Privacy for payments & credits
Supplement to the privacy policy
Payment processing (Stripe)
We use the service provider Stripe Payments Europe, Ltd. to process payments. The data required for payment (e.g. payment method, amount, card or account data where applicable) is transmitted directly to Stripe and processed there. We do not store full payment data ourselves. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).
Third-country transfer
Payment processing may involve a transfer of data to Stripe, LLC in the USA (known as Stripe, Inc. until January 2026). Stripe, LLC is self-certified under the EU-U.S. Data Privacy Framework (DPF); the transfer is based primarily on the European Commission's adequacy decision for the DPF. Where the DPF does not apply, the EU Standard Contractual Clauses (SCC) apply in addition. The order of precedence between both mechanisms is governed by Stripe's Data Transfers Addendum, which forms part of the data processing agreement concluded with us: https://stripe.com/legal/dpa
Credits & wallet
To manage your balance we process your credit wallet and the associated transaction ledger.
•
Data processed: balances of the credit buckets, transactions (grant/consumption), timestamps and reference object (e.g. trip plan).
•
Purpose/legal basis: performance of a contract and billing (Art. 6 (1) (b) GDPR); retention in accordance with commercial and tax obligations.
Fraud protection (device fingerprint)
To prevent abuse of the invitation/referral programme (e.g. self-invitations) we process a pseudonymous device characteristic.
•
Purpose: detecting and preventing multiple/self-referrals and other abuse.
•
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in fraud prevention).
•
Method: no raw identifier is stored, but a salted HMAC-SHA256 hash; this makes it harder for us to draw conclusions about the device.
•
Storage period: the hash is automatically deleted/nulled after a fixed period (TTL).
You may object to this processing on grounds relating to your particular situation pursuant to Art. 21 GDPR — informally at
[email protected].
Our balancing of interests: We store no raw identifier, only a salted hash; we use it solely to detect abuse in the invitation/referral programme, never combine it with advertising or profiling purposes, and delete it once the retention period expires. Your interest in informational self-determination is therefore only marginally affected, whereas without this check the bonus system could be systematically abused through self-invitations and duplicate invitations.