CrossBorders

Privacy Policy

Last updated: July 2026DE·EN

1. Controller

Alexander Burkhard, Münsterlandstraße 68, 10317 Berlin, Deutschland. Email: alex@crossborders.io.

No data protection officer is appointed (not legally required, § 38 BDSG).

2. What we process

  • Questionnaire answers: your preferences (e.g. climate, cost, pace, priorities), country of origin, income details (range / portable income), spoken languages and household details. You do not need to give your name to get a result.
  • Result snapshots: the computed, immutable ranking that powers your shareable results page.
  • Values preference: the question “How important is a secular / liberal public culture?” captures a preference about the destination — not your own beliefs. We use the answer only to compute city fit, never for advertising or profiling.
  • Payment and entitlement data: for a web purchase or €19 report we store the order status and a Stripe reference. For an app purchase, RevenueCat processes the Apple or Google purchase state under an anonymous purchase identifier. Card or account details go only to Stripe, Apple or Google — we do not store them.
  • Feedback: your answers in the feedback section, if you submit it.
  • Newsletter sign-up: your email address plus the time and confirmation of the sign-up (double opt-in), so we can evidence the consent. If you sign up from a results page or the Android app, we link the sign-up to the relevant entitlement record. This is a consent and unlock record, not a CrossBorders account or login.
  • Server logs: IP address, timestamp, user agent and technical error information.
  • No data sale: we do not sell personal data or use it for third-party advertising.

3. Purposes and legal bases

  • Providing the ranking and the full-list unlock — Art. 6(1)(b) GDPR (contract / pre-contractual measure).
  • Product analytics via PostHog on the website (cookieless — no device storage, server-side daily-rotating hash) and in iOS and Android (forwarded server-side, identifier valid for one app session only) — Art. 6(1)(f) GDPR (legitimate interest in improving the service). As no device storage is accessed for this purpose, § 25 TDDDG does not apply.
  • Sending the CrossBorders newsletter, in exchange for unlocking the full city list — Art. 6(1)(a) GDPR (consent, confirmed by double opt-in). Consent is optional: you can see your results without giving an email address at all, and you can buy the full list without the newsletter instead. You can withdraw at any time with future effect (unsubscribe link in every email); an unlock you already have stays.
  • Stability, error analysis, abuse prevention and product improvement — Art. 6(1)(f) GDPR (legitimate interest).
  • Retention of payment and invoice records — Art. 6(1)(c) GDPR (commercial and tax-law obligations).

4. Pricing

On the web, the full city list costs €1.99 or is free with a verified newsletter email. In the iOS app, the one-time unlock through Apple costs €3.99 (German App Store price). In the Android app, the unlock is free with a verified newsletter email or available as a one-time Google Play purchase at the €1.99 German base price. In other countries and currencies, the local price displayed by the relevant checkout or store applies. The prices are not personalized. The separate, in-depth report costs a flat €19 and also unlocks the full list.

5. Recipients and processors

We use the following service providers under data-processing agreements:

  • Supabase Inc. (USA, Daten gespeichert in der EU / data stored in the EU): PostgreSQL database for result snapshots, orders, feedback, newsletter consent records and mobile entitlement records.
  • Stripe Payments Europe, Ltd. (Irland / Ireland): Payment processing as merchant of record for unlocking the full city list (Checkout): Stripe handles the purchase, issues the receipt and remits any applicable VAT. Card data goes only to Stripe — we never store it.
  • PostHog (EU-Instanz / EU instance, eu.posthog.com) (EU): Cookieless product analytics: no cookies, no device storage; visitor counting via a server-side hash that changes daily (the IP address is not stored). Website events include an approximate country that our CDN (Cloudflare) derives from your IP at the edge; the IP address itself is never passed to or stored by PostHog. Mobile events from the iOS and Android apps do not include a country. They are forwarded by our server only — the apps themselves never connect to PostHog — and carry an identifier valid for a single app session.
  • Functional Software, Inc. (Sentry) (USA): Error detection and analysis to keep the service stable (website, iOS and Android apps).
  • RevenueCat, Inc. (USA): Purchase and entitlement management for the iOS and Android apps: processes Apple App Store and Google Play purchases under an anonymous purchase identifier and confirms unlock status. Payment data stays with Apple or Google.
  • Expo (650 Industries, Inc.) (USA): Delivery of app updates for the iOS and Android apps (EAS Update): when an app checks for updates, Expo sees the IP address and technical app/update metadata.
  • Resend (USA): Transactional email delivery (e.g. payment receipts, messages you request) and the CrossBorders newsletter including its confirmation email (double opt-in).
  • Google Cloud (Cloud Run) (USA, Hosting in Frankfurt / hosting in Frankfurt): Application hosting.
  • Cloudflare, Inc. (USA): DNS, CDN and abuse protection; sees visitors’ IP addresses in the process.
  • Google (Gemini Developer API / Google AI Studio) (USA / EU): AI generation of the personalized prose in the paid €19 report. Only the non-directly-identifying profile/result data needed for this is processed; on the paid API tier, inputs are not used to train the models (Google Cloud Data Processing Addendum).

6. Third-country transfers

Where providers process data in the USA, this is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or certification under the EU-US Data Privacy Framework.

7. Retention

  • Result snapshots and raw feedback: automatically deleted after 30 days. Only a result snapshot linked to a paid web order is retained beyond that period. A newsletter unlock is not a paid web order, so its snapshot is also deleted after 30 days.
  • Anonymous aggregate statistics (counts only, no personal data): kept indefinitely, as they contain no personal data.
  • Newsletter sign-up: pending or expired confirmation attempts remain stored until a verified deletion request. We keep a confirmed sign-up until you withdraw consent. After that we keep the unsubscribe so we do not contact you again. If you unsubscribe, your already-earned ranking access remains.
  • Payment and invoice records: per statutory retention periods (up to 10 years, § 147 AO).
  • Server logs: typically 30 days.
  • Error reports (Sentry): typically 30 days.

8. Cookies and local storage

Technically necessary storage is kept in your browser’s local storage so your in-progress answers are not lost. We also remember there that you have already seen the unlock prompt on your results page, so it does not reappear on every visit. Analytics (PostHog) is cookieless: it sets no cookies and uses no device storage; recognition uses a server-side hash that rotates daily and cannot be traced back to you. We additionally record an approximate country that our CDN (Cloudflare) derives from your IP at the edge; the IP address itself is not stored. Affiliate links to accommodation providers are ordinary links: clicking one sends you to the provider, where their own privacy policy and cookie rules apply. We embed no provider code on our pages and load no images from their servers — accommodation photos are fetched by us and served from our own domain — so nothing is stored on your device by them, and they do not see your IP address, while you are here.

9. Mobile apps (CrossBorders for iOS and Android)

  • No account: the apps work without a CrossBorders registration or name. An email address is needed only if you voluntarily choose the newsletter unlock on Android. A confirmed newsletter email is a consent and unlock record, not a login account. Unsubscribing stops future newsletter messages but does not remove ranking access you already earned.
  • Questionnaire and results: your answers are sent to our server (crossborders.io) to compute your ranking, as described above. Saved runs (“Past runs”) live only on your device and can be deleted in Settings at any time (“Delete all local runs”). Server-side result snapshots created from the app are automatically deleted after 30 days, regardless of any purchase.
  • In-app purchases: on iOS the unlock is a one-time €3.99 purchase through the Apple App Store; Apple is the seller and payment processor. The Android app is only distributed in countries/regions where Google is the merchant of record under the then-current Google Play terms. Its one-time purchase at the local price shown (German base price €1.99) uses Google Play Billing only; the Android app does not offer alternative billing or user-choice billing. Google processes the purchase and issues the receipt there. We never receive payment details. RevenueCat manages both purchase states under an anonymous purchase identifier and confirms the entitlement status.
  • Local credentials: our server verifies the purchase or confirmed newsletter unlock. iOS stores a device-scoped access token in the device keychain. Android stores the access token, a random installation credential, and any pending email-confirmation claim in Android secure storage (SecureStore).
  • Crash reports: on app errors, technical crash data is sent to Sentry (see recipient list); sensitive fields are removed before sending.
  • App updates: on launch the app checks Expo (EAS Update) for updated content (see recipient list).
  • Usage measurement: iOS and Android measure anonymous usage — for example how far into the questionnaire people get — to find where the apps are confusing. They contain no analytics SDK and no advertising SDK, including no PostHog SDK: events go to our own server, which forwards them to PostHog; the apps themselves never contact PostHog and never transmit your answers, income figures or free text. Nothing is stored on your device for this purpose. The identifier is valid for a single app session, generated fresh each time you open the app, and discarded when you close it, so sessions cannot be linked to each other or to website visits.
  • No tracking: the app does not track you across apps or websites on either iOS or Android, uses no advertising identifier, and requests no device permissions (no location, no camera, no contacts).

10. No automated decision under Art. 22 GDPR

The ranking is an explainable decision aid with no legal or similarly significant effect. There is no solely automated individual decision within the meaning of Art. 22 GDPR.

11. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Arts. 15–21 GDPR), and the right to withdraw consent at any time (Art. 7(3) GDPR). Contact alex@crossborders.io to exercise them.

You can start the deletion of your data yourself at any time at /delete-data: we email you a one-time confirmation link and then delete the newsletter subscriber record, mobile newsletter claim and newsletter entitlement records. Payment and order records are kept only in anonymized form (email address and identifier removed) for statutory tax and commercial-law reasons.

12. Right to complain

You may lodge a complaint with a supervisory authority, e.g. Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.

13. Changes

We may update this policy when features or the legal situation change. The version published here applies.