Privacy policy for the circles app
1. Controller
360degrees Software UG (haftungsbeschränkt)
Am Hauptbahnhof 6, 53111 Bonn, Germany
Managing director: Felix Bröhl
Commercial register: HRB 29347, Amtsgericht Bonn
Telephone: +49 228 76374989
E-mail: [email protected]
We have not appointed a data protection officer. We are a small company and none of the cases in Art. 37 GDPR that would require one applies to us. Please address all requests to the contact above.
2. What we process
You provide these to us
| Category | Details |
|---|---|
| Account | Name, e-mail address, optional profile picture, language. If you sign in with Apple or Google, the data those services return to us. |
| Circles | The circles you create or join, their members and your role in them. |
| Finances | Shared expenses, who paid, how an amount is split, open and settled payments, PayPal.Me links and IBANs you store. |
| Receipts | Images and PDFs you upload, and the data read from them. |
| Tasks and lists | Tasks, their assignment and completion, shopping lists and their entries. |
| Invitations | The name, e-mail address or phone number you enter to invite someone. |
| Settings | Your notification settings per channel and category. |
We collect these automatically
| Category | Details |
|---|---|
| Device | Device type, operating system, and the push token that identifies your app installation. |
| Log data | IP address, user agent and access token, server-side, for operating and securing the service. |
| Activity | An activity feed of what happens in your circles, and when you last read it. |
| Delivery | Whether a mail to you was delivered, bounced or reported as spam, and addresses that opted out. |
| Usage | Counters for rate-limited features, for example receipt scanning and invitations. |
3. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, authentication | Art. 6(1)(b) GDPR, performance of the contract |
| Circles, expenses, tasks, lists, receipts — the app's functions | Art. 6(1)(b) GDPR |
| Sending invitations you trigger, by e-mail or SMS | Art. 6(1)(b) GDPR |
| Push and e-mail notifications about your circles | Art. 6(1)(b) GDPR; you can switch every category off in the app |
| Product updates by e-mail or push | Art. 6(1)(a) GDPR, consent, withdrawable in the app at any time |
| Operating, securing and stabilising the service, including error analysis | Art. 6(1)(f) GDPR, our legitimate interest in a working service |
| Rate limits and abuse prevention | Art. 6(1)(f) GDPR |
| In-app subscriptions | Art. 6(1)(b) GDPR |
| Advertising in the free version through our own ad server | Art. 6(1)(f) GDPR |
| Affiliate links | Art. 6(1)(a) GDPR and § 25 TTDSG, consent |
4. Who receives your data
We use the following processors. Unless stated otherwise, they act on our instructions under a data processing agreement pursuant to Art. 28 GDPR.
| Recipient | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting and storage of uploaded files | Germany |
| Cloudflare | Protection in front of our servers | EU/USA |
| Lettermint B.V. | Sending our transactional e-mail: invitations, notifications, address verification | Netherlands, EU |
| Twilio | Sending invitation SMS | USA |
| Google Firebase Cloud Messaging | Delivering push notifications | USA |
| Microsoft Azure Document Intelligence | Reading the receipts you upload | Sweden (Stockholm region) |
| RevenueCat, Inc. | Managing in-app subscriptions | USA |
| Sentry (Functional Software, Inc.) | Error and crash analysis in the app; technical data only, IP addresses anonymised | USA |
| Revive Adserver | Advertising in the free version; self-hosted, no permanent cookies, no profiles | Germany |
| AWIN and affiliate partners | Commission accounting for affiliate links, only with your consent | EU/USA |
Other members of a circle see the data you contribute to it: your name and picture, the expenses, repayments, tasks, list entries and receipts you add. That is the purpose of a shared circle.
Processing inside the EU. Hetzner (Germany), Lettermint (Netherlands), Microsoft Azure Document Intelligence (Stockholm region) and our ad server (Germany) process data within the European Union, so no transfer to a third country takes place for these services.
Transfers to the USA. RevenueCat processes data in the USA on the basis of the European Commission's Standard Contractual Clauses. Sentry processes data in the USA under suitable safeguards pursuant to Art. 44 et seq. GDPR.
Google (Firebase Cloud Messaging), Cloudflare and Twilio also process data in the USA. Google LLC, Cloudflare, Inc. and Twilio Inc. are each certified under the EU-US Data Privacy Framework. Transfers to them therefore rest on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). Should the certification or the adequacy decision lapse, the data processing agreements of the three providers fall back on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), and for Twilio primarily on its approved Binding Corporate Rules (Art. 47 GDPR). You can look up the certifications at https://www.dataprivacyframework.gov.
5. How long we keep it
| Data | Retention |
|---|---|
| Account and circle data | Until you delete your account |
| Uploaded receipts and profile pictures | With the receipt or until you replace or delete them |
| Data in a circle with other members after you delete your account | The entries stay so the others' balances remain correct, with your name removed and replaced by "Deleted user" |
| Server log data | 90 days |
| Delivery, bounce and complaint records | 12 months. An address that has opted out or has been reported as undeliverable stays on our suppression list beyond that, because that is the only way to keep honouring the opt-out. |
| Usage and rate-limit counters | 13 months |
| Database backups | 90 days |
| Tracking data for affiliate commission | As long as needed for accounting, or as statutory retention requires |
Our providers keep their own delivery logs, over which we have limited control:
| Provider | Data | Retention |
|---|---|---|
| Lettermint | Content, metadata and delivery and engagement events of sent e-mails | 28 days, then automatic and permanent deletion |
| Twilio | Records of sent SMS: phone number, message text, time, delivery status | 12 months, then permanent deletion |
| Firebase Cloud Messaging | Push messages not yet delivered | At most 28 days, until delivered to your device |
| Firebase Cloud Messaging | The installation ID used to address your device | Until the ID is deleted through the Firebase API; afterwards removed from live and backup systems within 180 days |
Where Twilio additionally processes connection data as a controller in its own right, for example for billing, abuse prevention or telecommunications-law obligations, Twilio keeps it under its own policies; see https://www.twilio.com/legal/privacy.
6. Where data about you comes from, if not from you
If someone invites you to a circle before you have an account, we receive the name, e-mail address or phone number that person entered. If you sign in with Apple or Google, we receive the profile data that service passes to us.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of what happened before.
To exercise a right, contact us at the address in section 1. On an access request we provide a copy of your data as a machine-readable file, including the receipts and pictures you uploaded.
You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany — https://www.ldi.nrw.de
8. Automated decision-making
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
9. Changes
We may update this policy. The current version always applies, and the date of the last change is shown at the top.