Privacy

This policy explains which personal data is processed when you use JustSawIt, why it is needed and which rights you have.

Privacy is a matter of trust.
We process data only to the extent required for secure and reliable operation. We currently do not use personal data for personalised advertising and do not sell personal data.
01

Controller

The controller within the meaning of the General Data Protection Regulation is:

Schmitzundkunzt e.V.
(Postal address)
Wittekindstr. 35
50937 Cologne
Germany

For privacy-related enquiries, please preferably use our contact form.

Open contact form
02

Data processed at a glance

Depending on how you use JustSawIt, the following categories of data may be processed:

Account dataAlias, e-mail address, password hash, language, verification and account status.
Find dataTitle, description, category, images, timestamps and location.
Usage and security dataSession identifiers, IP-related security data, device and browser information and logs.
Communication dataSupport requests, ticket history, notifications and delivery logs.

Data is not collected merely for stockpiling. Each processing activity is connected with a platform function or security purpose.

03

Registration and user account

When you create an account, we process the information needed to provide and secure it, including your alias, e-mail address, cryptographic password hash, language settings, verification and account status.

Passwords are not stored in plain text. The alias is the identity normally displayed within the platform; the e-mail address is not publicly displayed through the account.

E-mail addresses are used in particular for account management, verification, security-related messages, password recovery and, where enabled, notifications about relevant finds.

04

Find reports, images and public content

When a find is reported, the submitted information is stored and displayed according to the platform’s visibility rules. This may include title, description, categories, images, submission time and location information.

Please do not upload images or descriptions containing unnecessary personal data, recognisable persons, private documents, licence plates or other sensitive information.

Uploaded images may be processed automatically for technical and security purposes, for example by resizing, optimisation or removal of technical metadata, insofar as this is necessary for secure and efficient platform operation.

Public preview links may allow people without an account to view limited information about a find. Protected details remain subject to the platform’s access rules.

05

Location data and map display

Location data is processed to place a reported find on the map and make it discoverable. This concerns the location of the find, not continuous tracking of the person using the platform.

Location information may be displayed with different precision depending on login status and function. Public previews are designed to withhold exact protected details.

Users who are not logged in or whose accounts have not yet been confirmed and activated are shown only an approximate find location for privacy and security reasons. Exact addresses and coordinates are available only to registered, confirmed and activated members.

When external map tiles or geocoding services are used, technical connection data such as the IP address may be transmitted to the relevant provider.

JustSawIt does not use location functions to create movement profiles.
06

Moderation, reports and trust system

Find reports and user activity may be reviewed to maintain quality and prevent misuse. Authorised moderators and administrators may review finds, process reports and document relevant actions.

Trust levels and trust-related events may support moderation. They do not constitute decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.

Moderation decisions and security-relevant moderation events may be logged in order to document decisions, detect misuse and protect the integrity of the platform.

07

E-mail notifications and daily digests

Registered users may configure notifications for categories or areas. We process the selected settings, matching finds, queue status and delivery logs.

Notifications may be bundled into a daily digest. A secure preview token may display the finds included in a digest for a limited period.

Notifications are sent automatically through an internal notification system and may be delivered with a technical delay. Before sending, the system checks whether the account is active and whether the relevant notification setting is still enabled.

Temporarily failed delivery attempts may be retried automatically. Delivery logs are used for error analysis, prevention of duplicate delivery and reliable operation.

Notification settings can be changed or disabled in the user area. Essential account and security messages may still be sent.

08

Contact form and support tickets

When you use the contact form, the selected topic, name or account alias, e-mail address, subject, message, ticket number, time, technical security data and subsequent communication are stored in the support system.

For authenticated users, alias and e-mail address are taken from the account. Authorised staff can assign tickets, add internal notes, change status and reply by e-mail.

Spam protection uses a calculation task, honeypot, minimum submission time and rate limiting. For rate limiting, an IP-derived hash is stored instead of the plain IP address.

09

Technical connection and security data

When the website is accessed, the web server and security systems may process technical data such as IP address, time, requested address, referring page, browser, operating system, device information, response status and transferred data volume.

Technical security measures such as session management, form protection through CSRF tokens, rate limiting, abuse detection and security-related system logs are also used to protect the platform.

This data is used to deliver the service, detect errors, protect sessions, investigate attacks and ensure stable operation. Administrative and moderation actions may also be recorded in audit logs.

Operational monitoring may process aggregated counts, queue and cron statuses, database and file-storage sizes, backup statuses and technical version information. Automated backups may contain account, find, moderation and other platform data for recovery purposes. Access to monitoring and backup functions is restricted to authorised administrators.

10

Cookies, sessions and progressive web app

JustSawIt uses technically necessary session mechanisms to maintain login status, protect forms and prevent unauthorised requests. CSRF tokens protect form submissions.

As a progressive web app, program files, icons and other resources may be stored in the browser cache or service-worker storage. You can remove them through browser or device settings.

No consent-requiring advertising or tracking cookies are currently intended. If introduced in the future, the required information and consent options will be provided first.

11

Recipients and service providers

Personal data is accessible only to authorised persons who need it for operation, support, moderation, security or administration.

Technical service providers may process data on our behalf, particularly for hosting, server operation, backup and e-mail delivery. Where required, processors are contractually bound under Article 28 GDPR.

Disclosure to authorities or other third parties takes place only where a legal basis exists.

Transfers outside the European Economic Area are not intended unless required by a specifically used service. Where relevant, the legally required safeguards will be applied.

12

Storage periods

Data is stored only as long as necessary for the stated purpose or statutory retention requirements.

  • Account data: generally until account deletion, subject to required residual storage.
  • Find data: until expiry, archiving or deletion, with limited records retained where necessary for moderation.
  • Notification queues and delivery logs: for operational monitoring and duplicate prevention.
  • Support tickets: during processing and for an appropriate documentation period thereafter.
  • Security and server logs: for the period required to detect errors and misuse.

Where longer storage is required by statutory obligations, legitimate interests or the documentation of security-relevant events, the data is restricted for other purposes or processed only to the extent necessary for that purpose.

13

Your data protection rights

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.

You also have the right to lodge a complaint with a supervisory authority. For the operator’s registered office, the competent authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf, Germany

14

Changes to this privacy policy

We may update this privacy policy when functions, legal requirements or technical processes change. The version published on this page is the current version.

We aim to make legal information understandable. Please contact us if anything remains unclear.
Version 1.1Last updated: 16 July 2026