Jyn Schultze-Melling, Köpenicker Strasse 126, Email: info@gearshack.app. No Data Protection Officer required (Art. 37 GDPR — under 20 employees).
Account management: Art. 6(1)(b) GDPR. Email marketing: Art. 6(1)(a). Sentry error tracking: Art. 6(1)(f). GA4/Amplitude: Art. 6(1)(a) — only with consent.
Supabase (Frankfurt EU), Cloudinary (EU+US CDN), Stripe (US/Ireland), Resend (US), Google Analytics 4 (US), Amplitude (US), Vercel (US/EU edge), Sentry (US/EU).
Stripe, Amplitude, Resend, Vercel-Edge are DPF-certified (Data Privacy Framework, Schrems-III successor since 2023-07-10). Standard Contractual Clauses (SCCs) apply alternatively.
Account data: until deletion + 30 days soft-delete. Auth logs: max 90 days. GA4: 14 months.
Access, rectification, deletion, portability, objection. Account deletion and data export available in Settings > Account.
You have the right to complain to a data protection authority — your residence's authority or the Bavarian Office for Data Protection Supervision.