Privacy policy
Information pursuant to Articles 13 and 14 GDPR
Last updated: 3 October 20261. Controller
Markus Pehaim
Stuttgarter Straße 40, 2380 Perchtoldsdorf, Austria
Email: cheqpert@schmeggspert.com
2. Data processed by CHEQPERT
Depending on how you use the service, CHEQPERT processes technical connection and security data, session and language settings, search locations or location coordinates, account and login data, and personal place data such as saved or visited places, ratings and notes.
If purchase products are enabled and you start a purchase, CHEQPERT also processes server-side order and payment-status data such as the internal order identifier, selected product, price and currency, status, provider references, and information about refunds or disputes. Full card details are not stored in CHEQPERT; payment data required for processing is handled directly by the server-selected payment provider, Stripe Checkout or SumUp Hosted Checkout.
If you use the online withdrawal function, CHEQPERT additionally processes the name you provide, the relevant order identifier, the email address specified for confirmation of receipt, the content and version of the withdrawal declaration, the recorded receipt time, and delivery and refund status. To calculate a proportional refund server-side, CHEQPERT also processes the unused or used Q-Checks attributable to that specific purchase and, for a Travel Pass, the elapsed duration; this is stored with the order as a refund snapshot. The withdrawal declaration is stored server-side before the affected entitlement is blocked and external delivery or refund attempts are made.If you use the online withdrawal function, CHEQPERT additionally processes the name you provide, the relevant order identifier, the email address specified for confirmation of receipt, the content and version of the withdrawal declaration, the recorded receipt time, and delivery and refund status. To calculate a proportional refund server-side, CHEQPERT also processes the unused or used -Checks attributable to that specific purchase and, for a Travel Pass, the elapsed duration; this is stored with the order as a refund snapshot. The withdrawal declaration is stored server-side before the affected entitlement is blocked and external delivery or refund attempts are made.
CHEQPERT is not designed to collect special categories of personal data within the meaning of Article 9 GDPR. Please do not enter such data in personal notes.
Which data must be provided depends on the feature used: technically necessary connection, security and session data is required for secure operation; a place to be checked must be provided for a Q-Check. Account and login data is required only for account and synchronization features. Device location and push notifications are optional. If data required for a feature is not provided, only that feature may be unavailable or limited; other available features remain unaffected.Which data must be provided depends on the feature used: technically necessary connection, security and session data is required for secure operation; a place to be checked must be provided for a -Check. Account and login data is required only for account and synchronization features. Device location and push notifications are optional. If data required for a feature is not provided, only that feature may be unavailable or limited; other available features remain unaffected.
3. App delivery and security
When the app is accessed, technically necessary connection data is generated. This may include IP address, time, requested resource, browser and device information, and technical error and security information. CHEQPERT also processes pseudonymized or hashed identifiers and usage counters to detect abuse, duplicate requests, quotas and technical failures.
Purpose and legal basis: secure and stable operation of the app and protection against abuse based on Article 6(1)(f) GDPR. The legitimate interest is the security, availability and economically controlled operation of the service.
4. Location and place search
Access to your current device location only occurs if you grant location permission in your device or browser. Coordinates are used to find nearby places, calculate distances and position the map. You can instead enter a search location or address manually at any time.
Location permission can be withdrawn at any time in your browser or operating system settings. Manual place searches remain available without location permission.
For Nearby searches, CHEQPERT stores discovered public place data server-side in the shared place catalog so known places can be available immediately in later searches. For individual search scopes, CHEQPERT stores only a technical hashed search-scope key together with search mode, radius and refresh status; raw search coordinates are not persisted for this purpose. For fully imported public OpenStreetMap regions, CHEQPERT may additionally store the public boundary geometry of the imported region and the timestamp of the underlying OSM data snapshot. This geometry describes the imported data region, not a user's location or location history. Coverage metadata contains no user, account, device or IP identifier.
Legal basis: Article 6(1)(a) GDPR for access to the current device location; Article 6(1)(b) GDPR for manually selected search locations and providing the requested search function. Reuse of public place data and non-user-specific technical refresh metadata is based on Article 6(1)(f) GDPR; the legitimate interest is a reliable, fast and resource-efficient place search.
5. Account, login and personal place data
An account is not required for every use. If you sign in, CHEQPERT processes the data required for authentication and account assignment. With the currently offered Google login, this may include your email address, display name and a technical provider identifier.
CHEQPERT is not specifically directed at children under 14. Where Austrian law requires consent for a consent-based feature, persons under 14 should use that feature only with the required consent of their legal representative. Manual place search remains available without location permission.
For installed Home Screen web apps or native app shells, Google sign-in may take place in a separate browser context. CHEQPERT therefore uses a one-time technical login handoff that is valid for no more than five minutes. The login request first switches through a separate CHEQPERT delivery address into the external browser; at the canonical CHEQPERT origin, a short-lived signed technical HttpOnly cookie is then set to securely correlate the provider return. The cookie contains neither access tokens nor the app proof. Provider session data is kept encrypted server-side and is transferred into secure HttpOnly cookies only by the original app context. CHEQPERT additionally uses a short-lived technical context binding that is kept only in the running app's volatile memory and is not stored in browser or native storage. After the provider return, the external browser shows only a completion page and does not take over the app session. The handoff is deleted immediately after successful transfer. Access and refresh tokens are not stored in URLs, JavaScript, browser storage or native storage.
With an account, saved and visited places, visit times, personal ratings, notes and the required place information may be stored server-side and synchronized across devices.
After the initial location step, CHEQPERT may ask signed-in users once whether push notifications should be enabled. Browser or operating-system notification permission is requested only after you explicitly choose to enable push. CHEQPERT stores server-side, in the existing push preference record, the time when this one-time activation prompt was answered or dismissed with “Later” so it is not repeated on every start. If you enable push, CHEQPERT additionally stores the Web Push subscription required for delivery to the relevant device. This includes a technical push endpoint and cryptographic delivery keys. This data is used solely for CHEQPERT notifications you have enabled. You can disable push again in your account; registered push devices are then removed server-side.
For operations and product observation, CHEQPERT may show authorized operators pseudonymized usage statistics and activity events. These include app opens or resumptions, active, new and returning visitors, new accounts, repeat sign-ins, started or failed Q-Checks, and actionable technical operational incidents. App opens are counted server-side at most once per 30-minute activity window; the technical session/account reference is purpose-bound and HMAC-pseudonymized before storage, is not exposed to operators, and is retained for at most 35 days. Account-linked pseudonyms are additionally removed through the account-deletion path. Terminal processing, push, provider/budget, and server-side sign-in failures may appear as operator notices; temporary retries are not stored as persistent notices. Operator push notifications do not contain a full email address; received event types are configurable server-side and visible only to centrally authorized operators.For operations and product observation, CHEQPERT may show authorized operators pseudonymized usage statistics and activity events. These include app opens or resumptions, active, new and returning visitors, new accounts, repeat sign-ins, started or failed -Checks, and actionable technical operational incidents. App opens are counted server-side at most once per 30-minute activity window; the technical session/account reference is purpose-bound and HMAC-pseudonymized before storage, is not exposed to operators, and is retained for at most 35 days. Account-linked pseudonyms are additionally removed through the account-deletion path. Terminal processing, push, provider/budget, and server-side sign-in failures may appear as operator notices; temporary retries are not stored as persistent notices. Operator push notifications do not contain a full email address; received event types are configurable server-side and visible only to centrally authorized operators.
Legal basis: Article 6(1)(b) GDPR for providing account and synchronization features; Article 6(1)(a) GDPR for voluntarily enabled push notifications; Article 6(1)(f) GDPR for the technical state of the one-time activation prompt and for pseudonymized operational, security and failure monitoring. The legitimate interest is to avoid repeated activation prompts and to ensure service stability, abuse prevention, troubleshooting, incident response and secure service improvement.
6. Q-Checks and publicly available sources6. -Checks and publicly available sources
For a newly started Q-Check, place-related information such as name, address, category and coordinates, together with publicly available information about the selected place, is processed. This information may be sent to an AI service to perform web research, summarization and structured assessment. Account email addresses or personal notes are not required for the research request and are not intended to be sent to the AI service.For a newly started -Check, place-related information such as name, address, category and coordinates, together with publicly available information about the selected place, is processed. This information may be sent to an AI service to perform web research, summarization and structured assessment. Account email addresses or personal notes are not required for the research request and are not intended to be sent to the AI service.
Publicly available place-related information may come in particular from websites, review platforms, editorial sources and community contributions. CHEQPERT does not aim to build profiles about individual reviewers or other natural persons. Personal references from third-party sources are processed only where they are technically or contextually unavoidable within the publicly available source.
Even without an account, CHEQPERT may associate a Q-Check you start server-side with a signed anonymous session scope. While that scope remains valid and the centrally resolved plan permits owner access, the same browser can retrieve the previously unlocked snapshot assigned to that scope. This does not grant access to other users' or global snapshots. The Q-Check result itself is not stored in persistent browser or device storage; only the technically necessary HttpOnly session identifier remains in the browser.Even without an account, CHEQPERT may associate a -Check you start server-side with a signed anonymous session scope. While that scope remains valid and the centrally resolved plan permits owner access, the same browser can retrieve the previously unlocked snapshot assigned to that scope. This does not grant access to other users' or global snapshots. The -Check result itself is not stored in persistent browser or device storage; only the technically necessary HttpOnly session identifier remains in the browser.
Completed general Q-Check results and their history are shared product knowledge and may also be shown to other users. Internal account associations are used only for technical purposes such as quotas, job control and provenance; when an account is deleted, the personal association with Q-Checks is removed.Completed general -Check results and their history are shared product knowledge and may also be shown to other users. Internal account associations are used only for technical purposes such as quotas, job control and provenance; when an account is deleted, the personal association with -Checks is removed.
Legal basis: Article 6(1)(b) GDPR for the requested Q-Check; Article 6(1)(f) GDPR for quotas, deduplication, cost control and abuse prevention.Article 6(1)(b) GDPR for the requested -Check; Article 6(1)(f) GDPR for quotas, deduplication, cost control and abuse prevention.
7. Cookies and local storage
CHEQPERT uses technically necessary cookies for session, login and language settings. The selected language may be stored for up to twelve months. The signed anonymous guest session may remain valid for up to 30 days and is used, among other things, for quota control and to reopen the guest’s own previously unlocked Q-Checks. Authentication cookies apply for the respective session or until logout or account deletion.CHEQPERT uses technically necessary cookies for session, login and language settings. The selected language may be stored for up to twelve months. The signed anonymous guest session may remain valid for up to 30 days and is used, among other things, for quota control and to reopen the guest’s own previously unlocked -Checks. Authentication cookies apply for the respective session or until logout or account deletion.
CHEQPERT currently does not use advertising, marketing or analytics cookies. Personal product data is not stored in persistent browser storage. The PWA cache contains only the app shell and static files, not personal API responses.
8. Recipients and service providers
CHEQPERT currently uses the following categories of service providers for operation and functionality:
- Vercel – hosting and delivery of the web application
- Supabase – database, server-side storage and authentication infrastructure
- OpenAI – AI-assisted research, summarization, structuring and translation
- Google – optional login via Google OAuth
- Stripe – payment processing for enabled one-time purchases through Stripe Checkout; payment and transaction data required for payment, fraud prevention, tax determination, refunds and payment disputes is processed for this purpose
- SumUp – alternative payment provider for enabled one-time purchases through SumUp Hosted Checkout; payment and transaction data required for payment, fraud prevention, refunds and payment disputes is processed for this purpose
- Resend – delivery of transactional purchase, withdrawal and refund confirmations; depending on the message, this involves transmitting in particular the verified account email address or the confirmation email address you provide, your name, order and product data, amount and status, and for withdrawals the content and receipt time of the withdrawal declaration
- OpenFreeMap and OpenStreetMap-based services – place, address, map and nearby data; the map view primarily loads vector tiles and style resources from OpenFreeMap and uses OpenStreetMap raster tiles as a fallback on technical failure. Browser connection data may therefore be transmitted directly to the map service currently in use
- Web Push infrastructure – when push is voluntarily enabled, technical delivery through the push service used by the relevant browser or operating system, for example Apple, Google/Firebase, Mozilla or Microsoft
For processing steps technically classified as share-safe and limited to place-related product data, CHEQPERT may use a separate OpenAI project. If optional OpenAI data sharing is enabled for that project, the API inputs and outputs sent through it may be used by OpenAI to evaluate and improve its services and models. CHEQPERT does not send account identities, email addresses, IP or session data, personal notes, ratings or scores, or the user's location coordinates through this route. The comprehensive internal research methodology is processed through a separate project without this sharing enabled.
In addition, publicly accessible websites may be accessed as information sources during AI web research. The sources used for a specific Q-Check are shown with the result where available.In addition, publicly accessible websites may be accessed as information sources during AI web research. The sources used for a specific -Check are shown with the result where available.
9. International data transfers
Some service providers operate internationally or use group companies or subprocessors outside the European Economic Area. Where personal data is transferred to third countries, this is based on safeguards permitted by the GDPR, in particular adequacy decisions of the European Commission — including the EU-U.S. Data Privacy Framework where applicable — or Standard Contractual Clauses under Article 46 GDPR.
For Stripe services in the European Economic Area, the current Stripe contract involves in particular Stripe Payments Europe, Limited in Ireland. Depending on the processing, Stripe may act as a processor and/or as a separate or joint controller. Where Stripe transfers personal data to the United States or other third countries, Stripe identifies in particular the EU-U.S. Data Privacy Framework and Standard Contractual Clauses as transfer mechanisms.
For SumUp payment services, SumUp Limited in Ireland is involved and is regulated by the Central Bank of Ireland. Any additional recipients or international transfers involved in a specific payment depend on SumUp's then-current privacy information and the payment method used.
You can request information about the safeguards used for a specific third-country transfer, as well as a copy or information on where they are available, at cheqpert@schmeggspert.com.
10. Retention
Personal data is stored only for as long as required for the relevant purpose or as long as legal obligations require longer retention. Account and personal place data are generally stored until you delete them or delete your account. Pseudonymized app-usage events are retained for at most 35 days; account-linked pseudonyms are additionally removed when the account is deleted. Push subscriptions are removed when push is disabled, when the relevant device is detached, or when the account is deleted; invalid push subscriptions are also cleaned up during delivery. Technical security, quota and job data is limited according to operational requirements and deleted or anonymized once it is no longer needed for security, billing, troubleshooting or legal defense.
Order and payment-status data is retained for as long as required for contract performance, accounting, refunds, abuse and replay prevention, payment-dispute handling, legal defense, and applicable statutory retention obligations. Technical webhook evidence is limited to metadata and fingerprints required for idempotency, security and auditability; complete provider payloads are not persistently stored.
Withdrawal declarations, recorded receipt times, and evidence relating to confirmation of receipt and refunds are retained for as long as required to process the withdrawal, for accounting and refunds, to meet statutory evidence and retention obligations, and for legal defense.
General Q-Check results and Q-Check histories may be retained for longer as place-related product knowledge. Any existing personal provenance is detached when an account is deleted.General -Check results and -Check histories may be retained for longer as place-related product knowledge. Any existing personal provenance is detached when an account is deleted.
11. Your rights
Under the GDPR, subject to the applicable conditions, you have in particular the following rights:
- access to your personal data
- rectification of inaccurate data
- erasure and restriction of processing
- data portability
- objection to processing based on legitimate interests
- withdrawal of consent with effect for the future
Where available, the account includes functions for data export and account deletion. You can also contact the address listed above at any time.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, email: dsb@dsb.gv.at.
13. Automated decision-making
CHEQPERT assesses places and offerings, not people. No solely automated decision is made about you that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).
14. Changes to this privacy policy
This privacy policy will be updated if features, service providers or legal requirements change materially. The current version is available through CHEQPERT.