Privacy policy for the circles app

1. Controller

360degrees Software UG (haftungsbeschränkt)
Am Hauptbahnhof 6, 53111 Bonn, Germany
Managing director: Felix Bröhl
Commercial register: HRB 29347, Amtsgericht Bonn
Telephone: +49 228 76374989
E-mail: [email protected]

We have not appointed a data protection officer. We are a small company and none of the cases in Art. 37 GDPR that would require one applies to us. Please address all requests to the contact above.

2. What we process

You provide these to us

Category Details
Account Name, e-mail address, optional profile picture, language. If you sign in with Apple or Google, the data those services return to us.
Circles The circles you create or join, their members and your role in them.
Finances Shared expenses, who paid, how an amount is split, open and settled payments, PayPal.Me links and IBANs you store.
Receipts Images and PDFs you upload, and the data read from them.
Tasks and lists Tasks, their assignment and completion, shopping lists and their entries.
Invitations The name, e-mail address or phone number you enter to invite someone.
Settings Your notification settings per channel and category.

We collect these automatically

Category Details
Device Device type, operating system, and the push token that identifies your app installation.
Log data IP address, user agent and access token, server-side, for operating and securing the service.
Activity An activity feed of what happens in your circles, and when you last read it.
Delivery Whether a mail to you was delivered, bounced or reported as spam, and addresses that opted out.
Usage Counters for rate-limited features, for example receipt scanning and invitations.

3. Why, and on what legal basis

Purpose Legal basis
Creating and managing your account, authentication Art. 6(1)(b) GDPR, performance of the contract
Circles, expenses, tasks, lists, receipts — the app's functions Art. 6(1)(b) GDPR
Sending invitations you trigger, by e-mail or SMS Art. 6(1)(b) GDPR
Push and e-mail notifications about your circles Art. 6(1)(b) GDPR; you can switch every category off in the app
Product updates by e-mail or push Art. 6(1)(a) GDPR, consent, withdrawable in the app at any time
Operating, securing and stabilising the service, including error analysis Art. 6(1)(f) GDPR, our legitimate interest in a working service
Rate limits and abuse prevention Art. 6(1)(f) GDPR
In-app subscriptions Art. 6(1)(b) GDPR
Advertising in the free version through our own ad server Art. 6(1)(f) GDPR
Affiliate links Art. 6(1)(a) GDPR and § 25 TTDSG, consent

4. Who receives your data

We use the following processors. Unless stated otherwise, they act on our instructions under a data processing agreement pursuant to Art. 28 GDPR.

Recipient Purpose Location
Hetzner Online GmbH Server hosting and storage of uploaded files Germany
Cloudflare Protection in front of our servers EU/USA
Lettermint B.V. Sending our transactional e-mail: invitations, notifications, address verification Netherlands, EU
Twilio Sending invitation SMS USA
Google Firebase Cloud Messaging Delivering push notifications USA
Microsoft Azure Document Intelligence Reading the receipts you upload Sweden (Stockholm region)
RevenueCat, Inc. Managing in-app subscriptions USA
Sentry (Functional Software, Inc.) Error and crash analysis in the app; technical data only, IP addresses anonymised USA
Revive Adserver Advertising in the free version; self-hosted, no permanent cookies, no profiles Germany
AWIN and affiliate partners Commission accounting for affiliate links, only with your consent EU/USA

Other members of a circle see the data you contribute to it: your name and picture, the expenses, repayments, tasks, list entries and receipts you add. That is the purpose of a shared circle.

Processing inside the EU. Hetzner (Germany), Lettermint (Netherlands), Microsoft Azure Document Intelligence (Stockholm region) and our ad server (Germany) process data within the European Union, so no transfer to a third country takes place for these services.

Transfers to the USA. RevenueCat processes data in the USA on the basis of the European Commission's Standard Contractual Clauses. Sentry processes data in the USA under suitable safeguards pursuant to Art. 44 et seq. GDPR.

Google (Firebase Cloud Messaging), Cloudflare and Twilio also process data in the USA. Google LLC, Cloudflare, Inc. and Twilio Inc. are each certified under the EU-US Data Privacy Framework. Transfers to them therefore rest on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). Should the certification or the adequacy decision lapse, the data processing agreements of the three providers fall back on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), and for Twilio primarily on its approved Binding Corporate Rules (Art. 47 GDPR). You can look up the certifications at https://www.dataprivacyframework.gov.

5. How long we keep it

Data Retention
Account and circle data Until you delete your account
Uploaded receipts and profile pictures With the receipt or until you replace or delete them
Data in a circle with other members after you delete your account The entries stay so the others' balances remain correct, with your name removed and replaced by "Deleted user"
Server log data 90 days
Delivery, bounce and complaint records 12 months. An address that has opted out or has been reported as undeliverable stays on our suppression list beyond that, because that is the only way to keep honouring the opt-out.
Usage and rate-limit counters 13 months
Database backups 90 days
Tracking data for affiliate commission As long as needed for accounting, or as statutory retention requires

Our providers keep their own delivery logs, over which we have limited control:

Provider Data Retention
Lettermint Content, metadata and delivery and engagement events of sent e-mails 28 days, then automatic and permanent deletion
Twilio Records of sent SMS: phone number, message text, time, delivery status 12 months, then permanent deletion
Firebase Cloud Messaging Push messages not yet delivered At most 28 days, until delivered to your device
Firebase Cloud Messaging The installation ID used to address your device Until the ID is deleted through the Firebase API; afterwards removed from live and backup systems within 180 days

Where Twilio additionally processes connection data as a controller in its own right, for example for billing, abuse prevention or telecommunications-law obligations, Twilio keeps it under its own policies; see https://www.twilio.com/legal/privacy.

6. Where data about you comes from, if not from you

If someone invites you to a circle before you have an account, we receive the name, e-mail address or phone number that person entered. If you sign in with Apple or Google, we receive the profile data that service passes to us.

7. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of what happened before.

To exercise a right, contact us at the address in section 1. On an access request we provide a copy of your data as a machine-readable file, including the receipts and pictures you uploaded.

You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany — https://www.ldi.nrw.de

8. Automated decision-making

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.

9. Changes

We may update this policy. The current version always applies, and the date of the last change is shown at the top.