Legal

Privacy Policy

Last updated: 7 July 2026

1. Data Controller

This privacy policy explains how personal data is processed when you use Passé — the web app at passe.cc and the Passé mobile app (together, the "Service").

The controller within the meaning of the General Data Protection Regulation (GDPR) is: Passé, Franz-Philipp-Straße, 77656 Offenburg, Germany.

You can reach us at any time at thepasseapp@gmail.com.

2. Privacy by Default

Passé is built privacy-first. Every trip and every memory you create is private by default and visible only to you. Nothing you upload is shown to anyone else unless you explicitly make it public.

We only collect the data we need to operate the Service. We do not sell your personal data and we do not use it for advertising.

3. Data We Collect

Depending on how you use the Service, we process the following categories of personal data:

  • Account data — your name, email address, and password (stored in hashed form by our authentication provider). If you sign in with Google or Apple, we receive your name, email address, and profile picture from that provider.
  • Content data — the trips and memories you create, including photos, notes, dates, countries, cities, and the location coordinates you attach to memories.
  • Payment data — if you subscribe to a paid plan, our payment provider Stripe processes your payment details. We never see or store your full card number; we only store your subscription status and plan.
  • Technical data — IP address, browser or device information, and server logs generated automatically when you use the Service.

4. Purposes and Legal Bases

We process your data on the following legal bases under Art. 6(1) GDPR:

  • Performance of the contract (Art. 6(1)(b) GDPR) — creating your account, storing your trips and memories, displaying content you chose to make public, and managing your subscription.
  • Legitimate interests (Art. 6(1)(f) GDPR) — securing the Service, preventing abuse, and diagnosing technical problems.
  • Legal obligations (Art. 6(1)(c) GDPR) — retaining billing records under commercial and tax law.
  • Consent (Art. 6(1)(a) GDPR) — where you have given it, for example for optional features; you can withdraw consent at any time with effect for the future.

5. Service Providers

We use the following service providers (processors) to operate Passé. Each receives only the data required for its function:

  • Clerk (Clerk, Inc., USA) — authentication and account management, including sign-in with Google and Apple.
  • Neon (Neon, Inc., USA) — hosting of our database, where your account, trip, and memory data is stored.
  • Cloudinary (Cloudinary Ltd.) — storage and delivery of the photos you upload.
  • Stripe (Stripe, Inc., USA / Stripe Payments Europe Ltd., Ireland) — payment processing and subscription management.
  • Vercel (Vercel, Inc., USA) — hosting of the web application.
  • OpenStreetMap Nominatim (OpenStreetMap Foundation, UK) — converting location coordinates into place names (and vice versa) when you attach a location to a memory.

6. Public Content

If you make your portfolio, a trip, or individual memories public, that content — including photos, notes, place names, and your display name — is visible to anyone who has the link, without signing in. Search engines may index public pages.

You can make public content private again at any time. Copies cached by third parties (for example search engines) may remain available for some time after that.

7. Cookies and Local Storage

We only use cookies and similar technologies that are strictly necessary to operate the Service: keeping you signed in (session cookies set by our authentication provider) and remembering your language and theme preferences.

We do not use advertising, tracking, or analytics cookies.

8. International Data Transfers

Some of our service providers are based in the United States. Where personal data is transferred outside the EU/EEA, the transfer is protected by an adequacy decision (such as the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses.

9. Data Retention

We keep your personal data for as long as your account exists. When you delete your account, your account data, trips, memories, and photos are deleted.

Data we are legally required to retain (for example billing records) is kept for the statutory retention periods and deleted afterwards.

10. Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Access (Art. 15 GDPR) — obtain a copy of the data we hold about you.
  • Rectification (Art. 16 GDPR) — have inaccurate data corrected.
  • Erasure (Art. 17 GDPR) — have your data deleted.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR) — receive your data in a machine-readable format.
  • Objection (Art. 21 GDPR) — object to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or workplace.

11. Changes to This Policy

We may update this privacy policy when the Service or the legal requirements change. The current version is always available on this page; the date above shows when it was last revised.

12. Contact

For any questions about this privacy policy or your personal data, contact us at thepasseapp@gmail.com.