Legal
Privacy Policy
Information on how personal data is processed when you use the EMESEE platform.
Last updated: August 28, 2026
1. Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation ("GDPR") is:
EMESEE GmbH
Further contact details can be found in the legal notice (Imprint) on our website.
2. General Information
Protecting your personal data is important to us. We process your personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and any other applicable legal requirements.
This Privacy Policy explains what personal data we collect when you use our platform, the purposes for which we process your data, the legal basis for such processing, and the rights you have under applicable data protection law.
3. Hosting and Technical Infrastructure
Our platform is operated using the following service providers:
- Technical hosting and operations: Laforet-IT
- Cloud infrastructure: Oracle Cloud (Frankfurt am Main, Germany)
- Backend services, authentication, database and file storage: Supabase (EU Region)
- Content Delivery Network (CDN), DNS services, SSL/TLS encryption and security services: Cloudflare
When you access our website, certain technical information is automatically processed in order to ensure the secure and reliable operation of the platform. This may include:
- IP address
- Date and time of access
- Browser type and version
- Operating system
- Referring website (Referrer URL)
- Requested pages and resources
- Technical log and connection data
This processing is necessary to maintain the security, integrity, availability and proper functioning of our services.
Legal basis: Article 6(1)(f) GDPR (legitimate interests).
4. User Registration and Account
Certain features of our platform require the creation of a user account.
You may register using:
- an email address and password;
- your Google account; or
- your Apple account.
Depending on the chosen authentication method, we may process the following personal data:
- email address;
- internal user ID;
- display name;
- encrypted authentication credentials;
- profile picture or avatar (where provided by the authentication provider);
- account creation date;
- last login date and time;
- user roles and permissions.
When you register, we also record your acceptance of our Terms of Use, including the date and time of acceptance.
Legal basis: Article 6(1)(b) GDPR (performance of a contract).
5. Reviews and Community Features
Registered users may publish reviews and other user-generated content on our platform.
When you submit a review, we process the following information:
- user ID;
- display name;
- profile picture (if available);
- rating;
- review text;
- date and time of publication.
Reviews are publicly visible to other users of the platform.
Users may delete their own reviews at any time.
For legal, security or moderation purposes, administrators may remove reviews that violate applicable laws, our Terms of Use or our Community Guidelines.
Legal basis: Article 6(1)(b) GDPR.
6. Favorites
Registered users may save stores or locations as favorites.
For this purpose, we process:
- user ID;
- store ID;
- date and time when the favorite was added.
Favorites are visible only to the respective user and are not publicly accessible.
Legal basis: Article 6(1)(b) GDPR.
7. Store Submissions
Registered users may submit new stores or locations for inclusion on our platform.
Depending on the information provided, we may process:
- store name;
- store type;
- postal address;
- geographic coordinates;
- description;
- tags and keywords;
- telephone number;
- website;
- opening hours;
- uploaded photographs;
- moderation status.
The submitted information is processed for the purpose of reviewing the submission and, where appropriate, publishing the store on the platform.
Submission of a store does not guarantee publication. All submissions may be reviewed by our administrators before being made publicly available.
Legal basis: Article 6(1)(b) GDPR.
8. Photo Uploads
Registered users and verified store owners may upload photographs relating to stores listed on our platform.
When a photograph is uploaded, we may process the following information:
- the uploaded image;
- file name;
- upload date and time;
- the associated store;
- the uploading user.
Uploaded photographs may be reviewed before publication. Once approved, they become publicly available and may be viewed by all users of the platform.
Users should only upload photographs that they own or are otherwise authorized to publish and that do not infringe the rights of third parties.
Legal basis: Article 6(1)(b) GDPR.
9. Store Owner Applications
Users may apply to become the verified owner or representative of a listed store.
To process such applications, we may collect and process:
- user ID;
- store ID;
- application statement;
- supporting documentation provided by the applicant;
- file metadata (such as file name, file size and storage path);
- application status;
- internal review notes;
- identity of the reviewing administrator;
- date and time of the review.
Supporting documents are stored in a protected area with restricted access and are used exclusively for verifying the applicant's eligibility.
Such documents are retained only for as long as necessary to complete the verification process and are deleted after the application has been approved or rejected, unless legal retention obligations require otherwise.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
10. Location Data
With your consent, our platform may access your device's current location using your browser's location services.
Location data is used solely for purposes such as:
- displaying your current position on the map;
- identifying nearby stores and locations;
- improving map-based search functionality.
Your current location is processed only temporarily during your active session and is not permanently stored by us.
If you decline location access, the platform remains fully usable. In such cases, a default map view may be displayed instead.
Legal basis: Article 6(1)(a) GDPR (consent).
11. Map and Search Services
Our platform uses Mapbox to provide interactive maps, address searches and geolocation services.
When using these features, Mapbox may process certain technical information directly, including:
- IP address;
- technical connection data;
- browser and device information;
- map interactions;
- map viewport information;
- search queries;
- geographic coordinates;
- geocoding and reverse geocoding requests;
- Mapbox session tokens and place identifiers.
These processing activities are carried out by Mapbox as an independent service provider in accordance with its own Privacy Policy.
Further information is available in Mapbox's Privacy Policy.
Legal basis: Article 6(1)(f) GDPR and, where location data is involved, Article 6(1)(a) GDPR.
12. Google Maps Links
Our platform may provide external links to Google Maps for route planning and navigation.
Google Maps is not embedded into our platform.
Personal data is transferred to Google only after you actively click on the respective external link.
The processing of any personal data after leaving our platform is governed exclusively by Google's own Privacy Policy.
13. Cookies and Browser Storage
Our platform distinguishes between storage that is strictly necessary to operate the service and storage that is optional and only used with your consent.
13.1 Strictly necessary storage
The following is required for the platform to function and cannot be switched off:
| Name | Purpose | Retention |
|---|---|---|
sb-*-auth-token | Keeps you signed in to your account. Only set once you log in. | Until you sign out |
NEXT_LOCALE | Stores whether you are using the platform in English or German. | 1 year |
cc_cookie | Records the cookie decision you make, so you are not asked again. | 6 months |
These entries are set by us alone, are not shared with third parties, and are not used for advertising, profiling or cross-site tracking.
Legal basis: Section 25(2) no. 2 TDDDG (storage strictly necessary to provide a service you have expressly requested), in conjunction with Article 6(1)(b) and Article 6(1)(f) GDPR.
13.2 Optional storage: map usage measurement (Mapbox)
The interactive map is provided by Mapbox (see section 11). By default, the Mapbox library stores a randomly generated identifier in your browser's local storage (mapbox.eventData.uuid and associated metadata) and transmits map usage events to Mapbox servers in the United States, where they are used to produce aggregate usage statistics.
We do not enable this by default. When you first visit the platform, a cookie banner asks whether you wish to allow it. Unless you actively consent, we suppress this behaviour: no identifier is written to your device and no usage events are transmitted to Mapbox. The map remains fully functional either way, and declining has no effect on how it works.
Legal basis: Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR (consent). You may withdraw your consent at any time with effect for the future.
13.3 What consent does not cover
Displaying a map always requires map tiles to be retrieved from Mapbox. Your IP address is therefore transmitted to Mapbox whenever a map is displayed, irrespective of the choice described in section 13.2. This transfer is necessary to provide the map itself and is addressed in section 11; the consent above relates solely to the additional identifier and usage measurement.
13.4 Changing or withdrawing your choice
You can review and change your decision at any time via the Cookie settings link available on this page and on our legal notice and terms pages. Withdrawing consent takes effect immediately and is as straightforward as granting it. You can additionally delete cookies and local storage at any time through your browser settings.
14. Administration and Moderation
To ensure the secure and lawful operation of the platform, authorized administrators may process personal data as necessary for moderation and administrative purposes.
This may include the ability to:
- manage user accounts;
- activate, suspend or delete user accounts;
- review, edit, approve or remove store listings;
- remove reviews or other user-generated content;
- review store owner applications;
- process moderation records and administrative notes.
Access to administrative functions is restricted to authorized personnel who require such access in the performance of their duties.
Administrative access is granted solely for the purposes of maintaining platform security, enforcing our Terms of Use and Community Guidelines, preventing abuse, complying with legal obligations and protecting the legitimate interests of our users and our platform.
Legal basis: Article 6(1)(f) GDPR.
15. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable legal obligations.
Where statutory retention periods apply, the relevant data will be retained for the duration prescribed by law and deleted thereafter.
If you delete your user account, your personal data will generally be deleted or irreversibly anonymized, unless we are legally required or otherwise entitled to retain certain information.
Publicly available content that you have created, such as reviews or store submissions, may be retained in anonymized form so that it can no longer be attributed to you personally.
Supporting documents submitted as part of a Store Owner Application are retained only until the application has been approved or rejected and are subsequently deleted, unless legal obligations require a longer retention period.
Deleting your account
You can delete your account yourself at any time under Profile → Delete account. The deletion is carried out immediately; there is no waiting period and the account cannot be restored afterwards. When you delete your account:
- your login credentials, email address, authentication provider identities, display name, profile picture and account metadata are deleted;
- your favorites, your store owner applications and the supporting documents you uploaded with them are deleted;
- store submissions that are still awaiting review or that were rejected are deleted, including the photographs uploaded with them;
- stores that have already been published remain available on the platform, but the link to your account is removed;
- your published reviews are either deleted or retained in anonymized form, depending on the option you choose during deletion. An anonymized review keeps only the rating, the review text and the date of publication; the user ID, display name and profile picture are removed irreversibly, so the review can no longer be attributed to you;
- the sign-in records kept by our authentication service, including the email address and the IP addresses recorded there, are deleted, and all active sessions are terminated.
Once the deletion has been completed, we send a confirmation message to the email address of the deleted account. This is done so that a deletion carried out without your knowledge does not go unnoticed. The message is sent through our email service provider and the address is not retained afterwards.
To demonstrate compliance with our erasure obligations (Article 5(2) GDPR), we retain a record of the deletion itself. That record consists of the internal user ID, the date and time, whether the deletion was requested by you or performed by an administrator, and the number of affected records. It contains no name, no email address and no content.
Accounts with administrator permissions are deleted by another administrator on request.
Administrators may also delete an account, for example following a request addressed to us or as a moderation measure. The same erasure and anonymization steps apply.
16. Legal Bases for Processing
Depending on the nature and purpose of the processing activity, we process personal data on one or more of the following legal bases under the GDPR:
- Article 6(1)(a) GDPR – where you have given your consent to the processing of your personal data;
- Article 6(1)(b) GDPR – where processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract;
- Article 6(1)(c) GDPR – where processing is necessary to comply with a legal obligation to which we are subject;
- Article 6(1)(f) GDPR – where processing is necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your interests or fundamental rights and freedoms.
Where processing is based on your consent, you may withdraw your consent at any time with future effect. The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
17. Recipients of Personal Data
In order to provide and operate our platform, we may disclose personal data to carefully selected service providers acting on our behalf.
These recipients may include providers of:
- cloud hosting and infrastructure services;
- authentication and identity management services;
- database and file storage services;
- content delivery network (CDN) and security services;
- mapping and geolocation services;
- email delivery services, used to send the account deletion confirmation;
- technical maintenance and support services.
Where required by applicable law, we have entered into data processing agreements with our service providers in accordance with Article 28 GDPR.
Where personal data is transferred to recipients outside the European Economic Area (EEA), appropriate safeguards are implemented in accordance with Chapter V of the GDPR, including, where applicable, the European Commission's Standard Contractual Clauses or another legally recognized transfer mechanism.
18. Your Rights under the GDPR
Subject to the applicable legal requirements, you have the following rights regarding your personal data:
- the right to obtain confirmation as to whether we process your personal data and to access such data (Article 15 GDPR);
- the right to request the rectification of inaccurate or incomplete personal data (Article 16 GDPR);
- the right to request the erasure of your personal data under certain circumstances (Article 17 GDPR);
- the right to request the restriction of processing (Article 18 GDPR);
- the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to transmit that data to another controller (Article 20 GDPR);
- the right to object to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR);
- the right to withdraw your consent at any time where processing is based on your consent.
You can exercise two of these rights directly in the application:
- Access and data portability: under Profile → Your data you can download all data stored for your account at any time, as a structured, machine-readable JSON file;
- Erasure: under Profile → Delete account (see Section 15, "Deleting your account").
For all other requests, please contact us using the details in the legal notice (Imprint).
You also have the right to lodge a complaint with a competent supervisory authority if you believe that the processing of your personal data violates applicable data protection law.
19. Data Security
We implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access.
These measures are regularly reviewed and updated to reflect technological developments and current security standards.
Communication between your device and our platform is encrypted using Transport Layer Security (TLS/HTTPS).
Although we take reasonable steps to protect personal data, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure.
20. Changes to this Privacy Policy
We reserve the right to amend or update this Privacy Policy from time to time in order to reflect changes in legal requirements, technological developments, our services or our data processing practices.
The current version of this Privacy Policy will always be made available on our website together with the date of its latest revision.
Where required by applicable law, we will notify users of material changes in an appropriate manner before such changes become effective.
We encourage you to review this Privacy Policy periodically to remain informed about how we protect your personal data.
