
ZeitPass - Privacy Policy
Last updated: 12 August 2026
ZeitPass takes your privacy seriously. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have over it. We operate in full compliance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
If you have any questions, contact us at contact@zeitpass.com.
1. Who We Are
The data controller for all personal data collected through ZeitPass services is:
ZeitPass UG (haftungsbeschränkt)
Südliche Münchner Str. 62, 82031 Grünwald, Germany
HRB 312002, Amtsgericht München
Email: contact@zeitpass.com
2. What This Policy Covers
This Privacy Policy applies to all ZeitPass services, including:
-
The ZeitPass website at zeitpass.com and all associated pages and subdomains.
-
The Munich Shortlist, our free weekly email newsletter.
-
The ZeitPass User Portal, available on a free basis (Free Tier) and, for paid subscribers, on a membership basis.
3. What Personal Data We Collect
3.1 Newsletter Subscribers
When you subscribe to The Munich Shortlist, we may collect:
-
Your name and email address, as provided during subscription.
-
Technical and engagement data such as email open rates, link clicks, and subscription source, collected automatically by our email platform.
3.2 Website Visitors
When you visit zeitpass.com, we may collect:
-
Usage data such as pages visited, clicks, session identifiers, and navigation patterns, collected through analytics tools subject to your cookie consent.
-
Technical data such as your IP address, browser type, operating system, and device information.
-
Advertising and marketing data, such as advertising identifiers and browsing behaviour, collected through the Meta/Facebook Pixel and Google’s advertising tags, subject to your cookie consent.
3.3 User Portal (All Users)
When you register for the User Portal, whether or not you take out a paid membership, we collect the following categories of data:
-
Account and identity data: your name, email address, phone number (optional), and securely stored authentication credentials.
-
Preferences: information you provide during onboarding about your interests and preferences, used to build a personalisation profile and generate your event recommendations.
-
Usage and activity data: information about how you interact with the portal, such as features used, content viewed, and actions taken, used to improve our service and personalise your experience.
Where you choose to register or sign in using ‘Continue with Google,’ Google acts as an identity provider. Google shares your name and email address with us to create or authenticate your account. We do not receive your Google password or access your Google account beyond this basic profile information. This processing is separate from our use of Google Fonts and Google Maps described elsewhere in this policy. Any data processed by Google as part of this sign-in is also subject to Google’s own privacy policy.
3.4 Paid Membership (Additional Data)
If you take out a paid membership, we additionally collect:
-
Membership data: your membership plan, renewal date, and experience quota, as assigned by ZeitPass.
-
Booking data: details relating to booking requests you make through the portal, including your preferences for venue, date, and language, as well as booking status, feedback, and related correspondence.
3.5 Data We Do Not Collect
ZeitPass does not collect:
-
Payment card details. All payment processing is handled by our payment processor.
-
Precise GPS or device location data.
-
Biometric data.
-
Personal data from individuals under the age of 18.
4. How We Use Your Personal Data
We use your personal data only for the purposes set out below and on the legal basis indicated.
-
Consent (Art. 6(1)(a)): Delivering The Munich Shortlist newsletter to your inbox; setting non-essential cookies on the website; sending you WhatsApp messages where you have opted in.
-
Contract performance (Art. 6(1)(b)): Creating and managing your User Portal account; processing and coordinating bookings; enforcing membership terms.
-
Legitimate interest (Art. 6(1)(f)): Improving and personalising our services; analysing usage patterns; maintaining security; communicating service-related updates.
-
Legal obligation (Art. 6(1)(c)): Retaining records as required under applicable German commercial and tax law.
ZeitPass does not use your personal data for targeted advertising and does not sell, rent, or trade your data to any third party for commercial purposes.
5. Third-Party Service Providers
We share your personal data only with trusted third-party service providers who support the operation of ZeitPass services. All providers are bound by data processing agreements and are required to process data in accordance with the GDPR. The following providers may process your data depending on which ZeitPass services you use.
5.1 Email Platform
We use Beehiiv, Inc. as our email platform provider to deliver The Munich Shortlist newsletter, manage subscriber lists, and provide engagement analytics. Subscriber names, email addresses, and engagement data may be processed by Beehiiv. Privacy policy: beehiiv.com/privacy.
5.2 Infrastructure and Data Storage
User Portal data, including account information, preferences, booking records, and associated documents, is stored and processed using Supabase (database, authentication, and file storage) and Railway (backend processing, including sending transactional emails and running our event recommendation engine). Both are hosted within the European Union, and data processed under this arrangement does not leave the EEA. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.3 Analytics
We use PostHog to understand how our website and portal are used and to improve our services. Where this involves cookies or similar technologies, it is subject to your consent. Analytics data is anonymised or pseudonymised where possible and is not used to identify you individually. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.4 Artificial Intelligence and Automated Processing
We use third-party artificial intelligence providers, including commercial and open-weight large language models, to support and improve our content, workflows, and product features. Where such tools are used in ways that involve your personal data, we ensure that appropriate safeguards and processing agreements are in place. No automated decision-making with legal or similarly significant effects is applied to individual users without human oversight. A current list of specific providers is available on request by contacting contact@zeitpass.com.
5.5 Content Delivery and Media
We use Cloudinary to host and deliver images, and Google Fonts to load website typography. These services may process your IP address as part of standard content delivery operations. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.6 Mapping Services
Where the portal displays venue information, we may provide links to Google Maps for directions. These links open in a new tab and are only activated by your deliberate action. Any data subsequently processed by Google is subject to Google’s own privacy policy.
5.7 Cookie Consent Management
Cookie consent on the ZeitPass website (zeitpass.com) is managed through Usercentrics, a consent management platform integrated with our website provider, Wix. Your preferences are stored to ensure they are respected across sessions. The ZeitPass User Portal is a separate platform with its own cookie consent mechanism, described in Section 6.
5.8 Payment Processing
Membership payments are processed by Stripe. Payment card details are handled entirely by Stripe and are never stored by ZeitPass. Stripe also acts as an independent data controller for its own fraud-prevention and regulatory purposes; details are available in Stripe’s privacy policy. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.9 Security Verification
We use Cloudflare Turnstile to distinguish genuine sign-ups and account actions from automated ones. This processes your IP address and device signals as part of the verification check. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.10 Messaging
Where you have opted in to receive messages via WhatsApp, we use Twilio to deliver them. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.11 Email Delivery
We use Resend to deliver transactional emails, including account confirmations, booking confirmations, and service notifications. This processes your email address and the content of the relevant message. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.12 Advertising and Marketing
On the ZeitPass website (zeitpass.com), we use the Meta/Facebook Pixel and Google’s advertising tags (delivered via Google Tag Manager) to measure the performance of our advertising campaigns and understand how visitors reach our site. These tools may process standard advertising identifiers, your IP address, and your browsing behaviour on the website. They are set only with your consent. The specific provider we use for this purpose may change over time. Any successor provider will be bound by the same data protection obligations, and such a change will not itself constitute a material revision of this policy, provided the purpose and categories of data processed remain the same.
5.13 Legal Disclosure
ZeitPass may disclose personal data to law enforcement or regulatory authorities where required by applicable German or EU law, or where necessary to protect the rights of ZeitPass or its users.
6. Cookies and Tracking
ZeitPass operates two separate online properties, each with its own cookie consent mechanism, in accordance with the GDPR and § 25 TTDSG.
-
The ZeitPass website (zeitpass.com): built on Wix, with cookie consent managed through Usercentrics (see Section 5.7). On your first visit, you will be presented with a consent banner. You may accept all cookies, essential cookies only, or adjust your preferences at any time. Non-essential cookies, including the Meta/Facebook Pixel and Google’s advertising tags, are set only once you have given consent.
-
The ZeitPass User Portal: a separate platform with its own consent banner, governing non-essential cookies including our analytics tool, PostHog.
-
Essential cookies: required for each platform to function correctly. These cannot be disabled.
-
Non-essential cookies (analytics and advertising): only activated with your consent, and only used for the purposes described in Section 5.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy or as required by law.
-
Newsletter subscriber data: Retained while you remain an active subscriber. Removed from active lists upon unsubscription. Permanently erased upon a valid erasure request.
-
Account and profile data: Your directly identifying account data (name, phone number, email address) is permanently deleted upon a valid account deletion request.
-
Preferences and personalisation data: Retained while your account is active. Deleted with your account.
-
Booking and financial records: Your booking history is retained for 10 years from the end of your membership, in a form that no longer directly identifies you, linked to your account only by an internal reference, in order to meet our record-keeping obligations under German commercial and tax law (§ 257 HGB, § 147 AO). Deleting your ZeitPass account does not affect data retained independently by Stripe, our payment processor, under its own regulatory obligations.
-
Usage and activity data: Retained for 12 months from collection, then deleted on a rolling basis. ZeitPass does not retain granular activity data indefinitely.
-
Analytics data: Retained per the settings of the applicable analytics provider, typically up to 12 months.
You may request deletion of your personal data at any time. See Section 8 for details.
8. Your Rights Under GDPR
As a data subject, you have the following rights. All rights are exercisable free of charge by contacting contact@zeitpass.com.
-
Right of access (Art. 15): Request a copy of all personal data we hold about you.
-
Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
-
Right to erasure (Art. 17): Request permanent deletion of your personal data, subject to any legal retention obligations.
-
Right to restriction (Art. 18): Request that we limit the processing of your data under certain circumstances.
-
Right to data portability (Art. 20): Request your data in a structured, machine-readable format.
-
Right to object (Art. 21): Object to processing based on legitimate interest at any time, including product analytics.
-
Right to withdraw consent (Art. 7(3)): Where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing.
ZeitPass will respond to all GDPR rights requests within 30 days of receipt, in accordance with GDPR Article 12.
8.1 Supervisory Authority
If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with the competent supervisory authority. In Bavaria, this is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
If you reside in another EU member state, you may also contact the supervisory authority in your country of residence.
9. Data Security
ZeitPass applies appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or alteration. These include encrypted data transmission, access controls, role-based permissions, and secure storage practices.
In the event of a personal data breach likely to result in a risk to your rights, ZeitPass will notify the competent supervisory authority within 72 hours and will inform affected users without undue delay, in accordance with GDPR Articles 33 and 34.
10. International Data Transfers
Where possible, ZeitPass processes personal data within the European Union. Where certain service providers are based outside the EEA, we ensure that appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as approved by the European Commission or reliance on an adequacy decision where applicable.
ZeitPass does not transfer personal data to any country or organisation that does not provide an adequate level of protection.
11. Age Restriction
ZeitPass services are intended exclusively for individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, their data will be deleted promptly. If you believe a minor has accessed a ZeitPass service, please notify us at contact@zeitpass.com.
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, data practices, or applicable law. The current version is always available at zeitpass.com/privacy-policy. Where changes are material, we will notify active newsletter subscribers, Free Tier users, and members by email at least 14 days before the changes take effect.
13. Contact
For any questions or requests regarding this Privacy Policy or the handling of your personal data:
ZeitPass UG (haftungsbeschränkt)
Südliche Münchner Str. 62, 82031 Grünwald, Germany
HRB 312002, Amtsgericht München
Email: contact@zeitpass.com
Website: zeitpass.com
ZeitPass will respond to all data protection enquiries within 5 business days and to formal GDPR rights requests within 30 days.
