Stefan Heinsen
Sternstr. 31, 39104 Magdeburg, Deutschland
legal@groupgrocer.app
GroupGrocer ist eine geteilte Einkaufsliste. Damit mehrere Leute dieselbe Liste sehen, müssen die Listen auf einem Server liegen — das ist der Zweck der App und der Grund, warum überhaupt Daten verarbeitet werden. Werbung und Analyse laufen nur, wenn du zugestimmt hast. Ohne Zustimmung bleiben beide aus.
Zum Anmelden nutzen wir Firebase Authentication von Google. Du hast vier Wege:
Dazu kommt eine Nutzerkennung, die deine Listen dir zuordnet. Dein Anzeigename und dein Profilbild sind für die anderen Mitglieder deiner Listen sichtbar — anders könnten sie nicht sehen, wer etwas eingetragen hat.
Listen, Artikel, Mengen, Einheiten, Abteilungen, Notizen und die Mitgliederliste liegen in Cloud Firestore. Wer über einen Einladungslink beitritt, wird Mitglied und sieht ab dann alles in dieser Liste und kann es ändern. Das ist der Sinn der Sache — denk trotzdem daran, bevor du einen Link weitergibst.
Ein Teil davon liegt zusätzlich auf deinem Gerät, damit die App ohne Netz funktioniert. Diese Kopie verschwindet, wenn du die App deinstallierst.
Wenn du Benachrichtigungen erlaubst, erzeugt Firebase Cloud Messaging eine Gerätekennung für den Versand. Sie steckt an der Liste, zu der sie gehört, und dient nur dazu, den Mitgliedern zu melden, dass jemand einkaufen geht.
Die App zeigt Werbebanner über Google AdMob. Dafür wird die Werbe-ID deines Geräts an Google übertragen — das ist die einzige Stelle, an der Daten aus der App an ein anderes Unternehmen gehen.
Vor der ersten Anzeige fragt dich ein Einwilligungsdialog von Google (die sogenannte UMP-Plattform). Sagst du nein, wird keine personalisierte Werbung ausgespielt. Deine Entscheidung kannst du jederzeit über denselben Dialog wieder ändern.
Du kannst Werbung auch dauerhaft abschalten, indem du in der App die werbefreie Fassung kaufst.
Wir nutzen Firebase Analytics, um zu sehen, ob die App überhaupt benutzbar ist. Die Erfassung ist ab Werk ausgeschaltet und wird nur eingeschaltet, wenn du der Werbung zustimmst — einen zweiten Dialog dafür gibt es nicht.
Erfasst werden fünf Ereignisse, und zwar ausschließlich als Zählwerte, nie mit Inhalten deiner Listen:
Die werbefreie Fassung wird über Google Play abgewickelt. Deine Zahlungsdaten bekommen wir nie zu sehen — sie liegen bei Google. Bei uns landet nur die Information, dass ein Kauf gültig ist.
Wir betreiben keine eigenen Server. Alles läuft über Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Analytics, AdMob), mit dem ein Auftragsverarbeitungsvertrag besteht. Unsere Server-Funktionen laufen in der EU (europe-west1). Google kann Daten auch außerhalb der EU verarbeiten; dafür gelten die Standardvertragsklauseln der EU-Kommission.
Wir verkaufen keine Daten und geben nichts an Werbenetzwerke weiter außer der oben genannten Werbe-ID.
Deine Listen bleiben, solange dein Konto besteht. Betriebsprotokolle werden nach spätestens 30 Tagen überschrieben. Kaufbelege müssen wir steuerlich aufbewahren; sie liegen ohnehin bei Google.
Du kannst dein Konto in der App selbst löschen: Profilbild oben rechts → Konto löschen. Was dabei genau passiert — und wie du nur einzelne Daten loswirst, ohne das Konto aufzugeben — steht auf einer eigenen Seite:
groupgrocer.app/delete-account.html
Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch. Eine erteilte Einwilligung kannst du jederzeit widerrufen; das Vorherige bleibt davon unberührt.
Schreib dafür an legal@groupgrocer.app. Du kannst dich außerdem bei einer Datenschutz-Aufsichtsbehörde beschweren — für uns zuständig ist der Landesbeauftragte für den Datenschutz Sachsen-Anhalt.
Die App richtet sich nicht an Kinder. Wir erheben nicht wissentlich Daten von Personen unter 16 Jahren. Wenn du feststellst, dass das doch passiert ist, schreib uns — wir löschen es.
Ändert sich, was die App tut, ändert sich diese Seite mit. Das Datum oben sagt dir, wann das zuletzt der Fall war.
Stefan Heinsen
Sternstr. 31, 39104 Magdeburg, Germany
legal@groupgrocer.app
GroupGrocer is a shared shopping list. For several people to see the same list, the lists have to live on a server — that is the purpose of the app and the reason any data is processed at all. Ads and analytics only run if you agreed to them. Without your consent, both stay off.
We use Firebase Authentication by Google. You have four options:
On top of that there is a user identifier that links your lists to you. Your display name and picture are visible to the other members of your lists — otherwise they could not tell who added what.
Lists, items, quantities, units, departments, notes and the member list are stored in Cloud Firestore. Anyone who joins through an invitation link becomes a member and can see and change everything in that list from then on. That is the point of the app — still, keep it in mind before you pass a link on.
A copy is also kept on your device so the app works without a connection. That copy disappears when you uninstall the app.
If you allow notifications, Firebase Cloud Messaging creates a device identifier for delivery. It is attached to the list it belongs to and is used only to tell members that someone is going shopping.
The app shows banner ads through Google AdMob. This transmits your device's advertising ID to Google — the only point at which data from the app goes to another company.
Before the first ad, a consent dialog from Google (the UMP platform) asks you. If you decline, no personalised advertising is served. You can change your decision at any time through that same dialog.
You can also switch ads off permanently by buying the ad-free version in the app.
We use Firebase Analytics to see whether the app is usable at all. Collection is off by default and is only switched on if you consent to advertising — there is no second dialog for it.
Five events are recorded, as counts only, never with the contents of your lists:
The ad-free version is handled by Google Play. We never see your payment details — they stay with Google. All we receive is the information that a purchase is valid.
We run no servers of our own. Everything goes through Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Analytics, AdMob), with whom a data processing agreement is in place. Our server functions run in the EU (europe-west1). Google may process data outside the EU; the European Commission's Standard Contractual Clauses apply to that.
We do not sell data and pass nothing to ad networks other than the advertising ID mentioned above.
Your lists remain for as long as your account exists. Operational logs are overwritten after 30 days at the latest. Purchase records must be retained for tax purposes; they are held by Google anyway.
You can delete your account in the app: profile picture in the top right → Delete account. Exactly what happens then — and how to remove individual data without giving up the account — is on its own page:
groupgrocer.app/delete-account.html
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent at any time; processing carried out beforehand remains lawful.
Write to legal@groupgrocer.app. You may also lodge a complaint with a data protection supervisory authority — ours is the Landesbeauftragter für den Datenschutz Sachsen-Anhalt.
The app is not directed at children. We do not knowingly collect data from people under 16. If you find that we have, write to us and we will delete it.
If what the app does changes, this page changes with it. The date at the top tells you when that last happened.