Privacy policy

How Moser Kunden handles personal data. Last updated 2026-08-16.

Diese Seite ist noch nicht vollständig: Die mit „⚠ noch eintragen“ markierten Angaben stehen in lib/firma.ts und müssen vor dem Livegang eingetragen werden. Der Text ist eine sorgfältige Vorlage und ersetzt keine rechtliche Prüfung.

1. Who is responsible

⚠ noch eintragen, ⚠ noch eintragen, is the controller for the data described under "Your account data" below. You can reach us at ⚠ noch eintragen.

2. Your account data

To run your account we store what you gave us when signing up and what the service produces while you use it:

  • Email address, name and — if entered — company name.
  • Your plan, its status, billing interval and paid-through date.
  • Your Stripe customer and subscription identifiers.
  • Last login, plus an audit log of security-relevant actions (sign-in, plan changes, exports) with a timestamp.

3. Your customer book — we are the processor, not the controller

The customers you record here are other people. Their names, insurance lines, premiums, service dates, deposit values and savings amounts are their personal data — and for that data you are the controller, not us. We process it solely on your instruction, in order to provide the service.

That relationship requires a data processing agreement under Art. 28 GDPR between you and us. Ask us for it before you enter real customer data.

We do not read this data, do not analyse it, and do not pass it to anyone beyond the providers named in section 6.

4. Payment data

Payments run through Stripe. Card numbers and bank details are entered on Stripe's own pages and never reach our servers — we only ever see the identifiers Stripe gives back, the plan, and whether an invoice was paid.

For VAT purposes Stripe collects a billing address and, optionally, your VAT ID. Invoices are available in the Stripe customer portal.

5. Cookies

Only two kinds, both strictly necessary — no tracking, no advertising, no analytics, and therefore no consent banner:

  • Session cookies from Supabase Auth, so you stay signed in.
  • "kc_sprache", which remembers whether you want German or English. Valid for one year.

6. Who else touches the data

We use three providers, each as a processor under a data processing agreement:

  • Vercel — hosting and delivery of the application.
  • Supabase — database and authentication. Region: ⚠ noch eintragen.
  • Stripe — payment processing and invoicing.

7. How long we keep it

Your customer book stays as long as your account exists. Delete a customer and the record goes, along with its service history and custom fields.

Cancelling a paid plan does not delete anything — the account drops to the free plan and the book stays readable and exportable. Ask us to delete the account and we remove it along with the whole book.

Invoices and payment records are kept for as long as tax law requires, independently of the above.

8. Your rights

Under the GDPR you may request access, rectification, erasure, restriction of processing, data portability, and object to processing. A CSV export of your entire book is available in the app at any time, on every plan.

Write to ⚠ noch eintragen. You may also complain to a supervisory authority — for us that is ⚠ noch eintragen.

9. Security

Traffic is encrypted in transit. Access to your rows is enforced by the database itself through row-level security, not merely by the application — a missing filter in our code cannot show one account the book of another. Passwords are stored hashed by Supabase Auth and are never visible to us.

10. Changes

We will update this page when the service changes. The date at the top tells you which version you are reading.