feed a cat

Privacy policy of the feed a cat app

1. Scope of application, general information

The protection of your personal data is very important to us. In all data processing procedures (e.g. collection, processing and transmission) we strictly comply with the statutory data protection regulations, in particular the General Data Protection Regulation (GDPR) and the Federal Data Protection Act.

The data processing of the app is carried out by the app operator as the person responsible for data protection. 

Name and address of the App operator data protection officer as data controller

The person responsible within the meaning of the Basic Data Protection Regulation and other national data protection laws of the EU member states and other data protection regulations is:

Gooding GmbH
Oeder Weg 11
60318 Frankfurt
Phone: +49 69 - 242 417 33
Email: feedback@feedacat.com

Website: www.feedacat.com

Name and address of the data protection officer
The external data protection officer of the controller is:

Lawyer Dr. Thomas Kienle
Friedenstr. 1
89073 Ulm
Email: dataprivacy@feedadog.com

The following provisions provide an overview of what kind of data is collected, how and for what purpose this data is used and finally, what rights you are entitled to. 

Your trust is important to us. We are therefore very concerned about transparency. Gooding, as the initiator of the feed a dog app, would like to collect as many food contributions as possible for the charitable organisations (hereinafter referred to as "associations"). If you have any questions that are not answered by this privacy policy or if you would like more detailed information on a particular point, please contact datenschutz@feedadog.de.

2. Data collection and processing

When you install and use the feed a dog app, we collect the following data which is technically and operationally necessary for us to provide our service and to collect food contributions.

a)    Data collection when we install the app: 

  • Device ID (if notification setting has been enabled).
  • Location data (if the localisation function has been activated).

b)    Data collection when contributing food:

  • First name
  • Surname
  • E-mail address
  • Type of contribution (one-time, recurring)
  • Contribution amount
  • Contribution target

c)    Data collection by third parties
Third party providers may also collect data in this app. Please see Item 4. implemented third-party technologies.

d)    Data from App Stores
We may receive information about you from third parties. If you access our services through a third party app vendor such as the App Store/Google Play Store, we may collect personal information that you have made public through the respective privacy settings of those third party app vendors.

e)    Permissions for the App

  • Location detection (only at the request of the user)
  • Push notification (only at the user's request)
  • Network connection (offline/online)

Description of the purposes and legal basis on which the data is collected:

  • Optimisation of the user experience (predominant legitimate interest, para. 6. sec. 1 lit. f GDPR)
  • Acquiring contributions for fulfilment (predominant legitimate interest, para. 6. sec. 1 lit. f GDPR)
  • Contributor and contribution administration (contract fulfilment or preparation, para. 6 sec. 1 lit. b GDPR)
  • Fulfilment of obligations under tax law (fulfilment or preparation of contracts, para. 6 sec. 1 lit. b GDPR)

3. Transfer to third parties

If you have provided us with personal data, this will not be passed on to third parties. We will only forward your information under these circumstances:

  • in the context of processing your payment to our payment service providers
  • in the context of the involvement of third parties in accordance with point 4
  • within the scope of processing your enquiries, and the use of our services to subcontractors who are only provided with the necessary data for the execution of this order and use it for the intended purpose.
  • within the scope of commissioned data processing in accordance with para. 28 GDPR to external service providers (e.g. hosting providers). These have been carefully selected and commissioned by us, are bound by our instructions and the provisions of the GDPR and are regularly checked.
  • in the context of the fulfilment of legal obligations to bodies entitled to receive information.

4. Implemented third-party technologies

Google Firebase

Service description
Analysis of app usage

Processing company
Google Ireland Limited
Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data protection officer of the processing company
Below you will find the email address of the data protection officer of the processing company.
https://support.google.com/policies/troubleshooter/7575787?hl=en

Data processing purposes
This list sets out the purposes for which data is collected and processed. Consent is only valid for the purposes indicated. The data collected cannot be used or stored for any purpose other than those listed below.

  • Analysis

Technologies used
This list includes all technologies used by this service to collect data. Typical technologies are cookies and pixels placed in the browser.

  • Cookies 

Data collected
This list contains all (personal) data collected by or through the use of this service.

  • Number of users and sessions
  • Session duration
  • Operating systems
  • Device models
  • Region
  • First launches
  • App launches
  • App updates

Legal basis
The following is the required legal basis for the processing of data

  • Art. 6 par. 1. cl. 1 lit. a GDPR

Place of processing
This is the primary place where the collected data is processed. If the data is also processed in other countries, you will be informed separately.

  • European Union 

Retention period
The retention period is the length of time that the collected data is stored for processing. The data must be deleted as soon as it is no longer needed for the specified processing purposes. The retention period depends on the type of data stored. Each customer can determine how long Google Analytics retains data before it is automatically deleted

Transfer to third countries
This service may transfer the collected data to another country. Please note that this service may transfer data outside the European Union and the European Economic Area and to a country that does not provide an adequate level of data protection. If the data is transferred to the US, there is a risk that your data may be processed by US authorities for control and monitoring purposes, without you possibly having any legal recourse. Below you will find a list of countries to which the data will be transferred. This may be for various purposes, such as storage or processing.

  • Worldwide 

Recipients of data
The following is a list of the recipients of the data collected.

  • Alphabet Inc.
  • Google LLC
  • Google Ireland Limited

Click here to object on all domains of the processing company
https://safety.google/privacy/privacy-controls/

Click here to read the privacy policy of the data processor
https://policies.google.com/privacy?hl=en

Click here to read the cookie policy of the data processor
https://policies.google.com/technologies/cookies?hl=en

Branch

Service description
Ensuring and optimising app functionality

Processing company
Branch Inc.
1400 Seaport Blvd Building B, 2nd Floor Redwood City, CA 94063 USA

Data protection officer of the processing company
Below you will find the email address of the data protection officer of the processing company.
privacy@branch.io

Data processing purposes
This list sets out the purposes for which data is collected and processed. Consent is only valid for the purposes indicated. The collected data cannot be used or stored for any purpose other than those listed below.

  • Ensuring and optimising the app functionality 

Technologies used
This list includes all technologies used by this service to collect data. Typical technologies are cookies and pixels placed in the browser.

  • Web beacons
  • Log files
  • Cookies

Data collected
This list contains all (personal) data collected by or through the use of this service.

  • Operating system and version
  • Timestamp
  • API key (identification key of the application)
  • Application version
  • Device model, manufacturer and identification number
  • iOS identification key for advertising
  • iOS identification key for vendors
  • Android identification key for advertising
  • IP address and network status
  • Branch Cookie ID
  • Referrer
  • CPU (Central Processing Unit) Type
  • Engagement Data

Legal basis
The following is the required legal basis for the processing of data

  • Art. 6 par. 1. cl. 1 lit. a GDPR

Place of processing
This is the primary place where the collected data is processed. If the data is also processed in other countries, you will be informed separately.
United States of America

Retention period
The retention period is the length of time that the collected data is stored for processing. Data must be deleted as soon as it is no longer needed for the specified processing purposes. The data will be deleted as soon as it is no longer needed for the processing purposes.

Transfer to third countries
This service may transfer the collected data to another country. Please note that this service may transfer data outside the European Union and the European Economic Area and to a country that does not provide an adequate level of data protection. If the data is transferred to the US, there is a risk that your data may be processed by US authorities for control and monitoring purposes, without you possibly having any legal recourse. Below you will find a list of countries to which the data will be transferred. This may be for various purposes, such as storage or processing.

  • Worldwide 

Recipients of data
The following is a list of the recipients of the data collected.

  • Zendesk, Inc.
  • Rollbar, Inc.
  • Amazon Web Services (AWS), Inc.
  • Twilio, Inc.
  • Atlassian, Pty Ltd.

Click here to object on all domains of the processing company
https://branch.io/policies/#privacy-collection-and-use-of-information-from-our-website-and-for-marketing-purposes

Click here to read the privacy policy of the data processor
https://branch.io/policies/#privacy-collection-and-use-of-information-from-our-website-and-for-marketing-purposes

Click here to read the data processor's cookie policy
https://branch.io/policies/#privacy-collection-and-use-of-information-from-our-website-and-for-marketing-purposes


Facebook

Service description
This is a tracking technology offered by Facebook and used by other Facebook services such as Facebook Custom Audiences.

Processing Company
Facebook Ireland Limited
4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland

Data protection officer of the processing company
Below you will find the email address of the data protection officer of the processing company.
https://www.facebook.com/policies/cookies

Data processing purposes
This list sets out the purposes for which data is collected and processed. Consent is only valid for the purposes indicated. The data collected cannot be used or stored for any purpose other than those listed below.

  • Marketing
  • Retargeting
  • Tracking
  • Analysis
  • Advertising

Technologies used
This list includes all technologies used by this service to collect data. Typical technologies are cookies and pixels placed in the browser.

  • Pixel

Data collected
This list contains all (personal) data collected by or through the use of this service.

  • Facebook user ID
  • Browser Information
  • Usage data
  • Non-sensitive custom data
  • Referrer URL
  • Pixel ID
  • User behaviour
  • Advertisements viewed
  • Interactions with advertising, services and products
  • Marketing information
  • Viewed content
  • IP address
  • Device information
  • Marketing campaign success
  • Geographical location

Legal basis
The following is the required legal basis for the processing of data

  • Art. 6  par. 1. cl. 1 lit. a GDPR

Place of processing
This is the primary place where the collected data is processed. If the data is also processed in other countries, you will be informed separately.

  • European Union

Retention period
The retention period is the length of time that the collected data is stored for processing. Data must be deleted as soon as it is no longer needed for the specified processing purposes. The data will be deleted as soon as it is no longer needed for the processing purposes.

Transfer to third countries
This service may transfer the collected data to another country. Please note that this service may transfer data outside the European Union and the European Economic Area and to a country that does not provide an adequate level of data protection. If the data is transferred to the US, there is a risk that your data may be processed by US authorities for control and monitoring purposes, without you possibly having any legal recourse. Below you will find a list of countries to which the data will be transferred. This may be for various purposes, such as storage or processing.

  • Worldwide 

Recipients of data
The following is a list of the recipients of the data collected.

  • Facebook Inc.

Click here to object on all domains of the processing company
https://www.facebook.com/ads/preferences

Click here to read the privacy policy of the data processor
https://www.facebook.com/privacy/explanation

Click here to read the cookie policy of the data processor
https://www.facebook.com/policies/cookies

Sentry

Service description

This is a bug tracking and performance monitoring platform for web apps, mobile apps, and games. It is used to monitor and fix crashes in real time.

Processing company

Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA

Data protection officer of the processing company

Below you will find the email address of the data protection officer of the processing company.

security@sentry.io

 

Data processing purposes

This list represents the purposes of data collection and processing. Consent is only valid for the specified purposes. 
The collected data cannot be used or stored for any purpose other than those listed below.

Data processing by Sentry serves the following purposes:

  • Tracking
  • Detection of code errors
  • Developing and improving products

 

Technologies used

This list contains all technologies with which this service collects data. Typical technologies are cookies and pixels that are placed in the browser.

  • Mobile SDK

 

Data collected

This list contains all (personal) data that is collected by or through the use of this service.

  • Usage data
  • Device
  • IP address
  • Error data

 

Legal

The required legal basis for the processing of data is specified below.

Art. 6 para. 1 sentence 1 lit. f GDPR

Place

This is the primary location where the collected data is processed. If the data is also processed in other countries, you will be informed separately.

United States

Retention

The retention period is the period of time during which the collected data is stored for processing. The data must be deleted as soon as it is no longer required for the specified processing purposes.

Data will be deleted as soon as it is no longer required for processing purposes.

Transfer to third countries

This service may transfer the collected data to another country. Please note that this service may transfer data outside the European Union and the European Economic Area and to a country that does not provide an adequate level of data protection. If the data is transferred to the US, there is a risk that your data may be processed by US authorities for control and monitoring purposes, without you necessarily having any legal recourse. Below is a list of the countries to which the data is transferred. This may be for various purposes, such as storage or processing.

United States of America

Data recipients

The recipients of the data collected are listed below.

Functional Software, Inc. dba Sentry

Click here to read the data processor's privacy policy

https://sentry.io/privacy/

Click here to read the data processor's cookie policy

https://sentry.io/privacy/#cookies


Usercentrics Consent Management Platform

Service Description
This is a consent management service. Usercentrics GmbH is used as a processor on the website for the purpose of consent management.
Pushwoosh

Service description
This is a service for push notifications.

Processing company
Pushwoosh Inc.
1224 M St, Suite 101 NW, Washington, DC, 2005

Data protection officer of the processing company
Below you will find the email address of the data protection officer of the processing company.
privacy@pushwoosh.com


Data processing purposes
This list sets out the purposes for which data is collected and processed. Consent is only valid for the purposes indicated. The data collected cannot be used or stored for any purpose other than those listed below.

  • Sending push messages

Technologies used
This list includes all technologies used by this service to collect data. Typical technologies are cookies and pixels placed in the browser.

  • Local storage
  • Cookies

Data collected
This list contains all (personal) data collected by or through the use of this service.

  • Push Token
  • Hardware ID
  • System Language
  • Timezone of device
  • Device Model
  • Application Version
  • OS Version
  • Geo-IP

Legal basis
The following is the required legal basis for the processing of data

  • Art. 6 par. 1. cl. 1 lit. a GDPR

Place of processing
This is the primary place where the collected data is processed. If the data is also processed in other countries, you will be informed separately.

United States of America

Retention period
The retention period is the length of time that the collected data is stored for processing. The data must be deleted as soon as it is no longer needed for the specified processing purposes. The data will be deleted as soon as it is no longer needed for the processing purposes.

Transfer to third countries
This service may transfer the collected data to another country. Please note that this service may transfer data outside the European Union and the European Economic Area and to a country that does not provide an adequate level of data protection. If the data is transferred to the US, there is a risk that your data may be processed by US authorities for control and monitoring purposes, without you possibly having any legal recourse. Below you will find a list of countries to which the data will be transferred. This may be for various purposes, such as storage or processing.

  • United States of America

Recipients of data
The following is a list of the recipients of the data collected.

  • Amazon Webservices Inc.
  • Salesforce. Com, Inc.
  • Zendesk, Inc.

Click here to object on all domains of the processing company
http://web-01-site.pushwoosh.com/privacy-policy-services/

Click here to read the privacy policy of the data processor
https://www.pushwoosh.com/privacy-policy/

Click here to read the cookie policy of the data processor
http://web-01-site.pushwoosh.com/privacy-cookie-policy/

Processing company

Usercentrics GmbH 
Sendlinger Str. 7, 80331 Munich, Germany

Data protection officer of the processing company
Below you will find the e-mail address of the data protection officer of the processing company.
datenschutz@usercentrics.com

Data processing purposes
This list represents the purposes of data collection and processing. Consent is only valid for the purposes indicated. The data collected cannot be used or stored for any purpose other than those listed below.

  • Compliance with legal obligations
  • Consent storage

Technologies used
This list includes all technologies used by this service to collect data. Typical technologies include cookies and pixels placed in the browser.

  • Local Storage 

Data collected
This list contains all (personal) data collected by or through the use of this service.

  • Opt-in and opt-out data
  • Referrer URL
  • User Agent
  • User preferences
  • Consent ID
  • Time of consent
  • Consent type
  • Template version
  • Banner language

Legal basis
The following is the required legal basis for the processing of data

  • Art. 6  par. 1. cl. 1 lit. c GDPR

Place of processing
This is the primary location where the collected data is processed. If the data is also processed in other countries, you will be informed separately.

  • European Union (consent database is located in Belgium).

Retention period
The retention period is the period during which the collected data are stored for processing. The data must be deleted as soon as it is no longer needed for the specified processing purposes. Consent data (consent and withdrawal of consent) is stored for three years. The data will then be deleted immediately.

Data recipients
The recipients of the data collected are listed below.

  • Usercentrics GmbH

Pushwoosh
You may receive so-called push messages from us, even if you are not currently using this app. These are part of the contractual service and therefore messages that we send to you as part of the performance of the contract pursuant to para. 6. sec. 1 lit. b GDPR (e.g. information on calls for help from the associations).

We use the provider Pushwoosh to send push messages for the above-mentioned purpose. Pushwoosh is provided by Pushwoosh Inc, 1224 M St NW, Suite 101, Washington, DC 20005, United States.

You can object to the collection or analysis of your data by this tool by setting the central "Notifications" slider on the "Settings" page to "Off".

Sendinblue
As a contributor, you will receive information at regular intervals about the appeals you have contributed to and similar appeals for help from associations. These serve to fulfil the original aim of the food contribution app. The legal basis for this is para. 6. sec. 1 lit. b GDPR. 

Right of objection: You can object to data processing for the aforementioned purposes at any time, free of charge and directly in the message sent. If you object, you will no longer receive information about the calls for help via this channel.

5. Your rights

You have the following rights in relation to the personal data concerning you:

  • Right to information,
  • Right of correction or deletion,
  • Right to restrict processing,
  • Right to object to the processing,
  • Right to data transferability.

Please send your written request or cancellation to datenschutz@feedacat.com.
If you wish to complain, please inform the external data protection officer, RA Dr. Thomas Kienle, at dataprivacy@feedacat.com.

You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us.

6. Duration of data storage

After a contribution, your data will be blocked for further use and deleted after expiry of the tax and commercial law retention periods (6 or 10 years), unless you have expressly consented the extended use of the data. You can delete the data stored in the app at any time under "Settings" with the function "Delete data”.

7. Changes to the privacy policy

Feed a cat may inform you that data protection policies are continuously being developed, also by the legislator. For this reason, feed a cat reserves the right to amend this data privacy declaration at any time in accordance with the applicable data protection regulations. As a customer, you will be informed of these changes by email before they come into effect.

feed a cat is a Gooding initiative | Made with by Gooding.de | Imprint | Privacy policy | Settings