This Privacy Policy explains how Pintumo UG processes personal data when you use the Advent App applications for iOS and Android, or the website at advent-app.com (together: "the Service"). We process your data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other applicable laws.
The controller responsible for data processing under Art. 4(7) GDPR is:
Pintumo UG (haftungsbeschränkt)
Max-Beer-Str. 27
10119 Berlin, Germany
Email: info@advent-app.com
We have not appointed a Data Protection Officer because we are not legally required to do so under Art. 37 GDPR. Please direct any data protection questions to the email above.
When you use the apps:
When you visit the website:
Information under Art. 14 GDPR for recipients: when a person receives an advent calendar, we process the recipient details entered by the sender in order to deliver it (Art. 6(1)(b) GDPR). Because we do not maintain recipient accounts and notifying each recipient individually would involve disproportionate effort, this information is provided through this publicly available Privacy Policy (Art. 14(5)(b) GDPR).
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Service's core functions | Art. 6(1)(b) — performance of the contract |
| Storing and serving calendar content | Art. 6(1)(b) |
| Processing the ad-free in-app purchase | Art. 6(1)(b) |
| Showing rewarded ads (AdMob) to unlock doors | Art. 6(1)(f) — legitimate interest in funding a free service; for personalised ads, Art. 6(1)(a) — your consent |
| Crash and stability diagnostics (Firebase Crashlytics) | Art. 6(1)(f) — legitimate interest in a stable product |
| Operating the website (logs, security) | Art. 6(1)(f) — legitimate interest in a secure service |
| Responding to support requests | Art. 6(1)(b) / (f) |
| Complying with legal obligations | Art. 6(1)(c) |
| Firebase Analytics (measuring app usage to improve the Service, and advertising & conversion measurement with Google Ads) | Art. 6(1)(a) in conjunction with § 25(1) TDDDG — your consent (Google Consent Mode v2; denied by default, granted only if you consent) |
| Recording recipient activity on Pro calendars (first opens, emoji reactions, short notes) | Art. 6(1)(a) — the recipient's consent, asked once per calendar before the first door is opened and withdrawable at any time in that calendar's settings |
| Notifying the sender of a Pro calendar about that activity | Art. 6(1)(b) — performance of the contract (the Pro option purchased) |
Google Consent Mode and your choices. Firebase Analytics (measuring app usage to improve the Service, and advertising & conversion measurement with Google Ads) is used solely on the basis of your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG and operates under Google Consent Mode v2. Without your consent — all analytics and advertising signals default to denied — no information intended for analytics or advertising purposes is stored on or read from your device, and no data is shared with Google Ads for conversion measurement. These signals are set to granted — enabling the analysis of app usage and the sharing of conversion data with Google Ads — only after you actively consent in the app's consent dialog. You can change your choice at any time using the "Privacy options" button in the app settings, and you can further limit ad tracking in your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads).
Storage of and access to information on your device (§ 25 TDDDG). For any storage of or access to information on your device that is not strictly necessary (analytics, advertising), we obtain your consent under § 25(1) TDDDG. Strictly necessary storage — such as the sender identifier, your consent state and your calendar content on the device — takes place without consent under § 25(2) no. 2 TDDDG.
Obligation to provide data (Art. 13(2)(e) GDPR): you are neither legally nor contractually obliged to provide personal data. However, without the data required for the core functions (such as calendar content and the sender identifier) we cannot provide the Service.
Some processors (Google LLC) are established in the United States; Apple Inc. may also process data — in particular for the iCloud synchronisation you control — outside the EU, under its own safeguards including the EU-US Data Privacy Framework and Standard Contractual Clauses. Transfers take place under the European Commission's adequacy decision for the EU-US Data Privacy Framework (where the recipient is certified) or under Standard Contractual Clauses (Art. 46(2)(c) GDPR). Amazon Web Services EMEA SARL operates the server data centres used for the Service inside the EU.
GIF search (Giphy). When you use the GIF search in the app, your search input is transmitted to the Giphy API of Giphy, Inc., 350 Fifth Ave, FL 20, New York, NY 10118, USA (part of the Shutterstock group) in order to display matching GIFs. Technical data (in particular your IP address) may be transferred to Giphy in the US in the process. No adequacy decision exists for the US in this respect: Giphy is currently not certified under the EU-US Data Privacy Framework, and no standard contractual clauses are in place. The transfer therefore takes place exclusively on the basis of your explicit consent under Art. 49(1)(a) GDPR, which you give before using the GIF search for the first time. Possible risks: the US does not provide a level of data protection equivalent to the GDPR, and US authorities may be able to access the data without effective legal remedies or an independent supervisory authority being available to you. You can simply leave the GIF search unused, and you can withdraw your consent at any time with effect for the future in the app settings.
To exercise any of these rights, email info@advent-app.com. We respond within one month, extendable by two further months for complex requests as permitted by Art. 12(3) GDPR.
Withdrawing consent to Pro activity sharing: if you received a Pro calendar, you can withdraw your consent at any time in that calendar's settings. This stops all further reporting from your device immediately. Because these records are stored without any identifier for you (Art. 11 GDPR), we cannot single out and erase the entries already recorded; they are deleted automatically within 60 days. Under Art. 11(2) GDPR, Arts. 15–20 GDPR do not apply to these records unless you provide additional information enabling your identification.
We do not use automated decision-making, including profiling, that produces legal effects within the meaning of Art. 22 GDPR.
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without the consent of a parent or legal guardian, as required by Art. 8 GDPR. If you are a parent or guardian and learn that your child has provided us with personal data, please contact us and we will delete it.
We use industry-standard technical and organisational measures to protect your data, including TLS transport encryption, encrypted storage at rest on AWS and Apple infrastructure, and access controls. We will notify you and the supervisory authority of any personal data breach in accordance with Arts. 33 and 34 GDPR.
Calendar links: access to a sent calendar works through a secret link. Anyone who possesses the link can open the calendar. Please treat the link confidentially and share it only with the person the calendar is intended for (Art. 32 GDPR).
We may update this Privacy Policy to reflect changes in the Service or the law. The current version is always available at this URL and dated at the top. Material changes are announced in-app and on the website before they take effect.
For any question about this Privacy Policy: info@advent-app.com.