Privacy policy
Stand / last updated: 2026-09-03
This policy covers personal data for which ZeroCrumb is the controller. For data a bakery processes through ZeroCrumb, the bakery is the controller — see the data processing agreement.
1. Controller
[Firmenname, Anschrift, E-Mail — identisch zum Impressum]
2. Two roles — please distinguish
ZeroCrumb acts in two distinct roles. This is not a formality — it determines who is accountable for which data:
| Data | Role | Governed by |
|---|---|---|
| Bakery account: email, business name, role, language, sign-in data | Controller | this policy |
| The bakery's receipt data: product, quantity, price, time, payment method. Customer name, VAT ID and address are NO LONGER collected or stored as of 6 September 2026. | Processor | DPA |
3. Data processed and legal bases
3.1 Account data
Email address, business name, role and language preference. Authentication runs on Amazon Cognito, which additionally processes sign-in times and security events. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
3.2 Business and sales data
Sales figures, product catalogue, opening days, and the business country and city. Largely non-personal, but linked to an account. Used to produce demand forecasts — the purpose of the service. Legal basis: Art. 6(1)(b) GDPR.
3.3 Server logs
Technically necessary data is processed on each request (IP address, timestamp, requested resource, status code). Legal basis: Art. 6(1)(f) GDPR (operational security).
4. No tracking, no cookie banner
ZeroCrumb uses no analytics, advertising or tracking services. Only strictly necessary cookies/storage entries are set, for sign-in and language preference. These require no consent under §25(2) TTDSG — which is why there is deliberately no cookie banner. This statement must be revisited the moment any analytics tool is added.
5. Recipients and sub-processors
| Service | Purpose | Location |
|---|---|---|
| Amazon Web Services (Cognito) | Authentication | EU (eu-north-1, Sweden) |
| netcup GmbH | Server and database hosting (application and database run on the same server) | Vienna, Austria |
| Vercel Inc. | Frontend hosting | EU (fra1) |
| OpenWeather | Weather per location — only country and city are sent, no personal data | may be outside the EU |
| helloCash | Cash-register import — data flows from the register to ZeroCrumb, not the reverse | Austria |
Server provider: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany (HRB 705547, Amtsgericht Mannheim). The server is located in the Vienna, Austria datacentre, so processing takes place exclusively within the EU.
For providers with a possible third-country element, appropriate safeguards (standard contractual clauses) must be verified and documented. Status of the Art. 28 GDPR processing agreements: [conclude and file the DPA with netcup GmbH — still outstanding]
6. Retention
- Account data: until the account is deleted.
- Forecast history: automatically deleted after 180 days.
- Register receipts: while the account exists, imported receipts are not deleted individually. If an import is rolled back the receipt is kept and marked as voided with a timestamp and reason, so the import history stays auditable.
- On account deletion ALL of the business’s data is removed, including imported receipts. The statutory retention duty (RKSV, roughly seven years) rests with the bakery and is met by its own cash register — ZeroCrumb holds only a working copy as processor and returns or deletes it at the end of the contract (Art. 28(3)(g) GDPR).
Deletion can be triggered in the application itself (Account → Data) and requires typing the business name to confirm. It removes the data from the database and the user account from the authentication service.
7. Automated forecasting
ZeroCrumb produces demand forecasts from each business’s own sales data. Models are trained per business only — one bakery’s data never informs another’s forecast. A forecast is decision support for production planning and has no legal effect on any individual, so Art. 22 GDPR is not expected to apply.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to lodge a complaint with a supervisory authority (Art. 77). Requests to: [datenschutz@…]
Where a request concerns data a bakery processes through ZeroCrumb (for example customer details on a receipt), the bakery is the controller. We forward such requests to them without delay.