Privacy Policy
1. Data Protection at a Glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you could be personally identified. Detailed information on data protection can be found in our privacy policy set out below this text.
Data collection on this website
Who is responsible for data collection on this website?
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you could be personally identified. Detailed information on data protection can be found in our privacy policy set out below this text.Data processing on this website is carried out by the website operator. You can find their contact details in the "Notice concerning the responsible party" section of this privacy policy.
How do we collect your data?
Your data is collected, in part, by you providing it to us. This may, for example, be data you enter into a contact form.
Other data is collected automatically, or after you have given your consent, by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system, or the time the page was accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure the website is provided without errors. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to receive, free of charge, information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you may revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time with regard to this matter as well as any further questions on the subject of data protection.
Analysis tools and tools provided by third parties
When visiting this website, your browsing behaviour may be statistically evaluated. This is done primarily using what are known as analysis programs.
Detailed information on these analysis programs can be found in the following privacy policy.
2. Hosting and Content Delivery Networks (CDN)
We host the content of our website with the following providers:
Webflow
The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter "Webflow"). When you visit our website, your personal data (e.g. IP address) is processed on Webflow's servers or on the servers of the content delivery networks used by Webflow. This may result in personal data being transferred to the USA. Webflow is certified under the EU-US Data Privacy Framework (DPF); the data transfer is additionally based on the European Commission's Standard Contractual Clauses. For details, please see Webflow's privacy policy: https://webflow.com/legal/privacy.
The use of Webflow is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable possible presentation of our website. Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act), to the extent the consent covers the storage of cookies or access to information on the user's device within the meaning of the TDDDG. Consent can be revoked at any time.
Data processing agreement: We have entered into a data processing agreement (Data Processing Addendum) for the use of the above-mentioned service. This is a contract mandated by data protection law that ensures the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Hetzner (Linetrack platform)
We operate the Linetrack platform (app.linetrack.de) — including its database and file storage — as well as the backend infrastructure of the Linetrack Mobile App, at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hereinafter "Hetzner"). Processing takes place at a data centre in Falkenstein, Germany. For details, please see Hetzner's privacy policy: https://www.hetzner.com/de/legal/privacy-policy.
The use of Hetzner is based on Art. 6(1)(b) GDPR (performance of our contracts with customers and users of the platform) as well as Art. 6(1)(f) GDPR (legitimate interest in a secure and reliable provision of our platform).
Data processing agreement: We have entered into a data processing agreement (DPA) for the use of the above-mentioned service.
Microsoft Azure Communication Services (email delivery)
We use Azure Communication Services to send system and notification emails from our platform (e.g. notices about tasks that are due, registration and security emails). The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Processing takes place in the Microsoft cloud region of Frankfurt am Main, Germany. To the extent that personal data is transferred to the USA in individual cases, Microsoft Corporation is certified under the EU-US Data Privacy Framework; the European Commission's Standard Contractual Clauses apply in addition. Further information: https://privacy.microsoft.com/de-de/privacystatement.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in the reliable delivery of system emails).
Data processing agreement: A data processing agreement (Microsoft Products and Services Data Protection Addendum) exists with Microsoft.
3. General Information and Mandatory Disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various pieces of personal data are collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission over the internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Notice concerning the responsible party
The party responsible for data processing on this website is:
Linetrack GmbH
Augsburger Str. 749
70329 Stuttgart
Phone: +49 172 7211850
Email: support@linetrack.de
The responsible party is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Storage period
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion will take place once these reasons cease to apply.
General information on the legal basis for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, insofar as special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), data processing is additionally carried out on the basis of Section 25(1) TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data if this is required to fulfil a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Notice regarding the transfer of data to the USA and other third countries
Among other things, we use tools from companies based in the USA or other third countries that are not deemed safe from a data protection perspective. If these tools are active, your personal data may be transferred to and processed in these third countries. We would like to point out that no level of data protection comparable to that in the EU can be guaranteed in these countries. For example, US companies are obliged to disclose personal data to security authorities without you, as the data subject, being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. intelligence agencies) may process, analyse, and permanently store your data held on US servers for surveillance purposes. We have no influence over these processing activities.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You may revoke consent you have already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to the collection of data in special cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work, or the place of the alleged violation. This right to lodge a complaint exists without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. Should you require the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
Information, rectification, and erasure
Within the scope of the applicable statutory provisions, you have the right at any time to free-of-charge information about your stored personal data, its origin and recipients, and the purpose of data processing, and, where applicable, a right to rectification or erasure of this data. You may contact us at any time with regard to this matter as well as any further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of this verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you may request the restriction of data processing instead of erasure.
- If we no longer need your personal data, but you need it to assert, exercise, or defend legal claims, you have the right to request the restriction of the processing of your personal data instead of its erasure.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data — with the exception of its storage — may only be processed with your consent, or for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from "http://" to "https://" and by the padlock symbol in your browser bar.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after the conclusion of a contract subject to charges, you are obliged to send us your payment details (e.g. account number for a direct debit authorisation), this data is required to process the payment.
Payment transactions using standard means of payment (Visa/MasterCard, direct debit) are processed exclusively via an encrypted SSL or TLS connection. You can recognise an encrypted connection by the fact that the address bar of your browser changes from "http://" to "https://" and by the padlock symbol in your browser bar.
With encrypted communication, your payment details, which you transmit to us, cannot be read by third parties.
4. Data Collection on this Website
Cookies
Our websites use what are known as "cookies". Cookies are small data packets and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.
Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies may be used to evaluate user behaviour or for advertising purposes.
Cookies that are required to carry out the electronic communication process, to provide certain functions that you have requested (e.g. for the shopping cart function), or to optimise the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is stated. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimised provision of its services. Insofar as consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
You can find out which cookies and services are used on this website in this privacy policy.
Contact form
If you send us enquiries via the contact form, the details you provide in the enquiry form, including the contact details you provide there, will be stored by us in order to process your enquiry and in case of any follow-up questions. We will not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR, if your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), provided this has been requested; consent can be revoked at any time.
The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to its storage, or the purpose for which the data is stored no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions — in particular retention periods — remain unaffected.
Enquiries by email, telephone, or fax
If you contact us by email, telephone, or fax, your enquiry, including all resulting personal data (name, enquiry), will be stored and processed by us for the purpose of handling your request. We will not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR, if your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), provided this has been requested; consent can be revoked at any time.
The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to its storage, or the purpose for which the data is stored no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.
Registration on this website
You can register on this website in order to use additional functions on the site. We only use the data entered for this purpose to use the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will refuse the registration.
For important changes, such as to the scope of the offer, or in the event of technically necessary changes, we use the email address provided during registration to inform you in this manner.
The processing of the data entered during registration is carried out for the purpose of performing the usage relationship established through registration and, where applicable, for initiating further contracts (Art. 6(1)(b) GDPR).
The data collected during registration is stored by us for as long as you are registered on this website and is deleted thereafter. Statutory retention periods remain unaffected.
5. Analysis Tools, Tag Management, and Advertising
The services listed in this section allow the provider to monitor and analyse traffic and track user behaviour.
Google Analytics 4 (Google LLC)
Google Analytics 4 is a web analytics service provided by Google LLC ("Google"). Google uses the collected data to track and examine how this application is used, to compile reports on its activities, and to share these with other Google services. Google may use the collected data to contextualise and personalise the advertisements of its own advertising network. In Google Analytics 4, IP addresses are used at the time of collection and are then deleted before the data is stored in a data centre or on a server. Users can learn more by consulting Google's official documentation.
To understand Google's use of data, please consult the Partner Policy and the Business Data page.
Personal data processed: number of users; usage data; session statistics; trackers.
Place of processing: United States – Privacy Policy – Opt Out.
Google Tag Manager (Google LLC)
Google Tag Manager is a service provided by Google LLC for the management of tags.
To understand Google's use of data, please consult the Partner Policy and the Business Data page.
Personal data processed: usage data; trackers.
Place of processing: United States – Privacy Policy.
Matomo
You have the option of preventing actions you have taken here from being analysed and linked. This will protect your privacy, but will also prevent the owner from learning from your actions and improving usability for you and other users.
Your visit to this website is currently being recorded by Matomo web analytics. Uncheck this box to opt out.
This website uses the open source web analytics service Matomo.
With the help of Matomo, we are able to collect and analyse data on the use of our website by visitors. Among other things, this allows us to find out when certain pages were viewed and from which region they came. We also collect various log files (e.g. IP address, referrer, browsers, and operating systems used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases, etc.).
The use of this analysis tool is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analysing user behaviour in order to optimise both its website and its advertising. Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, to the extent the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
IP anonymisation
We use IP anonymisation for the analysis carried out with Matomo. Your IP address is shortened prior to analysis, so that it can no longer be clearly attributed to you.
Cookie-free analysis
We have configured Matomo so that it does not store any cookies in your browser.
Hosting
We host Matomo exclusively on our own servers, so that all analysis data remains with us and is not passed on.
Microsoft Clarity
We use the web analytics software Microsoft Clarity for our website. The service is provided by the American company Microsoft Corporation, headquartered at One Microsoft Way, Redmond, WA 98052-6399, USA.
Microsoft processes your data, among other places, in the USA. Clarity, respectively Microsoft, is an active participant in the EU-US Data Privacy Framework, which governs the proper and secure transfer of personal data of EU citizens to the USA. Further information can be found at European Commission adequacy decision on the EU-US Data Privacy Framework.
In addition, Microsoft uses what are known as Standard Contractual Clauses pursuant to Article 46(2) and (3) GDPR. These clauses (Standard Contractual Clauses – SCC) are templates created by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Microsoft undertakes to comply with the European level of data protection when processing your relevant data, even if this data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. The decision and the corresponding Standard Contractual Clauses can be found, among other places, here: Implementing Decision (EU) 2021/914 on standard contractual clauses
Further information on Microsoft's Standard Contractual Clauses can be found at Microsoft's standard contractual clauses
Learn more about the data processed through the use of Microsoft in our privacy statement at https://privacy.microsoft.com/de-de/privacystatement.
6. Plugins and Tools
Apollo.io website tracker
On this website we use the website tracker provided by Apollo.io (ZenLeads Inc. d/b/a Apollo.io), 535 Mission St, Suite 502, San Francisco, CA 94105, USA. The service evaluates your device’s IP address in order to attribute page views to the company from whose network the access originates. The purpose is outreach to potential business customers by our sales team.
Use is based exclusively on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Without your consent the service is not loaded and no connection to Apollo.io is established. You can withdraw your consent at any time with effect for the future via the cookie settings.
This involves a transfer of data to the USA. Apollo.io is not certified under the EU-US Data Privacy Framework. The transfer is therefore based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR. A level of data protection equivalent to the European one cannot be guaranteed in the USA in all cases; in particular, access by US authorities is possible. For details see the provider’s privacy policy: https://www.apollo.io/privacy-policy.
Cal.com (appointment booking)
For booking demo appointments we use the Cal.com service provided by Cal.com, Inc., 2093 Philadelphia Pike #1483, Claymont, DE 19703, USA.
On our website we generally only link to the booking calendar; Cal.com is then only accessed once you actively click the link and open the provider’s page. Where the calendar is embedded directly, the embed is only loaded after your explicit release (two-click solution). Before that, no connection to Cal.com is established and your IP address is not transmitted.
The legal basis for loading the embed is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG, revocable via the cookie settings. Loading it transfers data to the USA; the transfer is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Further information: https://cal.com/privacy.
YouTube with extended data protection
This website embeds videos from the YouTube website. The operator of the pages is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in extended data protection mode. According to YouTube, this mode causes YouTube not to store any information about visitors to this website before they watch the video. However, the extended data protection mode does not necessarily rule out the sharing of data with YouTube partners. For example, regardless of whether you watch a video, YouTube establishes a connection to the Google DoubleClick network.
As soon as you start a YouTube video on this website, a connection is established to YouTube's servers. This informs the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to associate your browsing behaviour directly with your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, after starting a video, YouTube may store various cookies on your device or use comparable recognition technologies (e.g. device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to compile video statistics, improve user-friendliness, and prevent fraud attempts.
Depending on the case, further data processing operations may be triggered after a YouTube video is started, over which we have no influence.
YouTube is used in the interest of an appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, to the extent the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Further information on data protection at YouTube can be found in their privacy policy at: Google's privacy policy.
Google Fonts (locally hosted)
This site uses what are known as Google Fonts, provided by Google, for the uniform display of typefaces. Google Fonts are installed locally. No connection to Google's servers is established in this process.
Further information on Google Fonts can be found at Google Fonts FAQ and in Google's privacy policy: Google's privacy policy.
Font Awesome (locally hosted)
This site uses Font Awesome for the uniform display of typefaces. Font Awesome is installed locally. No connection to the servers of Fonticons, Inc. is established in this process.
Further information on Font Awesome can be found in the privacy policy for Font Awesome at: Font Awesome's privacy policy.
7. Optimisation and Distribution of Traffic
With this type of service, this application can distribute its content via servers located in various countries and optimise its performance. Which personal data is processed depends on the characteristics and manner of implementation of these services, whose function is to filter the communication taking place through this application and the user's browser. Given the widespread nature of this system, it is difficult to determine the locations to which content containing users' personal data is transmitted.
Cloudflare (Cloudflare Inc.)
Cloudflare is a service provided by Cloudflare Inc. for the optimisation and distribution of traffic. Due to the way in which Cloudflare's functions are integrated, the service filters all traffic occurring through this application, i.e. the communication taking place through this application and the user's browser, while also enabling the collection of analytical data contained in this application.
Personal data processed: trackers; various types of data, as described in the service's privacy policy.
Place of processing: United States – Privacy Policy.
8. Services for Protection Against Spam and Bots
This type of service analyses the traffic of this application, which may contain users' personal data, in order to filter out unwanted elements of traffic, messages, and content identified as spam, or to fend off malicious bot activity.
Cloudflare Bot Management (Cloudflare Inc.)
Cloudflare Bot Management is a service provided by Cloudflare Inc. for defending against and managing harmful bots.
Personal data processed: app executions; number of sessions; app launches; motion sensor recordings; custom events; operating systems; mouse movements; latitude (of city); browser information; browser history; county; video view data; device information; device logs; information about the application; interaction events; IP address; clicks; country; longitude (of city); metropolitan area; usage data; postal code; region; scroll-to-page interactions; scroll position; page views; page events; session duration; session statistics; language; state; city; search history; keystrokes; touch events; trackers; administrative district.
Place of processing: United States – Privacy Policy.
9. Special Data Protection Notices for the Linetrack Mobile App
The following notices supplement the preceding sections of this privacy policy with regard to the mobile application of Linetrack GmbH ("Linetrack Mobile App"). For all matters not expressly governed otherwise — in particular the identity of the responsible party, the general legal basis for data processing, your rights as a data subject, and the right to lodge a complaint with the competent supervisory authority — the provisions of the preceding sections 1 through 8 of this privacy policy continue to apply without restriction.
9.1 Scope
These notices apply to the mobile application of Linetrack GmbH, which is offered under the bundle identifiers de.linetrack.mobile (production), de.linetrack.mobile.preview, and de.linetrack.mobile.dev for Apple iOS and Google Android. The Linetrack Mobile App is part of our SaaS platform Linetrack and is used to access your Linetrack account on mobile devices. The project, task, user, and account data processed in the app is synchronised with the same backend infrastructure as the web application; the processing operations described in the preceding sections therefore apply in addition.
9.2 Obtaining the app via app stores (Apple, Google)
The Linetrack Mobile App is downloaded and installed exclusively via the Apple App Store (provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA) or the Google Play Store (provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, represented in the EU by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When obtaining the app through these stores, personal data (e.g. Apple ID or Google account, device identifiers, download time, IP address, and, where applicable, payment information) is processed independently by Apple Inc. or Google LLC. We have no influence over this processing. It is not the subject of this privacy policy. Only the respective provider's data protection provisions apply:
- Apple: Apple's privacy policy
- Google: Google's privacy policy
9.3 Categories of personal data processed in the app
In the course of providing and using the Linetrack Mobile App, we process the following categories of personal data:
Account and authentication data: the login details of your Linetrack account (email address, and, where applicable, name, organisational affiliation) as well as authentication tokens (access and refresh tokens), which, after successful login, are stored locally on your device with hardware-backed encryption (see Section 9.5).
Project and task data: all project, task, comment, and status data that you enter in the app or that is synchronised from the backend. The underlying processing in the Linetrack backend is described in the preceding sections of this privacy policy.
Uploaded content (attachments): photos you take using the camera, images you select from your photo library, and documents you select via the document picker, in order to submit them as attachments to tasks or projects. This content is transmitted to our backend via an encrypted connection and processed there in accordance with the preceding sections.
Technical data: IP address, device model, operating system and version, app version, device or app language, time zone, bundle identifier, and update channel. This data is technically necessary and arises with every call to the app's backend interfaces as well as when checking for available updates (see Section 9.6).
Crash and diagnostic data: technical information about program crashes and errors, including stack traces, device and OS information, app version, and app events that occurred immediately before the error ("breadcrumbs"), see Section 9.7.
Legal basis: Insofar as the processing of the aforementioned categories of data is necessary for the performance of the usage agreement for the Linetrack platform concluded between your employer or principal (Linetrack customer) and us, it is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract). Insofar as the processing — in particular with regard to technical data, stability, and crash reporting — also serves our legitimate interest in a secure, stable, and properly functioning operation of the app, it is additionally carried out on the basis of Art. 6(1)(f) GDPR. Insofar as your active permission is required for access to certain device resources (camera, photo library, document picker, see Section 9.4), the respective device access is additionally based on your consent pursuant to Art. 6(1)(a) GDPR, which you may revoke at any time via your device's system settings.
9.4 Device permissions
The Linetrack Mobile App only requests those device permissions that are required for the respective function being used. Granting these permissions is voluntary; without granting them, the respective function is not available, but the remaining functions of the app remain usable.
Camera – Purpose: taking photos for use as a task attachment. Platform reference: iOS NSCameraUsageDescription; Android android.permission.CAMERA. Legal basis: Art. 6(1)(a) GDPR (consent via system dialogue) in conjunction with Art. 6(1)(b) GDPR.
Read access to photo library – Purpose: selecting existing images for use as a task attachment. Platform reference: iOS NSPhotoLibraryUsageDescription; Android READ_MEDIA_IMAGES (Android 13+) or READ_EXTERNAL_STORAGE (older versions). Legal basis: Art. 6(1)(a) GDPR in conjunction with Art. 6(1)(b) GDPR.
Write access to photo library – Purpose: saving an image created in the app to your photo library. Platform reference: iOS NSPhotoLibraryAddUsageDescription; Android scoped storage via MediaStore. Legal basis: Art. 6(1)(a) GDPR.
Document access (document picker) – Purpose: selecting files from the file system or from iCloud Drive for use as a task attachment. Platform reference: iOS system UIDocumentPickerViewController with the "Production" iCloud container; Android system ACTION_OPEN_DOCUMENT. Legal basis: Art. 6(1)(a) GDPR (case-by-case selection) in conjunction with Art. 6(1)(b) GDPR.
You can revoke granted permissions at any time via your device's system settings (iOS: Settings › Linetrack; Android: Settings › Apps › Linetrack › Permissions). Insofar as you select documents from iCloud Drive, Apple Inc. independently processes the underlying cloud communication (see Section 9.2).
The Linetrack Mobile App does not use push notifications, does not track you across other apps or websites, does not use an advertising identifier (IDFA/AAID), and does not use location services. Apple's App Tracking Transparency (ATT) framework is therefore not requested.
9.5 Local data storage on the device
The Linetrack Mobile App stores certain data locally on your device to simplify login processes and — insofar as functionally necessary — to enable offline use:
- Authentication tokens are stored using expo-secure-store in the hardware-backed device security store: on iOS in the iOS Keychain (kSecClassGenericPassword), and on Android in the Android Keystore via EncryptedSharedPreferences. Encryption is performed by the operating system using a device-specific key.
- Local app cache (e.g. most recently synchronised project data, UI preferences) is stored in the app's own storage area, which is protected by the operating system.
Insofar as these storage operations constitute access to, or the storage of, information on the terminal equipment within the meaning of Section 25(2) No. 2 TDDDG, they are strictly necessary in order to be able to provide the digital service you have expressly requested (using your Linetrack account on the mobile device); consent under Section 25(1) TDDDG is not required in this respect. The associated processing of personal data is carried out on the basis of Art. 6(1)(b) GDPR.
When the app is uninstalled, the locally stored data — with the exception of certain entries stored in the iOS Keychain, whose persistence is determined by the operating system — is removed from the device. Deleting your Linetrack account and the data stored on the server side does not occur through uninstalling the app; account deletion pursuant to Section 9.10 is required for this.
9.6 Over-the-air updates (OTA) via Expo Application Services (EAS Update)
To provide bug fixes and security updates without requiring a new app store roll-out, we use the EAS Update service. The provider is 650 Industries, Inc. (operating under the name "Expo"), 624 University Avenue, Floor 1, Palo Alto, CA 94301, USA (hereinafter "Expo").
Each time the app is started, the Linetrack Mobile App checks via the address u.expo.dev whether an update is available for the currently applicable channel (production, preview, or development). In doing so, technical data is transmitted to Expo: IP address, operating system and version, app version, update channel, and randomised technical tokens. According to Expo, no identifying device or user identifiers are transmitted.
Purpose: providing security- and stability-relevant app updates without delay caused by a renewed store review.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in maintaining the security, stability, and currency of the app provided; this outweighs the interests of users warranting protection, since only technical, and no substantively personal, data is processed.
Third-country transfer / safeguards: Processing takes place in the USA. Expo (650 Industries, Inc.) has self-certified under the EU-U.S. Data Privacy Framework as well as its UK and Swiss extensions; in addition, the EU Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 exist between us and Expo as an additional transfer mechanism (Art. 46(2)(c) GDPR).
Data processing agreement: A data processing agreement (Data Processing Addendum) exists with Expo; Expo acts as a processor within the meaning of Art. 28 GDPR in this respect.
Further information: Expo's privacy policy at Expo's privacy policy.
9.7 Crash and error reports (Sentry)
To detect and fix program errors, we use the SDK @sentry/react-native. The provider is Functional Software, Inc. (operating under the name "Sentry"), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (hereinafter "Sentry").
In the event of a crash or an unhandled error, the app transmits the following data to Sentry: stack trace (technical call chain), error message, device model, operating system and version, app version, language, time zone, IP address (transmitted technically, used by Sentry for localisation and spam prevention), and so-called breadcrumbs (technical app events occurring immediately before the error, e.g. screens accessed, network calls without content). Where applicable, a pseudonymous user identifier is additionally transmitted in order to be able to attribute errors to a session; no real names are transmitted. We use Sentry in such a way that no personal content from input fields is transmitted in crash reports; sensitive fields are filtered out on the SDK side before transmission.
Purpose: stability, security, and error resolution for the app.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the early detection and resolution of errors, the avoidance of security risks, and ensuring stable app operation.
Retention period: Error events are stored by Sentry for 90 days by default.
Third-country transfer / safeguards: Sentry (Functional Software, Inc.) has self-certified under the EU-U.S. Data Privacy Framework as well as its UK and Swiss extensions. In addition, the EU Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 form part of our data processing agreement with Sentry.
Data processing agreement: A data processing agreement (Data Processing Addendum pursuant to Art. 28 GDPR) exists with Sentry.
Right to object: Pursuant to Art. 21(1) GDPR, you have the right to object at any time, for reasons arising from your particular situation, to the processing of your data for the purpose of crash reporting. Since crash and error reports are essential for the security and stability of the app and contain only technical data without substantive personal reference, technical deactivation can only be carried out on a case-by-case basis and following separate review. Please contact support@linetrack.de for this purpose.
Further information can be found in Sentry's privacy policy at Sentry's privacy policy.
9.8 Opening external content (in-app browser)
The Linetrack Mobile App may open external web content (e.g. OAuth login flows, help pages, further documentation) via the expo-web-browser component, either in the system browser or in an in-app browser integrated into the operating system (iOS SFSafariViewController or Android Chrome Custom Tabs). Only the privacy policies of the respective providers apply to data processing on the web pages opened in this way; we have no influence over this.
9.9 Transfers to third countries (consolidated overview)
In connection with the Linetrack Mobile App, personal data is transferred to the USA to the following recipients:
- Apple Inc., Cupertino, CA, USA – Purpose: app delivery via the App Store. Safeguards: Apple Inc. is certified under the EU-U.S. Data Privacy Framework; processing carried out independently.
- Google LLC, Mountain View, CA, USA – Purpose: app delivery via Google Play. Safeguards: Google LLC is certified under the EU-U.S. Data Privacy Framework; processing carried out independently.
- 650 Industries, Inc. (Expo), Palo Alto, CA, USA – Purpose: providing OTA updates (EAS Update). Safeguards: EU-U.S. Data Privacy Framework + EU Standard Contractual Clauses 2021/914, data processing agreement pursuant to Art. 28 GDPR.
- Functional Software, Inc. (Sentry), San Francisco, CA, USA – Purpose: crash and error reports. Safeguards: EU-U.S. Data Privacy Framework + EU Standard Contractual Clauses 2021/914, data processing agreement pursuant to Art. 28 GDPR.
You may request a copy of the Standard Contractual Clauses concluded with the aforementioned processors from us informally (contact: support@linetrack.de). We would like to point out that even where appropriate safeguards exist in third countries — in particular in the USA — a level of data protection fully comparable to that in the European Union cannot be guaranteed; in particular, there is a possibility of access by security authorities there, which can only be reviewed by courts to a limited extent.
9.10 Account deletion and data erasure
You may request the deletion of your Linetrack account and the associated personal data stored in our backend at any time. The following options are available to you for this purpose:
- Via our contact form at contact form, stating "account deletion" as the subject and providing the account data to be deleted (in particular the email address with which you registered, and, where applicable, your organisational affiliation).
- By email to support@linetrack.de, stating the account data to be deleted.
For security reasons, we reserve the right to carry out an identity check before final deletion, in order to prevent account deletion by unauthorised third parties. This may require confirmation via the email address stored in the account.
After receipt and verification of your deletion request, your personal data will be deleted without delay, and at the latest within 30 days, unless statutory retention obligations (in particular retention periods under commercial or tax law pursuant to Sections 147 of the German Fiscal Code (AO) and 257 of the German Commercial Code (HGB)) preclude this. Insofar as immediate deletion is not possible due to such retention obligations, processing of the data concerned will be restricted (Art. 18 GDPR) and finally deleted once the retention period has expired. Please note that any ongoing paid subscriptions must be cancelled separately; uninstalling the app does not automatically terminate an ongoing subscription.
Merely uninstalling the Linetrack Mobile App only results in the deletion of the data stored locally on your device (see Section 9.5), but not of your data stored in the Linetrack backend.
9.11 Data subject rights and contact
You may assert your rights as a data subject at any time and free of charge — in particular the right to information (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection (Art. 21 GDPR), as well as the right to withdraw consent given (Art. 7(3) GDPR) — against the responsible party named in Section 3 of this privacy policy. You also have the right to lodge a complaint with a data protection supervisory authority (for Linetrack: the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart).
9.12 Update and version
Version of this mobile app section: May 2026. We reserve the right to amend these data protection notices if the underlying processing operations, third-party services used, or legal framework change. The respective current version can be viewed at linetrack.de/datenschutz as well as within the Linetrack Mobile App itself under Settings › Legal › Privacy.