Privacy notice
1. Controller
Thomas Blank Marschallstraße 5 79115 Freiburg im Breisgau Germany
Telephone: +49 1520 9625443
Email: contact@xcflightart.com kontakt@gleitschirmposter.de
2. What we process
Website: When you visit, we process connection, device and security data, including your IP address and access logs. We use this to provide a secure and reliable service (Article 6(1)(f) GDPR).
Browser: We store your language choice for one year and temporarily store data needed for authentication and the editor. We do not use analytics, advertising or marketing tracking. This storage is necessary for the functions you request.
Flight files and designs: Opening and editing an IGC or GPX file initially takes place only in your browser. We upload track and design data only when you save a design or start checkout. This data may contain precise location, time and altitude information. Processing is necessary for the requested function or contract (Article 6(1)(b) GDPR).
Account and authentication: We process email, account, profile and authentication data. If you choose Google sign-in, the data needed for authentication is exchanged between Google and our authentication provider (Article 6(1)(b) GDPR).
Orders and payments: We process order, contact and payment-status data. You enter payment details directly with Stripe. If you purchase without signing in first, we use the checkout email address to create an account for order access. The legal bases are Article 6(1)(b) GDPR for the contract, Article 6(1)(c) GDPR for legal records and Article 6(1)(f) GDPR for payment and abuse prevention.
Contact and withdrawal: We process the information in your message or withdrawal request to handle it and keep required evidence. The legal bases are Article 6(1)(b) and (c) GDPR, or Article 6(1)(f) GDPR for other enquiries. Our legitimate interests are responding to genuine enquiries and preventing abuse.
3. Providers we use
We use the following providers where needed for the relevant function:
- Cloudflare for website delivery and security;
- Supabase for authentication, database and file storage;
- Stripe for payments;
- Resend and mailbox.org for email;
- Google only if you choose Google sign-in.
4. Processing outside the EEA
Some providers may process data outside the European Economic Area. Where required, these transfers rely on an adequacy decision, including the EU-US Data Privacy Framework, or EU Standard Contractual Clauses. You may ask us for information about the safeguard used in a particular case or for a copy.
5. How long we keep data
We keep technical data only as long as needed for operation, security and troubleshooting. Temporary editor data is removed when you close the tab.
Account and profile data is kept until account deletion. Designs are kept until you delete them or your account. When you delete an individual design, its associated track is also deleted; contact us if you require complete removal.
We delete pending orders after seven days. We remove the track and design snapshot for a paid order 180 days after access is released. Contract, payment, tax and consent records are kept while statutory retention or limitation periods apply.
We delete ordinary enquiries 12 months after completion. Contract, tax, withdrawal or dispute records may be kept longer where legally required.
6. Your rights
Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent for the future. Contact us using the details above.
You may complain to a data protection supervisory authority. The authority responsible for our establishment is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg Heilbronner Straße 35 70191 Stuttgart Germany https://www.baden-wuerttemberg.datenschutz.de/beschwerde/
7. Required information and automated decisions
No account is needed for local editing. Without the information needed for authentication, saving, ordering or delivery, we cannot provide that function or perform the contract.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Stripe may independently perform automated fraud and risk checks.