Privacy
Version 4.0
1. Privacy at a Glance
General information
The following information provides a simple overview of what happens to your personal data when you use this website and the PandaCards platform (app.pandacards.de, cards.pandacards.de). Personal data is any data that can be used to identify you personally.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice of this website.
How do we collect your data?
On one hand, through data you provide to us — e.g. when registering an account, creating a PandaCard, or making a contact enquiry. On the other hand, our IT systems automatically collect certain data when you visit the website (see Section 3). For the landing page we also evaluate — only with your consent given via the cookie banner — anonymised usage statistics; for digital business cards (PandaCards) and PandaForm, a cookie-free, anonymised statistic is carried out without consent on the basis of the respective cardholder's legitimate interest (see Section 4).
2. General Information and Mandatory Disclosures
Privacy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
Note on the responsible party
The party responsible for data processing on this website is:
EnglGroup GbR Englbrecht & Glasse
Hermülheimerstraße 283
50354 Hürth
Germany
Email: info@pandacards.de
PandaCards is a product of EnglGroup GbR Englbrecht & Glasse.
Data Protection Officer
No Data Protection Officer has been appointed, as there is no statutory obligation to do so (Sec. 38 BDSG). For any data protection questions, please contact the responsible party named above directly.
Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a justified request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data. See Section 7 for an overview of the most important concrete retention periods.
3. Data Collection on this Website
Cookies
Our website uses cookies. Cookies are small text files that do not damage your device. On your first visit, our cookie banner asks whether, in addition to the technically necessary cookies, you also consent to the statistics category. Without your consent, no statistics cookies are set and no usage data is collected for the landing page (see Section 4).
Specifically, we use the following cookies:
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
theme_preference |
stores your light/dark mode preference | 1 year | strictly necessary |
preferred_locale |
stores your language selection | 1 year | strictly necessary |
cookie_consent |
stores your choice in the cookie banner | 1 year | strictly necessary |
| Session cookie (login) incl. CSRF protection | keeps you logged in, protects forms from misuse | 2 hours of inactivity | strictly necessary |
landing_session |
links your page views into an anonymous session for statistics | 90 days | only with consent (statistics) |
The legal basis for strictly necessary cookies is Art. 6(1)(f) GDPR (legitimate interest in the technical operation of the website) in conjunction with Section 25(2) No. 2 TTDSG. The legal basis for the statistics cookie is your consent, Art. 6(1)(a) GDPR in conjunction with Section 25(1) TTDSG. You can withdraw your consent at any time with effect for the future by deleting the cookie in your browser — the banner will then reappear on your next visit.
All cookies are set with the "Secure" attribute (transmitted exclusively via HTTPS) and protected against cross-site misuse via "SameSite=Lax". The login session cookie is additionally marked "HttpOnly" and therefore cannot be read by JavaScript. The other cookies are deliberately not HttpOnly, as our website itself needs read access to them (e.g. to display your language selection).
Server log files
The website provider automatically collects and stores information in server log files that your browser transmits automatically. These are:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources. Collection is based on Art. 6(1)(f) GDPR. Server log files are automatically deleted after 14 days.
Contact
If you contact us by email or contact form, your details including the contact information you provide will be stored for the purpose of processing the enquiry and in case of follow-up questions. We do not share this data without your consent.
Newsletter and marketing emails
If you consent to the newsletter option during registration or in your settings, we use your email address to send marketing emails. Marketing emails are only sent with your prior consent; the legal basis is Art. 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future — via the unsubscribe link in every email or directly under Settings → "Notifications". Mandatory system notices (e.g. regarding contractual or legal changes) are not affected by this and are sent independently of this consent; the legal basis is Art. 6(1)(b) GDPR.
Registration and customer account
When you register an account with PandaCards, we collect and store the data you provide (name, email address, password, optionally phone number and company) to fulfil the usage agreement. Passwords are stored exclusively as a hash; sensitive profile data (name, email address, phone number, company) is stored encrypted in our database. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). If you register via Google, LinkedIn, or Facebook, we receive the basic data required for this (name, email address, and profile picture where applicable) from that provider — that provider's own privacy notices additionally apply to its processing.
Payment processing
For paid subscriptions we use the payment service provider Stripe. For customers in Germany, the contracting party is Stripe Payments Europe, Limited (Ireland, EU) — not the US parent company. The data required for payment processing (including name and payment information) is transmitted to Stripe. Stripe Payments Europe may pass on data to affiliated companies and sub-processors outside the EU as part of providing the service, in particular to Stripe, LLC in the USA; appropriate safeguards under Art. 44 et seq. GDPR are in place for this (including EU standard contractual clauses and/or the EU-US Data Privacy Framework). The legal basis is Art. 6(1)(b) GDPR. Your payment data (e.g. credit card number) is processed directly by Stripe — PandaCards itself never stores complete payment data, only a reference ID to the respective Stripe transaction. Further information: stripe.com/privacy.
PandaCards and third-party forms
If you visit a digital business card created by a PandaCards customer or fill out a contact form (PandaForm) embedded on it, the respective cardholder — not EnglGroup GbR Englbrecht & Glasse — is generally responsible for this specific data processing; in that case, we process this data as a processor under Art. 28 GDPR on their behalf. The cardholder can specify their own privacy policy link in their form settings; if none is specified, this privacy policy applies by default.
4. Analytics and Statistics
For the landing page (pandacards.de) we operate our own, self-hosted analytics without sharing data with Google Analytics or comparable third-party tools. The following data is collected per session — only with your consent given via the cookie banner:
- pages visited, their order, and your time spent on each page
- coarse device type (desktop/mobile/tablet) and country (via IP geolocation, see below)
- origin (referrer as well as UTM campaign parameters, if you arrived via a correspondingly tagged link)
- whether you clicked the "Get started for free" button and subsequently registered (to measure the success of our own campaigns)
Your IP address is not stored; it is truncated immediately upon receipt (the last octet for IPv4, or the last 80 bits set to zero for IPv6), and your browser identifier (user agent) is stored only as a non-reversible hash — it is not possible to draw conclusions about you as a person from this data. The country is determined entirely locally on our own server within Germany using a weekly-updated database (MaxMind GeoLite2); your IP address is never transmitted to an external service for this purpose. This data is automatically deleted after 90 days. The legal basis is your consent, Art. 6(1)(a) GDPR, since the statistics cookie landing_session is set for this purpose (see Section 3).
A different standard applies to digital business cards (PandaCards) and PandaForm: this statistics feature works without a cookie on your device — it evaluates data that is technically transmitted with every page request anyway (IP address, user agent), without storing any recognisable identifier on your device. Since no consent obligation under Section 25 TTDSG applies here (which only covers access to information already stored on the terminal device), we rely instead — where the cardholder has enabled the statistics feature for their card — on the cardholder's legitimate interest in usage statistics for their own card, Art. 6(1)(f) GDPR. We record views, contact saves, QR scans, and link clicks following the same technical pattern as above (IP truncated immediately, user agent hashed, 90-day retention).
We do not use cookies or scripts from Google, Meta, LinkedIn, or other advertising networks.
5. Recipients and Processors
As part of processing, we share data with the following categories of recipients:
- Stripe Payments Europe, Limited — payment processing (see Section 3), privacy policy: stripe.com/privacy
- Brevo — sending system and transactional emails (e.g. registration confirmation, invoices, notifications), privacy policy: brevo.com/legal/privacypolicy
- Strato GmbH — hosting, server location Germany, privacy policy: strato.de/datenschutz
As of version 2.0 of this privacy policy, country determination for the statistics feature (Section 4) is performed locally on our own server; no external provider is involved for this purpose anymore.
Where required, data processing agreements under Art. 28 GDPR are in place with the above providers. Data is not transferred to any other third parties unless we are legally obliged to do so or you have expressly consented.
One exception is the webhook feature (see Section 8): if an account holder enables it, we additionally transmit data to an internet address they have configured themselves. This recipient is determined solely by the account holder; we do not select the destination.
6. Your Rights
You have the right at any time to:
- obtain free information about the origin, recipients, and purpose of your stored personal data (Art. 15 GDPR)
- request the correction of inaccurate data (Art. 16 GDPR)
- request the deletion of your data (Art. 17 GDPR)
- request restriction of processing (Art. 18 GDPR)
- object to processing (Art. 21 GDPR)
- receive your data in a structured, commonly used, machine-readable format (Art. 20 GDPR)
- lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — the competent authority is that of your habitual residence, your place of work, or our registered office
How to submit a request
If you are registered with PandaCards, you can submit an access, export, correction, restriction, or objection request directly under Settings → "My Data". We process your request within 30 days (extendable to up to 90 days in justified cases, of which we will inform you). You can remove your account yourself, immediately, at any time under Settings → "Delete Account" — any active subscription is automatically cancelled at the same time. Statutory retention obligations (in particular for invoices, see Section 7) remain unaffected by account deletion and are deleted independently once the respective period has expired. Alternatively, you can reach us using the contact details listed in the legal notice.
7. Retention Periods at a Glance
| Data category | Retention period |
|---|---|
| Server log files (Apache) | 14 days |
| Landing page statistics (sessions, page views) | 90 days |
| PandaCard & PandaForm statistics (views, clicks, scans) | 90 days |
| Login and security logs | 365 days |
| Account activity log | 365 days |
| Data export download link (data portability) | 48 hours |
| Invoices and payment records | 10 years (Sec. 257 HGB, Sec. 147 AO) |
| API access tokens | 60 days (automatic expiry and deletion thereafter) |
| Webhook delivery content | deleted immediately after delivery or final failure |
| Webhook delivery log (metadata only) | 30 days |
8. API Access and Webhooks (Team Plan)
Account holders on the Team plan can access their own data programmatically (REST API) and receive automatic notifications about events (webhooks). Both features are technically disabled without this plan and can only be set up by team managers.
Access and permissions. Access is granted via personal access tokens, which are shown in plain text only once and are stored on our side exclusively as a cryptographic hash (SHA-256). Each token carries only the permissions selected when it was created (e.g. read-only access to form submissions) and expires automatically after 60 days. Every request is strictly limited to the data of the respective account.
Data minimisation. Customer data from appointment bookings is returned masked by default (e.g. "Max M.", "m***@firma.de"); returning it in plain text requires a separately granted additional permission. Internal identifiers, security tokens, and fields stored in encrypted form are never returned, enforced by fixed allow-lists. Statistics requests contain only aggregated figures without any personal reference.
Webhooks — transmission to a destination you choose. If an account holder enables webhooks, we automatically transmit the relevant data upon certain events (new form submission, and new, cancelled, or rescheduled appointment bookings) to an internet address they have configured themselves — typically their own CRM or calendar system. The full event data is transmitted, including, in the case of appointment bookings, the name, email address, and telephone number of the person booking. The recipient is determined solely by the account holder; from the moment of delivery the data lies within their sphere of responsibility. Account holders are obliged to inform the data subjects concerned about this transfer in their own privacy policy.
Security of transmission. Deliveries are made exclusively over encrypted connections (HTTPS); unencrypted destinations are rejected. Every delivery is signed with a secret key (HMAC-SHA256) and carries a timestamp, allowing the recipient to verify authenticity and integrity. Destination addresses are technically checked to ensure they are publicly reachable; addresses within internal or private networks are blocked — this check is repeated immediately before each individual delivery.
Storage of deliveries. For delivery purposes the content is stored temporarily in encrypted form and deleted immediately after successful or finally failed delivery. Only metadata (event type, status, timestamp) remains in the log and is deleted automatically after 30 days.
9. SSL / TLS Encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.