Privacy Policy

Last updated: August 26, 2026

Findyo.de processes your data primarily in German data centers and strictly complies with European data protection regulations (GDPR / DSGVO). For certain features (e.g. payment processing via Stripe, email delivery via Resend, or phone verification via Google Firebase), data may be transferred to other EU countries or to third countries (in particular the USA). In these cases, we rely on Standard Contractual Clauses pursuant to Art. 46 GDPR (DSGVO) and ensure an adequate level of protection. Data is exchanged exclusively between the parties involved in a search or the processors we use.

1. Data Controller

Findyo

Mustafa Marawi

Donaustraße 40

12043 Berlin

Deutschland

E-Mail: support@findyo.de

2. Types of Data Processed

2.1 Automatically Collected Data

Each time you visit the website, the following technical data is automatically collected:

  • IP address (anonymized after 7 days)
  • Timestamp of access
  • Browser information (User-Agent)
  • Referrer URL
  • Device information (screen resolution, operating system)
  • Pages visited (without query parameters) for reach measurement
  • Anonymous visitor identifier (randomly generated, stored locally in the browser)

2.2 Registration Data

  • Name (first and last name)
  • Email address
  • Phone number (optional)
  • Profile picture (optional)
  • Location/city

2.3 Search Data

  • Search profiles (apartment criteria, reward)
  • Contact information for searches
  • Chat messages between users
  • Ratings and feedback
  • Moderation and security logs (e.g. reports, internal notes for abuse prevention)

2.4 Payment Data

  • Transaction history
  • Reward amounts
  • Payment method (processed via Stripe)
  • Billing information

Note: Full credit card data is not stored by Findyo, but exclusively by our payment service provider Stripe (PCI-DSS Level 1 certified).

2.5 Phone Verification & reCAPTCHA

  • Phone number (international format)
  • SMS verification status and timestamps
  • reCAPTCHA token, IP address, browser information

For SMS verification, we use Google Firebase Authentication including reCAPTCHA (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). For security reasons, a transfer to Google LLC, USA may occur.

3. Legal Bases for Data Processing

Art. 6(1)(b) GDPR (DSGVO) – Performance of a Contract

Applies to: provision of platform features, lead search, payment processing (including Stripe Payment Intents), and setup of Stripe Connect payout accounts. This data is required to fulfill the platform usage contract.

Art. 6(1)(a) GDPR (DSGVO) – Consent

Applies to: marketing emails, optional features, extended profile information. You may withdraw this consent at any time.

Art. 6(1)(f) GDPR (DSGVO) – Legitimate Interests

Applies to: platform security, fraud prevention, documentation in contract disputes, anti-spam/bot detection (reCAPTCHA), technical optimization, and analysis of platform usage.

Art. 6(1)(c) GDPR (DSGVO) – Legal Obligation

Applies to: tax retention of transaction data, anti-money laundering prevention, and KYC/AML requirements under the Stripe Connect program. Statutory retention periods under the German Commercial Code (HGB), Fiscal Code (AO), and Anti-Money Laundering Act (GwG).

4. Storage Location and Data Transfers

Server Location: Germany

All data is stored exclusively in German data centers:

  • Firebase/Google Cloud: Region Frankfurt am Main (europe-west3)
  • Firestore database: Region Frankfurt
  • Firebase Storage: Region Frankfurt
  • Vercel hosting: EU region (Frankfurt)

Transfers to Third Countries (Art. 46 GDPR / DSGVO)

For individual services, transfers to third countries (in particular the USA and UK) may be necessary. This primarily affects Stripe (payments & Stripe Connect), Resend (email), and Google (Firebase Auth / reCAPTCHA). Transfers are carried out on the basis of EU Standard Contractual Clauses and additional security measures (encryption, role-based access controls).

Where possible, we process data within the EU/EEA. If you do not wish such transfers, alternative communication methods (e.g. email without phone verification) are only available to a limited extent.

5. Retention Periods

User Account Data

  • Active accounts: Until account deletion
  • After deletion: 30 days retention for recovery
  • Inactive accounts: Deletion after 3 years of inactivity

Transaction and Financial Data

  • Payment data: 10 years (§ 147 AO – German tax law)
  • Invoices/receipts: 10 years (§ 257 HGB – German Commercial Code)
  • Stripe transactions: In accordance with Stripe retention policies

Communication and Interaction Data

  • Lead transfers: 3 years (warranty period)
  • Support requests: 3 years
  • Chat messages: 1 year after last activity
  • Ratings: Permanently (public nature)

Log and System Data

  • Server logs: 30 days (security/debugging)
  • Anonymous analytics: 24 months
  • IP addresses: 7 days in full, then anonymized

Our systems automatically delete data after the respective retention periods expire.

6. Disclosure of Data to Third Parties

6.1 Within the Platform

Lead data is exchanged exclusively between tenants and finders who are involved in a specific search.

6.2 Technical Service Providers

Firebase/Google Cloud Platform

Purpose: Database, authentication, file storage

Location: Frankfurt am Main, Germany

Legal basis: Art. 28 GDPR (DSGVO) (data processing agreement)

Stripe (Payment Processing)

Purpose: Payment processing, escrow service, Stripe Connect onboarding (KYC/AML for finder payouts)

Data: Payment data, transaction history, payout bank details, identity documents (KYC)

Transfer: Stripe Technology Europe (Ireland) & Stripe Inc. (USA, Standard Contractual Clauses)

Privacy: stripe.com/privacy

Vercel (Hosting)

Purpose: Website hosting, CDN, performance optimization

Location: EU region (Frankfurt)

Privacy: vercel.com/legal/privacy-policy

Resend (Email Delivery)

Purpose: Transactional emails, notifications

Data: Email address, name, email content

Transfer: USA (Standard Contractual Clauses)

Privacy: resend.com/legal/privacy-policy

Google Firebase Auth / reCAPTCHA

Purpose: SMS verification, bot/abuse protection (reCAPTCHA), management of login sessions

Data: Phone number, IP address, device data, reCAPTCHA token

Transfer: Google Ireland Ltd. (EU) with possible access by Google LLC, USA (SCC)

Privacy: policies.google.com/privacy

6.3 No Sale or Rental of Data

Findyo does not sell or rent your data to third parties. Data is disclosed only:

  • With your explicit consent
  • To fulfill contractual obligations
  • Where required by law (e.g. law enforcement authorities)

7. Cookies and Tracking Technologies

Findyo.de uses cookies and similar technologies to operate the platform and – as described below – to measure advertising campaigns.

Strictly Necessary Cookies

Legal basis: Art. 6(1)(f) GDPR (DSGVO) (legitimate interests)

  • Session management: User login and session handling
  • Security: CSRF protection, bot detection
  • Functionality: Language settings, UI preferences
  • Load balancing: Even distribution across servers

Usage Statistics (First Party)

Legal basis: Art. 6(1)(f) GDPR (DSGVO) (legitimate interest in reach measurement)

  • Internal page view statistics: Number of views, unique visitors per day, most visited pages
  • Anonymous visitor identifier in localStorage (no IP storage in this statistic)
  • Distinction between guest and logged-in visits, without personal identification in aggregates

You can remove the identifier by clearing website data in your browser.

Marketing and Conversion Tracking (Meta)

Legal basis: Art. 6(1)(f) GDPR (DSGVO) (legitimate interest in measuring and optimizing our advertising measures)

To measure the effectiveness of advertising, we use technologies from Meta Platforms Ireland Ltd. (Facebook/Instagram). In particular, the following data may be processed:

  • Meta Pixel (browser): Cookies such as _fbp and _fbc, page views and click events
  • Meta Conversions API (server-side): Registration, profile progress, and product-related actions (e.g. search profile created)
  • For attribution: pseudonymized or hashed data (e.g. email, name, phone number, city), IP address, User-Agent, and referrer/UTM parameters

Personal contact data is hashed server-side with SHA-256 before being transmitted to Meta. Plain-text passwords are never transmitted directly.

Information on privacy at Meta: Meta Privacy Policy. You can limit interest-based advertising at Meta at facebook.com/settings/?tab=ads You can also delete or block cookies in your browser.

8. Technical and Organizational Security Measures

Findyo implements comprehensive security measures to protect your data:

Encryption

  • HTTPS/TLS 1.3 for all data transfers
  • End-to-end encryption for sensitive data
  • Encrypted database fields for particularly sensitive information

Access Control

  • Role-based access rights (RBAC)
  • Multi-factor authentication for critical functions
  • Regular review of access permissions

Monitoring and Auditing

  • 24/7 security monitoring
  • Automatic detection of suspicious activity
  • Regular security audits
  • Penetration tests by external security experts

Employee Training

  • Regular data protection and IT security training
  • Confidentiality agreements for all employees
  • Documented procedures for security incidents

9. Your Rights as a Data Subject

Under the GDPR (DSGVO), you have the following rights:

Right of Access (Art. 15 GDPR / DSGVO)

You may request information about the personal data we store about you.

Right to Rectification (Art. 16 GDPR / DSGVO)

You may request correction of inaccurate data.

Right to Erasure (Art. 17 GDPR / DSGVO)

You may request deletion of your data, provided no statutory retention obligations apply.

Right to Restriction of Processing (Art. 18 GDPR / DSGVO)

You may request restriction of the processing of your data.

Right to Data Portability (Art. 20 GDPR / DSGVO)

You may receive your data in a structured, commonly used, and machine-readable format.

Right to Object (Art. 21 GDPR / DSGVO)

You may object to the processing of your data on grounds relating to your particular situation.

Withdrawal of Consent (Art. 7(3) GDPR / DSGVO)

You may withdraw consent at any time. The lawfulness of processing carried out before withdrawal remains unaffected.

Exercising Your Rights

To exercise your rights, please contact us by email at: support@findyo.de

10. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.

Competent supervisory authority:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Friedrichstr. 219

10969 Berlin

Deutschland

Telefon: +49 30 13889-0
E-Mail: mailbox@datenschutz-berlin.de
Website: www.datenschutz-berlin.de

11. Changes to This Privacy Policy

We reserve the right to amend this privacy policy to reflect changes in legal requirements or changes to our services. The current version is available on our website.

Last updated: 14/09/2026

Version: 1.0

Privacy policy – Findyo.de | GDPR-compliant data processing