Skip to content
Zollwerk

Privacy

What this site does with data

This is a static site. It sets no cookies, embeds no tracking pixels, loads no fonts or scripts from anyone else’s server, and builds no profile of you. Reading it leaves nothing behind but the unavoidable server log.

Personal data arises only here: the server log when you visit (section 3), buying through Stripe (section 5), delivery via GitHub (section 6), emailing us (section 7), and the launch-notification signup (section 8).

The German Datenschutzerklärung is the binding text. This page is a summary written for readers who do not read German. It is kept faithful to the German document, but where the two differ, the German version governs — including every legal basis, retention period and recipient named there.

The section numbers below match the numbered clauses on the German page, so you can find any statement in the binding text.


Revision 2026-09-01

Status 1.0

1

Who is responsible

The controller under Art. 4(7) GDPR is the sole trader named in the Impressum.

Data protection contact: info@zollwerk.app

No data protection officer is appointed: neither Art. 37 GDPR nor § 38 BDSG requires one for a business of this size and activity.

2

What this site does not do

  • No cookies at all — not even “necessary” ones. That is why there is no cookie banner: there is nothing to consent to, and § 25 TDDG is not engaged because nothing is stored on or read from your device.
  • No tracking pixels, no ad networks, no profiling.
  • No third-party fonts. Typefaces are bundled at build time and served from our own server; no request goes to Google Fonts and no IP address reaches a font service.
  • No embedded third-party content — no maps, videos, social plugins or chat widgets.
  • No account, no login. Delivery runs through GitHub; there is nothing here to register for.

Everything is served over TLS. There is no plain-HTTP delivery.

3

Hosting and server logs

The site runs on a virtual server we operate ourselves at netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The servers are in the European Union; hosting involves no transfer to a third country.

The web server logs what your browser sends: IP address, timestamp, requested URL and method, status code, bytes transferred, referrer and user-agent. Purpose: delivering the page, security, abuse defence and debugging. Legal basis: Art. 6(1)(f) GDPR. Logs are not analysed for audience measurement and are not combined with other sources.

Retention: 14 days, then automatic deletion — except entries needed to investigate a specific security incident, which are deleted once it is resolved.

4

Analytics

There is no analytics of any kind on this site. No analytics software is loaded. Should that change, this notice is updated first.

5

Payment through Stripe

Purchases are handled by a Stripe payment link. The checkout itself runs on a page operated by Stripe (buy.stripe.com / checkout.stripe.com); afterwards you are redirected back to this site. The payment provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, which processes checkout data as a controller in its own right.

You enter payment details directly with Stripe, never on this site. Full card numbers never reach our systems. We receive what the contract and the invoice require: name, email address, billing address and country, the amount, a transaction reference and the payment status.

Legal basis: Art. 6(1)(b) GDPR for performing the contract, and Art. 6(1)(c) GDPR together with German commercial and tax retention duties (§ 147 AO, § 257 HGB) for invoices and accounting records. Stripe processes data for fraud prevention on the basis of Art. 6(1)(f) GDPR.

Third-country transfer: Stripe may transfer data to Stripe, Inc. in the United States, on the basis of the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) and, where applicable, the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). See Stripe’s privacy policy.

6

Delivery via GitHub

Delivery means inviting your GitHub account to a private repository as a collaborator. For that we need one thing from you: your GitHub username. We process it with your order and pass it to GitHub to issue the invitation. Legal basis: Art. 6(1)(b) GDPR — without it the contract cannot be performed.

GitHub runs your account on its own responsibility and is a separate controller for it, not our processor — for EEA users the contracting entity is GitHub B.V., Amsterdam, Netherlands, and GitHub participates in the EU-US Data Privacy Framework for transfers to the United States (Art. 45 GDPR); see the GitHub Privacy Statement. A GitHub account is technically required for delivery; if you do not want one, contact us before buying.

7 & 8

Email contact and mailing list

If you write to us we process your address, your name where given and the content of your message in order to answer it — Art. 6(1)(b) GDPR where it concerns a contract, otherwise Art. 6(1)(f) GDPR. Correspondence is deleted once the matter is closed and no retention duty applies.

The one form on this site is a single email field on the sales page (“Tell me when it ships”). Submitting it sends your email address, the time of signup and the page language to Formspree, Inc. (US), acting as our processor, which notifies info@zollwerk.app — for exactly one purpose: sending you the payment link and the launch notification. No newsletter, no sequence. Legal basis is your consent (Art. 6(1)(a) GDPR), given by actively submitting the field; withdraw it any time by writing to info@zollwerk.app and the address is deleted. The transfer to the United States rests on your explicit consent under Art. 49(1)(a) GDPR; no adequacy decision covers it and a level of protection comparable to EU law is not guaranteed there in every case (see Formspree’s privacy policy). Entries are deleted from Formspree once the launch notification is sent, at the latest at release. The binding wording is section 8 of the German Datenschutzerklärung.

10 & 11

Your rights

You have the right to:

  • access your data (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR), where no retention duty stands in the way,
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing based on legitimate interests (Art. 21 GDPR),
  • withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

An informal message to info@zollwerk.app is enough. We answer free of charge and within one month.

Right to object — Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6(1)(f) GDPR. If you do, we will stop processing the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.

You may also lodge a complaint with a supervisory authority under Art. 77 GDPR — in the member state of your residence, your place of work or the place of the alleged infringement. The authority competent for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, www.lda.bayern.de

There is no automated decision-making, including profiling, under Art. 22 GDPR.