Last updated: 20 September 2026
1. Controller
EITCons GmbH
Am Heidekrug 5
40724 Hilden
Germany
Email: support@vacharapp.com
Privacy requests: open the contact form
EITCons GmbH is the controller within the meaning of the General Data Protection Regulation (GDPR) for the VACHAR app, vacharapp.com, and the associated VACHAR services.
2. Scope and sources of data
This notice applies to the VACHAR mobile app, the public VACHAR websites, support, and VACHAR application interfaces. We obtain data in particular:
- directly from you, for example when you register, create a profile, publish a Connect, communicate, or contact support;
- automatically from your device and technical use, including device, log, and security data;
- from platform operators, particularly for app subscriptions and push delivery;
- from other users when they communicate with you, report content, or interact with your content.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide the account, profile, Connects, search, chat, contact sharing, and Premium | Art. 6(1)(b) GDPR |
| Voluntary functions and consent where expressly requested | Art. 6(1)(a) GDPR |
| Tax, commercial, consumer-protection, and regulatory duties | Art. 6(1)(c) GDPR |
| IT security, prevention of abuse and fraud, moderation, legal defence, and operational stability | Art. 6(1)(f) GDPR |
Our legitimate interests include the secure, reliable, and lawful operation of the platform, protection of users and systems, and prevention of spam, fraud, manipulation, and unauthorised access. Where processing is based on consent, you may withdraw it at any time with effect for the future.
4. Registration, sign-in, and account security
For a VACHAR account, we process in particular the user ID, email address, optional telephone number, sign-in and confirmation status, timestamps of security-relevant events, and technical authentication and session data. One-time codes and confirmation links are used for sign-in, confirmation of email addresses or telephone numbers, and account recovery.
To document acceptance of the Terms of Use and Community Guidelines, we may store the user ID, version of the legal texts, language, app version, time, and technical evidence. This supports contract performance, legal accountability, and the establishment or defence of legal claims.
5. Profile, Connects, and publicly visible content
Depending on your use, we process profile details such as alias, display name, profile image, place, biography, optional social links, and Connects you publish with text, images, category, price, validity, and location reference. Information marked as public may be visible to other users and discoverable through search or map functions.
Do not publish sensitive data, identity documents, private contact details, or information about another person unless this is necessary and lawful for the relevant Connect.
6. Location and maps
If you grant location permission, VACHAR may use the device location supplied by the operating system to show nearby content, calculate distances, or preselect a location. Where supported, you can select a place manually instead.
Your precise device location is not automatically displayed to other users as a live location. Published Connects may nevertheless include a place, map point, distance, or search radius selected by you. Maps are provided through Apple Maps on iOS and Google Maps on Android. Those providers may process technical data under their own privacy terms.
You can change location permission in iOS or Android at any time. Location-dependent functions may then be limited.
7. Camera, photo library, and images
VACHAR accesses the camera or selected media only within the permissions you grant. Profile, Connect, and chat images selected or captured by you are processed for the function you choose and may be stored in VACHAR file storage.
The app does not receive unrestricted access to all media in your library. iOS and Android allow you to limit or revoke access.
8. Local photo and movement check
The current iOS version can optionally analyse two front-camera images taken in quick succession locally on the device. Apple Vision functions evaluate only technical characteristics such as the number, position, and size of a face and a change in head pose.
This function does not transmit the images or analysis values to VACHAR, Supabase, or AWS and does not store them in the VACHAR backend. Temporary capture files are managed by the operating system inside the app sandbox. The check does not create a biometric identity profile, does not compare images with identity documents or reference databases, and does not set a server-side identity status.
If VACHAR introduces a different identity or biometric verification process in the future, we will provide separate advance information about the method, legal basis, recipients, and retention, and will obtain explicit consent where required.
9. Messages, attachments, and contact sharing
For chats, we process participants, message content, attachments, reactions, timestamps, delivery or read status, and technical identifiers. Messages are intended for the relevant participants. Limited administrative access may be necessary for security, troubleshooting, or handling reported content.
Stored email addresses and telephone numbers are not automatically shown to other users. They are shared only through the designated contact-sharing function. Removing a conversation from your own view does not necessarily erase the other participant’s copy or evidence that must lawfully be retained.
10. Push notifications
If you allow push notifications, we process an Expo push token, platform, device model or device name, app version, delivery status, and technical metadata associated with the notification. Delivery uses the Expo Push Service and then Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM).
You can disable notifications in the app or system settings. Push tokens are disabled or deleted upon sign-out, deactivation, confirmed invalidity, or account deletion.
11. Premium, in-app purchases, and payment data
Where Premium subscriptions are offered, the purchase is handled by the relevant app store. In the current iOS implementation, Apple processes the payment. VACHAR does not receive full credit-card or bank details; it receives in particular the product identifier, signed transaction information, transaction and original transaction IDs, purchase or term status, and the association with the VACHAR account.
These data are processed for contract performance, activation, restoration, fraud prevention, accounting, and legal obligations. The store operator’s privacy terms also apply to payment processing.
12. Support, reports, and moderation
For contact, support, or privacy requests, we process the contact details, subject, message, attachments, handling status, and correspondence you provide. Reports about users or content may additionally include the affected content, reasons, review outcome, and measures taken.
This processing is used to handle your request, enforce the rules, protect the community, comply with legal duties, and establish or defend legal claims.
13. Security, abuse prevention, and logs
To protect the platform, we may process IP address, device and session data, timestamps, failed access attempts, security-relevant actions, reports, and risk indicators. Automated rules may flag or temporarily limit unusual activity. VACHAR does not make decisions producing legal or similarly significant effects solely by automated means within the meaning of Art. 22 GDPR.
After a deletion request, normalised one-way values (HMAC fingerprints) derived from the email address, telephone number, and requesting IP address may be retained temporarily. They are used only to detect abuse, circumvention of justified restrictions, and automated re-registration during the security period; the original values cannot readily be recovered from them.
14. Website, server logs, and device access
When you access vacharapp.com or api.vacharapp.com, our servers process technically necessary connection data, including IP address, date and time, requested URL, HTTP status, transferred volume, referrer, and browser or device details. This is required to deliver the service, identify errors, and defend against attacks.
The public website currently does not use advertising, audience measurement, or profiling cookies. Information is stored on or accessed from your device only where technically necessary for a digital service expressly requested by you under section 25(2)(2) TDDDG. If optional technologies are introduced, any legally required consent will be obtained before activation.
15. Recipients and technical providers
Within VACHAR, personal data are available only to persons who need them for operation, support, security, accounting, or legal tasks. We use in particular:
- Supabase, Inc. – authentication, database, file storage, Realtime functions, and server-side functions. VACHAR’s primary project region is AWS eu-north-1 (Stockholm, Sweden).
- Hetzner Online GmbH – hosting for the VACHAR website, API, email infrastructure, and backup systems in Germany or the EU.
- 650 Industries, Inc. (Expo) – technical app infrastructure and push-message relay.
- Apple Inc. / Apple Distribution International Ltd. – App Store, in-app purchases, APNs, Apple Maps, and operating-system services on Apple devices.
- Google Ireland Limited / affiliated Google companies – Google Play, FCM, and Google Maps on Android devices where the relevant function is used.
Other recipients may include advisers, payment or communications providers, courts, public authorities, and law-enforcement bodies where required by law, necessary for legal defence, or necessary to protect a person. Processors are bound by agreements under Art. 28 GDPR where required.
16. International transfers
Some providers or their subprocessors are based outside the European Economic Area. Where personal data are transferred to a third country, we rely on an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for appropriately certified recipients, or on EU Standard Contractual Clauses and supplementary safeguards. You may request information about the applicable safeguards through our privacy contact.
17. Retention and deletion
We keep personal data only for as long as necessary for the relevant purpose or while legal duties or legitimate legal-enforcement interests apply. The following criteria are particularly relevant:
- Account and profile: for the life of the account; following a confirmed deletion request, access is blocked, public profile data are removed or anonymised, and active Connects are archived.
- Account deletion and security period: final technical deletion normally takes place after three months. The deletion request and HMAC security fingerprints are retained until that period expires and are then deleted unless a specific legal or security matter justifies longer retention.
- Connects and media: until deletion, expiry, or archiving; security or evidential copies only for as long as required for a specific matter.
- Chats: while required for communication, the account function, or handling reports. The rights and copies of other participants remain protected.
- Push data: until deactivation, invalidity, sign-out, or account deletion; delivery evidence only for the operationally necessary review period.
- Support and reports: until closure and then for an appropriate evidence and limitation period depending on the matter and risk.
- Contract, purchase, and accounting data: for the applicable commercial and tax retention periods.
- Server and security logs: until no longer required for operation, troubleshooting, or attack detection; for a specific security incident until investigation and possible enforcement are complete.
- Backups: overwritten in rolling backup cycles. Data already marked for deletion are not restored to active production use.
18. Security
We use appropriate technical and organisational measures, including encrypted transport, role-based access, Row Level Security in the backend, separated administrative access, security logging, spam and attack protection, backups, and regular system updates. Absolute protection against every risk cannot be guaranteed.
19. Your rights
Subject to the legal conditions, you have rights to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). You may withdraw consent at any time with effect for the future.
Where processing is based on legitimate interests, you may object for reasons arising from your particular situation. You may object to direct marketing at any time without giving particular reasons if VACHAR introduces it in the future.
Further explanations and direct routes are available on our User Rights page. Requests may be submitted through the contact form or by email. Where there are justified doubts, we may request proportionate proof of identity.
20. Right to complain
You may lodge a complaint with a data protection supervisory authority. The authority with particular responsibility for EITCons GmbH is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
PO Box 20 04 44
40102 Düsseldorf
Germany
www.ldi.nrw.de
21. Minors
VACHAR is intended exclusively for persons aged 18 or over. If we become aware that an account is used by a minor contrary to this requirement, we may review, restrict, or delete it.
22. Changes to this notice
We update this notice when functions, data flows, providers, or legal requirements change. Material changes will be communicated appropriately. The current version is available at vacharapp.com/en/privacy/.
