Skip to content
OurRound

OurRound Privacy Policy

Updated: July 20, 2026

Controller

Christian Hermann & Martina Hermann GbR, An Rainen 3, 72525 Münsingen, Germany. Contact: support@ourround.de.

Visiting the website

When you visit ourround.de, our hosting and security provider Cloudflare processes technically necessary connection data, in particular the IP address, time, requested address, amount of data transferred, and browser and operating-system information. This processing serves the secure and reliable delivery of the website and protection against attacks. The legal basis is Art. 6(1)(f) GDPR. We do not use analytics, advertising or marketing services on the website and do not store cookies ourselves.

What the app processes

OurRound records drink rounds at shared events. Without an account, events, participant aliases, drink entries, your own pictures and the history stay exclusively local on your device. Only when you sign in for connected groups or shared events is the data required for that processed on our servers. An optional private BAC estimate is processed exclusively on device and is never shared with anyone else.

Depending on use, processing may include settings, progress, entitlement status, support messages, optional account identifiers, store purchase verification and technical diagnostics needed to operate, support or restore the app.

Optional private BAC estimate

If you enable this feature, you enter your weight and one of two body-water parameters. OurRound stores this profile encrypted and separately for each locally used account on your device. The calculation uses only your own drink entries. Neither the profile nor the result is sent to our servers, shared with groups or other people, or included in the backup file. You can delete your profile at any time in Settings; it is deleted at the latest when you remove the app. The result is only a rough model range, not a measurement or guarantee and not medical advice. In particular, it does not assess fitness to drive and must never be used to decide whether you can drive.

Optional account and connected groups/events

For connected groups and shared events you sign in with Google or Apple via Firebase Authentication. Our database stores a pseudonymous account identifier and your freely chosen alias; your email address is processed by Firebase for sign-in and is not stored by us in plain text. In connected groups and events, the group name, event details, RSVP responses, schedule votes and your drink entries (drink, portion, time, corrections) are visible to the authorized members of that event. There is no public feed and no discovery. The legal basis is Art. 6(1)(b) GDPR. You can delete the account and the server-side data at any time in the app.

Push notifications (optional)

If you enable push notifications, we process your device's Firebase Cloud Messaging token together with the platform, language and a random installation identifier to deliver invitations and event notifications. The legal basis is Art. 6(1)(b) GDPR. You can disable push at any time in the settings; the registration is then removed on the server.

Local backup

The export under “Backup & device transfer” creates a local file containing your events, participant aliases, drink entries and pictures. The file is protected as an AES-256-encrypted ZIP with a password chosen by you and leaves your device only if you share or store it yourself. Restore is impossible without that password; keep the file and password separate and safe.

In-app feedback

If you use the feedback form, we store your voluntarily entered text, optionally your contact email, plus the app version, platform and language on our servers to handle your request. Cloudflare Email Service also sends a notification to support@ourround.de. The legal basis is Art. 6(1)(f) GDPR.

Ads and tracking

The app does not show third-party advertising and does not build advertising profiles.

Service providers

We use service providers for app distribution, purchases, hosting, authentication, storage and support, in particular Apple, Google Play, Google/Firebase and Cloudflare. Where providers act on our behalf, data processing agreements under Art. 28 GDPR are in place. Store purchases are regularly processed by Apple or Google as independent controllers.

International transfers

Some service providers may process personal data outside the EU/EEA. Where there is no adequacy decision, transfers rely on appropriate safeguards, in particular EU Standard Contractual Clauses, or on applicable statutory exceptions.

Purchases

Purchases are handled through the Apple App Store or Google Play. A store receipt is checked to unlock purchases.

Security

Personal data is transmitted only over encrypted connections. Local app data is stored in the protected app storage of your device.

Retention and deletion

Local data remains on your device until you delete it or remove the app. Optional account and cloud data is stored until account deletion or your deletion request. Finished or cancelled connected events, including their shared history, are automatically deleted no later than 90 days after they end; expired or revoked guest sessions and invitations are also removed regularly. Store transaction records and a one-way, secret-keyed provider binding are retained separately where needed for secure purchase restoration, refunds, fraud prevention or statutory retention duties. They contain no alias or plain-text email address.

Information about deleting app data and accounts is available at account-deletion.

Your rights

Subject to the statutory requirements, you have the rights under Art. 15–21 GDPR, including access, rectification, erasure, restriction, data portability and objection. You may also lodge a complaint with a data protection supervisory authority; the authority responsible for our registered office is the LfDI Baden-Württemberg. For privacy requests, contact us at: support@ourround.de.