1. Introduction and who is responsible
This Privacy Policy explains how Landr collects, uses and protects personal data when you use our web and mobile platform for activity operators (the "Service"), and when you visit our websites. It also describes, in section 5, how the optional Gmail integration uses data from your Google Account.
The controller responsible for the processing described here (except where we act as a processor — see section 2) is monkeytower internet agency, a sole proprietorship owned by Olaf Klein, Ellernstr. 87, 45326 Essen, Germany, email ok@monkeytower.net ("Landr", "we", "us").
2. Our two roles: controller and processor
As a controller we process personal data of Operators and their staff (account holders), website visitors, and prospects who contact us — for the purposes described below.
As a processor we process personal data about an Operator's customers ("Guests") on that Operator's behalf and on its instructions (for example, names, contact details and booking details that Guests provide when booking). For that data, the Operator is the controller and is responsible for informing its Guests and for the lawful basis of the processing. We process it only to provide the Service and under a data processing agreement.
3. What personal data we process
- Account and profile data — name, email address, password (stored hashed), operator/organisation details, role and settings.
- Booking and customer data — Guest names, email addresses, phone numbers, participant and pickup details, declarations, products booked, dates, prices and notes. (Processed on the Operator's behalf — see section 2.)
- Payment and invoicing data — where you use billing/invoicing features, transaction and invoice metadata (handled together with our payment and accounting providers; we do not store full card numbers).
- Communications — emails sent through the Service and support correspondence.
- Connected-account data — for accounts you choose to connect (e.g. Gmail), the connection metadata described in section 5.
- Technical and usage data — IP address, device and browser information, log data, and basic usage analytics needed to run and secure the Service.
4. Purposes and legal bases
Where the GDPR applies, we rely on the following legal bases (Art. 6(1) GDPR):
- Performance of a contract (Art. 6(1)(b)) — to create and manage your account, provide the Service, process bookings and send transactional emails (e.g. booking confirmations).
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain and improve the Service, prevent abuse and fraud, and communicate about the Service. You may object as set out in section 10.
- Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax and other legal requirements.
- Consent (Art. 6(1)(a)) — where we ask for it, for example for non-essential cookies or optional marketing. You may withdraw consent at any time.
For Guest data we process as a processor, the lawful basis is determined by the relevant Operator.
5. Google Account connection (Gmail)
Landr lets an Operator optionally connect their own Google / Gmail account so that booking-related emails (such as "booking received" and confirmation messages) are sent to Guests from the Operator's own email address. This connection is entirely optional and is only ever set up by the Operator's deliberate action.
Scope we request. When you connect your Google Account, Landr requests only the https://www.googleapis.com/auth/gmail.send scope (the ability to send email on your behalf) and https://www.googleapis.com/auth/userinfo.email (to read the address of the connected account so we can show you which account is connected). The gmail.send scope is send-only.
What Landr does and does not do. Landr uses this access solely to send transactional booking emails that you have configured. Landr cannot read, view, search, modify, label or delete any of your emails or mailbox content, and does not access your contacts. We do not use this access for advertising, and we do not sell this data.
What we store. For a connected account we store only the connected email address and an OAuth refresh token, which is held encrypted and used solely to obtain short-lived access tokens to send the messages you have configured. We do not store the content of your mailbox. The booking emails we send are retained as described in section 8.
Limited Use disclosure. Landr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. You can disconnect the integration at any time from your Landr settings, or revoke Landr's access directly in your Google Account at myaccount.google.com/permissions. After disconnection, Landr can no longer send email from your account, and the stored refresh token is deleted.
6. Service providers and recipients
We share personal data only as necessary, with service providers who process it on our behalf under appropriate agreements, and only as needed to run the Service. These currently include, among others: cloud hosting and infrastructure (Google Cloud Platform, hosted in the EU; Supabase, hosted in the EU), content delivery and edge services (Cloudflare), email delivery via the Operator's own connected Gmail (Google), and payment and accounting providers. We do not sell personal data.
7. International data transfers
We aim to host personal data within the European Union. Where a provider processes data outside the EU/EEA (for example certain payment, analytics or Google services), we rely on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request more information about these safeguards using the contact details below.
8. Data retention
We keep personal data only as long as needed for the purposes described here: for the life of your account and as required to provide the Service, and thereafter as required by law (for example, statutory retention periods for invoices and accounting records) or to establish, exercise or defend legal claims. Guest data processed on an Operator's behalf is retained according to the Operator's instructions and applicable law. When data is no longer needed, we delete or anonymise it.
9. How we protect your data
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, encryption of sensitive credentials (such as connected-account tokens) at rest, and least-privilege access. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.
10. Your rights
Subject to applicable law, you have the right to access your personal data and to request its rectification or erasure, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. To exercise these rights, contact us at ok@monkeytower.net. If your data is processed by an Operator (as controller), please direct your request to that Operator; we will assist them as their processor. You also have the right to lodge a complaint with a supervisory authority — for us this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
11. Cookies and similar technologies
Our websites and the Service use cookies and similar technologies that are strictly necessary to provide core functionality and security. Where we use non-essential cookies or analytics, we ask for your consent and you can manage your choices at any time.
12. Children
The Service is intended for businesses and adults. It is not directed to children, and we do not knowingly collect personal data from children. Operators are responsible for any age requirements that apply to their own bookings.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new "last updated" date and, where the changes are material, provide additional notice. Please review it periodically.
14. Contact
For privacy questions or to exercise your rights, contact us at ok@monkeytower.net — monkeytower internet agency, Olaf Klein, Ellernstr. 87, 45326 Essen, Germany.