Important
Draft — not yet reviewed by a lawyer. These texts were written against what this system actually does, but not by a legal professional. They must be reviewed by a qualified lawyer and the marked details filled in before the product operates commercially. The German version is authoritative: the statutory model texts reproduced here have legal effect in German only.
Last updated: 2026-07-26
Controller
The controller for the processing of personal data within the meaning of Art. 4(7) GDPR is:
To be supplied by the operator
Full legal name of the provider
First and last name of the individual operating Modefold (or the company name, if a company is formed). Mandatory under § 5(1) no. 1 DDG.
To be supplied by the operator
Serviceable postal address
Street, house number, postcode, town and country. A P.O. box or an email address alone does not satisfy § 5(1) no. 1 DDG. If the operator does not want to publish a home address, a serviceable alternative is needed (for example an imprint service authorised to accept service of process) — that is an operator decision.
Email for data protection matters: me@emilvinu.de
Data protection officer
No data protection officer has been appointed. Under § 38 BDSG the duty to appoint one generally arises only where at least twenty people are permanently engaged in automated processing, or where a data protection impact assessment is required or data is transferred commercially.
Open item before going live
Whether a data protection impact assessment under Art. 35 GDPR is required has not been assessed. Modefold stores individual travel and movement data, which depending on scale can trigger both an assessment and the duty to appoint an officer. To be clarified before going live.
What data we process
The following list reflects what this system actually stores, not a generic template.
•
Account: email address, password stored only as a scrypt hash (never in clear text), an optional display name, the time of registration and the time of the last sign-in. Sessions are held by tokens of which only a SHA-256 hash and the expiry time are stored.
•
Booking identity: legal first and last name, date of birth, telephone number and billing address — only where you provide them. All four are optional, the account works without them, and they can be deleted again in full from the account settings.
•
Acceptance of the terms: which version of the terms of use and of this privacy notice you accepted, and when.
•
Travellers: first and last name, traveller type (adult, child and so on), date of birth, any discount cards recorded (such as a BahnCard) and their validity period — for each person you add to your account.
•
Searches and journeys: your most recent searches (origin, destination, time and the options the search ran with, capped at a fixed number), favourites (stops, routes, commutes), your trip history — trips you committed to by watching them, never purchases — and watched trains (station, trip number, line, destination, planned departure and arrival, walking minutes).
•
Delay observations: for watched trips we record the planned and the observed arrival. These records are linked to your account.
•
Loyalty programmes: which operator programmes you have linked or are joining, and the membership number you entered.
•
Price alerts: route, target price, last observed price, travel date and how often the alert has fired.
•
Notifications: your device's push token, the platform (iOS, Android, web), your per-type notification settings and a record of which notification has already been sent so it is not repeated.
•
Support: subject, message text, timestamps and status of your requests.
•
Shared journeys: when you share a journey, the journey data is stored behind a random link token together with an expiry time.
•
Traveller reports: if you report a delay, disruption or crowding, we store the type, the stop or trip, any free-text note and the time.
•
Settings: colour scheme, language, display currency and travel preferences (class, risk profile, operators to avoid).
Location data is used on your device only, and only for nearby search and walking navigation. No location history is stored. No payment data of any kind is processed: Modefold sells nothing and takes no payment, so no card detail, bank detail or payment reference exists anywhere in this system. You complete a booking on the transport operator's own site, under their privacy notice, and we learn nothing about it — not even that it happened.
Purposes and legal bases
•
Account, sign-in and session management — performance of the user contract, Art. 6(1)(b) GDPR.
•
Journey search, favourites, trip history and train watching — performance of the user contract, Art. 6(1)(b) GDPR.
•
Booking identity: name, date of birth and address so the details a transport operator's booking form asks for can be filled in for you, and so a discount card's entitlement can be checked when a fare is priced; telephone number so a carrier can reach you during a disruption. All of it optional — Art. 6(1)(b) GDPR, and consent under Art. 6(1)(a) GDPR where you volunteer it.
•
Linked loyalty programmes: so the right membership number is at hand when you book with that operator — performance of the user contract, Art. 6(1)(b) GDPR.
•
Recording which version of the terms and of this notice was accepted, and showing the last sign-in — accountability under Art. 5(2) GDPR and legitimate interest in account security, Art. 6(1)(f) GDPR.
•
Push notifications about your journeys — performance of the contract, Art. 6(1)(b) GDPR, because you switch each type on yourself; the setting can be withdrawn at any time.
•
Handling support requests — Art. 6(1)(b) GDPR.
•
Improving delay forecasts from observed actual times — legitimate interest in a dependable forecast, Art. 6(1)(f) GDPR.
•
Operation, security and abuse prevention — legitimate interest, Art. 6(1)(f) GDPR.
Open item before going live
Delay observations are currently linked to the account even though a pseudonymised record would be enough for the forecast. That is hard to justify under the data minimisation principle (Art. 5(1)(c) GDPR) and should be changed to an account-independent record.
Recipients and processors
Most third-party services are called by our server. Your device does not connect to them and your IP address is not disclosed to them. Where that is different, it is stated expressly.
•
Microsoft Azure — hosting of the application and the PostgreSQL database in the Germany West Central and North Europe regions. Processor.
•
Cloudflare — delivery of the website and the shared-journey links. Your browser connects directly, so connection data including your IP address arises there.
•
Transport operators and ticket retailers — when you follow a booking link, your browser goes to that operator's own site. From that point they are the controller: what they collect, and what they do with it, is governed by their privacy notice, not this one. Modefold transmits no personal data to them; the link carries only the trip (origin, destination and, where the operator's page supports it, the date and time).
•
Google Maps Platform — geocoding, nearby search and walking directions are called from our server, transmitting place and route data but not your IP address. In the web version the map view is additionally loaded into your browser directly from Google, which gives Google your IP address and device data.
•
Expo (push service) together with the Apple Push Notification service and Firebase Cloud Messaging — delivery of push messages to your device. The push token and the message content are transmitted.
•
Deutsche Bahn (Timetables), gtfs.de and DELFI, Open-Meteo, OpenStreetMap/Overpass and the European Central Bank via the Frankfurter service — timetable, weather, geographic and exchange-rate lookups only, server-side and without personal data.
Open item before going live
It has not been evidenced that a processing agreement under Art. 28 GDPR is in place with every processor. Before going live, the agreements with Microsoft, Cloudflare, Google and Expo must be concluded or documented and the exact contracting entities and addresses entered here.
Open item before going live
No affiliate programme is currently in place, so booking links carry no tracking parameter today. If one is signed, following a link will identify Modefold to that partner as the source of the visit — which is a disclosure to a third party and must be described here, and marked as advertising in the interface, before any tag is switched on.
Transfers outside the EU/EEA
The database and the application run in the European Union. Some of the services listed above, however, belong to companies based in the United States, so access from a third country cannot be ruled out. Any such transfer relies on an adequacy decision of the European Commission or on standard contractual clauses under Art. 46(2)(c) GDPR.
To be supplied by the operator
Evidence for third-country transfers
For each provider, record what the transfer relies on (certification under the EU-US Data Privacy Framework, or standard contractual clauses together with a transfer impact assessment). The details are in the respective processing agreements and belong here once known.
Retention
•
Account data is kept for as long as the account exists.
•
Recent searches are capped at a fixed number; older entries are deleted when a new one is stored.
•
Shared journey links carry an expiry time and cannot be retrieved afterwards.
•
Price alerts, favourites, watched trains, saved travellers, linked loyalty programmes and the booking identity are deleted as soon as you remove them.
•
No tax or commercial retention period applies to anything here: Modefold issues no invoice and receives no payment, so there is nothing § 147 AO or § 14b UStG could reach.
Open item before going live
Beyond that there is no automatic deletion. In particular there is as yet no function to delete an account together with its trip history, delay observations and support threads, and no scheduled clean-up of old data. Erasure requests under Art. 17 GDPR currently have to be fulfilled by hand. Both must be implemented before going live.
Storage on your device
Modefold stores information on your device where that is strictly necessary for the service you asked for, which needs no consent under § 25(2) no. 2 TDDDG. What is stored: the sign-in token (in the app, in the operating system's secure key store), your colour-scheme, language and notification settings, and a cache of the timetable data last loaded so it is available offline. No analytics, advertising or tracking services are used.
Open item before going live
In the web version, opening a map loads program code from Google which accesses device storage on its own account. That is not strictly necessary for the service within the meaning of § 25(2) TDDDG and is likely to require prior consent. No consent prompt exists yet.
Your rights
You have the following rights in respect of your personal data:
•
Access to the data processed and a copy of it (Art. 15 GDPR).
•
Rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR).
•
Erasure (Art. 17 GDPR), unless a statutory retention obligation stands in the way.
•
Restriction of processing (Art. 18 GDPR).
•
Data portability: the data you provided, in a structured, commonly used and machine-readable format (Art. 20 GDPR).
•
Objection to processing based on legitimate interests — here, the analysis of delay observations (Art. 21(1) GDPR).
•
Withdrawal of a consent you gave, with effect for the future (Art. 7(3) GDPR).
An email to me@emilvinu.de is enough for any of these. We reply within the one-month period of Art. 12(3) GDPR.
Open item before going live
The app has neither a delete-my-account control nor a data export. Requests under Art. 15, 17 and 20 GDPR are therefore handled manually. Both functions should be added before going live.
Complaint to a supervisory authority
Without prejudice to any other remedy, Art. 77 GDPR gives you the right to lodge a complaint with a data protection supervisory authority — in particular in the Member State of your residence, place of work, or the place of the alleged infringement.
To be supplied by the operator
Competent supervisory authority
The authority competent for us is the state data protection authority of the German federal state in which the operator is established. That follows from the address to be entered above and must then be named here with its contact details.
Obligation to provide data and automated decisions
An email address and a password are required to create an account. Nothing else is required for anything: searching for journeys works without an account at all, and every field of the booking identity is optional — it only saves you retyping on the operator's booking form.
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The delay forecast shown is a statistical estimate, not a decision producing legal effects concerning you.
Changes to this notice
This notice is updated when the processing changes — for example when a service provider is added or dropped. The version published here, bearing the date shown above, is the one that applies.