sharing Data with Third Parties (Data Processors)
To operate and provide our App, we use specialized service providers. Data Processing Addendums (DPAs) pursuant to Art. 28 GDPR have been concluded with these service providers.
a) Hetzner (Backend Server Hosting)
- Recipient: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
- Purpose: Provision of physical/virtual server infrastructure for our backend API processing barcode queries.
- Server Location: The backend server is located in the European Union, specifically in Ireland.
- Self-Hosting: The backend is self-hosted by us via the Coolify deployment platform. We retain full administrative control over the virtual server instance. Hetzner acts purely as an infrastructure hosting provider with no access to data streams or application data.
- Legal Basis: Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR (legitimate interest in providing and ensuring technical functionality of the App).
b) Supabase (Database & Authentication)
- Recipient: Supabase, Inc., 970 Toa Payoh North, #07-04, Singapore (database infrastructure hosted in Amazon Web Services (AWS) data centers in the EU/Ireland).
- Purpose: Secure user authentication (exclusively native Apple Sign-In), session management, and storage of user profiles (email address only) and quotas.
- Transfer & Security: Supabase processes registration data and IDs. A Data Processing Addendum (DPA) has been concluded. Any transfer to third countries is safeguarded by the EU Standard Contractual Clauses (SCCs).
- Legal Basis: Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR (legitimate interest in providing a user profile and its technical functionality).
c) Sentry (Error Analysis & Crash Reporting)
- Recipient: Functional Software, Inc. d/b/a Sentry, 45 2nd Street, 3rd Floor, San Francisco, CA 94105, USA (Server Location: European Union).
- Purpose: Real-time logging and analysis of system errors, server crashes, and app crashes to ensure technical stability, functionality, and rapid software bug resolution.
- Processed Data: In the event of an unexpected error or crash, technical diagnostic data (e.g., crash timestamp, device type, operating system version, stack traces/error codes, and filtered system logs) is transmitted to Sentry. Sensitive information (such as authentication tokens) is automatically scrubbed prior to transmission.
- Server Location & Security: Sentry stores and processes crash reports on servers located within the European Union (EU). A Data Processing Addendum (DPA) pursuant to Art. 28 GDPR has been concluded.
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in maintaining system security, error resolution, and overall stability of the App and server backend).
6. International Data Transfers
The primary backend server, database, and crash reporting infrastructure (Sentry) of the App are located within the European Union (EU). Some of the auxiliary service providers mentioned above are based in or process metadata in countries outside the European Union (EU) or European Economic Area (EEA)—specifically in the USA and Singapore (Supabase).
To ensure an adequate level of data protection, we have concluded Data Processing Addendums and, where required, current Standard Contractual Clauses (SCCs) of the European Commission with all external service providers.
7. Your Rights as a Data Subject
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights, provided the legal prerequisites are met:
- Right of Access (Art. 15 GDPR): You can request information on whether and which personal data we process about you.
- Right to Rectification (Art. 16 GDPR): If your data stored with us is inaccurate or incomplete, you can demand its correction.
- Right to Erasure (Art. 17 GDPR): You have the right to request deletion of your data, provided no statutory retention obligations exist.
- Right to Restriction of Processing (Art. 18 GDPR): Under certain conditions, you can request restriction of processing of your data.
- Right to Data Portability (Art. 20 GDPR): If you provided data based on a contract or consent and processing is automated, you can request to receive your data in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent (Art. 7 (3) GDPR): You may withdraw consent (e.g. camera access) at any time with future effect. The lawfulness of processing up to withdrawal remains unaffected.
Asserting Your Rights: To exercise your rights, you can contact us informally at any time, e.g., by email. Please ensure clear identification of your identity is possible.
If you believe that the processing of your personal data violates data protection law, you also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State or federal state of your habitual residence, place of work, or place of the alleged infringement.