Privacy policy

This privacy policy explains how we process personal data when you use this web application (the “service”). The controller under the GDPR is the operator named in the legal notice (imprint) or comparable information. The implementation and subprocessors reflect the current software; the main processing activities are described below.

1. Data we process

Depending on how you use the service, we may process in particular: • Identification and account data when you register or sign in (e.g. email address, name, phone if provided) and technical identifiers for your user account with our authentication provider. • Profile and organisation data (e.g. role, link to a company) where the app provides it. • Content and usage data from the studio flow: projects, drafts, share links, room photos, fabric and material images, and related metadata. These are stored in the database and, when you upload files, in object storage. • Guest session data: the app may create anonymous or guest sessions through the same auth service so drafts and media can sync server-side. • Technical access data automatically generated when you request pages or APIs (e.g. IP address, timestamp, resource, user-agent, referrer), mainly via hosting and protective infrastructure. • Communication data when you contact us or we send email (e.g. address, subject, body, delivery events if the provider logs them). • Consent state for statistics/marketing stored in browser localStorage under the key `raumausstatter_analytics_consent_v1` (values “granted” or “denied”).

2. Purposes and legal bases

We process personal data for the following purposes and, where the GDPR applies, on these legal bases: • Performance of the service and, where applicable, contract (Art. 6(1)(b) GDPR): account handling, storing and displaying your projects and media, draft sync, share and collaboration features. • Legitimate interests (Art. 6(1)(f) GDPR): security and stability (e.g. abuse detection, server logs), troubleshooting, technical administration, and asserting legal claims where necessary, balancing your interests. • Consent (Art. 6(1)(a) GDPR): loading Google Tag Manager (container GTM-PFSBCMMX) and Vercel Web Analytics only if you accept in the cookie banner. Without consent those tools are not loaded. • Legal obligations (Art. 6(1)(c) GDPR) where we must retain or disclose data.

3. Cookies and browser storage

We use cookies from the Supabase authentication service for sign-in and session handling (names depend on your project reference, typically prefixed `sb-`). They support secure login, session refresh (e.g. PKCE), and — in production optionally — shared sessions across configured domains (`NEXT_PUBLIC_AUTH_COOKIE_DOMAIN`). These cookies are generally necessary for protected features. We store your statistics/marketing choice in localStorage (not a cookie), key `raumausstatter_analytics_consent_v1`. You can clear it in browser dev tools so the consent banner shows again, or use **Cookie / analytics settings** in the footer (clears the choice and reloads the page). A service worker (PWA / Serwist) may cache assets for offline use; it normally does not persist personal content beyond ordinary caching.

4. Hosting (Vercel)

The application runs on Vercel. Requests are processed through Vercel’s infrastructure; technical metadata may be processed in the United States or other locations where Vercel operates. Vercel’s privacy policy applies. Vercel Web Analytics is loaded only after consent and records usage events according to Vercel’s product configuration.

5. Database, storage, and auth (Supabase)

Database, file storage (Supabase Storage for flow uploads, catalogue media, etc.), and authentication are provided by Supabase Inc. Location and subprocessors follow the Supabase project configuration used by the operator. Processing relies on a data processing agreement with Supabase and, for transfers to third countries, appropriate safeguards (e.g. Standard Contractual Clauses) where required. Content access is enforced with row-level security and application logic; service-role credentials are used only on the server for administration, integrations, or batch jobs, never in the browser.

6. Artificial intelligence (Vercel AI Gateway)

Some features (e.g. room photo analysis, image suitability checks, fabric-in-room preview, optional text analysis) use Vercel AI Gateway with Google models (e.g. `google/gemini-3-pro-image`, `google/gemini-2.5-flash`, or an image model set via environment variable). Images and text you submit to these features are sent server-side to the gateway/model provider for processing. We do not permanently store AI traffic separately except where you already store the underlying content in the service (e.g. uploaded photos). Legal basis is primarily contract / pre-contract (Art. 6(1)(b) GDPR) and, where no direct contract applies, legitimate interest in providing AI-assisted preview (Art. 6(1)(f) GDPR).

7. Email and webhooks (Resend)

Transactional email from the app may be sent via Resend, which processes recipient, content, and delivery metadata as needed. Messages submitted through the public contact form (linked as “Contact” in the footer) are also sent server-side via Resend as email to the operator’s configured inboxes; your submitted address is set as Reply-To. Supabase Auth can optionally send auth emails through Resend SMTP; then both providers’ terms apply. Inbound Resend webhooks (e.g. delivery status) hit a secured endpoint verified with Svix signatures per Resend’s documentation.

8. Google Tag Manager

After consent we load Google Tag Manager (container ID GTM-PFSBCMMX; provider Google Ireland Ltd. / Google LLC). GTM may load further tags configured in that container that can also process personal data (e.g. analytics, remarketing). Without consent GTM is not loaded. See Google’s privacy policy for details. You can withdraw consent by clearing the localStorage entry and reloading, using **Cookie / analytics settings** in the footer, or when the consent banner is shown again.

9. Organisation API access

If your organisation uses API tokens for the public API (`/api/v1/...`), we process related technical and business data for authentication, logging, and abuse prevention. Legal basis is contract and/or legitimate interests of the operator and, where applicable, the organisation.

10. Retention

We keep personal data only as long as needed for the purposes above or as required by law. Projects and media remain until you delete them or the operator runs deletion. Account data remains until deletion of the account or as mandated by law. Server and security logs are deleted or anonymised after an appropriate period where possible.

11. Recipients, processors, and international transfers

We use processors including Supabase, Vercel, Resend, and Google (via GTM and AI models), and their own subprocessors. Processing may occur in third countries (e.g. the United States). Where required, we implement appropriate safeguards (e.g. Standard Contractual Clauses, adequacy decisions, or other measures under Art. 46 GDPR). Current provider documentation and DPAs are available from the operator on request or in each provider’s dashboard.

12. Your rights

Where the GDPR or similar law applies, you may have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), object to processing based on legitimate interests (Art. 21), withdraw consent with future effect (Art. 7(3)), and lodge a complaint with a supervisory authority (Art. 77). Contact the operator using the details in the legal notice to exercise these rights. You may also use the contact form linked as “Contact” in the app footer (paths `/de/contact` and `/en/contact` depending on language). **Erasure (Art. 17):** use the **Data deletion request** link in the footer (paths `/de/privacy/data-deletion-request` and `/en/privacy/data-deletion-request`). That sends an email to the operator only; we verify your identity before deleting any account. For registered users, a **superadmin** can run full erasure (storage and database tied to the account) in the administration area after verification. **Access (Art. 15) and portability (Art. 20):** you can view much of your data in the app (account and projects). For a structured export or additional information, contact the operator via the legal notice or the contact form — we can provide data on request where applicable.

13. Security

We apply technical and organisational measures (e.g. TLS in transit, server-side access controls, tenant separation in the database on a least-privilege basis). No system is perfectly secure; use strong passwords and protect your credentials.

14. Changes and contact

We may update this policy when processing or the law changes. The current version is always available in the app. For privacy questions or questions about how we process your personal data, you can reach the operator through the channels listed in the legal notice. The app also provides a contact page with a form (link “Contact” in the footer, e.g. /de/contact or /en/contact). The information you submit there — in particular name, email address, and message — is processed so we can handle and respond to your request (legal basis: Art. 6(1)(b) GDPR for contract-related or pre-contractual requests, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries). Delivery to the operator is sent by email through Resend (see the “Email and webhooks (Resend)” section above); your submitted address is used as Reply-To for replies. **Data deletion:** use the **Data deletion request** page linked in the footer if you want us to erase personal data (see section 12).

15. Children

The service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe we have processed a child’s data in error, contact the operator using the legal notice.

16. Automated decisions

We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.

For the legal rules that apply when you use the service, see:

Terms of service

To request erasure of personal data (GDPR Art. 17):

Data deletion request