Privacy Policy

Updated at 2026-07-10

Oldtimer Map ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share personal information when you use our website (oldtimer-map.com and its subdomains), our iOS and Android application Oldtimer Map, and related services (collectively, the "Service").

By using the Service, you acknowledge this Privacy Policy and our Terms of Service. If you do not agree, please do not use the Service.

Controller

The data controller responsible for processing under this policy is Florian Pollakowsky, Büschingstraße 11, 10249 Berlin, Germany. Contact: contact@oldtimer-map.com

We have not appointed a separate data protection officer. For privacy enquiries, please contact the controller at the address above.

What information we collect

We collect information in the following categories, depending on how you use the Service:

  • Account data: email address, first and last name, and password (stored in hashed form).
  • User-generated content: event listings (titles, descriptions, dates, locations, categories, contact details), images you upload, place suggestions, and reports.
  • Technical data: IP address, browser or app type, authentication tokens, language preference (including the preferred_locale cookie on the website), and push notification device tokens when you enable notifications.
  • Security data: information processed by Google reCAPTCHA when you use protected forms (e.g. login, reports, support contact); technical access data when you fetch events via the public events API (see "Server logs & API security").
  • Analytics data: usage events when you have given analytics consent (see PostHog below).
  • Support messages: your email address and the content of messages you send via our support contact form.
  • Marketing data: your email address when you opt in to our newsletter (app; website signup when available).

User-Generated Content

We collect content you submit through the Service, such as event listings, images, place suggestions, and reports. This may include personal data about you or third parties (for example organiser names, phone numbers, or email addresses on an event listing or flyer).

Event details you publish are generally visible to other users and the public where we display the map and event list. We use this information to operate and provide the Service. You may request access, correction, or deletion of your content by contacting us or through your account settings where available.

AI-assisted event creation (flyer analysis)

In the mobile app, signed-in users with permission to create events may upload an event flyer image so we can prefill event fields (title, description, dates, location, categories, and images). This feature is optional; you can always enter event details manually.

When you use it, the image is sent to our servers and then to OpenAI for automated extraction of event information. Flyers may contain personal data visible on the image (e.g. organiser contact details or photographs). We ask OpenAI not to store the request for training (store: false). Extracted data is shown to you for review before you publish; you are responsible for checking accuracy.

Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR) — providing the event-creation feature you requested.

The flyer image is stored on our systems as a pending event image until you publish or it is removed under our retention rules. OpenAI may process data in the United States. OpenAI privacy policy: https://openai.com/policies/privacy-policy

How we use information

We use personal information to:

Provide, operate, and maintain the Service (accounts, events, maps, search, favourites, and related features).
Moderate content and protect the Service from abuse and fraud.
Respond to support requests and communicate with you about the Service.
Improve the product through analytics when you have consented.
Send marketing emails only when you have opted in (you may unsubscribe at any time).
Comply with legal obligations and enforce our terms.

Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)): account management, event creation and publication (including AI flyer prefill when you choose that feature), and providing the Service you request.
  • Consent (Art. 6(1)(a)): PostHog product analytics, push notifications, and marketing newsletter emails. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Legitimate interests (Art. 6(1)(f)): security and abuse prevention (including reCAPTCHA and logging of events API access), operating and improving the Service in a proportionate way, and handling support enquiries — balanced against your rights.

Sharing and processors

We use trusted service providers who process data on our behalf, including:

Our backend and hosting infrastructure (event and account data, and server logs).
OpenAI (flyer image analysis and optional description translation).
Google (reCAPTCHA for bot protection).
Firebase / Google (push notification delivery).
PostHog (product analytics with consent, error tracking, and backend API security monitoring; EU infrastructure).
CCM19 (consent management on the website).
Resend (delivery of support contact form emails).

We do not sell your personal information. We may disclose information if required by law or to protect rights, safety, and security.

International transfers

Some providers process data outside the European Economic Area, including in the United States (notably OpenAI, Google reCAPTCHA, and Firebase). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions under applicable law.

Retention

We keep personal information only as long as needed for the purposes described in this policy:

  • Account and event data: while your account is active and you use the Service; you may request deletion.
  • Consent-based processing (analytics, marketing, push): until you withdraw consent or delete your account, subject to technical limits.
  • Pending flyer images from AI analysis: until you publish the event or they are cleaned up under our image retention rules.
  • Support correspondence: as long as needed to handle your request and for a reasonable period thereafter.
  • Events API access logs: as long as needed for security and abuse detection; then deleted or anonymised according to our hosting provider and PostHog retention settings.

Security

We implement appropriate technical and organisational measures to protect personal information. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Server logs & API security

When you browse events through our app or website, our servers process technical access data for the public events API endpoints (GET /events, GET /events/minimal, GET /events/:id). This may include your IP address, HTTP method and path, browser or app user agent, HTTP status code, and optional search or filter parameters (such as page, limit, location, radius, categories, date range, or search query).

We use this information to detect unusual or abusive request patterns that could indicate unauthorised scraping of our event data. This processing is based on our legitimate interest in protecting our Service (Art. 6(1)(f) GDPR). We do not use this data for advertising or unrelated profiling.

Access data may be stored in server logs on our hosting infrastructure and transmitted to PostHog (EU, eu.posthog.com) for security monitoring and alerting. PostHog privacy policy: https://posthog.com/privacy

This monitoring is for detection and alerting only; we do not automatically block users based on it.

Please note that IP addresses are personal data and that mobile networks or corporate proxies may share one IP address among multiple users.

You may exercise your rights (access, erasure, objection) as described under "Your rights" by contacting us at contact@oldtimer-map.com.

Your rights

If the GDPR or similar laws apply, you may have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing. Where processing is based on consent, you may withdraw consent at any time.

To exercise your rights, contact contact@oldtimer-map.com. You also have the right to lodge a complaint with a supervisory authority in your country of residence or work.

Children

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data without parental consent, contact us and we will take steps to delete it.

Changes to this policy

We may update this Privacy Policy when our practices or the law change. We will post the updated version on the website with a new "updated" date. Continued use of the Service after changes take effect constitutes acceptance where permitted by law.

Links to other websites

The Service may link to third-party sites (e.g. event websites, Google Maps, OpenStreetMap). We are not responsible for their privacy practices. Their policies apply when you leave our Service.

Tracking Technologies

  • OpenStreetMap (map tiles and assets)

    The map shows geographic features using tiles from the OpenStreetMap project and open data. When you open a map, your device requests tiles from OpenStreetMap tile servers; their privacy information applies to those requests. Default map pin images are served from our own infrastructure (first-party), not from advertising networks.

  • PostHog

    We use PostHog for product analytics (EU infrastructure). Analytics are off by default until you consent.

    On the website: if you accept analytics cookies in CCM19, we may store an analytics identifier (cookies / local storage) to recognise repeat visits. If you reject, we use a more limited, privacy-preserving mode without that persistent identifier. We minimise data sent from the browser (including omitting IP and precise geo properties). Change or withdraw consent via .

    In the app: we ask for analytics consent in an in-app dialog on first use; you can enable or disable analytics anytime in your profile settings. On iOS, Apple's App Tracking Transparency may also apply when you allow analytics.

    When you are signed in and have accepted analytics, usage events may be linked to your account.

    In addition to consent-based product analytics, our backend sends technical access events for the public events API to PostHog for error tracking and security monitoring (e.g. detecting unusual request volumes). This processing is based on our legitimate interest in protecting the Service and does not depend on your analytics consent. See "Server logs & API security" above for details. PostHog privacy policy: https://posthog.com/privacy

  • CCM19

    On the website we use CCM19 as our consent management platform to record your cookie and analytics choices. CCM19 may store consent data on your device. More information: https://www.ccm19.de/en/privacy.html

  • Google reCAPTCHA

    We use Google reCAPTCHA on certain forms (e.g. login, event reports, support contact) to protect against abuse. Google may process technical data including IP address and interaction signals. This may involve transfers to the United States. Google privacy policy: https://policies.google.com/privacy

  • Firebase Cloud Messaging

    In the mobile app we use Firebase Cloud Messaging to deliver push notifications. If you grant permission on your device, a device token is generated and stored on our servers so we can send notifications. You can disable notifications in your device settings; tokens are removed when you log out or disable push. Firebase privacy information: https://firebase.google.com/support/privacy

  • Cookies

    We use cookies and similar technologies for essential operation (e.g. authentication, language preference via preferred_locale), and for analytics only with your consent. Most browsers let you block cookies; blocking essential cookies may limit functionality.

  • Local Storage

    We use local storage in the browser for authentication tokens and, if you accept analytics, PostHog identifiers. Local storage holds more data than cookies and is not sent automatically with every HTTP request.

  • Sessions

    We use session-related storage to keep you signed in and to remember preferences during your visit.

California Residents

If you are a California resident, you may have rights under the CCPA including to know what categories of personal information we collect and how we use them (as described above), to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise rights, contact contact@oldtimer-map.com; we respond within one month where applicable.

Contact Us

Don't hesitate to contact us if you have any questions.