How it works Features Pricing Blog Login Get Started
Legal

Privacy Policy

// Last updated: July 2026 · in accordance with GDPR and the Austrian DSG
This is a courtesy translation of the German-language privacy policy. The German version (Datenschutzerklärung) is legally binding.

1. Controller

The controller within the meaning of the GDPR is:
Lukas Pratter
Kirchberg 53, 8422 Sankt Nikolai ob Drassling
Austria
Email: lukas.pratter@gmail.com

Further details can be found in the Legal Notice.

2. What Data We Process

2.1 Registration & Account

When you create a ReiseSOS account, we process: first name, last name, date of birth, PIN (stored exclusively as a bcrypt hash, never in plain text), a self-chosen security question with its answer (also stored only as a hash), and an email address. The email address is not used for login, but solely for email confirmation and account recovery if you forget your PIN or security answer.

2.2 Emergency Contacts & Optional Additional Data

You can store the names and phone numbers of emergency contacts. With Premium access, you can additionally store optional details for a bank hotline, insurance hotline, hotel (name, address, phone, email) and travel documents (flight number, booking number, notes). Providing this information is voluntary and serves solely to display it back to you in an emergency.

2.3 Security Log (Audit Log)

To detect unauthorized access attempts, we log the following for every login attempt: event type (e.g. successful/failed PIN entry), IP address, browser identifier (user agent), and timestamp. These entries are automatically deleted after 90 days and are visible to you in the Dashboard under "Recent login attempts".

2.4 Payment Data

For a Premium purchase (selectable term: 7 days/€0.99, 14 days/€1.50, 30 days/€2.90, 90 days/€7.80, or 365 days/€20), we redirect you to our payment provider Stripe (Stripe Payments Europe, Ltd.). Card details are processed exclusively by Stripe and never pass through our own servers at any point. We only receive confirmation from Stripe that a payment was successful, in order to activate your Premium access. Further details are governed by Stripe's privacy policy.

2.5 Technical Data in Your Browser

Your session token (proof of login) is stored in your browser's sessionStorage and is automatically cleared when the tab is closed – deliberately not in localStorage, so that no persistent login remains on borrowed or public devices. Your language preference (DE/EN) and your cookie decision (see 2.6) are stored in localStorage. These technically necessary storage operations do not require consent.

2.6 Cookies, Google Analytics and Meta Pixel

On your first visit, we show you a cookie banner. Only once you have explicitly given your consent there do we load Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing may also be carried out by its parent company Google LLC, USA) for anonymized reach measurement (e.g. page views, time on page), as well as the Meta Pixel (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; processing may also be carried out by its parent company Meta Platforms, Inc., USA) to analyze and optimize our Facebook/Instagram ads. IP anonymization is enabled for Google Analytics. Without your consent, neither the scripts are loaded nor the corresponding cookies set.

The legal basis in each case is your consent (Art. 6(1)(a) GDPR, § 165(3) Austrian Telecommunications Act (TKG)). The cookies set in this process (including _ga, _ga_* from Google Analytics as well as _fbp, _fbc from the Meta Pixel) have a lifetime of up to 2 or 3 months (Meta) or up to 2 years (Google). Since Google LLC and Meta Platforms, Inc. are based in the USA, this may involve a data transfer to a third country; both providers have either adopted the EU-US Data Privacy Framework or otherwise rely on the EU Standard Contractual Clauses for the transfer.

You can withdraw your consent at any time with effect for the future (Art. 7(3) GDPR): via the "Cookie settings" link in the footer of every page. If you withdraw, any tracking cookies already set are deleted and no further data is collected.

3. Purposes and Legal Bases

  • Providing and managing your account, displaying your emergency data: Art. 6(1)(b) GDPR (performance of a contract)
  • Processing the Premium purchase: Art. 6(1)(b) GDPR
  • Detecting and preventing abuse (audit log, rate limiting, account locks): Art. 6(1)(f) GDPR (legitimate interest in the security of the Service)
  • Fulfilling legal obligations (e.g. retention of invoice data): Art. 6(1)(c) GDPR
  • Reach measurement via Google Analytics and Meta Pixel, only after consent in the cookie banner: Art. 6(1)(a) GDPR (consent)

4. Recipients of Your Data

Your data is shared with the following categories of recipients, to the extent necessary for the respective purpose:

  • Hosting: operation of the web application on a server provided by Hetzner Online GmbH, located in Falkenstein (Germany)
  • Database: MongoDB Atlas (MongoDB, Inc.), server location AWS Frankfurt am Main, eu-central-1 (EU)
  • Stripe (payment processing), if you make a Premium upgrade – partly based outside the EU (USA); Stripe has adopted the EU Standard Contractual Clauses
  • Email delivery (confirmation/recovery links) via World4You Internet Services GmbH (Austria)
  • Google Analytics (Google Ireland Limited or Google LLC, USA), only if you have given consent in the cookie banner (see 2.6)
  • Meta Pixel (Meta Platforms Ireland Limited or Meta Platforms, Inc., USA), only if you have given consent in the cookie banner (see 2.6)

We do not transfer data to any other third parties or for advertising purposes beyond what is described above.

5. Retention Period

We store account data for as long as your account exists. Audit log entries are automatically deleted after 90 days. You can delete your account, along with all associated data, yourself and immediately at any time: in the Dashboard under "Delete account" → "Delete account permanently" (confirmation with your PIN required). Alternatively, you can also contact the email address stated above.

6. Your Rights

Under the GDPR, you have the following rights:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of consent already given, with effect for the future (Art. 7(3) GDPR), e.g. your consent to Google Analytics/Meta Pixel via "Cookie settings" in the footer
  • Lodging a complaint with a supervisory authority (Art. 77 GDPR) – in Austria, the competent authority is: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at

You can exercise many of these rights directly in the Dashboard yourself (view or edit your data, or remove contacts). For anything else, please contact the address given above.

7. Voluntary Nature of the Information

The registration data (name, date of birth, PIN, security question, email) is required to use the Service. Emergency contacts as well as bank, insurance, hotel and travel data are voluntary and can be added, changed or removed at any time in the Dashboard.

8. Changes to this Policy

We update this privacy policy whenever the Service or legal requirements change. The current version is always available on this page.