Privacy Policy
As of: August 10, 2026
This data protection declaration provides information about which personal data is processed when using HelpInDeal UG (limited liability). Personal data is any information that can be used to personally identify you.
1. Responsible person
Responsible within the meaning of the General Data Protection Regulation (GDPR) is:
Cinja Christmas Night
c/o flexdienst – #11525
Kurt-Schumacher-Strasse 76
67663 Kaiserslautern
Germany
E-mail: info@helpindeal.com
The person responsible decides alone or jointly with others on the purposes and means of processing personal data.
This website uses SSL or TLS encryption for security reasons and to protect confidential content. You can recognize an encrypted connection by “https://“and the lock symbol in the browser line.
2. Access data and server log files
When you access our website, the web server processes technically necessary data, in particular the page accessed, date and time of access, amount of data transferred, referrer URL, browser type and version, operating system and the IP address. The processing is carried out on the basis of Article 6 Paragraph 1 Letter f of the GDPR because we have a legitimate interest in the secure, stable and error-free provision of the website. We reserve the right to carry out a subsequent check if there are concrete indications of illegal use.
3. Hosting by AWS
Our website is hosted on Amazon Web Services. The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg (“AWS”). When you visit the website, personal data is processed on AWS servers. Data can also be transmitted to affiliated companies in third countries, especially the USA. AWS bases such transfers on, among other things, appropriate safeguards such as EU Standard Contractual Clauses and, where applicable, other recognized transfer mechanisms.
The use of AWS is based on Article 6 Paragraph 1 Letter f GDPR. We have a legitimate interest in the secure and reliable provision of our online offering. There is a contract for order processing with AWS. Further information: https://aws.amazon.com/de/privacy/.
4. Cookies, local storage and consent
We use technically necessary cookies and comparable storage technologies so that the website functions, sessions are protected, login states are recognized and forms can be processed securely. This includes in particular session cookies, CSRF/security mechanisms and functional status information, for example in the credits area. The legal basis is Article 6 Paragraph 1 Letter f GDPR and Section 25 Paragraph 2 TDDDG; to the extent that processing is necessary to fulfill the contract, additionally Art. 6 Para. 1 lit. b GDPR.
We only use non-essential cookies or similar access to your device, in particular for statistical, marketing or map/third-party functions, if you have given your consent. The legal basis is Article 6 Paragraph 1 Letter a GDPR in conjunction with Section 25 Paragraph 1 TDDDG. You can revoke your consent at any time with future effect.
We use CCM19 to obtain, manage and document consent. The provider is Papoo Software&Media GmbH, Auguststr. 4, 53229 Bonn. For this purpose, CCM19 processes in particular the date and time of the call, a randomly generated ID, consent status, language and technically required device/browser information. The legal basis is Article 6 Paragraph 1 Letter c GDPR for the fulfillment of legal obligations to provide evidence and Article 6 Paragraph 1 Letter f GDPR for the legally compliant management of consent. Further information: https://www.ccm19.de/datenschutzerklaerung.html.
Additionally, Google Funding Choices or Google Privacy&Messaging can be integrated to manage consent and notifications for Google advertising and publisher products. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The processing serves to manage consent and to implement data protection regulations for Google services. The legal basis is Art. 6 Para. 1 lit. c GDPR and, to the extent that non-essential cookies or device access is affected, Art. 6 Para.
You can also delete or block cookies in your browser. If cookies are blocked, the functionality of the website may be restricted.
When you actively start identity verification via Stripe Identity on the Verification page, we load additional scripts and session technologies from Stripe (Stripe.js) that are technically necessary to perform the verification. These are only loaded after your conscious interaction and consent for verification, not when you generally access the website. The legal basis is Article 6 Paragraph 1 Letter b GDPR and, as far as device information is concerned, Article 6 Paragraph 1 Letter a GDPR in conjunction with Section 25 Paragraph 1 TDDDG. Further information can be found under Section 10 (Identity verification via Stripe Identity).
5. Registration, user account and contract processing
If you create a user account or use our platform functions, we process the data that you provide to us via input forms, in particular your name, email address, password, profile information, address or location information, information about advertisements/deals, messages, favorites, reviews, reports, credits and account settings. The processing takes place to set up and manage the user account, to provide the platform functions and to carry out pre-contractual or contractual measures on the basis of Article 6 Paragraph 1 Letter b GDPR.
Your location information may be stored as an address, coordinates or location area to provide search, matching and deal functions. Depending on the function, this information can be displayed to other users if this is necessary to display your profile, your deals or platform communication.
You can request deletion of your user account at any time by sending a message to the above contact address. After deletion or complete contract processing, data will be deleted or blocked unless there are legal retention obligations or legitimate interests in further storage.
6. Registration and login via Google or Facebook
You can register or log in using an existing Google or Facebook account. When you select the respective social login option, you will be redirected to the provider where you can authorize the transmission of certain profile data to us. In particular, name, email address, user ID and optionally a profile picture can be transmitted. We only use this data to set up, log in and manage your user account.
The provider of the Google login is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data protection information: https://policies.google.com/privacy.
The Facebook login provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Data protection information: https://www.facebook.com/privacy/policy/.
The legal basis is Article 6 Paragraph 1 Letter a GDPR, provided you consciously select and release the link, as well as Article 6 Paragraph 1 Letter b GDPR for subsequent account and contract processing. You can terminate the link in the settings of the respective provider or by deleting your user account.
7. Contact Us, Platform Messages and Email Notifications
If you contact us by email, contact form or via platform functions, we process the data you provide to process the request and for technical administration. The legal basis is Article 6 Paragraph 1 Letter f GDPR; If your request relates to a contract or its implementation, additionally Art. 6 Para. 1 lit. b GDPR.
Users can communicate with each other within the platform. We process message content, participants, times and technical status information in order to provide the chat and notification functions. The legal basis is Article 6 Paragraph 1 Letter b GDPR.
We also send transactional system emails, such as registration confirmations, password and security messages, chat notifications, status information about deals, credits or reviews. Depending on the reason, this processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR or Article 6 Paragraph 1 Letter f GDPR.
8. Newsletters and Matching Notifications
If you subscribe to newsletters or matching/top match notifications, we process your email address, your choice of notifications, registration and unsubscription times and technical evidence data. The processing takes place on the basis of your consent in accordance with Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time using the unsubscribe links in the emails, via your account settings or by sending us a message.
Matching notifications are based on your profile, search, deal and preference information as well as matching scores calculated from them. They serve to suggest suitable offers or contacts. The legal basis is Article 6 Paragraph 1 Letter b GDPR for the provision of the desired platform function; Your consent or the notification setting you have selected also applies to email notifications.
9. Credits and payment processing via Stripe
We use Stripe as a payment service provider to purchase credits. The provider is Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; Depending on the service, other Stripe companies may be involved. When a checkout is started, order and payment information is transmitted to Stripe, in particular order identifier, user reference, package, price, currency, payment status as well as checkout, payment intent, customer and event identifiers generated by Stripe. Payment data such as credit card details are generally processed directly by Stripe.
The processing takes place for payment processing and contract fulfillment on the basis of Art. 6 Para. 1 lit. b GDPR as well as for fraud prevention, payment security and accounting on the basis of Art. 6 Para. 1 lit. f GDPR. Stripe can also process data in third countries and uses suitable transfer mechanisms for this. Further information: https://stripe.com/privacy and https://stripe.com/legal/privacy-center.
10. Identity verification via Stripe Identity
We offer voluntary profile verification for certain platform functions. The prerequisite is the purchase of a credit package or an active subscription; The verification itself is free under the conditions presented there or is billed in credits. To carry this out, we use the Stripe Identity service from the payment service provider Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; Depending on the service, other Stripe companies may be involved.
After your express consent, a check window provided by Stripe opens. You upload your ID document and, depending on the configuration, a selfie picture directly to Stripe. These document and facial images, derived biometric comparison data, identification information, and device and fraud prevention signals are processed exclusively by Stripe and do not reach our servers. We only store the session ID, the check status, any error code and the time of your consent.
Processing is carried out to fulfill the user contract and to prevent fraud on the basis of Article 6 Paragraph 1 Letter b and Letter f GDPR and, as far as biometric data is concerned, on the basis of your express consent in accordance with Article 9 Paragraph 2 Letter a GDPR. You can separately consent or object to the use of your data to improve Stripe's biometric verification technology; Stripe will inform you of this separately during the check process. Stripe can also process data in third countries and uses suitable transfer mechanisms for this. Further information: https://stripe.com/privacy and https://stripe.com/legal/privacy-center.
Once the check has been completed, we will delete the verification session conducted with Stripe after the retention period configured by us has expired or immediately upon deletion of your user account. You can also have the data stored by Stripe deleted directly via Stripe Support or revoke your consent to use it for technology improvements: https://support.stripe.com.
11. Maps, location search and geocoding
We use Google Maps/Google Places for location and map services. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When loading or using corresponding map and autocomplete functions, IP address, browser and device data, search terms entered, selected locations and usage data can be transmitted to Google. Google may also transfer data to Google LLC in the USA. The legal basis, to the extent legally required, is your consent in accordance with Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TDDDG; Furthermore, Art. 6 Para. 1 lit. f GDPR for a user-friendly location and map display.
Further information: https://policies.google.com/privacy and Google Maps Terms of Use.
We use LocationIQ for certain map displays, map tiles and location autocomplete functions. The provider is Unwired Labs (India) Pvt Ltd, Plot #128, Prashasan Nagar, Jubilee Hills, Hyderabad, Telangana, India - 500033. Depending on the function, your IP address, technical browser/device information, map views, entered search terms, selected locations and location references may be processed. Individual location requests are made via a server-side interface; Map tiles or map displays can also be loaded directly from LocationIQ through your browser. The legal basis is Art. 6 Para. 1 lit. b GDPR, insofar as the location search or map display is necessary to use the platform function, as well as Art. 6 Para. 1 lit. f GDPR for the reliable provision of the search and map functions. To the extent legally required, integration will only take place with your consent in accordance with Article 6 (1) (a) GDPR and Section 25 (1) TDDDG. Further information: https://www.locationiq.com/privacy.
12. Google Tag Manager and Google Analytics 4
We use a Google Tag Manager / Google Analytics 4 setup for statistics and event measurement. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Analysis tags can be managed centrally via the Tag Manager. Google Analytics 4 can process event data such as page area, login status, search and interaction events, checkout start or successful checkout, technical device information and shortened or pseudonymized identifiers. We do not transmit payment data or message content to Google Analytics.
Use is only based on your consent in accordance with Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TDDDG. You can revoke your consent at any time with future effect. Google can also transfer data to the USA and bases such transfers on appropriate guarantees. Further information: https://policies.google.com/privacy and Information about Google Analytics 4.
We only use Google Ads and Google AdSense if they are shown separately in the consent banner and permitted by you. Without such active integration, no processing for advertising purposes takes place via these services. Google Optimize is technically discontinued and we do not use it as an active service.
13. AI support from DeepInfra
We use DeepInfra for optional AI functions, in particular text suggestions, matching explanations and the generation of example/template images. The provider is Deep Infra Inc., 2625 Middlefield Road #460, Palo Alto, CA 94306, USA. When you use AI features, the content you enter or select, as well as technical request information, may be sent to DeepInfra to produce the desired output. Please do not enter confidential or sensitive personal information in AI fields that is not necessary for the function.
The legal basis is Article 6 Paragraph 1 Letter b GDPR, insofar as the AI function is provided as a desired platform function, as well as Article 6 Paragraph 1 Letter f GDPR for the improvement and efficient provision of input assistance. If consent is requested, Art. 6 Para. 1 lit. a GDPR is the legal basis. When transferring data to the USA, we use appropriate guarantees where necessary. Further information: https://deepinfra.com/privacy.
14. Social sharing and social media presence
Our website may offer sharing links to Facebook, X/Twitter, LinkedIn, WhatsApp and email. These buttons are implemented as links or Shariff-like solutions. Simply loading our site does not establish a connection to the social networks. Only when you click on a share link do you open the offer from the respective provider; The provider’s data protection regulations apply there.
Further information can be found from the respective providers: Meta/Facebook https://www.facebook.com/privacy/policy/, X/Twitter https://x.com/de/privacy, LinkedIn https://www.linkedin.com/legal/privacy-policy, WhatsApp https://www.whatsapp.com/legal/privacy-policy-eea.
We also maintain publicly accessible profiles on social networks, in particular Facebook, Instagram, X/Twitter and LinkedIn. When you visit our social media presence, the providers can analyze your usage behavior and assign it to your account. To the extent required by law, we are jointly responsible with the respective platform operator for the processing operations initiated there. Please assert data subject rights directly with the respective provider, as they have access to the data processed there.
If you commission paid or managed social promotion services for deals, the deal and campaign information required for this can be processed internally and, if necessary for implementation, transmitted to social media platforms such as Meta/Facebook or Instagram. The legal basis is Art. 6 Para. 1 lit. b GDPR for the implementation of the commissioned service and Art. 6 Para. 1 lit. f GDPR for documentation and evidence.
15. External Video Content
If external video content, for example from YouTube or Vimeo, is embedded on individual pages or opened via a media/lightbox function, a connection to the respective provider is generally only established when the content is accessed. In particular, IP address, browser and device data, referrer URL and usage data can be transmitted to the provider. YouTube is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Data protection information: https://policies.google.com/privacy. The provider of Vimeo is Vimeo.com, Inc., 330 West 34th Street, 5th Floor, New York, NY 10001, USA; Data protection information: https://vimeo.com/privacy. The legal basis, to the extent legally required, is your consent in accordance with Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TDDDG; Furthermore, Article 6 Paragraph 1 Letter f GDPR for an attractive presentation of media content.
16. External fonts, libraries and local Google Fonts
External libraries, in particular Font Awesome and MarkerClusterer/CDN resources, can be loaded to display icons and technical map functions. When accessing such files, the respective provider processes technically necessary access data such as IP address, browser information and time of retrieval. The legal basis is Article 6 Paragraph 1 Letter f GDPR; Our legitimate interest lies in a uniform, secure and high-performance presentation of the website. Where legally required, we obtain consent before charging.
Google Fonts are integrated locally if used on the website. There is no connection to Google servers for locally hosted fonts.
17. Legal basis and storage period
Unless a specific storage period is specified in this data protection declaration, we only store personal data for as long as is necessary for the respective purpose. We store data that is processed on the basis of consent until revoked, unless there is another legal basis. We store data for contract processing for the duration of the contractual relationship and then only if there are legal retention obligations, obligations to provide evidence or legitimate interests. Data relevant to commercial and tax law can be stored for six or ten years.
18. Your Rights
Within the framework of the legal requirements, you have the right to information according to Art. 15 GDPR, correction according to Art. 16 GDPR, deletion according to Art. 17 GDPR, restriction of processing according to Art. 18 GDPR, information according to Art. 77 GDPR.
If we process personal data on the basis of Article 6 Paragraph 1 Letter f of the GDPR, you can object to this processing at any time for reasons arising from your particular situation. If personal data is processed for the purpose of direct advertising, you can object to this processing at any time.
19. Controller
The person responsible is the one HelpInDeal UG (limited liability), represented by the managing director Cinja Christnacht, with headquarters in Cologne and delivery address c/o flexdienst - #11525, Kurt-Schumacher-Straße 76, 67663 Kaiserslautern, Germany. Registration court: Cologne District Court, registration number: HRB 128141. Email: info@helpindeal.com.
20. Automatic translation of user content
If the corresponding function is activated, texts from deals, reviews and chat messages are automatically translated. For this purpose, the respective text, the source language recognized or used, the target language and technical metadata can be transmitted to our AI service provider DeepInfra and processed there. Processing can take place in the USA or in other third countries. The translations are marked as machine translations; Please do not transmit sensitive data in such texts that is not necessary for the function.