Skip to content

Privacy Policy

Last updated: August 2026

This is a convenience translation of our German-language privacy policy. In case of any discrepancy, the German version at /de/privacy is authoritative.

1. Data Controller

The party responsible for data processing on this platform is the entity named in the Imprint. For privacy questions, contact hello@barranetworks.io.

2. What Data We Process

As part of the application and membership process, we process in particular: contact data (name, email, phone), profile data (location, professional role, interests, goals, optionally your Strava profile), usage data (posts, comments, event sign-ups, messages, buddy check-ins), billing and payment data for paid memberships (billing address, payment status, payment method — full card data is processed exclusively by our payment providers, see section 9), and technical data (e.g. time of last login, IP address in server logs, error reports).

3. Purpose of Processing

We process your data to review and administer your membership, enable suitable hub and buddy matches, provide the community features (feed, events, messages), bill paid memberships and issue the required invoices, notify you by email about relevant activity, and detect and fix technical errors.

4. Legal Basis

Processing is based on performing the membership relationship or pre-contractual steps such as reviewing your application (Art. 6(1)(b) GDPR), on statutory retention obligations for billing data (Art. 6(1)(c) GDPR in conjunction with German tax and commercial law), on your consent, e.g. via the cookie banner (Art. 6(1)(a) GDPR), and on our legitimate interest in a functioning, moderated, technically stable community (Art. 6(1)(f) GDPR).

5. Visibility of Your Profile Data

You control which profile fields are visible to whom (admins only, your hub only, all members, or private). You'll find these settings under Settings → Privacy.

6. Retention Period

We store usage and profile data for as long as your membership lasts. After cancellation or account deletion, personal data is deleted or anonymized within 30 days. Billing and payment data is excluded from this: it is subject to statutory retention obligations of up to 10 years under German tax law and is only deleted after that period.

7. Your Rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection. You can request a data export and delete your account directly under Settings → Account. You also have the right to lodge a complaint with a data protection supervisory authority — typically the data protection authority of North Rhine-Westphalia (LDI NRW), Germany, since that is where we are based.

8. Cookies and Analytics

The only technically necessary cookies are the session cookie for your login and a cookie that stores your cookie choice. Only if you select "Accept all" in the cookie banner do we additionally load Google Analytics for audience measurement — based on your consent (Art. 6(1)(a) GDPR), revocable at any time via the cookie banner. Without this consent, no analytics or advertising tracking takes place.

9. Processors and Recipients

We use carefully selected service providers as data processors: Vercel Inc. (hosting/application operation), Neon Inc. (database, EU Frankfurt region), Cloudflare Inc. (object storage for images), Resend (email delivery), Sentry (error monitoring, EU Frankfurt region), Stripe and PayPal (payment processing, for paid memberships), and Lexoffice (invoicing). If you use optional Google sign-in or consent to Google Analytics, Google Ireland Ltd. is also involved. We have data processing agreements under Art. 28 GDPR with all providers.

10. International Transfers

Some service providers (including Vercel, Stripe, PayPal, Google) are based, or operate servers, outside the EU/EEA, in particular in the United States. In these cases we ensure an adequate level of data protection through appropriate safeguards — such as EU Standard Contractual Clauses (Art. 46 GDPR) or the provider's participation in the EU–U.S. Data Privacy Framework.

11. Automated Individual Decisions

Hub and buddy matching is partially automated but always involves human input and has no legal or similarly significant effect within the meaning of Art. 22 GDPR. No fully automated decision-making takes place.

12. Data Security

We transmit all data in encrypted form (TLS) and apply appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access.

13. Data Protection Officer

Under § 38 BDSG (German Federal Data Protection Act) we are currently not required to appoint a data protection officer. For privacy questions, reach us directly at hello@barranetworks.io.