Xstrm

Privacy policy

Translation of the Datenschutzerklärung. If the two differ, the German version applies.

1. Controller

Daniel Bühner, Kolbergstr. 6b, 83109 Großkarolinenfeld, Deutschland
Email: hello@xstrm.net

2. Hosting

The website and the service run on Laravel Cloud (Laravel Holdings Inc., USA) in an Amazon Web Services data centre in Frankfurt am Main. All databases and storage are located there. Laravel Cloud routes all requests through the network of Cloudflare, Inc. (USA), which secures the connection and fends off attacks. In doing so, Cloudflare processes your IP address. We have a data processing agreement with Laravel. Where access from the USA is possible, it is based on the EU Standard Contractual Clauses.

3. Visiting the website

When you visit, the server processes technically necessary data: IP address, time, requested address, referrer and browser identifier. This is needed to deliver the page and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR. Logs of the hosting platform are deleted as soon as they are no longer needed for this purpose.

4. Audience measurement

We monitor this website with Xstrm itself. For every page view we record the path, the route, the referrer domain, the country, the browser, the operating system, the device category and a visitor hash that is only valid for one day. For every request we also record the method, address, status code and response time. If an error occurs, we store the error message, the stack trace, the full address and the request headers without cookies and credentials. The IP address is only used at the moment of the request to derive the country and the hash, and is then discarded. No cookies are set and no profiles are built. The legal basis is our legitimate interest in usage statistics and in running the site without errors (Art. 6(1)(f) GDPR). For retention, see section 12.

5. Cookies

We only set technically necessary cookies: a session cookie and a security cookie that protects forms against forged requests. Both expire after at most two hours of inactivity. If you sign in to the customer area with "Remember me", you also receive a cookie that lasts until you sign out. The hosting platform also sets Cloudflare's __cf_bm cookie to detect bots, which expires after 30 minutes, and one further technically necessary cookie, which expires after two hours. The legal basis is § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR. No consent is required for these.

6. Waitlist

If you join the waitlist, we store your email address and the link that brought you to us, and send you an email with a confirmation link (double opt-in). You are only on the list once you confirm. We keep the time of signup and of confirmation as proof of your consent. Unconfirmed addresses are deleted after 30 days. We only use the address to tell you when Xstrm is available. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by emailing hello@xstrm.net. We then delete the entry.

7. Customer account

For an account we store name, email address, a hashed password, the account name and the country. This is necessary for the contract (Art. 6(1)(b) GDPR). The data is deleted when the account ends, unless statutory retention periods apply.

8. Payments

Payments are handled by Stripe Payments Europe Ltd., Dublin, Ireland. Ordering and payment management take place on Stripe's pages. Stripe is an independent controller for the payment processing itself, and Stripe's privacy policy applies. Card details go directly to Stripe. We only store the card brand and the last four digits. The legal basis is Art. 6(1)(b) GDPR. We keep invoice data for ten years, as required by § 147 AO and § 257 HGB (Art. 6(1)(c) GDPR).

9. Email

We send system emails, such as error alerts and usage notices, through Resend (Resend Inc., USA) from servers in the EU. We have a data processing agreement with Resend based on the EU Standard Contractual Clauses. If you write to us, we process your message in order to reply (Art. 6(1)(b) or (f) GDPR).

10. Fonts in the customer area

The signed-in customer area loads fonts from Bunny Fonts (BunnyWay d.o.o., Slovenia). This transmits your IP address to Bunny. According to Bunny, it does not store personal data. The legal basis is Art. 6(1)(f) GDPR.

11. Our customers' data

We process the data that Xstrm collects in our customers' applications on their behalf. The customer is then the controller. The details are set out in the data processing agreement (AVV). IP addresses are never stored. They are only used at the moment of receipt to derive the country and the daily hash.

12. Retention

Raw data on visits and response times is deleted after 30 days, individual error events with their details after 90 days. Deletion happens a month at a time, so in individual cases up to 60 or 120 days can pass. The summary of an error (error type, error message, location in the code, first and last occurrence, count) is kept until the project is deleted. Error messages can contain personal data if the application writes it into them.

13. Recipients

We only pass data to the service providers named here. The full list is at Subprocessors. We do not sell data.

14. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future.

Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation (Art. 21 GDPR).

An email to hello@xstrm.net is enough. You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

15. No automated decisions

We do not make automated decisions within the meaning of Art. 22 GDPR.

Last updated: September 2026