Privacy Policy

Transparency about which data StickerMap processes, why it is processed and which rights data subjects have.

1. Controller

The controller within the meaning of Article 4(7) GDPR is:
Manuel Gruda
Operator of StickerMap.de
Sandstraße 26
57072 Siegen
Germany
Email: info@stickermap.de

No data protection officer has been appointed because the statutory requirements for an appointment are not met.

2. Principles and scope

StickerMap is designed to minimise data. Public use does not require a user account. Reports, feedback and objections can be submitted without registration. We do not create advertising profiles or use tracking cookies. A protected, non-public account system is available only to authorised administrators.

A web service cannot operate entirely without processing personal or technically attributable data. The following sections explain the nature, purpose, legal basis, recipients and retention period of each processing activity.

3. Server access and abuse prevention

When the website is accessed, the IP address is technically processed to establish the connection. The complete IP address is not stored in application logs. The date and time, requested resource, HTTP status code and amount of data transferred are logged for delivery, diagnostics and defence against attacks and retained for no more than seven days.

To limit automated or repeated requests, a hash that cannot be directly traced back is derived from the IP address. The IP address itself is not stored. These hashes and counters are generally deleted after no more than 48 hours.

Purpose and legal basis: secure and reliable operation and abuse prevention under Article 6(1)(f) GDPR.

4. Reports and uploaded photographs

When a report is submitted, its coordinates, category, type, status, description, time and any photographs are stored. A hash of the anonymous session identifier described in section 13 is also assigned. Following editorial review where required, the report content and location are displayed publicly on the map.

Purpose and legal basis: documenting and publicly displaying hateful symbols and promoting civic awareness under Article 6(1)(f) GDPR. Content is retained until removed by the editorial team or following a justified deletion request.

Photographs should not show identifiable people, private addresses, vehicle registration plates or other identifying features. Such content will be removed or obscured once we become aware of it. EXIF metadata, particularly GPS and device information, is removed during image processing. By uploading a photograph, the submitting person confirms that they took it and grants StickerMap a non-exclusive, perpetual right to make it publicly available as part of the platform.

5. Hosting, database and email

The website, database, file storage, Umami and GlitchTip are operated on a server administered by us and hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. The server is located in Germany. STRATO acts as a processor under an Article 28 GDPR data processing agreement. The data hosted there is not intended to be stored in a third country.

Email is sent through Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes the sender, recipient, message and technical connection data required for delivery as a processor. Further information is available in Hetzner's privacy policy.

6. Audience measurement with Umami

StickerMap uses a self-hosted Umami instance for privacy-friendly audience measurement. Umami is delivered through our own domain, does not set cookies and does not create persistent user profiles. It records the page viewed, time, referrer, browser, operating system and device type, and an approximate geographic region. The IP address is not stored permanently. The browser's Do Not Track setting is respected.

Purpose and legal basis: statistical evaluation and improvement of the service under Article 6(1)(f) GDPR. Analytics data is deleted after six months. This cookieless, self-hosted configuration does not require consent or a cookie banner.

7. Error analysis with GlitchTip

We use a self-hosted GlitchTip instance on the same server to identify and fix technical errors. Error reports may contain the error type, time, affected page, technical browser and device information, and program data required for diagnosis. Personal user details are not sent by default. IP addresses, cookies and authorisation data are removed before storage.

Purpose and legal basis: stability, security and troubleshooting under Article 6(1)(f) GDPR. Error and performance data is deleted after 30 days.

8. Maps, location and geodata services

The open-source Leaflet library is delivered from our own server. The street map and 3D globe obtain map tiles from the OpenStreetMap Foundation. The browser connects directly to its servers and may transmit the IP address, browser and device information, referring page, time and displayed map area. See the OpenStreetMap Foundation privacy policy.

Address searches and place names are processed server-side through Nominatim. The search term or selected coordinates are sent to OpenStreetMap, but the visitor's IP address is not. When the optional satellite view is selected, imagery is loaded from Esri. The IP address, browser information, time and map area may be transferred to Esri in the United States. Esri is certified under the EU-US Data Privacy Framework. See Esri's privacy statement.

With browser permission, StickerMap can access the device location to centre the map, filter nearby results or pre-fill a report location. The location may be updated while the map is open; StickerMap does not create a movement profile. When “Report here” is used, the selected coordinates are transferred and are stored permanently and displayed publicly only when the report is submitted. Location permission can be revoked in the browser or device settings.

Legal basis: Article 6(1)(f) GDPR for the core mapping and search functions and Article 6(1)(a) GDPR for optional access to the device location.

9. Instagram and external links

The links page displays publicly available content from StickerMap's own Instagram profile. Profile and post information is retrieved server-side and images are delivered through our own image optimisation. No Instagram iframe, Meta Pixel or Meta SDK is embedded. Merely opening the page therefore does not connect the visitor's browser directly to Meta.

A direct connection to Instagram or another external provider is established only after an external link is actively selected. The provider may process the IP address and browser and device information. External links open in a new tab and are protected against access to the originating window and against transfer of the referrer. See Meta's privacy policy.

This also applies to PayPal, Google Maps, Apple Maps, Waze, OpenStreetMap and sharing links for WhatsApp, Facebook and X. These ordinary links do not load provider content before they are actively selected.

10. Contact and feedback

Depending on the enquiry, the contact form processes a name, email address, organisation, subject and message. The feedback form stores a category, message and optional contact detail. This information is used only to respond and to improve the platform.

Internal notifications are sent by email through Hetzner. A notification may also be sent through Discord. Discord receives only the internal reference number, category and submission time, not the name, email address, organisation, subject or message. Processing in the United States is possible; Discord uses safeguards including Standard Contractual Clauses and the EU-US Data Privacy Framework. See Discord's privacy policy.

Legal basis: Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR. Data is retained for no more than twelve months after completion unless a statutory duty requires longer retention.

11. Data protection requests

The privacy request form can be used in particular for access, rectification, erasure, restriction and objection requests. The message and an optional contact method are processed. Access is limited to administrators with the relevant privacy permission. An internal email is sent through Hetzner; these requests are not sent to Discord.

Legal basis: Article 6(1)(c) GDPR in conjunction with Articles 12 to 22 and Article 5(2) GDPR. After completion, the data is retained for no more than three years to demonstrate proper handling and is then deleted unless statutory obligations or ongoing proceedings require otherwise.

12. Administration and authentication

For authorised persons, we process their email address, permissions, authentication policy and account creation time. Authentication uses an emailed one-time code, a passkey or a recovery code. For passkeys, StickerMap stores only the public key, technical identifier, device name, passkey type, and creation and usage times. Private keys and biometric characteristics remain on the device or in the password manager. Recovery codes are stored only as hashes.

Security logs may contain the administrator's email address, action, affected object, time and a hash of the IP address. Passwords, one-time codes, recovery codes, cookies and private passkey keys are not logged. Security logs are retained for no more than twelve months and email delivery logs for no more than 90 days. Account data is deleted when access is permanently withdrawn unless evidence must be retained.

Purpose and legal basis: providing and securing administration and ensuring accountability for administrative changes under Article 6(1)(f) GDPR.

13. Cookies, local storage and service worker

StickerMap does not use cookies or browser storage for advertising, profiling or cross-site tracking. The following technically or functionally necessary cookies are used:

  • NEXT_LOCALE: selected language, for the browser session

  • info_dismissed: dismissed introduction, 30 days

  • sm_anon: random anonymous protection identifier for public forms, one year

NEXT_LOCALE and info_dismissed must be readable by the user interface and contain no login credentials.

Display preferences, map view, statistics map size, dismissed notices, a local count of the visitor's own reports and an unsubmitted report draft may be stored locally. The draft contains category, type, status and description, but no photograph or coordinates. Session storage records notices and holds a map-selected report position once until the form opens; it is then removed immediately. Other entries remain until removed by the application or until website data is cleared in the browser.

The service worker enables installation as a web app. It forwards requests to the network and does not create its own offline store containing reports or form data. The browser may cache public files according to its ordinary cache rules.

Legal basis: section 25(2)(2) TDDDG and, where personal data is concerned, Article 6(1)(f) GDPR. These necessary and function-related storage operations do not require a cookie banner.

14. Donations and supporter list

The donation link leads to PayPal; no PayPal form or tracking element is embedded on StickerMap. For a donation, PayPal processes the required account, payment, device and transaction data. Depending on the payment method, StickerMap may receive details such as the name, email address, amount, time, transaction number and message. The provider in the EU is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. See PayPal's privacy statement.

Legal basis: Article 6(1)(b) GDPR for the donation and Article 6(1)(c) GDPR for statutory records. Payment and accounting records are retained for the statutory period, generally up to eight years.

Names of natural persons, roles and profile or post links are displayed publicly in the supporter list and, where applicable, the ticker only with prior consent under Article 6(1)(a) GDPR. Consent may be withdrawn at any time by email. The entry will then be removed; copies held by search engines or external archives may remain temporarily available.

15. Objections and authority suggestions

When a report is challenged, we process the report concerned, reason, optional note and proposed corrections. Authority suggestions may contain the authority name and type, official contact details, website, form URL, postal address, notes and an optional contact method for the submitting person. Access is restricted to appropriately authorised administrators. Notifications are sent by email through Hetzner, not through Discord.

Accepted official authority details may be displayed publicly. The submitting person's contact detail is not published. Private contact details of individual employees should not be submitted.

Legal basis: Article 6(1)(f) GDPR and, where statutory privacy obligations must be fulfilled, Article 6(1)(c) GDPR. Data is retained for no more than twelve months after completion. Optional contact details are removed as soon as they are no longer required for questions.

16. Data security

StickerMap uses appropriate technical and organisational safeguards. These include HTTPS, role-based access, passkeys and time-limited one-time codes, secure session cookies, hashed recovery codes, size and rate limits, security logs, removal of image metadata, and limiting database and file access to necessary server processes and authorised persons. Components are updated regularly. Nevertheless, absolute security of data transmitted over the internet cannot be guaranteed.

17. Data subject rights

Subject to the statutory requirements, data subjects have rights of access under Article 15, rectification under Article 16, erasure under Article 17, restriction under Article 18, data portability under Article 20 and objection under Article 21 GDPR. Consent may be withdrawn at any time with future effect under Article 7(3) GDPR.

A request can be sent informally to info@stickermap.de or through the privacy request form. Additional details may be requested to verify identity or identify the relevant report and protect other people's data. Requests are generally free of charge and answered within one month. For complex or numerous requests, the period may be extended by two months where permitted by law.

Data subjects also have the right to lodge a complaint with a supervisory authority. The competent authority is in particular the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, email: poststelle@ldi.nrw.de, www.ldi.nrw.de.

18. Automated checks

Technical rules limit repeated requests, identify possible abuse and flag unusual or geographically clustered reports. A submission may therefore be rejected automatically or held for manual review. These checks do not evaluate personal characteristics and are not used for advertising or profiling. No solely automated decision producing legal or similarly significant effects within the meaning of Article 22 GDPR takes place. If a legitimate submission is blocked by mistake, a review can be requested through info@stickermap.de.

19. Changes and version

This privacy policy is updated when services, processing activities or legal requirements change. The current version is available on this website, and material changes will be highlighted appropriately.

Last updated: 4 August 2026

The German version of this privacy policy is legally authoritative.

Only needed if you want a reply. Deleted after processing.

Min. 10, max. 2000 characters. Please use understandable words.