We take the protection of your personal data very seriously. We ensure compliance with data protection regulations through technical and organizational measures. This document describes how we use the data processed within the Cashinator App and the website www.cashinator.de (hereinafter referred to as the Cashinator Website).
With this Privacy Policy, we also want to inform you about the nature, scope, and purpose of the processing of personal data (hereinafter also referred to simply as "data"). Personal data includes all information that can be related to you personally, such as your name, address, email address, or your usage behavior. This Privacy Policy applies to all data processing operations we carry out, both as part of our core activities and for the online media we provide.
The data controller is:
Daniel Mikus
Oderberger Str. 39
10435 Berlin
Germany
Further contact options can be found in the Imprint.
Depending on the features you use, Cashinator may request access to certain functions of your device. Access is requested only when required for a specific feature and, where required by the operating system, only after you have given your explicit consent.
Additional technical system permissions may be used by the operating system to ensure the secure and reliable operation of the app. These permissions do not by themselves result in the collection or transmission of personal data.
On both iOS and Android, access to protected device functions is requested by the operating system whenever required. The requested permissions correspond to the features described above.
The data you enter in the app is stored exclusively for the purpose of synchronization between multiple devices on servers located in Germany (see section "Web Hosting").
Since Cashinator can be used without registration or a user account, we are generally unable to associate the stored data with a registered user account. As part of a support request, we may use the information you provide to identify a trip or group you have used, where this is necessary to process your request. This may include, for example, information about the trip or group, the travel period, participants, or recorded expenses. Data will only be disclosed, restored, or made accessible if your authorization can be established with sufficient plausibility based on the information provided. If sufficient verification is not possible, we may refuse to disclose, restore, or unlock the requested data. The data is not combined with other data sources.
The applicable legal bases are described in the relevant sections of this Privacy Policy, in particular under "Web Hosting" and "Contacting Us".
For statistical analysis and improvement of the Cashinator App, we use Google Firebase Analytics. Firebase Analytics is an analytics service provided by Google.
In particular, information about the usage of the app may be processed, such as features accessed, app interactions, session information, app version, device model, operating system, technical identifiers, and, where applicable, approximate location information derived from technical connection data.
Firebase Analytics uses technical identifiers to assign events to a specific app installation. Data is processed in pseudonymized form. Through Firebase Analytics, we do not receive directly identifying information such as your name, email address, or postal address, and we cannot associate the collected usage data with any specific individual.
This processing is used to statistically evaluate the usage of individual features and to further develop the app.
Firebase Analytics is currently permanently enabled. An opt-out option within the Cashinator App is not currently provided.
We currently base this processing on our legitimate interest pursuant to Art. 6(1)(f) GDPR to statistically evaluate app usage, identify technical issues, and continuously improve the app.
Firebase Analytics uses technical identifiers – in particular an identifier assigned to the respective app installation – to statistically evaluate usage events.
The recipient is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Processing by Google LLC in the United States cannot be excluded. Where personal data is transferred to the United States or other countries outside the European Economic Area, this is done on the basis of an adequacy decision by the European Commission or appropriate safeguards pursuant to Art. 44 et seq. GDPR.
For further information on data processing by Google, please visit: https://firebase.google.com/support/privacy
The Cashinator App contains a link to the Cashinator websites, whose privacy policies are described in this document.
In the Cashinator App, you can either manually enter the location for a transaction during your trip, or allow the device's GPS signal to be automatically used to add the location to the transaction. You can individually choose which details of the determined location to include. Available information includes city, country, postal code, street, and specific latitude and longitude. The GPS signal and the location information derived from it are read only after explicit user consent and are then stored together with the transaction on the Cashinator servers.
Sensitive GPS information stored on the servers is neither shared with third parties nor used for additional analysis or tracking purposes outside your personal app instance. By consistently avoiding registration and login within the Cashinator App, the stored location information cannot generally be associated with a registered user account.
Location data is only accessible to persons who have access to the associated trip or group. All stored location data can be viewed, manually modified, and deleted at any time within the app.
Once consented, GPS sensor data is read only at the exact moment the user initiates a new expense entry or taps the button to capture the current location. Cashinator never reads location data in the background without the user's knowledge.
Data recorded through the use of the Cashinator App, visiting this website, or contacting us, will generally only be transmitted to third parties if this is legally required, stipulated by a court order, or if disclosure is necessary in the event of attacks on the internet infrastructure of the Cashinator App for legal or criminal prosecution purposes. Data is only shared with third parties where a legal basis exists – in particular where transmission is required for the performance of a contract, is based on a legitimate interest, is required by law, or where you have given your explicit consent.
Under the GDPR, you have the following rights, which you can exercise at any time by contacting the responsible party listed in section 1 of this Privacy Policy:
[1] We wish to inform you about this data processing in advance. As a general rule, Cashinator can be used without registration. Personal data is processed only where required for specific features – for example, when sending personalized postcards. The data you enter in the app is stored exclusively on servers in Germany (see section "Web Hosting") and is generally only accessible to persons to whom you have granted access to the respective trip or group. Data is only shared with third parties in the cases described in this Privacy Policy. If you share a trip or group with other people, those persons can access the data contained therein. Access is provided via a time-limited sharing code that is only valid for a few days.
[2] Personal data is processed only where required for the operation of individual features, technical security, or responding to inquiries. If you have any further questions, you are welcome to contact us using the contact information provided in section 1.
[3] Deletion of specific trips, groups, or other data stored on our servers is only possible if we are able to clearly identify the relevant data and sufficiently verify your authorization. For this purpose, you may provide us with the keys stored on your device. If these keys are no longer available, we may, as part of a support request, attempt to identify the relevant data based on the information you provide. In such cases, deletion will only be carried out if both the identification of the data and your authorization are sufficiently plausible. If adequate verification is not possible, we may refuse the deletion request in order to protect the data of other users against unauthorized access or deletion. Alternatively, you can delete your own data by removing your groups, trips, and backups from your device, provided they have not previously been shared with third parties.
You may withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal shall not be affected.
Consents for optional cookies and analytics services on our website can be withdrawn via the Cookie Settings. You can access the Cookie Settings at any time, change your previous selection, and withdraw any consent already granted with effect for the future. When you reset your selection, your previous decision is deleted, the page reloads, and the consent banner is displayed again.
The collection and storage of server log files (e.g., IP address, access times, and pages visited) is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR to ensure the technical security, stability, and error analysis of our website.
You generally have the right to object to this processing on grounds relating to your particular situation. We may, however, continue the processing where compelling legitimate grounds exist or where the processing is necessary for the establishment, exercise, or defense of legal claims.
Personal data is only stored for as long as necessary for the respective processing purposes or as required by statutory retention obligations. Server log files collected for technical security purposes are automatically deleted after 30 days. Cookies and analytics services have varying retention periods. Information about the cookies and analytics services used on the website can be found in the Cookie Settings. For user-related and event-related data in Firebase Analytics, a retention period of 14 months is currently configured. After this period, the relevant data is deleted in accordance with the deletion procedures provided by Google. Aggregated statistical reports may remain unaffected.
If you submit a support request to us via email and provide personal data (such as a key pair to access data you have entered in the app), we store your data only as long as necessary to respond to your request. Once your request has been completed, your data will be deleted. We also delete your data if we no longer require it or if you request its deletion. This means that – unless otherwise stated in specific notices within this Privacy Policy – we will delete your data:
However, if we are required to retain your data (or certain parts of it) for other purposes – such as compliance with statutory retention obligations (typically 6 years for business correspondence or 8 years for accounting records), or for the establishment, exercise, or defense of legal claims arising from contractual relationships (up to 4 years), or if the data is necessary to protect the rights of another natural or legal person – we will delete (that part of) your data only after these retention periods have expired. Until such time, we restrict the processing of this data solely to fulfilling these retention obligations.
The Cashinator Website uses cookies as well as the browser's Local Storage. Cookies are small text files stored on your device. Local Storage allows information to be stored in the browser beyond the duration of a single browsing session.
Technically necessary storage is used to provide the basic functionality of the website and to save your choices in the Cookie Settings. This storage is required for the operation of the website.
Optional cookies and comparable technologies for statistical, analytical, or marketing purposes are only used if you have previously consented via our Cookie Settings. Without your consent, only technically necessary storage operations are performed.
Google tags for web analytics and ad conversion tracking are loaded only after your prior consent to the respective category (analytics or marketing) in Basic Consent Mode. Before your decision and if you decline, the relevant Google tags are not loaded. Therefore, no data is transmitted to Google via those tags.
Your Cookie Settings selection is stored in your browser's Local Storage so that you are not asked for your preferences again on every page visit. The legal basis for accessing or storing information on your device is § 25(2)(2) TDDDG. Subsequent processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR to provide the website properly and in a user-friendly manner.
In addition, your consent decision is transmitted to our server. In this context, we process the selected consent statuses and technically necessary connection data within server communication (e.g., timestamp and IP address). This processing is performed exclusively for documenting and managing your consent decision.
Where you have consented, cookies or comparable technologies may be used on the Cashinator Website to statistically evaluate website usage, measure the success of advertising campaigns, and improve our offering.
The legal basis for storing information on your device or accessing information stored there is your consent pursuant to § 25(1) TDDDG. The legal basis for subsequent processing of personal data is your consent pursuant to Art. 6(1)(a) GDPR.
You can open the Cookie Settings at any time, change your previous selection, and withdraw any consent already granted with effect for the future. When you reset your selection, the previous decision is deleted, the page reloads, and the consent banner is shown again.
Where personal data is transferred to recipients outside the European Union or the European Economic Area, this is done on the basis of an adequacy decision by the European Commission or appropriate safeguards pursuant to Art. 44 et seq. GDPR.
To provide our websites and store backup and synchronization data within the Cashinator App, we use one or more hosting providers whose servers store our websites and make them accessible on the internet (hosting). These providers may process all data transmitted via your browser when you access our website. This includes, in particular, your IP address, which the provider needs to deliver our website content to your browser, as well as any inputs you make via our website. Additionally, our hosting providers may collect:
The above-mentioned data is stored as log files on our providers' servers. This is required to ensure the stability and security of our website. Backup and synchronization data from the Cashinator App is also stored on our providers' servers in a database system. The data is protected by appropriate technical and organizational measures, in particular through encryption during transmission and suitable access controls.
When you send a postcard via the Cashinator App, we transmit the personal data required to carry out the order to our commissioned printing and shipping service provider.
This includes in particular:
The recipient data is not collected directly from the recipient but is provided exclusively by the user who places the postcard order. We generally do not have any contact information for the recipient beyond their postal address. The recipient data is used exclusively for the production and delivery of the postcard ordered by the user.
The processing and transmission of this data is carried out exclusively for the purpose of executing the printing and shipping order you have placed. The data is not used for advertising purposes, to create user profiles, or for any other proprietary purposes. The legal basis for processing is Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
By sending a postcard, you confirm that you have accurately provided the recipient's data to the best of your knowledge and that you are authorized to transmit it to us for the purpose of fulfilling the shipping order.
The content and recipient data required for printing and shipping are stored by us only until successful transmission and for the handling of any potential technical errors or complaints. The data is deleted after completion of the printing and shipping order, unless it is still required for a limited period for handling technical errors or complaints and no statutory retention obligations apply. The specific retention period at the printing and shipping service provider is governed by their contractual deletion terms.
For the production and shipping of postcards, we use the following printing and shipping service provider:
MyPostcard.com GmbH
Hohenzollerndamm 3
D-10717 Berlin
For further information on the processing of personal data by the service provider, please visit:
https://www.mypostcard.com/en/privacy?changelang=1&apply=1
Only the personal data required for the execution of the printing and shipping order is transmitted.
If you contact us via email, social media, telephone, fax, mail, or through other personal means, providing us with personal data such as your name, telephone number, or email address, or any further details about yourself or your inquiry, we will process this information to respond to your request within the scope of our pre-contractual or contractual relationship.
We advertise Cashinator via Google Ads and Apple Ads. Displaying ads on those external platforms does not itself result in cookies being set by us on the Cashinator Website.
Apple Ads is used exclusively to place ads within the Apple advertising network. No Apple tracking tag is embedded on the Cashinator Website for this purpose.
The Google Ads tag on our website is loaded only after your explicit consent to marketing as a category (Basic Consent Mode). Before your decision and if you decline, the Google Ads tag is not loaded. Therefore, no data is transmitted to Google via this tag.
Processing by Google LLC or Apple Inc. in the United States cannot be excluded. Where personal data is transferred to the United States or other countries outside the European Economic Area, this is done on the basis of an adequacy decision by the European Commission or appropriate safeguards pursuant to Art. 44 et seq. GDPR.
We use Google Analytics 4 (GA4) to statistically evaluate website usage and improve our website.
Google Analytics is loaded only after your explicit consent to the analytics category (Basic Consent Mode). Before your decision and if you decline, the Google Analytics tag is not loaded. Therefore, no data is transmitted to Google via this tag.
Consent pursuant to § 25(1) TDDDG and Art. 6(1)(a) GDPR.
You can open the Cookie Settings at any time, change your previous selection, and withdraw any consent already granted with effect for the future. When you reset your selection, the previous decision is deleted, the page reloads, and the consent banner is shown again.
We maintain social media pages on the social networks listed below. When you visit one of these profiles, data described below will be collected and processed by the respective platform provider. In general, this data is collected for advertising and market research purposes, and usage profiles are created from it. Data in these profiles can be stored independently of the device you use, particularly if you are a member of the respective platform and logged into your account. The providers may use these profiles to display interest-based advertisements. You have the right to object to the creation of such user profiles; to exercise this right, you must contact the respective provider directly.
If you have an account with one of the providers listed below and are logged in when visiting our website, the respective provider may collect data about your browsing behavior on our site. To prevent such linking of your data, you can log out of the provider's service before visiting our website.
Details on the purpose and scope of data collection by each provider can be found in their respective privacy policies, linked below.
Please note that depending on the provider's country of operation, personal data collected through their platforms may also be processed outside the European Union or the European Economic Area. Where such a transfer takes place, it is done on the basis of an adequacy decision by the European Commission or appropriate safeguards pursuant to Art. 44 et seq. GDPR.
We implement technical and organizational security measures in accordance with the current state of the art to comply with data protection laws and to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties.
As the Cashinator App and Cashinator Website continue to develop and in response to new legal requirements, changes to this Privacy Policy may become necessary. We reserve the right to update these provisions at any time in compliance with applicable data protection laws.
This Privacy Policy is currently valid and effective as of July 2026. Due to changes in applicable laws or official regulations, it may become necessary to amend this Privacy Policy accordingly.