Privacy policy
Last updated: September 2026
Controller
Ute SchultzSchlossberg 15a
63688 Gedern
Deutschland
ute@schultz.ws
1. General information
This privacy policy explains which personal data is processed when you visit this website or make a booking. Personal data is any information that can be used to identify you personally.
We process personal data only where necessary to operate the website, handle and fulfil your booking, communicate with you or comply with legal obligations.
2. Hosting and technical logs
This website is hosted by Vercel Inc. When you access the website, the hosting provider processes technically necessary connection data, including your IP address, access date and time, requested page, referrer URL, browser and device information, and status or error data. This is necessary to provide the website securely and reliably and to detect attacks or technical faults.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and economical operation of this website. Technical logs are retained only for as long as necessary for security, troubleshooting and abuse prevention.
3. Availability requests
When you open the booking calendar, your browser requests available and occupied periods from our server. No name or contact information is submitted during this request, although technically necessary connection data is processed.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is displaying current availability and preventing double bookings.
4. Booking and contacting us
When you book a pitch, we process the information you enter. Arrival, departure, name, email address and telephone number are required. You may optionally provide the number of guests, vehicle information and a message. We also store the agreed price, booking status, timestamps and technical identifiers used to prevent duplicate submissions.
The data is used to check availability, enter into and perform the pitch rental agreement, communicate about the booking, and handle changes or cancellations. The legal basis is Article 6(1)(b) GDPR. Where statutory retention requirements apply, continued storage is based on Article 6(1)(c) GDPR.
The required details must be supplied so that the booking can be completed and administered. Online booking is not possible without them. This website does not collect payment or credit-card information.
5. Booking confirmation by email
Emails are sent to confirm your booking and notify the operator. We use Resend for email delivery. In particular, your email address, name and the booking information required for the confirmation are processed.
The legal basis is Article 6(1)(b) GDPR. Delivery is necessary to administer the booking and provide your confirmation.
6. Database and recipients
Booking information is stored in a PostgreSQL database provided by Neon. Access is limited to the operator and technical service providers where required for hosting, database operation and email delivery. Data is not disclosed for advertising purposes.
The legally required data processing agreements are concluded with processors. Vercel, Neon and Resend are providers based or operating infrastructure outside the European Union. Data may therefore be processed in third countries, particularly the United States. Transfers are based on the applicable safeguards under Chapter V GDPR, especially adequacy decisions or EU Standard Contractual Clauses where required.
7. Retention
Booking and communication data is retained for as long as necessary to perform and settle the stay and handle possible questions or claims. Data subject to statutory tax or commercial retention requirements is retained for the applicable legal period. It is then deleted or anonymised unless another legal basis requires continued storage.
8. Cookies and browser storage
The public booking website does not use analytics, advertising or profiling cookies. After a successful booking, confirmation data is stored temporarily in your browser’s session storage so it can be displayed on the confirmation page. This does not additionally transmit the data from your browser and it is normally removed when the browser tab or session is closed.
A technically necessary session cookie is used for the protected administration area. It is used solely to sign in and secure administrative access. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is protecting the non-public administration area.
9. External links
This website links to Google Maps and external information, accommodation and dining websites. The respective provider processes data under its own privacy policy only after you follow such a link. No external maps, analytics tools or social media content are embedded on this website.
10. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction of processing and data portability. You may also object to processing based on Article 6(1)(f) GDPR.
You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is, in particular, the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.
11. Security and automated decisions
Data is transmitted using HTTPS encryption. We do not make solely automated decisions that produce legal or similarly significant effects and do not create user profiles.
12. Changes to this privacy policy
We update this privacy policy if the website, service providers or legal requirements change. The version published on this page applies.