Privacy Policy

As of: August 2026

Note: The legally binding version is the German original. This English translation is provided for convenience only.

This privacy policy applies to the website camperproof.app and the CamperProof application provided through it (web app/PWA, together the “service”). It informs you which personal data we process, for what purpose, on what legal basis, and to which recipients it may be disclosed.

1. Controller

Daniels Digital Solutions UG (haftungsbeschränkt)
Marcel Daniels (Managing Director)
Lindenweg 27, 67346 Speyer, Germany

Email: datenschutz@camperproof.app

We have not appointed a data protection officer, as the legal requirements for doing so are not currently met.

2. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object (Art. 21). Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR); this does not affect the lawfulness of processing before the withdrawal. To exercise your rights, an informal message to datenschutz@camperproof.app is sufficient. You can also view, export and delete most of your data directly in your account (sections 5 and 6).

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, poststelle@datenschutz.rlp.de. You may also contact the authority of your habitual residence.

3. Accessing the website (server log files) and hosting

When you access the website and web app, our hosting provider automatically collects information transmitted by your browser (browser type/version, operating system, referrer URL, date and time of access, IP address — generally processed in shortened/anonymized form).

  • Purpose: provision, stability, and security of the service
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in error-free, secure provision)
  • Retention: logs are stored briefly and then deleted, unless required to investigate security incidents.

Website hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Servers are in EU data centers (Germany/Finland). A DPA under Art. 28 GDPR is in place. The app (backend, database, file storage) runs on Supabase (section 8).

4. Registration and user account

To use CamperProof beyond the publicly accessible area, you create an account. We process:

  • email address
  • password (stored only as a cryptographic hash; not readable by us in plain text)
  • time of registration and technical login metadata (e.g. login times)
  • your account status (free basic use, Premium)

Purpose: provision and management of your account, authentication, performance of the usage contract. Legal basis: Art. 6(1)(b) GDPR (performance of the contract under our Terms of Use). Retention: for the duration of your account; after deletion, your account and content data are deleted unless statutory retention obligations apply (section 6). Account and authentication are technically provided via our backend provider Supabase (section 8).

5. Content data: your camper inventory

The core of CamperProof is documenting your camper inventory. We process the content you enter or upload to provide the service:

  • vehicle data (type, model, VIN, optionally insurance details)
  • inventory items (name, category, serial numbers, purchase values/dates)
  • photos of items and receipts/proofs of purchase (image/document files)
  • the structured PDF reports you generate from them (Premium)

This information may contain personal data (e.g. if receipts bear your name or photos show people). You are responsible for the content you enter and its lawfulness; please do not enter content you are not entitled to use.

Purpose: providing the documentation and reporting functions. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Retention: until you delete the content or your account. Database content and files are stored via Supabase in an EU region (section 8).

6. Data export and deletion

You can view, export (in a common format) and delete the data stored in your account at any time. If you delete your account, your account and content data (including uploaded photos and receipts) are deleted, unless statutory retention obligations (e.g. for invoicing/payment data) apply. Backups are overwritten in the usual backup cycles. One exception applies to a declaration of withdrawal submitted through the withdrawal button: it is retained as evidence of an exercised right — see section 7 for details.

7. Payment processing (Premium) via Paddle

The paid purchase of CamperProof Premium (monthly subscription or Lifetime) is handled by Paddle.com Market Limited, registered in England and Wales under company number 8172165, 30 Old Bailey, London EC4M 7AU, United Kingdom (“Paddle”), as the Merchant of Record. Paddle is therefore the seller of the Premium licence and your contracting party for the purchase, issues the invoice and remits VAT.

During checkout, Paddle processes the payment and billing data you enter (e.g. name, email, billing address/country, payment method data, transaction and tax information) under its own data protection responsibility. Full card data is not stored by us. We receive from Paddle the information needed for contract handling and accounting (e.g. purchase status, invoice and subscription data).

Purpose: handling the Premium purchase, invoicing, subscription management, accounting and tax obligations. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (statutory retention/tax obligations). Retention: invoice, payment and accounting data are stored in line with statutory retention periods (generally 8 or 10 years under § 257 HGB and § 147 AO) and deleted thereafter. Third-country transfer: Paddle is based in the UK, for which an EU Commission adequacy decision exists. See Paddle's privacy policy: paddle.com/legal/privacy.

Consent before purchase: before you complete a paid purchase, we ask you for two express declarations — that we may start performance immediately, and that you know when your right of withdrawal expires (§ 356(4), § 357(8) BGB). For this we store your user id, the plan chosen, the version of the wording shown, the language and the time. Purpose: proof of these legally required declarations. Legal basis: Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(b) GDPR. You can see these records in your settings under “Premium”; they are included in your data export.

Withdrawal button: via Withdraw from contract you can declare your withdrawal without logging in (§ 356a BGB). We store the email address you provide, optionally an order reference and a free-text message, the language, the time of receipt and your IP address; where the address can be matched to an account, its id as well. Purpose: receiving your declaration, the legally required confirmation of receipt, forwarding it to Paddle as the seller, and proving that and when your declaration was received. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in being able to evidence the receipt of an exercised right and to defend against claims; providing the withdrawal function itself is required of us by § 356a BGB. Important: because a declaration of withdrawal may also come from someone without an account, and because it is the evidence of an exercised right, this record is retained if you later delete your account — the link to the account is removed, but the email address you provided remains stored (Art. 17(3)(e) GDPR). This is the only exception to the immediate deletion described in section 6. Retention: we delete a declaration of withdrawal at the end of the third year after it was received. This period follows the standard limitation period (§§ 195, 199 BGB) — after that no one can derive claims from the matter and the legitimate interest ends.

8. Backend, database and file storage: Supabase

To operate the app — in particular accounts/authentication, database and storage of uploaded files (photos, receipts) — we use the Supabase platform, operated by Supabase, Inc. (USA) or its affiliates. Data is stored and processed in an EU region (AWS eu-central-1, Frankfurt am Main). A data processing addendum under Art. 28 GDPR is in place.

Third-country note: Supabase, Inc. is a US-based company. Even with storage in an EU region, access from a third country (USA or Singapore) during operation and support cannot always be excluded. For such transfers, Supabase relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary measures. Details and the current sub-processor list are provided by Supabase: supabase.com/legal/dpa.

Purpose: technical operation of the service (accounts, database, file storage). Legal basis: Art. 6(1)(b) GDPR (contract); for security and stability Art. 6(1)(f) GDPR.

9. Transactional emails

To perform the usage contract we send necessary transactional/system emails, e.g. to confirm registration, reset your password, or notify you of important account changes. We process your email address and the respective occasion/content of the email.

Purpose: secure provision and management of your account. Legal basis: Art. 6(1)(b) GDPR. Email provider: Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin; parent company: Brevo SAS, France). Sending is via servers within the EU; a DPA under Art. 28 GDPR is in place.

10. Newsletter / info emails and free downloads (double opt-in)

On the website you can sign up with your email address for product information or to receive free content (e.g. guide checklists/templates). We process your email address, date/time of sign-up and confirmation, and the IP address used (to prove consent).

Double opt-in: only after you confirm via the link in the confirmation email do we add you. Purpose: sending the requested content and information about the product and news. Legal basis: Art. 6(1)(a) GDPR (consent); logging serves as proof (Art. 6(1)(f) GDPR). Retention: until you unsubscribe/withdraw.

Newsletter via the download form: when requesting a free download you can also opt into the newsletter via a checkbox. In that case confirming the download email is enough — that click also enrols you in the newsletter list; we do not send a separate newsletter confirmation email for this path. If you leave the box unticked you only receive the requested download. If you instead sign up for the newsletter directly in the app, the double opt-in described above with its own confirmation email applies.

Email provider: Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany; parent company: Brevo SAS, France). Processing on servers within the EU; a DPA under Art. 28 GDPR is in place. Unsubscribe at any time via the link in every email or by messaging datenschutz@camperproof.app. Brevo's privacy policy: brevo.com/legal/privacypolicy

11. Cookieless analytics

For statistical evaluation of website usage we use cookieless, privacy-friendly analytics with Plausible Analytics, self-hosted (Community Edition) on our own Hetzner servers in Germany; no data is transferred to third parties.

No cookies are set and no personal profiles are created; only aggregated, anonymized metrics are recorded (e.g. page views, referrer, approximate region, browser/device type). Individual visitors cannot be identified; the IP address is not stored permanently.

  • Purpose: statistical evaluation to improve our offering
  • Legal basis: Art. 6(1)(f) GDPR. As the cookieless operation neither stores information on nor reads information from your device, the consent requirement of § 25(1) TDDDG does not apply; no consent is therefore required.

12. Error and availability monitoring (Sentry)

To detect and fix technical errors and outages during operation, we use the Sentry service. When an error occurs, only technical error data is transmitted to Sentry: error type and message, the program flow (stack trace), the affected page or component, rough environment information (e.g. browser or server type), and a timestamp.

No cookies are set. Personal data is actively removed before transmission: the IP address is not stored; no user identifiers, email addresses, request contents or form data are transmitted, and in particular no inventory or vehicle data (e.g. serial numbers, purchase prices, VIN, license plates or receipt contents). Only error monitoring takes place — no performance measurement and no session recording (“session replay”).

  • Purpose: detecting, analyzing and fixing errors to ensure the stability and security of the service
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation). As no device information beyond the technically necessary is stored or read, no consent is required under § 25(2) TDDDG.
  • Provider: Functional Software, Inc. (Sentry), a US-based company. Processing takes place in a data-center region within the EU (EU data region). A data processing addendum under Art. 28 GDPR is in place. Where access from a third country (USA) during operation and support cannot be excluded, such access is based on the Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary measures.

13. Functional cookies / local storage

We store technically necessary information such as your language selection (functional cookie) and the session/authentication tokens required for login (e.g. in your browser's local storage). These contain no advertising-tracking data and serve only the function of the service. Legal basis: § 25(2) No. 2 TDDDG together with Art. 6(1)(f) or (b) GDPR (for login/session functions).

14. Recipients / processors

We only disclose personal data to the following recipients:

ProviderPurposeRoleLocation
Hetzner Online GmbHWebsite hostingProcessor (DPA)Germany (EU)
Supabase, Inc.Backend, database, authentication, file storageProcessor (DPA)EU region (Frankfurt); US-based provider
Paddle.com Market LimitedPremium sale and payment processing (Merchant of Record, seller)Own controllerUnited Kingdom (adequacy decision)
Sendinblue GmbH (Brevo)Transactional emails, info emails/downloadsProcessor (DPA)Germany / EU
Functional Software, Inc. (Sentry)Error and availability monitoringProcessor (DPA)EU data region (Frankfurt/Amsterdam)
Plausible (Community Edition, self-hosted)AnalyticsSelf-operatedOwn Hetzner servers (EU)

15. Third-country transfers

Data is generally held in the EU. A third-country element may exist in the following cases:

  • United Kingdom (Paddle): an EU Commission adequacy decision exists for the UK; an adequate level of protection is recognized.
  • USA/Singapore (Supabase, Inc. as a US-based provider): where access from a third country during operation/support cannot be excluded, the transfer is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary measures.
  • USA (Sentry / Functional Software, Inc. as a US-based provider): processing takes place in an EU data region; where access from the USA during operation/support cannot be excluded, it is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary measures.

No further transfers to third countries take place.

16. No automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

17. Data security

We use TLS encryption (https) when the service is accessed. To protect your data we apply appropriate technical and organizational measures, including access controls, tenant separation at the database level, encryption of stored data, and regular backups.

18. Updates and changes to this privacy policy

This privacy policy is dated August 2026. As the service evolves or due to changed legal/regulatory requirements, an update may become necessary. The current version is available at camperproof.app/datenschutz.

Back