Camper Explorer

Privacy

Privacy Policy

This policy explains how personal data is processed when you use camper-explorer.de and the services offered through it (the “Service”), under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

Last updated: August 29, 2026

1. Controller

Controller:

Schwarz Digital Works e.U.
Allerheiligenplatz 16/45, 1200 Vienna, Austria
hello@camper-explorer.de

For any question about data protection and to exercise your rights, reach us at the email address above. We are not legally required to appoint a data protection officer.

2. Processing in detail

For every processing operation we set out the data involved, the purpose, the legal basis and how long the data is kept.

2.1 Website delivery and server logs

Data
IP address, date and time of access, pages and files requested, amount of data transferred, referrer URL, browser and operating system.
Purpose
Technical delivery of the website, ensuring stability and security, preventing misuse.
Legal basis
Art 6(1)(f) GDPR — our legitimate interest in a secure, working service.
Storage period
Server logs are deleted or anonymised after 7 days.
Note
The website is delivered via Cloudflare Workers (Cloudflare, Inc., USA), which processes access and connection data including your IP address as our processor under Art 28 GDPR. Further components run on Oracle Austria GmbH servers in the Frankfurt am Main data centre in Germany.

2.2 User account and sign-in (Clerk)

Data
Email address, authentication data, a unique user id, where applicable your name and the data provided by a linked login provider (e.g. Google), and the time you registered.
Purpose
Creating and managing your account, authenticating you, and providing account-bound features.
Legal basis
Art 6(1)(b) GDPR — performance of the user contract and pre-contractual steps.
Storage period
For as long as your account exists. You can delete it yourself at any time under “My account”; a running subscription has to be cancelled first. Deleting removes your account and the data linked to it, unless statutory retention duties apply.
Note
Authentication runs through Clerk (Clerk, Inc., USA); its privacy policy and terms of service apply in addition. We also store your user id, email address and preferred language in our own database so that features such as Deal Alerts work and reach you in the right language.

2.3 Deal Alert settings

Data
The stations, routes and operators you want to be alerted about, an optional display name, whether the alert is active, and your user id.
Purpose
Storing your Deal Alert settings and matching them against newly published deals.
Legal basis
Art 6(1)(b) GDPR — performance of the user contract.
Storage period
Until you delete the preference or your account.

2.4 Deal Alert emails (Resend)

Data
Email address, the content of the Deal Alert (the matching deals), and send and delivery metadata.
Purpose
Sending the Deal Alerts you switched on.
Legal basis
Art 6(1)(b) GDPR — performance of the user contract; where processing goes beyond that contractual function, Art 6(1)(a) GDPR (consent), which you can withdraw at any time.
Storage period
Send metadata for 30 days, after which it is deleted or anonymised.
Note
Emails are sent through Resend (Resend, Inc., USA); its privacy policy applies in addition. Every Deal Alert email carries a one-click unsubscribe link, and you can switch Deal Alerts off in your account at any time.

2.5 Paid subscription and payments (Creem)

Data
The data needed for the purchase — name, email address, payment and invoicing data, and the plan you chose. Payment details such as card numbers are processed exclusively by Creem, never by us.
Purpose
Handling the purchase of a Pro subscription, processing payment, issuing invoices, and meeting tax and commercial law obligations.
Legal basis
Art 6(1)(b) GDPR — performance of a contract — and Art 6(1)(c) GDPR — statutory retention duties.
Storage period
Invoice-relevant data for the statutory retention periods (in Austria generally 7 years under § 132 BAO).
Note
Sale and payment are handled by Armitage Labs OÜ (Estonia (EU)) as merchant of record. For the payment itself Creem is a controller in its own right, and its privacy policy and terms of service apply in addition.

2.6 Reach measurement (Umami)

Data
Pages viewed, the referring page, your approximate location at country level, browser type and device category, plus interactions with the site like which buttons and links are used.
Purpose
Understanding in aggregate how the site is used, in order to improve it.
Legal basis
Art 6(1)(f) GDPR — our legitimate interest in measuring reach without tracking individuals.
Storage period
Pseudonymous usage data, evaluated only in aggregate; no data that can be traced back to you.
Note
We use Umami, self-hosted on our own server in the EU — no external analytics provider receives your data. Umami is cookieless and stores nothing on your device, builds no profile across sites, devices or days, and the statistics are not linked to your user account.

2.7 Error and performance monitoring (Sentry)

Data
Technical error and diagnostic data such as IP address, browser and device data, the URL called, the time and the error message.
Purpose
Detecting, analysing and fixing technical faults and keeping the Service stable.
Legal basis
Art 6(1)(f) GDPR — our legitimate interest in a stable, working service.
Storage period
30 days.
Note
Monitoring runs through Sentry (Functional Software, Inc., USA); event data is stored in Sentry’s EU region.

2.8 Getting in touch

Data
Your email address and whatever you tell us in your message.
Purpose
Handling your enquiry.
Legal basis
Art 6(1)(b) GDPR for contract-related enquiries, otherwise Art 6(1)(f) GDPR — our legitimate interest in answering you.
Storage period
Until your enquiry has been dealt with, then deleted unless retention duties apply.
Note
Our contact page only provides an email address — there is no contact form and no server-side processing of your message on our side.

3. Transfers outside the EU

Some of the providers named above — in particular Cloudflare, Clerk, Resend, Sentry — are based in the USA or process data outside the EU/EEA. Such transfers take place on the basis of appropriate safeguards under Art 46 GDPR, in particular the European Commission’s standard contractual clauses, and/or, where the provider is certified, the EU-U.S. Data Privacy Framework (adequacy decision under Art 45 GDPR).

4. How long data is kept

Personal data is kept only as long as it is needed for the purpose it was collected for, or as long as statutory retention duties — in particular under tax and commercial law — require. The specific periods are listed with each processing operation in section 2.

Beyond that, we delete accounts that have been inactive for 24 months — no sign-in and no other use of the account — together with the data attached to them, such as your Deal Alert settings. Data we are legally required to keep, in particular invoicing data, is unaffected.

5. Your rights

Under the GDPR you have the following rights:

  • Access (Art 15 GDPR) to the data we process about you
  • Rectification of inaccurate data (Art 16 GDPR)
  • Erasure (Art 17 GDPR)
  • Restriction of processing (Art 18 GDPR)
  • Data portability (Art 20 GDPR)
  • Objection to processing based on legitimate interests (Art 21 GDPR)
  • Withdrawal of consent with effect for the future (Art 7(3) GDPR)

An informal email to the address in section 1 is enough to exercise any of them.

You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna: dsb.gv.at

6. Cookies and local storage

We use only technically necessary cookies and comparable storage: session cookies from our authentication provider (Clerk) to keep you signed in, a cookie remembering your language, and — in your browser’s local storage — your theme (light/dark) and the state of the sidebar. Our reach measurement (Umami) is cookieless.

Because only strictly necessary or cookieless technologies are used, no separate cookie consent is required.

7. No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art 22 GDPR.

8. Do you have to provide data?

Browsing the public deal feed requires no personal data at all. A user account, Deal Alerts and a paid subscription do require certain data — in particular your email address and, for a subscription, payment data. Without it, those features cannot be provided.

9. Changes to this policy

We update this policy when our processing or the legal situation changes. The version published on this page is always the current one.

Last updated: August 29, 2026