Imprint
Information pursuant to § 5 of the German Digital Services Act (DDG)
Christian Maniyar
Sophienstr. 131
76135 Karlsruhe
...
Disclaimer
Liability for content
The contents of our pages were created with the greatest care. However, we cannot guarantee the accuracy, completeness and timeliness of the content.
As a service provider, we are responsible for our own content on these pages under the general laws pursuant to § 7 (1) DDG. According to §§ 8 to 10 DDG, however, we as a service provider are not obliged to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.
Liability for links
Our offer contains links to external third-party websites over whose content we have no influence. Therefore, we cannot assume any liability for this third-party content. The respective provider or operator of the pages is always responsible for the content of the linked pages.
Copyright
The content and works created by us on these pages are subject to German copyright law. Reproduction, editing, distribution and any kind of use outside the limits of copyright require the prior written consent of the respective author or creator.
Privacy policy
Last updated: 8 August 2026
This version is a comprehensive revision accompanying the introduction of teams. Key changes: visibility of profile picture and collection location as well as the legal basis for each processing activity (section 7), aggregation of the map per postal code, notice to fellow collectors when a collection is assigned to a team later, details transmitted to OpenStreetMap (sections 4 and 5), and how the anti-abuse counters are stored and deleted (section 3b).
1. General information
The protection of your personal data is important to us. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
2. Hosting
This website is hosted by netcup GmbH.
When the website is accessed, the hosting provider automatically collects and stores information in so-called server log files, which your browser transmits automatically.
These are in particular:
- IP address
- date and time of the request
- page accessed
- browser type and version
- operating system
The processing of this data is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the technically error-free presentation and the security of the website.
You can find more information on data protection at netcup in the netcup privacy policy.
3. Cookies and reach measurement
This website uses no tracking, advertising or third-party cookies and integrates no external analytics or tracking services. To improve the platform, we collect anonymised usage statistics with no personal reference (details in Section 3a).
During login, only technically necessary cookies are set:
| Cookie | Purpose | Storage period |
|---|---|---|
kh_session |
Maintaining the login session in the browser | Until the browser is closed or you log out |
kh_remember_me |
Staying logged in permanently if the “Stay logged in” option was activated at login | 1 year (deleted immediately on logout) |
Both cookies contain only a randomly generated pseudonym that is assigned to your account on the server side; because of this assignment they qualify as personal data within the meaning of Art. 4 No. 1 GDPR. The kh_remember_me cookie is only set if you actively select the corresponding option when logging in. Until the changeover is complete, a browser that was already signed in may still hold an equivalent cookie under the former name remember_me; it is replaced by the new one and deleted on the next page load.
Security measures: Both cookies are configured as HttpOnly and Secure (no access by JavaScript, transmitted only via HTTPS). The session cookie kh_session uses SameSite=Strict, the kh_remember_me cookie SameSite=Lax, both to protect against CSRF attacks. The kh_remember_me token is stored on the server as a SHA-256 hash and rotated on every use.
Processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract) and § 25 para. 2 no. 2 TDDDG (technically necessary cookies).
Local display hint (localStorage): After login, the site additionally stores a technically necessary entry kh_auth in your browser's localStorage. It contains no name, no identifier and no contact details, only whether a login exists in this browser and whether it is an administrator account, so that the site can immediately show the appropriate navigation on load instead of briefly flashing the guest view. The entry never leaves your browser, is removed on logout and is not a prerequisite for using the site.
Language choice (localStorage): When you choose the language via the switcher in the header, the site remembers your choice in a technically necessary localStorage entry kh_lang (only the language code, e.g. “de”, “nl” or “en”). It contains no personal data and serves to direct you to the chosen language version on your next visit, provided the respective page is available in it. If you are logged in, we additionally store your language choice in your account (see Section 7): this is the only way e-mails and notifications can reach you in your language, and the choice then also applies in another browser. If you have not yet chosen a language, on your first visit the site evaluates your browser's language setting once and shows a notice if the page exists in that language; you are only redirected once you accept the notice. This evaluation happens only locally at the moment of the page load, is not stored and is not transmitted to us. A deliberate choice via the switcher always takes precedence.
Sort preference for collection lists (localStorage): If you change the sort order of a collection list (e.g. in the feed), the site remembers your choice per device in a localStorage entry kh_feed_sort — only the sort key is stored (created or date). It contains no personal data, never leaves your browser and is not a prerequisite for using the site.
3a. Anonymised reach measurement
To improve the platform, we collect anonymised usage statistics with no personal reference. Specifically, we count per day how often the individual page types were accessed (home, collections, map, leaderboard, team directory, team page, profile page, single collection, “add collection”, “my area”, “about us” and registration) and whether the access was made by a logged-in member or a guest. Only the page type is counted, never a specific team, person or collection. We also count how many logins and completed registrations take place per day.
Only the following fields are stored per event: date, event type, page slug, login status (yes/no), counter. No individual event recording takes place. All values are aggregated directly (UPSERT counter).
We do not store:
- no IP address
- no user agent / browser fingerprint
- no location or GPS data
- no user ID, no username, no session identifier
- no cookies are set for the statistics
Daily activity of logged-in members: To estimate how many distinct members are active per day, we generate a random salt (256-bit random value) per day and store a SHA-256 hash derived from it per day and member. The salt is deleted when the next day begins. After that, the stored hashes can no longer be assigned to a person. This creates neither a daily nor a permanent movement profile.
The evaluation takes place exclusively on our own server (first-party); no data is transmitted to third parties and no external analytics services are used. Since no personal data is processed, the processing does not require consent (no cookie banner required). The legal basis follows, insofar as applicable at all, from Art. 6 para. 1 lit. f GDPR (legitimate interest in improving the platform).
3b. Protection against misuse (rate limiting)
To protect against automated attacks (e.g. mass password guessing), we limit the number of certain requests (login, registration, password reset, entries, uploads, location queries) per time window. For this we store neither your IP address nor your account identifier in plain text, but exclusively a SHA-256 hash salted with a secret, server-side random value, plus a counter and a timestamp. The original value practically cannot be reconstructed from the hash. An entry loses all effect once its time window has expired; after 24 hours at the latest it is deleted by a daily clean-up run. If you delete your account, we remove the associated counters immediately. Processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in the security of the platform).
4. Map view and OpenStreetMap
On the “Map” page, on team pages and on profile pages with a shared personal map, map tiles from the OpenStreetMap service are loaded, operated by the OpenStreetMap Foundation (OSMF), St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom.
When the map tiles are loaded, your IP address is transmitted to the OSMF servers for technical reasons. OpenStreetMap does not set any cookies on your device. The transmission of the IP address is technically necessary to display the map and is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in the functional presentation of the core feature).
Geocoding for entries: When you save a collection, our server determines a normalised map location (city-centre coordinate) based on the entered postal code and country. For this, the geocoding service Nominatim of the OSMF is used on the server side. What is transmitted is exclusively the IP address of our server (not your personal IP address) as well as the postal code, country, the entered place name and the requested response language, no user identifier. The determined coordinate is stored and serves to display your entry on the map. Processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract).
Plausibility check of the postal code: While you fill in the entry form, we check in real time after you enter the postal code whether the combination of postal code and country can be assigned to an address, and show you the recognised place for confirmation. Our server (not your browser) also queries Nominatim for this; only the IP address of our server is transmitted, not your personal IP address. Neither the input nor the result is stored permanently. The response only serves the immediate display in the form. Processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract) or Art. 6 para. 1 lit. f GDPR (legitimate interest in plausible input).
You can find more information on data processing by OpenStreetMap in the OSMF privacy policy.
5. Location detection when adding an entry
When adding a collection, you can optionally use automatic location detection to pre-fill the postal code, place and country fields. This function is activated only when you actively click the location button. Your browser first asks for your explicit permission. Without this permission, no processing takes place.
If you give permission, your browser determines your location (GPS coordinates) and transmits it to our server. Our server forwards the coordinates server-side to the reverse geocoding service Nominatim of the OpenStreetMap Foundation (OSMF), St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom, solely to resolve the address (postal code, place, country). What is transmitted are the coordinates and the requested response language as well as the IP address of our server, not your personal IP address and no user identifier. This protection applies only to the geocoding process described here: when the map itself is displayed (see section 4), the map tiles are loaded directly by your browser, so your personal IP address is transmitted to OpenStreetMap.
The GPS coordinates are neither stored on our server nor written to the database. On the way from your browser to us they are transmitted in the body of the request and not as part of the address — which means they do not appear in the server logs of our hosting provider (section 2). On the onward request to the OSMF, however, they are technically part of the request address and may appear in the OSMF’s logs; their privacy policy governs the details. Only the address data derived from them (postal code, place, country) are used to pre-fill the form fields. When the form is subsequently submitted, a normalised city-centre coordinate is determined from postal code and country, as with every entry, and stored (see Section 4).
Processing is based on Art. 6 para. 1 lit. a GDPR (consent). You can revoke the browser permission granted at any time in your browser settings. You can find more information on data processing by the OSMF in the OSMF privacy policy.
6. Contact by email
If you contact us by email, the personal data you transmit (e.g. email address, name, content of the message) will be processed exclusively to handle your request.
Processing is based on Art. 6 para. 1 lit. b GDPR (contract or pre-contractual request) or Art. 6 para. 1 lit. f GDPR (legitimate interest in communication).
7. User account, collection data and email dispatch
To use certain functions (add collection, leaderboard), registration is required. In doing so, we collect the following data:
- Username (shown publicly)
- Email address (for account confirmation and system emails such as the password reset; not publicly visible, viewable in the admin area for running the platform)
- Password (stored encrypted, not in plain text)
- Registered collections (date, count, postal code, place, country as well as a normalised city-centre coordinate derived from them for the map view, optional photo, publicly visible; username and place are shown separately)
- Joint collections (additionally with title, number of people/participants and the time at which someone was added as a participant). Of these, the usernames of the participants are publicly visible — together with the collection location when assigned to a team. The time of being added is only stored and determines the order of display; it is not published anywhere.
- Thank-you reactions given to collections (which collection you thanked and when, with or without a photo; the total number of thanks per collection is publicly visible, individual reactions are currently not shown; see Section 9)
- Team memberships (which teams you have joined, your role in them and the time you joined; your username and your profile picture are shown publicly in the member list on that team's detail page) In exceptional cases the platform administration can add you to a team, for example if you clearly belong to it and cannot complete the join yourself; we notify you about it, and you can leave the team again at any time.
- Voluntary profile details (profile picture, display name, short introduction, place, website and social media links) as well as the two related visibility decisions (collection location public yes/no, map of collection spots visible to signed-in members yes/no; both off by default). Display name, introduction, place and links appear on your profile page, which is readable only by signed-in members. Your profile picture, by contrast, is publicly visible wherever you appear, just like your username: on collections, in the leaderboard and in team member lists. All details are optional and can be changed or deleted in your profile at any time; profile pictures are stored without GPS data like all photos (see section 8).
- Edits of other members' collections by team admins (who edited a collection of their own team, removed it from the team, or withdrew someone else's participation in it, and when). The record serves internal traceability; the person affected is notified about the event and learns which team triggered it. The username of the editing member is not shown to them. If the editing member's account is deleted, the record remains without any link to a person.
- The language setting of your account (only the chosen language code, e.g. “de”; it controls the language of e-mails and notifications and is not publicly visible)
- Technical account data (the time of registration and of email confirmation, your account role, its moderation status, short-lived confirmation and password reset codes, and internal markers so that notifications do not appear twice). None of this is publicly visible and it serves operations only: the moderation status allows us to temporarily remove an account from public view or block it in case of abuse — its contributions then no longer count. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interest in running a working, moderated platform), and Art. 6 para. 1 lit. b GDPR for the remaining data. All of it is deleted together with the account.
Transactional emails: As part of registration and for password resets, we automatically send emails to the address you provided (e.g. confirmation code, reset link). Dispatch takes place via the SMTP service of our hosting provider netcup. Your email address is used exclusively for the technically necessary dispatch and is not passed on to third parties. The language of these emails follows the language setting stored in your account. Processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract). System emails to the operators: In addition, the platform automatically notifies our own operations mailbox — twice for a registration (once the account has been created and once the email address has been confirmed), each time with the username and email address, and for collections awaiting approval because of their size, with the username, amount, location and date of the collection. These notices go exclusively to us as the operators, never to third parties; the legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in running a working, moderated platform).
Data minimisation for location: Usernames are public on the platform (e.g. in the leaderboards and feed). Your username and the collection location, however, are only shown together with your consent: for your own collections, the location appears only if you allow it on your profile in the “Collections” section (opt-in, off by default; the settings point you there). The general map shows collection spots only aggregated per postal code and without any name. If you assign a collection to a team, the location is shown together with the usernames of the participants. Assigning it to a team is deemed consent to this presentation. If this happens later on, we notify the other listed participants about it; they can remove themselves from the collection at any time and thereby remove their username again. Platform administrators can also add this assignment later, but only to a team the creator belongs to; in that case both the creator and the other participants are notified.
Map of your collection spots: On your profile you can additionally allow your own collection spots to appear there as points on a map (opt-in, off by default). Even once shared, this map is visible only to signed-in members, never publicly. Without sharing, the map section does not appear for other viewers at all; the points are not even transmitted and only you can see the map. It shows exclusively the stored normalised city-centre coordinates of your collections (see section 4), no GPS points from your device. You can withdraw the sharing on your profile at any time; the map then disappears for others immediately.
The legal bases depend on the processing in question: your account, signing in, registered collections, team membership, thank-you reactions and notifications are based on Art. 6 para. 1 lit. b GDPR (performance of a contract). The voluntary profile details, releasing the collection location and releasing your personal map are based on Art. 6 para. 1 lit. a GDPR (consent); you can withdraw them in your profile at any time. Art. 6 para. 1 lit. f GDPR (legitimate interest in running a working, moderated platform) covers the system emails to us mentioned above, the record of edits by team admins, and the review of particularly large collections before they are published. You can remove your account and all associated account data yourself at any time under Settings → Delete account.
When you delete your account: Your account data (username, email address, password) is deleted. Registered collections remain anonymised, i.e. without username and without any link to your person, for the community statistics; this includes the photos you uploaded to them. If you do not want to keep those photos, delete them in your own area before deleting the account, or write to us. Your participations in joint collections (entries in participant lists), your team memberships as well as your notifications are deleted completely; regarding thank-you reactions given, see Section 9. Voluntary profile details (profile picture, display name, introduction, place, links) are deleted together with the account, the profile picture also as a file. A record that you edited someone else's collection as a team admin remains, without any link to a person.
8. Photo upload and usage rights
Uploading a photo when adding a collection is voluntary. By uploading a photo, you agree that:
- the photo is stored and displayed publicly visible on the Kippenhelden platform,
- Kippenhelden receives the non-exclusive right to display the photo on the Kippenhelden platform.
The copyright remains with you as the uploading person. By uploading, you affirm that you hold the necessary rights to the image and that recognisably depicted persons agree to publication.
GPS data: Uploaded photos are automatically re-encoded when saved. In doing so, all EXIF metadata, including GPS coordinates, is removed. The stored version contains no location information.
Processing of the photo is based on Art. 6 para. 1 lit. a GDPR (consent through active upload). This consent can be revoked at any time with effect for the future by deleting the photo yourself in your profile under Collections or by contacting us by email.
9. Thank-you reactions to collections
As a logged-in member you can give a “thank you” (heart) to another member's collection — whether or not it contains a photo. In doing so, we store which member thanked which collection and when. The total number of thanks per collection is publicly visible, individual reactions are currently not shown.
Processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract: use of the platform functions).
When you delete your account: When you delete your account, your personal data is removed. Reactions such as thanks that you gave to others' public contributions remain as anonymous counters and are no longer linked to you.
10. Notifications
As a logged-in member, you see a notification bell in the header of the site. Through it we inform you about platform-wide news (e.g. new features, milestones reached), about other members thanking you for your collections, and about changes to your own collections: when a team admin has edited one of your collections or removed it from the team, or when your participation in a collection has been withdrawn. For thanks received, we process exclusively the aggregated number; the identity of the thanking persons is not shown to you. For each notification we store its text, the time, a reference to the collection or team concerned, and whether you have already read it, so that it does not appear as unread again. They are visible to you alone.
No additional personal data is collected for this that would not arise anyway in the course of using the platform, and no additional cookies or third parties are used. Processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract: use of the platform functions). When you delete your account, your notifications are also removed.
11. Your rights
You have the right at any time to:
- information about your stored personal data
- rectification of incorrect data
- erasure or restriction of processing
- objection to processing
- data portability
You also have the right to lodge a complaint with a competent data protection supervisory authority.
If you have any questions about data protection, you can contact us by email at any time.