Pointr – Privacy Policy

Last updated: 23 July 2025


1. Who We Are

Pointr AG ("Pointr", "we", "us") is the controller of your personal data under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection 2023 (FADP).

2. Where Your Data Is Stored

Your data is processed only in Frankfurt am Main, Germany (EU) and the Zurich region, Switzerland. Germany is in the EEA; Switzerland enjoys an EU adequacy decision (Art. 45 GDPR). Back-ups are mirrored between the two sites; no routine transfers occur elsewhere.

3. What Data We Collect

CategoryExamplesSource
Account Dataname, email, phone, password hashyou
Listing Dataservice description, pricing, profile photoyou
Usage DataIP address, device IDs, interaction logs, crash reportsautomatically
Payment Metadata (listers)Stripe customer ID, payment status, fee amountStripe API
Optional Device Datacontacts, camera, photos, locationyou (permission-based)

We never receive or store full card numbers or CVCs. Payments are handled directly by Stripe Payments Europe Ltd.

4. Legal Bases for Processing (Art. 6 GDPR / Art. 31 FADP)

5. Retention Periods

6. International Transfers

If vendors outside the EEA/Switzerland are engaged, we rely on EU Standard Contractual Clauses with the Swiss addendum plus industry-standard technical safeguards. Copies are available on request.

7. Who Receives Your Data

We do not sell personal data.

8. Your Rights

RightGDPRFADP
AccessArt. 15Art. 25
RectificationArt. 16Art. 32
ErasureArt. 17Art. 32
RestrictionArt. 18
PortabilityArt. 20Art. 28
ObjectArt. 21Art. 30
Withdraw consentArt. 7 (3)Art. 6 (6)

To exercise any right, email privacy@pointr.org. We reply within one month (GDPR) or 30 days (FADP).

9. Automated Decision-Making

No automated decisions with legal or similar effect are made.

10. Security

All data in transit is protected by industry-standard TLS encryption. Data at rest is encrypted using industry-standard encryption algorithms. We implement multi-factor authentication, role-based access controls, and conduct regular security assessments. No system is 100% secure.

11. Children

The service targets users 16 +. If we learn we hold data of a younger child, we delete it promptly.

12. Changes

Material changes are announced by email 30 days before they take effect and published here.

13. Contact

You may also contact your local EU data-protection authority or the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.

© 2025 Pointr AG. All rights reserved.

Innovation with Timeless Touch