🔒privacy policy

This document has not been translated yet and is shown in English.

Privacy Policy (Datenschutzerklärung)

Scope: this policy covers the website amarbaro.com only. The AMARBARO Android applications each have their own policy: ABCam, ABSend, ABDoc.

Last updated: 17 September 2026

Summary

This site is server-rendered, not static: it has accounts and logged-in, moderated blog comments, still no tracking pixels and no advertising. It loads no third-party resources: no external fonts, no CDN, no embedded video. Visiting a page produces no request to any server other than ours.

We run one optional, self-hosted, cookieless analytics counter, and it loads only if you allow it. Until you do, no analytics script is fetched and no analytics request is made. If you decline, nothing is loaded and nothing is stored. The only other personal data processed is the server log described below, generated for every visit to keep the site secure, and whatever you choose to put in an email if you write to us.

Controller

Tomi Alexandru
Hersfelder Str. 15
34596 Knullwald
Germany

Email: privacy@amarbaro.com

There is no statutory obligation to appoint a Data Protection Officer for this site (Art. 37 GDPR, § 38 BDSG), and none has been appointed.

Server log data

This site writes its own request log to its database (not a Caddy access log file): one row per page you request, so we can see traffic, errors and abuse patterns without needing shell access to the server. A row can contain:

Field Example
IP address 203.0.113.7
Date and time of the request 2026-09-02T14:03:11Z
Requested path and HTTP method GET /impressum/
HTTP status code 200
How long the request took 12 milliseconds
Referrer, if your browser sends one https://example.org/
User agent string Mozilla/5.0 (…) Firefox/141.0
The account you were signed in as, if any an internal account id, not shown here

Stylesheets, scripts, images and this site's own internal endpoints are not logged: a crawler that fetches one page shows up once, not once per file that page also loads.

Purpose and legal basis. Delivering the site, keeping it stable, and detecting attacks and abuse. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in operating a functioning and secure website. An IP address is personal data, which is why it is listed here even though we do not use this log to reconstruct what an anonymous visitor looked at.

When you are signed in. A request made while you are logged in also records which account made it. We use that link for two purposes: security (for example, recognising when an account is being used in an unexpected pattern) and your customer profile, where we can see which pages you visited while signed in, so we can support you and understand how customers use the site. The legal basis for both is Art. 6 (1) (f) GDPR. That is the one respect in which this log identifies you: an anonymous visit does not link to anyone, a signed-in request links to your account, and the profile never reaches further back than the retention period below. This activity is included when you request a copy of your data. It is never joined with the analytics counter described below, which cannot identify anyone in the first place.

Retention. Rows are kept for 30 days by default (configurable by us in the admin) and deleted automatically by a daily job once past that window. They are not merged with any data source beyond the account link described above, and are not used to build a cross-session profile of a visitor who is not signed in.

Accounts

You can create an account at /account/signup. It is optional: browsing this site, reading the blog and viewing the portfolio never require one.

What we store. Your name, your email address, a bcrypt hash of your password (never the password itself), and the time the account was verified. Legal basis: Art. 6 (1) (b) GDPR, performance of the contract you asked for by signing up.

Verification. We email a one-time link to confirm you control the address. Until you click it, the account cannot sign in. An unclicked link expires after 24 hours.

Retention. We keep account data for as long as the account exists. You can download a copy of it, or delete the account entirely, from /account/profile at any time. Deletion anonymises your personal data while keeping records the law requires us to retain, consistent with the erasure right described under Your rights below.

One account, several surfaces. The same account signs you in here, lets you comment on the blog, and covers anything bought through the shop. We do not keep a separate account per surface.

Orders and payments

Buying something in the shop requires the account described above: there is no guest checkout, because what an order grants (a licence, credit, or a prepaid code) has to belong to somebody.

What we store. The order itself (what you bought, the price, the currency) and the payment reference our payment processor gives it. We never see or store your card number, bank details or any other payment credential: those go directly to the processor's hosted payment page, not through our server.

Payment processing. Checkout is handled by Paysipa, our payment processor, under a data processing agreement (Art. 28 GDPR). Paysipa tells us, via a signed, verified notification, whether a payment succeeded, which is how an order is confirmed as paid; it does not tell us how you paid.

What a paid order writes. Confirmation grants exactly what you paid for: a licence entry, a credit top-up, or a prepaid code, recorded against your account so /account can show it back to you. Legal basis: Art. 6 (1) (b) GDPR, performance of the purchase contract.

Retention. Order records are kept for as long as Swiss and German commercial and tax law require records of a sale to be kept, which is longer than the account itself. Deleting your account anonymises the personal data on past orders (the same way it anonymises the rest of your account, described above) but does not delete the transaction record itself, consistent with the erasure right described under Your rights below.

Comments

You can comment on a blog post while signed in. There is no anonymous form: a comment is tied to your account, not to a name typed into a box.

What we store. The comment text, which account posted it, the time it was posted, and the time it was reviewed. Legal basis: Art. 6 (1) (b) GDPR, performance of the contract you asked for by posting a comment.

Moderation. A new comment is held and shown to nobody, including its author, until we review and approve it.

Retention. A comment is kept for as long as the account that posted it exists. Deleting the account removes the comments posted under it along with everything else the erasure right covers, described under Your rights below.

Quote requests

You can ask for a quote on "Software on request" at /shop/request. It does not require an account: this is a pre-sale enquiry, not a purchase.

What we store. Your name, your email address, and the description of what you are asking about, attached to your customer record. Legal basis: Art. 6 (1) (b) GDPR, steps taken at your request before entering into a contract.

Retention. We keep it as part of your customer record until you ask us to delete it (see Your rights below) or the record is otherwise cleared out.

Hosting

The site is served from a virtual server rented from Contabo GmbH, Aschauer Straße 32a, 81549 München, Germany. Contabo processes the log data described above on our behalf as a processor under Art. 28 GDPR, under a data processing agreement. The servers are located in the European Union.

Cookies and local storage

This site sets no cookies at all — not for analytics, not for anything else. It stores two values in your browser's localStorage:

Key Value Purpose
amarbaro-theme "dark" or "light" Remembers whether you chose the dark or light appearance.
ab_consent {"v":1,"analytics":true|false,"ts":…} Remembers your answer to the analytics question, so we stop asking.

Neither value ever leaves your browser — they are not transmitted to us or to anyone else. Both are strictly necessary in the sense of § 25 (2) no. 2 TDDDG: one provides the display setting you explicitly asked for, the other records the choice you made about analytics (storing a refusal is what keeps us from asking again). You can delete them at any time through your browser's site-data settings; the site will then follow your operating system's dark/light preference again and ask about analytics once more.

We use Plausible Community Edition, which we host ourselves on the same virtual server that serves this site, reachable at analytics.amarbaro.com. It is not a third-party service: no data is sent to Plausible Insights OÜ or to any other company, and the data never leaves our server.

It only runs if you allow it. On your first visit the site asks. Until you accept, the analytics script is not fetched and no request is made to analytics.amarbaro.com. Legal basis: your consent, Art. 6 (1) (a) GDPR, together with § 25 (1) TDDDG.

When it does run, each page view records:

Recorded Not recorded
The page URL, referrer, and UTM parameters if present Your IP address (used only transiently to derive the items at left, never stored)
Country, region and city at city level, derived from the IP Any cookie or identifier on your device
Browser, operating system and device type Anything that would let us recognise you on a later visit or across sites
Screen size bucket Any cross-site or cross-device profile

Plausible is cookieless: it stores nothing on your device — no cookie, no localStorage entry, no fingerprint. Visitor counts are derived from a daily-rotating, salted hash that we cannot reverse and that cannot be linked between days. The result is aggregate statistics — how many people read a post, which page they came from — and no profile of any individual.

How long it is kept. Raw analytics rows are deleted automatically 24 months after they are recorded — the database enforces this itself, it is not a promise about future housekeeping.

Withdrawing consent. Use the Cookie settings link in the footer of any page and turn analytics off. That takes effect immediately: the script is removed from the page and no further requests are made. Withdrawal does not affect the lawfulness of what was collected beforehand (Art. 7 (3) GDPR). Because the data is aggregate and contains no identifier, we cannot single out and delete past measurements relating to you — there is nothing in the data that points to you.

Contacting us by email

If you write to support@amarbaro.com, bugs@amarbaro.com or privacy@amarbaro.com, we process your email address, your message and any information you choose to include, for the sole purpose of answering you. The legal basis is Art. 6 (1) (b) GDPR where your message concerns a contract or pre-contractual steps, otherwise Art. 6 (1) (f) GDPR — our legitimate interest in responding to enquiries. We keep correspondence for as long as it is needed to handle the matter and to comply with statutory retention periods, then delete it.

Our mailboxes are hosted by Purelymail LLC (United States), which acts as a processor. Transfers to the United States are covered by the EU Standard Contractual Clauses. Email is inherently not confidential in transit unless both ends use encryption; please do not send us sensitive personal data by unencrypted email.

What we do not do

  • No third-party analytics. The only analytics is the self-hosted, cookieless counter described above, and it runs only with your consent.
  • No advertising, no ad networks, no conversion tracking.
  • No social media plugins, no share buttons that phone home.
  • No third-party fonts, scripts, or CDNs — every asset is served from amarbaro.com or, for the analytics script once you allow it, from our own analytics.amarbaro.com.
  • Accounts, blog comments and a quote-request form exist now (see Accounts, Comments and Quote requests below); still no newsletters.
  • No automated decision-making or profiling within the meaning of Art. 22 GDPR.
  • No sale or sharing of personal data with third parties, other than the processors named above acting strictly on our instructions.

Your rights

Under the GDPR you have the right to:

  • Access (Art. 15) — ask what data we hold about you.
  • Rectification (Art. 16) — have inaccurate data corrected.
  • Erasure (Art. 17) — have data deleted.
  • Restriction (Art. 18) — have processing limited.
  • Data portability (Art. 20) — receive your data in a machine-readable format.
  • Object (Art. 21) — object at any time to processing based on legitimate interest, including the server logging described above.
  • Withdraw consent (Art. 7 (3)) — where processing rests on consent, withdraw it at any time with effect for the future.

To exercise any of these, email privacy@amarbaro.com. For a visit where you were not signed in, our server log contains no identifier that lets us connect an IP address to you, so for an access request about that data we may be unable to identify you within the meaning of Art. 11 (2) GDPR. For a request made while you were signed in, the log row is linked to your account, and we can locate it the same way as the rest of your account data.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in the EU member state of your residence, place of work, or of the alleged infringement.

TLS

The whole site is served over HTTPS with certificates from Let's Encrypt. Plain HTTP requests are redirected to HTTPS.

Changes to this policy

We update this policy when the site changes in a way that affects it: on 4 September 2026, when the consent-gated analytics described above was added, on 15 September 2026, when accounts, blog comments and the server-side request log described above replaced the earlier Caddy access log description, and on 17 September 2026, when signed-in activity became part of your customer profile. The date at the top always reflects the current version.


Language note. This Datenschutzerklärung is published in English and in German. Where German law requires German-language information, the German version governs.