Privacy Policy
Information about the processing of your personal data
Protecting your personal data is particularly important to us. We therefore process your data exclusively on the basis of applicable law (GDPR, TDDDG, DDG). This Privacy Policy explains the main aspects of data processing in our app and on our website.
1. Controller
nord-code UG (haftungsbeschränkt)
Rotdornweg 28, 25451 Quickborn, Germany
Represented by managing directors Michael Ebert and Rico Flaegel
Email: info@nord-code.de
2. Data we collect
When you use our app and website, we collect the following personal data:
2.1 Registration and user account
- Name: To identify you within your team
- Email address: For account management, notifications and communication
- Profile picture: Optional, to personalise your profile
- Phone number: Optional, for contact within the team
- Date of birth: To check age-related requirements for account use and parental consent (section 3), and to determine the team's age group
2.2 Team and event data
- Team memberships and roles
- Training and match dates
- Event acceptances and declines
- Absences (holidays, injuries)
- Financial transactions and contributions
- Chat messages, including attachments, sender and time sent — visible to participants in the respective chat
2.3 Photos and media
- Uploaded images (profile pictures, team logos, event photos)
- Stored on servers of Hetzner Online GmbH (Germany/EU)
- Images are delivered through Cloudflare's Content Delivery Network (CDN; see section 5.3) and cached on edge servers for fast delivery
- Profile pictures and logos can be accessed through long, unguessable addresses provided only to authorised users within the app; no public directory or image listing exists
- When an image is replaced or deleted (e.g. when an account is deleted), it is removed from storage and purged from the CDN cache
2.4 Location data
- Only with express permission for the location search feature
- To find teams and clubs near you
- Location permission can be withdrawn at any time in your device settings
2.5 Health data (Apple Health / Google Health Connect)
You can import completed workouts from Apple Health (iOS) or Google Health Connect (Android) into your player profile. This happens only at your express request: you grant permission in the operating system and then individually select each workout to import. Without this step, bolzn does not access your health data.
- Only workouts and their associated distance are read
- Access is read-only — bolzn does not write any data back to Apple Health or Google Health Connect
- For each imported workout, we store: activity type, start and end times, duration, distance covered, the name of the recording app and a workout identifier to prevent duplicate imports
- Imported workouts are stored in your player profile and shown to your teammates — this is the purpose of the feature, to which you agree before importing. Recipients are limited to members of your teams and the processors used for our database and servers (section 6)
- Health data is neither sold nor used for advertising, marketing or data analysis outside this feature, and is not shared with other third parties
- You can withdraw permission at any time (iOS: Settings › Privacy & Security › Health; Android: in the “Health Connect” app). Delete previously imported workouts in your profile in the app
2.6 Push notifications
To keep you informed about events, acceptances and declines, chat messages and team news, we send push notifications through Firebase Cloud Messaging (Google) and, on iOS, also through the Apple Push Notification Service. A device token is generated on your device, assigned to your user account and stored by us. Because it is linked to your account, we treat it as personal data.
- Data processed: device token, device type and operating system, and the content of each notification
- Notifications are sent only if you have allowed them in your operating system; you can withdraw permission at any time in your device settings and disable individual notification types in the app
- The token is deleted when you sign out or delete your account
2.7 Payment data
We bill paid Team and Club plans through the payment provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland). You enter your payment details (e.g. card number, IBAN) directly with Stripe; we do not receive or store complete payment details ourselves.
- We store: the contracting party's name and billing address, email address, selected plan, term, payment status and invoices, and a Stripe customer identifier
- Stripe processes your payment data as an independent controller, including for fraud prevention. Further information: Stripe Privacy Policy
- Invoice data is subject to statutory retention periods (see section 9)
2.8 Invitations and email delivery
When you invite a team member, we send an invitation containing your name and the team name to the email address you enter — even if the invitee does not yet have a bolzn account. You are responsible for inviting only people who agree to this. We also send emails for account verification, password resets and invoices. We use Mailtrap (Railsware Products Studio LLC, USA; see section 7) for delivery. The recipient address, subject, email content and delivery logs are processed and stored by the provider for a short period. We delete the addresses of invitees without an account once the invitation has been accepted or has expired.
2.9 Sports pitch addresses
To display venues on a map and make them discoverable in nearby searches, we convert the sports pitch or club grounds address you enter into coordinates. We send only the entered address — no user data and not your IP address — from our servers to HERE Europe B.V., Kennedyplein 222-226, 5611 ZT Eindhoven, Netherlands. Further information: HERE Privacy Policy.
2.10 Maps and weather
To display maps, we load map tiles from OpenStreetMap (tile.openstreetmap.org, OpenStreetMap Foundation). For event weather forecasts, we query Open-Meteo (api.open-meteo.com, Open-Meteo, Switzerland). Your device's IP address and the requested map area or the event's location and time are transmitted to the respective provider. No user account or personal identifier is sent. The legal basis is our legitimate interest in displaying venues and weather conditions (Article 6(1)(f) GDPR).
2.11 Exporting member data
Coaches and team staff can export their team's member list to a Google spreadsheet. An export takes place only when they initiate it themselves, and the data is transferred to the exporting person's Google account. From that point on, that person is responsible for the exported data; processing within Google services is governed by the Google Privacy Policy.
3. Minors
bolzn is also used by youth teams but is not directed at children. For players under 16, a legal guardian creates and manages the profile; the guardian is our contracting party and provides the consent required for data processing (Article 8 GDPR) — particularly for importing health data (section 2.5) and sharing location (section 2.4). We do not collect data from minors beyond what is necessary for team organisation, and do not use their data for advertising or profiling.
If we learn that a profile for someone under 16 was created without a legal guardian's involvement, we suspend it and delete the data unless consent is subsequently obtained. Legal guardians can exercise the rights in section 10 on behalf of their child and contact info@nord-code.de at any time. Our rules for interactions with minors in teams also include the Community Guidelines and section 4 of the Terms of Use.
4. Signing in through third-party providers
You can sign in to bolzn through the following services:
4.1 Google Sign-In
When you sign in through Google, we receive access to your name, email address and profile picture. Further information: Google Privacy Policy
4.2 Apple Sign-In
When you sign in through Apple, we receive your name and email address (you may choose to use a private relay email address). Further information: Apple Privacy Policy
5. Analytics and troubleshooting
We use the following services to improve our app:
5.1 Google Analytics
We use Google Analytics (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) to analyse use of our website. No analytics tool is integrated into the bolzn app; no usage data is collected there for analytics purposes. On the website, usage data is collected with a shortened IP address; transfer to Google LLC in the USA is possible (see section 7). You can prevent collection by Google Analytics by installing a browser add-on: Google Analytics Opt-out
5.2 Error monitoring (Bugsink)
We use Bugsink for error monitoring, a self-hosted, Sentry-compatible application running exclusively on our own servers. No data is transmitted to third parties. When a technical error occurs, error reports containing technical details (e.g. error message, app version, device type and operating system) are collected to identify and resolve problems quickly.
Error reports are transmitted only if you have enabled this feature in your profile. The legal basis is your consent (Article 6(1)(a) GDPR); you can withdraw it at any time in your profile.
5.3 Cloudflare (CDN and attack protection)
We use Cloudflare, a service of Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare acts as a reverse proxy and content delivery network in front of our servers: all connections to the app and API pass through Cloudflare's network. Cloudflare processes your IP address and technical connection data (e.g. requested URL, browser and device identifier, time). Uploaded images are cached on Cloudflare edge servers for fast delivery.
The purpose is to protect against attacks (including DDoS), secure our service and improve its speed. The legal basis is Article 6(1)(f) GDPR (legitimate interest in security and availability). We have a data processing agreement with Cloudflare; for transfers to the USA, Cloudflare is certified under the EU-US Data Privacy Framework. Cloudflare stores connection data only briefly. Further information: Cloudflare Privacy Policy.
6. Hosting and processors
Your data is processed by the following providers. Unless stated otherwise, they act as processors under Article 28 GDPR on the basis of a data processing agreement and solely on our instructions.
- MongoDB Atlas (MongoDB Ltd., Building Two, Number One Ballsbridge, Dublin 4, Ireland): database for accounts, team, event and chat data; data is stored in an EU data centre (Frankfurt am Main)
- Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany): our own servers for the app interface (API), image file storage, cache, error monitoring and backups; located in Germany
- Cloudflare Inc. (USA): CDN and attack protection, see section 5.3
- Google Ireland Ltd. (Ireland) — Firebase: authentication (Firebase Authentication), push notifications (section 2.6), analytics (section 5.1)
- Apple Inc. (USA): Apple Push Notification Service (section 2.6) and Apple Sign-In (section 4.2)
- Stripe Payments Europe, Ltd. (Ireland): payment processing, independent controller (section 2.7)
- Mailtrap (Railsware Products Studio LLC, USA): email delivery (section 2.8)
- HERE Europe B.V. (Netherlands): conversion of sports pitch addresses into coordinates (section 2.9)
We do not otherwise share your data with third parties unless legally required or with your consent.
7. Transfers to third countries
Some of the providers listed are based in the USA or process data there (Google LLC as the parent company of Google Ireland, Cloudflare Inc., Apple Inc., Stripe Inc. as the parent company of Stripe Payments Europe, Railsware Products Studio LLC). The USA does not have a general adequacy status; we base transfers there on Article 45 or Article 46 GDPR:
- Google LLC, Cloudflare Inc., Apple Inc. and Stripe Inc. are certified under the EU-US Data Privacy Framework ; the European Commission's adequacy decision of 10 July 2023 applies to them (Article 45 GDPR)
- The European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Article 46(2)(c) GDPR) have also been agreed with all listed providers, supplemented by technical measures such as encryption in transit
Our primary database, our own servers and image storage are located in Germany or the EU. This is separate from processing and possible caching by providers named in this policy (particularly Cloudflare, Google and Mailtrap), to which this section applies. You can request a copy of the Standard Contractual Clauses at info@nord-code.de.
8. Legal bases
Your data is processed on the following legal bases:
- Performance of a contract (Article 6(1)(b) GDPR): To provide our services, including push notifications, invitation and account emails, payment processing and map display of venues
- Legal obligation (Article 6(1)(c) GDPR): For retaining invoice and accounting data
- Consent (Article 6(1)(a) GDPR): For optional features such as location sharing and error reports; for users under 16, consent is given by the legal guardian (Article 8 GDPR, section 3)
- Explicit consent (Article 9(2)(a) GDPR): For importing workouts from Apple Health or Google Health Connect (section 2.5). Health data is a special category of personal data; we do not process it without your explicit consent. You may withdraw consent at any time with effect for the future
- Legitimate interests (Article 6(1)(f) GDPR): To improve and secure our services
9. Data storage and deletion
Your data is stored while you have an active bolzn user account. If you delete your account in the app, your personal data is deleted immediately. If you request deletion by email instead, it is completed within 30 days of your confirmation — in each case subject to statutory retention obligations.
Team data (e.g. events and financial transactions) remains available to other team members but is detached from your profile. To preserve these team histories, an anonymised record with no personal reference is permanently retained for profiles you managed exclusively; all personal details and the profile picture are removed. Chat messages you wrote also remain readable for other participants but are detached from your name.
We retain invoice and accounting data for 6 to 10 years to meet legal obligations (section 147 AO, section 257 HGB); it is blocked from any further use. Your data may remain in encrypted backups for a limited period until they are overwritten in the normal cycle.
For detailed step-by-step instructions and a complete overview of which data is deleted and which is retained, see Delete account.
10. Your rights
You have the following rights regarding your personal data:
- Access: You may request information about your stored data at any time
- Rectification: You may request correction of inaccurate data
- Erasure: You may request deletion of your data
- Restriction: You may request restriction of processing
- Data portability: You may receive your data in a commonly used format
- Objection: You may object to the processing of your data
- Withdrawal of consent: You may withdraw consent at any time
To exercise your rights, please contact us at: info@nord-code.de
11. Data security
We use technical and organisational security measures to protect your data against manipulation, loss, destruction and unauthorised access. We continually improve our security measures in line with technological developments.
- Encrypted data transmission (HTTPS/TLS)
- Database, servers and image storage in data centres in Germany and the EU (section 6), encrypted daily backups
- Providers to whom we transmit data are contractually required to maintain a level of protection consistent with this Privacy Policy (sections 6 and 7)
- Regular security updates
- Access restrictions for staff
12. Right to lodge a complaint
If you believe the processing of your data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority.
13. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy to reflect changes in the law or our service. The current version is always available on this page.
Website language preference
We save your manually selected language locally in your browser (Local Storage) to remember it for your next visit. Without a saved choice, we use your browser language. We do not look up your location.
14. Contact
For privacy-related questions, contact us at:
Email: info@nord-code.de
Last updated: September 2026
nord-code UG (haftungsbeschränkt)