Privacy policy
This English version is provided for convenience. Only the German version is legally binding.
Information on the processing of personal data pursuant to Art. 13 GDPR
1. Controller
The controller responsible for data processing on this website and in the hmstr app is:
Daniel König
Im Langen Feld 3
30880 Laatzen
Germany
Email: hmstr@tada.ae
No data protection officer has been appointed, as the legal requirements for this are not met.
2. General
This website is deliberately designed to collect as little data as possible. It sets no cookies, uses no analytics or tracking services, does not embed external fonts or content and contains no advertising. There is no profiling and no automated decision-making.
The light or dark appearance initially follows your device setting. If you change it using the switch in the menu, your choice is stored only locally in your browser (localStorage) so that it is kept when you move between pages. It is not transmitted to us and can be removed at any time by clearing the site data in your browser. The legal basis is § 25 (2) no. 2 TDDDG, as storage is strictly necessary for the function you requested. Switching between German and English uses separate page addresses and is not stored.
3. Server log files
When you visit this website, the web server automatically processes data transmitted by your browser:
IP address, date and time of access, name of the file retrieved, amount of data transferred, HTTP status code, browser and operating system used, and the previously visited page (referrer).
Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technically error-free operation and the security of the website. The data is deleted after 30 days and is not combined with other data sources.
4. Hosting
The website and the app's notification server are hosted by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The provider processes the data mentioned in sections 3 and 6 on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place.
5. Contact by email
If you contact us by email, we process your details to handle your enquiry. The legal basis is Art. 6 (1) (f) GDPR or, for contract-related enquiries, Art. 6 (1) (b) GDPR. The data is deleted as soon as it is no longer needed and no statutory retention obligations apply.
6. The hmstr app
You do not need an account with us, and there is no registration. The app contains no advertising and no analytics or tracking tools.
Storage and sharing via iCloud
Your lists, storage places and items are stored in your iCloud account with Apple. If you share a list, this is done via iCloud's sharing feature. We have no access to this data. Apple's privacy policy applies to processing by Apple: apple.com/legal/privacy.
Notifications
So that members of a shared list are informed about changes and low supplies, the app sends the following to our notification server: a device token issued by Apple, an identifier of the list, a pseudonymous user identifier, the selected language and, for changes, the name of the item concerned, the remaining quantity and the configured minimum stock. Notifications are delivered via Apple's push service.
The legal basis for notifying the other members is Art. 6 (1) (b) GDPR, as this is part of the sharing feature you use. You can turn off receiving notifications at any time in the app or in the system settings.
This data is stored on the notification server for as long as the app is installed on your device. After you uninstall the app, Apple reports the device token as invalid at the next delivery attempt. We then delete the associated data.
Product data from Open Food Facts
When you scan a barcode, the app sends this barcode to Open Food Facts (Open Food Facts, France) to retrieve the product's name, brand and photo. For technical reasons, your IP address is also transmitted to the provider. The lookup is enabled by default and can be turned off in the app's settings.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is to spare you from typing in product details. Provider's privacy information: openfoodfacts.org/privacy.
7. Your rights
You have the right at any time to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR).
You can withdraw any consent you have given at any time with effect for the future. A message to the address given in section 1 is sufficient to exercise your rights.
8. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible is the one at your habitual residence or at the controller's registered location:
Der Landesbeauftragte für den Datenschutz Niedersachsen
Denis Lehmkemper
Prinzenstraße 5, 30159 Hannover, Germany
9. Status and changes
This privacy policy is as of October 2026. Changes may become necessary as the website or the app evolve or legal requirements change. The current version is always available on this page.