Privacy

Privacy Policy for Piss-Pott-Pass

Applies to the Android app Piss-Pott-Pass and the associated public websites. Last updated: 22 August 2026.

1. Controller

Giuseppe D'Agata
Weidenstraße 1
25421 Pinneberg
Germany

Email: support@loki-reflections.de
Phone: +49 1573 7641499

2. Basic principle of the app

Piss-Pott-Pass is designed as an offline-first app. Many functions and local guest progress can be used without a cloud account. Data required for online services is transferred only when you sign in with Google or use an online function.

3. Accessing this website

The public Piss-Pott-Pass pages are hosted through a STRATO web hosting package. When a page is accessed, technically necessary connection and log data may be processed, including IP address, access time, requested resource, status code and browser/device information.

This processing is required for delivery, stability and security of the website. The legal basis is Art. 6(1)(f) GDPR.

Hosting provider: STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Further information: STRATO Privacy Policy .

These static Piss-Pott-Pass pages do not themselves use analytics, advertising or tracking scripts and do not set their own marketing cookies.

4. Contact, support and deletion requests

If you contact us by email, we process the sender address, message content and technically necessary message metadata in order to handle your request. Depending on the matter, processing is based on Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

Correspondence is deleted when it is no longer required, unless legal retention obligations or necessary documentation interests apply.

5. Local app data

Your device may store profiles, visited places, visit dates, personal notes, progress, badges and unlocks as well as app settings. Local visit photos are stored in the app's document area. Authentication sessions are stored using protected device storage.

The current Android version does not allow app backups through the Android backup function. Guest progress that has not been adopted by an account generally remains local.

6. Google sign-in

Google sign-in is used for account-related online functions. Piss-Pott-Pass requests access to your email address and profile. Data processed may include your Google account ID, email address, display name and, where available, profile image URL. We do not receive your Google password.

Google provides short-lived authentication data. In the current app version, the Google ID token is used only in working memory and is not stored in the local Piss-Pott-Pass database. Tokens are used to authenticate with the Piss-Pott-Pass backend via Supabase.

Further information: Google Privacy Policy .

7. Supabase: account, backend and synchronization

Piss-Pott-Pass uses Supabase for authentication, database functions, synchronization and server-side functions. Depending on the function used, the following data may be processed:

Processing is performed to provide the selected account and online functions, for optional sharing based on your choice or consent, and for security, abuse prevention and moderation.

Supabase processes data as a technical service provider. Primary data is stored in the region selected for the Piss-Pott-Pass Supabase project. Supabase may use subprocessors. Where international transfers occur, appropriate transfer mechanisms such as Standard Contractual Clauses may be used.

Further information: Supabase Privacy Policy .

8. Location

The app may request precise or approximate device location when you actively start a location verification. There is no background location tracking.

The app reads a current position and accuracy value to determine the distance to a place or perform location-related functions. The measured coordinates are currently neither stored as visit coordinates nor synchronized with Supabase.

After successful verification, only the fact that verification succeeded and its timestamp may be stored or synchronized. You can revoke location permission at any time in Android system settings.

9. Private visit photos

If you voluntarily select a photo for a visit, it is copied from your gallery into the app's local document area. In the current version, the photo remains on your device and is not uploaded to the Piss-Pott-Pass cloud.

For points and badge logic, only the fact that a photo bonus was awarded may be stored and synchronized.

10. Account and profile

When you sign in, a profile is associated with your Piss-Pott-Pass account. Data processed includes a profile identifier, display name, possibly an avatar, and progress and synchronization settings.

11. Friends, progress sharing and leaderboard

Online social functions use a Piss-Pott-Pass friend code, profile identifier, display name/avatar, friendship requests, blocks and sharing settings. Progress sharing and leaderboard participation are disabled by default.

If you enable sharing, only an aggregated progress summary is shared, such as rank, PottPoints, number of visited places, badges, completed cities, countries, continents and World Highlights.

Individual visited places, visit timestamps, private notes, photos, location information, account data and device data are not part of this shared progress view.

12. Ratings and community submissions

Signed-in users can rate places. The rating is associated with the account server-side so that only one current rating per account and place is counted. An aggregated rating may be displayed.

Voluntary community submissions may include a title, address, city/country, description, optional source URL, correction information or abuse reports, together with a profile identifier and processing status.

13. Purchases through Google Play

Purchases of digital area packs are processed through Google Play. Piss-Pott-Pass does not receive complete payment or credit-card details.

For purchase verification and unlocking, the app or Supabase backend may process product ID, purchase token, purchase status, where applicable order ID, completion or acknowledgement timestamp and verification data from Google Play.

Server-side verification uses the Google Play Developer API. Further information: Google Privacy Policy .

14. Recipients and service providers

Depending on how the app is used, data may be processed by STRATO GmbH for web hosting, Supabase for backend, database, authentication and Edge Functions, and Google for Google Sign-In, Google Play and purchase verification.

Data is not sold for advertising purposes.

15. Retention period and account deletion

Account-related app data is generally stored for as long as it is needed for the account and selected functions. After confirmed account deletion, the Piss-Pott-Pass authentication account and associated server data are deleted.

The in-app deletion process additionally removes account-linked local data, private visit photos and local entitlement/test data.

Deletion can also be requested through the public Delete account page. Purely local data stored on a device cannot technically be removed remotely through an external request.

16. Your privacy rights

Subject to the GDPR, you have rights including access, correction, deletion, restriction of processing, data portability and objection. Consent can be withdrawn at any time with effect for the future.

Contact: support@loki-reflections.de .

You may also lodge a complaint with a data protection supervisory authority. For the controller's registered location, the relevant authority is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98
24103 Kiel
Germany
Email: mail@datenschutzzentrum.de
www.datenschutzzentrum.de

17. Security

We use appropriate technical and organizational measures, including HTTPS connections, server-side access controls, authenticated backend sessions and protected local storage for sensitive session data.

Absolute security of electronic data processing cannot be guaranteed.

18. Changes to this Privacy Policy

We update this Privacy Policy when functions, service providers or legal requirements change. The current version is published on this page.