Contents
1. Verantwortlicher2. Scope3. Rechtsgrundlagen4. Hosting, Serverlogs und technischer Betrieb5. Consent Management mit Usercentrics/Cookiebot6. Technisch notwendige Cookies und lokale Speicher6a. Local contribution drafts7. MagicPoster-Keys, NFC und QR8. Admin-Konten und Dashboard9. Friend Book10. Digital moments11. WiFi Magic12. Former plant handbook13. GPlate14. Uploads, Medien und PDF-Exporte15. Supabase16. Stripe17. Emailing18. Apple, StoreKit und Sign in with Apple18a. Android, Google Sign-in und Google Play18b. Optional app push notifications and event displays19. Vercel Web Analytics20. Manuelle externe Bewertungs- und Kartenlinks21. Previous Support Channels22. Externe Links23. Support-Hub, Claims, Migration und Admin Terminal24. Datensicherheit25. Recipients, third country transfers and storage period26. Inhalte Dritter und Daten von Kindern27. Your Rights28. Beschwerderecht29. Changes and Contact

Rechtliches

Privacy Policy

For app.getmagicposter.de, app.getmagicposter.com and technically connected function pages.

Last updated: September 22, 2026

1. Verantwortlicher

The person responsible within the meaning of the General Data Protection Regulation (GDPR) is Denscha IT & E-Commerce e.K., owner Dennis Scharf, Von-der-Tann-Straße 29, 93047 Regensburg, Germany.

Contact: hello@getmagicposter.com. Data protection inquiries can be directed to this email address at any time.

2. Scope

This Privacy Policy applies to the web application at app.getmagicposter.de, app.getmagicposter.com and technically connected functional pages such as setup.gplate.de, insofar as this declaration is referred to there. The shop page at www.getmagicposter.com may contain its own privacy policy.

3. Rechtsgrundlagen

We process personal data in particular on the basis of Art. 6 Para. 1 lit. b GDPR to fulfill the contract, Art. 6 Para. 1 lit. c GDPR to fulfill legal obligations, Art. 6 Para.

To the extent that special categories of personal data are voluntarily disclosed in free texts, images, audio or video files, the processing takes place on the basis of Art. 9 Para. 2 lit. a GDPR. Section 25 TDDDG also applies to cookies and comparable technologies.

4. Hosting, Serverlogs und technischer Betrieb

When the app is accessed, technical access data is processed, in particular IP address, date and time, URL, referrer, browser, operating system, HTTP header, response status, error events and, if applicable, MagicPoster or GPlate keys in the URL.

This data is used to deliver the app, routing between the MagicPoster modules, error analysis, attack detection and protection against misuse. The legal basis is Article 6 Paragraph 1 Letter f GDPR; If the call to use a purchased or set-up product is necessary, additionally Art. 6 Para. 1 lit. b GDPR.

The app is provided by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. A transfer to third countries, especially to the USA, cannot be ruled out. We base these on appropriate safeguards such as standard contractual clauses and, where relevant, the EU-US Data Privacy Framework.

Vercel Privacy PolicyVercel DPA

5. Consent Management mit Usercentrics/Cookiebot

We use Usercentrics/Cookiebot to obtain, manage and document consent for non-technically necessary services. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany.

Consent ID, consent status, time of consent or rejection, language, banner version and technical information such as IP address, browser and device information can be processed.

The legal basis is Article 6 Paragraph 1 Letter c GDPR in conjunction with Section 25 TDDDG and Article 6 Paragraph 1 Letter f GDPR. Non-essential services are generally only activated after consent. Consent can be revoked or changed at any time via the cookie/privacy settings.

Usercentrics Privacy Policy

6. Technisch notwendige Cookies und lokale Speicher

For admin sessions we use the cookie friendbook_admin_session. It is used for authentication in admin areas, is set as an HttpOnly cookie, is secure in production, SameSite=Lax and expires at the latest after 30 days or when you log out.

Session storage or local storage can be used in individual demo, promo or form flows, e.g. B. to quickly remember a demo entry that has started or a promo status. The legal basis is Article 6 Paragraph 1 Letter b GDPR or Article 6 Paragraph 1 Letter f GDPR and Section 25 Paragraph 2 TDDDG.

6a. Local contribution drafts

To resume interrupted contributions, text, selected files and a stable submission identifier may be stored locally on the device. The local submission is removed after saving is confirmed. Native retry files have a limited lifetime; browser drafts remain until successful submission or until browser storage is cleared. This storage does not automatically create a new contribution.

7. MagicPoster-Keys, NFC und QR

MagicPoster works with individual keys contained in NFC or QR links. Opening a link checks which module is associated with the key, such as a friend book, Digital Moments, WiFi Magic or GPlate.

Key, module assignment, setup status, connected keys, admin assignments and technical access data can be processed. The NFC chip itself usually only contains a URL or key and no direct personal content.

8. Admin-Konten und Dashboard

For setup, dashboard and admin areas we process email address, password in hashed form, optional name, email verification status, password reset token in hashed form, associated MagicPoster keys, session data and administrative changes.

Purposes are registration, login, email confirmation, password reset, management of MagicPoster functions, restoration or transfer of admin access and protection against unauthorized access. The legal basis is Article 6 Paragraph 1 Letter b GDPR and Article 6 Paragraph 1 Letter f GDPR for security measures.

9. Friend Book

With the digital Friend Book, project owners can set up a book and guests can create entries. Name or display name, date of birth or other voluntary information, answers to questions, personal words, photos, optional links such as Spotify links, times, book titles, subtitles, design, cover image, questions and admin assignments can be processed.

For guest contributions, a pseudonymous contributor ID can be saved for each book and browser or reliable identity. It allows you to avoid duplicate reports and block further contributions within the same book. Old entries without an identifier can be deleted, but cannot be reliably assigned to a contributor.

By default, people with the book link can view entries. The owner can disable guest viewing while guests can still contribute. Private entries and their media are then delivered only to authorized viewers. Copies already downloaded cannot be recalled.

The legal basis for project owners is Article 6(1)(b) GDPR. For guests, processing is based on voluntary submission and Article 6(1)(f) GDPR.

10. Digital moments

With Digital Moments, memories can be collected chronologically. Title, description, date, names, photos, videos, audio files, voice memos, questions, answers, cover images, design settings, order, status and admin assignments can be processed.

A pseudonymous, book-related contributor identifier can also be saved here. The visibility depends on the respective MagicPoster link and the admin settings. The legal basis is Article 6 Paragraph 1 Letter b GDPR for project owners and Article 6 Paragraph 1 Letter f GDPR for guests and users.

11. WiFi Magic

With WiFi Magic, admins can set up a WiFi guest page. The Wi-Fi name (SSID), Wi-Fi password, encryption type, network parameters, welcome message, title, images, design information, additional links such as Google review, Instagram profile or website, admin account, key and payment/upgrade status can be processed.

Wi-Fi passwords are stored protected on the server side. Admins should still preferably use guest networks. The legal basis is Article 6 Paragraph 1 Letter b GDPR and Article 6 Paragraph 1 Letter f GDPR for secure storage.

12. Former plant handbook

The plant handbook has been retired. Former plant content, care calendars and related administrative data are kept separately with restricted access for controlled restoration. New plant projects or contributions are no longer created. Existing rights to erasure and access remain unaffected.

13. GPlate

GPlate is a module for NFC/QR plates, specifically for Google reviews, Instagram profiles and website redirects. GPlate key, plate variant, Google Place ID, Google company label, Instagram username, website URL, target URL, setup status, legacy import status, admin assignment and technical access data can be processed.

Once a disk has been set up, you can be redirected directly to the stored external target page. If it is not set up, a setup flow will be displayed. For migrated old disks, a key-based change may be temporarily possible. The legal basis is Article 6 Paragraph 1 Letter b GDPR and Article 6 Paragraph 1 Letter f GDPR.

14. Uploads, Medien und PDF-Exporte

When uploading, we process the files provided, in particular photos, videos, audio files, profile or cover images, PDF export files as well as technical file information such as file name, size, MIME type and storage path.

Files can be processed on the server side, for example for image optimization, PDF creation, preview generation or storage. The legal basis is Article 6 (1) (b) GDPR and Article 6 (1) (f) GDPR for security checks and technical integrity.

15. Supabase

We use Supabase for database, storage and server-side management processes. The provider is Supabase, Inc. or affiliated Supabase companies.

Supabase can store MagicPoster keys, module mappings, admin accounts, access rights, book, moment, WiFi, Plant Guide and GPlate data, media paths, payment and upgrade status, support, claim, migration and audit data.

The Supabase project used for MagicPoster is set up in eu-central-1 (Frankfurt). If individual support or sub-processing services require transfer outside the EU/EEA, this will take place on the basis of appropriate guarantees such as standard contractual clauses and contractual data protection regulations.

Supabase PrivacySupabase DPA

16. Stripe

We use Stripe Checkout and the Stripe API for paid upgrades, PDF exports, business add-ons or similar payments. The provider is Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland.

Name, email address, payment data, Stripe Customer ID, Checkout Session ID, Payment Intent ID, Subscription ID, product, price, amount, currency, payment status, MagicPoster key, module and admin account can be processed as metadata.

The actual payment processing is carried out by Stripe. We regularly do not receive complete credit card information. The legal basis is Article 6 Paragraph 1 Letter b GDPR, Article 6 Paragraph 1 Letter c GDPR for tax and commercial law obligations and Article 6 Paragraph 1 Letter f GDPR for fraud prevention.

Stripe PrivacyStripe DPA

17. Emailing

We send transactional emails, in particular for email confirmation, password reset, restoration of admin access, claim or migration confirmation and for important account or functional processes.

E-mail address, subject, content, time of sending and technical shipping information are processed. Shipping takes place via SMTP infrastructure, currently using IONOS as standard, unless another SMTP configuration is stored. The legal basis is Article 6 Paragraph 1 Letter b GDPR, Article 6 Paragraph 1 Letter c GDPR and Article 6 Paragraph 1 Letter f GDPR.

IONOS data protection

18. Apple, StoreKit und Sign in with Apple

For in-app purchases, Apple processes payment and billing data under its own responsibility. MagicPoster processes signed transactions, product ID, status, Apple account association, project association, restore status, and audit history to determine server-side permissions and prevent reuse.

When you sign in with Apple, we receive an Apple ID and, if applicable, your name and relay email address. If an associated account is deleted, you may be required to sign in to Apple again; The Apple token is then revoked on the server side.

Apple privacy policy

18a. Android, Google Sign-in und Google Play

In the Android app, Google Sign-in can be used via the Android Credential Manager. MagicPoster checks the Google ID token on the server side and processes the Google ID, confirmed email address and, if applicable, the name provided by Google. A confirmed identical email address can be linked to an existing MagicPoster account.

Google Play processes payment and billing data under its own responsibility. MagicPoster checks package ID, product, purchase status, account allocation, project allocation, term and reuse via Android Publisher API. Purchase tokens are permanently stored only as a hash. Google Cloud Pub/Sub submits renewal, cancellation, grace period, expiration, refund, and chargeback status events.

Firebase Auth, Firebase Analytics and Crashlytics are not used for MagicPoster Android. Optional push delivery through Firebase Cloud Messaging is described in the following section.

Google privacy policyGoogle Play-Nutzungsbedingungen

18b. Optional app push notifications and event displays

For optional app notifications, we use Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. We process device and installation tokens, platform, app version, language, permission status and the association with the signed-in account. Photo book events also use book-specific activity tokens, start and end times and update status.

New-entry notifications are enabled explicitly for each project and contain no answers or photos by default. You can turn them off in the project settings and device settings. Signing out disables that device association for delivery; invalid tokens are no longer used. An ownership transfer ends the previous owner’s access to new project notifications. Necessary account, transfer and moderation emails are unaffected.

Delivery and the providers’ technical services may process connection data such as IP addresses and installation identifiers. The privacy information from Apple and Firebase also applies.

Firebase privacyApple privacy policy

19. Vercel Web Analytics

We use Vercel Web Analytics to technically and statistically evaluate the use of the app. Page views, referrers, browser and device information, approximate location and network data as well as technical query information can be processed.

According to Vercel, Vercel Web Analytics does not use third-party cookies. We still run the service in the consent banner under statistics. The legal basis is Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TDDDG.

Vercel Analytics Privacy

20. Manuelle externe Bewertungs- und Kartenlinks

MagicPoster no longer uses active Google Places search or autocomplete functionality. Project owners can still provide manually verified HTTPS links to Google Reviews, Maps, Instagram, Spotify or other websites.

As long as such content is only displayed as a link, there is no automatic transmission to the respective provider. Only when you click does the external provider process data under its own responsibility.

21. Previous Support Channels

MagicPoster no longer offers AI technical chat or WhatsApp support. Support is available via email at hello@getmagicposter.com. If WhatsApp or AI support data still exists from previous support contacts, it will not be further processed for new inquiries and will only be stored until the required proof, statute of limitations or legal retention periods have expired; They are then deleted or anonymized.

22. Externe Links

In MagicPoster functions, admins or users can store external links, such as Instagram profiles, Spotify songs, Google review sites, websites, PDF files or other external content. As long as such content is only saved and displayed as a link, data is not necessarily automatically transferred to the respective third party provider. When you click, the respective provider processes data under its own responsibility.

23. Support-Hub, Claims, Migration und Admin Terminal

For support, system migration, restoration of admin access and internal administration, MagicPoster key, order number, name, shipping name, order email address, desired admin email address, product name, technical test results, audit entries, activation status and password reset processes can be processed.

The purpose is to securely assign old posters, avoid unauthorized takeovers, transfer admin access, troubleshooting and support. The legal basis is Article 6 Paragraph 1 Letter b GDPR and Article 6 Paragraph 1 Letter f GDPR.

Reports on guest posts contain the affected post, reason, optional description, pseudonymous report identifier, status, processing history and, if applicable, a blocking decision. The project owner is notified via IONOS SMTP. A failed send does not change the storage of the message.

24. Datensicherheit

We take technical and organizational measures to protect personal data, in particular HTTPS encryption, HttpOnly session cookies, password hashing, server-side secret management, access restrictions for admin areas, separate server-side service roles, signed download URLs, protected storage of sensitive configuration data and logging of security-relevant processes.

25. Recipients, third country transfers and storage period

Active recipients can in particular be Vercel, Supabase, Usercentrics, Apple, Stripe, IONOS, tax advisors, legal advisors, banks, authorities and technical service providers. External link targets only receive data when they are consciously accessed. If necessary, we conclude agreements with processors in accordance with Art. 28 GDPR.

Some providers have their headquarters or infrastructure outside the EU or EEA. In such cases, we use appropriate guarantees in accordance with Art. 44 ff. GDPR, in particular standard contractual clauses, adequacy decisions and additional protective measures.

Admin accounts and MagicPoster content generally remain saved as long as the respective account, poster or module is active. Session cookies expire after 30 days at the latest. Open reports are saved until completion; Moderation processes and blocking identifiers are then only used for as long as legal enforcement, protection against misuse or obligations to provide evidence require this. Purchase ledgers as well as evidence relevant to commercial and tax law can be stored for up to ten years.

26. Inhalte Dritter und Daten von Kindern

The project owner bears primary contractual responsibility for the setup, invited guests, own content and the ongoing moderation of his friends or Photo Book or WiFi page. Each guest remains responsible for their own upload, its legality and the necessary copyright, personal and consent rights.

MagicPoster does not generally check content in advance and does not adopt it as its own. However, MagicPoster retains legally required inspection, information, security, deletion and blocking rights. Legal obligations cannot be completely transferred to the project owner.

The app is not aimed specifically at children. However, it may happen that users upload children's data as part of Friend Books, moments or family posters. In this case, the uploading user is responsible for ensuring that he or she is authorized to do so and that the necessary consent is available.

27. Your Rights

In accordance with the GDPR, you have the right to information, correction, deletion, restriction of processing, data portability, objection, revocation of consent given and complaint to a data protection supervisory authority.

If we process data on the basis of Article 6 Paragraph 1 Letter f of the GDPR, you can object for reasons arising from your particular situation. If processing is based on consent, you can revoke it at any time with future effect.

To exercise your rights, contact us at hello@getmagicposter.com and, if possible, indicate which MagicPoster key, admin account or function your request relates to.

28. Beschwerderecht

You have the right to complain to a data protection supervisory authority. The Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, is regularly responsible for non-public bodies based in Bavaria.

BayLDA

29. Changes and Contact

We may adapt this Privacy Policy if the app, services used, legal requirements or our processing processes change. The version published on the app applies.

Contact for data protection questions: hello@getmagicposter.com or by post to Denscha IT & E-Commerce e.K., Von-der-Tann-Straße 29, 93047 Regensburg, Germany.

Rechtliches
DatenschutzerklärungImpressumNutzungsbedingungen