Privacy policy for runschmiede.de and runschmiede.com
Last updated: October 2026. This policy covers the project pages and the customer account. For orders in the shop, the shop’s privacy policy (German) also applies. In case of doubt, the German version of this policy prevails.
1. Controller
Rafael Kinder, Runschmiede, Manitiusstraße 1, 01067 Dresden, Germany
Phone +49 157 30206668, email kontakt@itservice-kinder.de
2. Visiting the website
When you open our pages, our hosting provider Henrik Kramer e.K. (Prepaid-Hoster.de), Kurpromenade 48, 23743 Grömitz, Germany, processes technically necessary data: IP address, date and time, page requested, browser and operating system. This serves delivery and security of the website (Art. 6(1)(f) GDPR). The servers are located in Germany. Log data is deleted after 14 days at the latest. A data processing agreement is in place with the provider.
Fonts are served from our own server. We do not use any analytics, tracking or advertising tools.
3. Cookies and local storage
When you log in, we set a session cookie to keep you logged in. It is deleted when you close your browser. If you choose the dark design, your browser remembers this setting locally. Both are strictly necessary for the function you requested (§ 25(2) no. 2 TDDDG).
4. Customer account
For your account we process your name, email address, an encrypted password (hash) and your chosen language, as well as the times of registration and confirmation. To prevent abuse, we log failed login attempts in hashed form for 24 hours. Legal bases are Art. 6(1)(b) GDPR (providing the account) and Art. 6(1)(f) GDPR (security).
Your account shows the orders from our shop that were placed with the same email address.
5. Bot tokens
If you enter the token of your own Telegram bot, we store it encrypted and use it solely to operate your bot (Art. 6(1)(b) GDPR). It is deleted when you delete your account or the contract ends.
6. Invoices and payment details
To display your invoices and next charge, we retrieve them from Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. “Manage payment details and subscriptions” takes you to Stripe’s customer portal. Stripe may also transfer data to Stripe, Inc. in the USA (EU-US Data Privacy Framework or EU Standard Contractual Clauses). Legal basis is Art. 6(1)(b) GDPR.
7. Emails
We send confirmation links, password links and account notices via the mail server of our email provider, STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (Art. 6(1)(b) GDPR).
8. Retention
We keep account data until you delete your account. Unconfirmed registrations are deleted after 30 days. Invoice data is subject to statutory retention periods of up to ten years.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR). You can delete your account yourself at any time under “Settings”. You may also lodge a complaint with the supervisory authority: Die Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden, Germany.
10. Right to object
Where we process data based on legitimate interests (Art. 6(1)(f) GDPR), you may object to this processing at any time on grounds relating to your particular situation.