werk2
LocalLoop privacy legal
en de

LocalLoop — Privacy

Last updated: 19 September 2026 · werk2 UG (haftungsbeschränkt) · Contact: info@werk2.group

The German product text at localloop-app.de/privacy.html is authoritative for LocalLoop (partner app and guest web). This page summarises the same processing in English.

1. Controller

werk2 UG (haftungsbeschränkt)
Von-Schildeck-Str. 15, 36043 Fulda, Germany
Email: info@werk2.group
Commercial register: Amtsgericht Fulda, HRB 9279

2. Scope

LocalLoop connects neighbourhood businesses and guides guests via offers. This policy covers the LocalLoop B2B partner app and localloop-app.de (guest and marketing entry). werk2 is the controller for this processing. The general app privacy policy on werk2.group does not apply to LocalLoop.

3. Data we process

  • Pilot interest form — name, shop name, address, email, phone (contact within about 24 hours)
  • Usage events — product analytics (prefix llb2b), including coarse local hour/weekday buckets; cookieless landing analytics (prefix llweb)
  • Partner account and operations data — email, display name (display_name), company/locations/campaigns/claims/ledger; optional custom subcategory label; password-reset mails via Supabase Auth
  • Partner address search — Google Places (autocomplete/geocode) via our edge function; Nominatim/OSM fallback; search text and chosen address — no guest GPS
  • Partner push — Expo push token and notify preferences (notify_enabled / notify_feedback / notify_redeem
  • Guest use on localloop-app.de — QR resolve, optional star/text feedback, offer code; device pseudonym for abuse control and daily limits; optional product feedback to localloop (not shown to partner shops)
  • Apple Wallet pass (optional) — signed .pkpass with offer title, partner/location name, validity and QR; no pass updates, no wallet device registration, no wallet push after redeem
  • Spend buckets — coarse spend estimate at redeem; partners see aggregates only
  • Website tech — Vercel hosting logs; Google Fonts on page load
  • Payments — no money in the pilot; later Stripe for partner billing (not App Store IAP)
  • Support — messages to info@werk2.group

4. Purposes and legal bases

  • Providing the service — Art. 6(1)(b) GDPR
  • Pilot interest follow-up — Art. 6(1)(b) GDPR
  • Security and abuse prevention — Art. 6(1)(f) GDPR
  • Product analytics — Art. 6(1)(f) GDPR
  • Optional guest product feedback — Art. 6(1)(f) GDPR
  • Payments when enabled — Art. 6(1)(b) GDPR
  • Legal obligations — Art. 6(1)(c) GDPR

5. Recipients / processors

  • Supabase — auth, database, analytics events (EU region where configured)
  • Vercel — hosting of localloop-app.de
  • Google Places — partner address search/geocoding
  • Nominatim / OpenStreetMap — geocoding fallback
  • Google Fonts — web fonts on localloop-app.de
  • Apple Wallet — when the guest saves a pass on their iPhone
  • Expo / Apple / Google — app distribution and push
  • Stripe — partner billing after the pilot, when keys are active

6. Retention

We keep personal data only as long as needed for the stated purposes or legal retention. In-app deletion removes auth, company/location data, claims, feedback, push tokens and related operations data. Product analytics may remain without name, email, user id or location/device linkage. Full detail: localloop-app.de/privacy.html.

7. Your rights

Access, rectification, erasure, restriction, portability, objection to Art. 6(1)(f) processing, and complaint to a supervisory authority (including HBDI, Hesse). Contact: info@werk2.group.

8. Children

LocalLoop is not directed at persons under 16.

9. Changes

The version published on this page with the stated date applies.

LocalLoop — werk2 UG (haftungsbeschränkt)

terms support imprint localloop-app.de privacy