🔒

Privacy Policy

MyCre / MyCre Adventures

Privacy Policy – MyCre / MyCre Adventures

MyCreBooking Website and Mobile App

Last Updated: August 12, 2026

1. Controller

Vonhöne GmbH
Katja Vonhöne
Kleehof
67305 Ramsen
Germany
Email: info@pfk-coaching.de

Vonhöne GmbH is the controller of personal data within the meaning of the GDPR.

2. Data Protection Contact

Privacy contact:
Katja Vonhöne
info@pfk-coaching.de

Whether a formal Data Protection Officer is legally required depends on the actual processing activities and applicable statutory requirements and will be assessed accordingly.

3. Scope

This Privacy Policy applies to the MyCre / MyCre Adventures mobile application (“App”), the MyCreBooking website and related digital services (“Services”).

MyCre Adventures is not a separate application or platform. It is an interactive experience provided within the MyCre mobile application.

4. Legal Bases

We process personal data only where a valid legal basis applies. Depending on the purpose, this may include Article 6(1)(a) GDPR (consent), Article 6(1)(b) (contract), Article 6(1)(c) (legal obligation), and Article 6(1)(f) (legitimate interests).

Where processing is based on consent, you may withdraw your consent at any time with effect for the future.

5. Personal Data We Process

Depending on how you use the Services, we may process:

  • Account/identification data: name, email address, user account information, login credentials and JWT-related authentication information.
  • Booking data: selected activity, activity provider, date, time, participant information and booking status.
  • Location data: where a location-based feature is enabled and the relevant device permission has been granted.
  • Camera/AR/QR data: where required for QR scanning, augmented reality or interactive features.
  • Technical data: IP address, device type, operating system, app version, browser information and technical server/access data, where actually processed.
  • Communication data: information you provide when contacting us or support.

A phone number is not listed as a routinely required data category in this Privacy Policy.

6. Purposes of Processing

We process personal data in particular to provide and secure the Website and App, manage accounts, authenticate users, display and facilitate activities, process bookings, provide location-based functions, QR/AR features and MyCre Adventures, process payments, deliver push notifications, provide customer support, prevent fraud and security incidents, comply with legal obligations, and establish, exercise or defend legal claims.

7. MyCreBooking and Activity Providers

MyCreBooking connects users/families with independent activity providers. Information necessary to fulfil and manage a booking may be shared with the relevant provider.

Where an activity provider independently determines the purposes and means of processing, that provider may act as a separate controller and its own privacy notice may apply.

8. JWT Authentication

The App uses JWT (JSON Web Token) for authentication. JWT is a technical authentication mechanism used by the MyCre backend and is not an independent external service provider.

Authentication and session information may be processed to authenticate users and manage their accounts. The actual storage and validity period of tokens depends on the technical implementation.

9. Hosting and Technical Infrastructure

The MyCre Website and/or backend infrastructure is hosted with IONOS.

IONOS states that its Web Hosting products may process certain technical visitor data such as referrer, requested website/file, browser and operating-system information, device type, access time and an anonymised IP address for website security and stability. For the Web Hosting products described by IONOS, this visitor data is stored for eight weeks.

The specific IONOS product configuration and any required data processing agreement should be verified by the operator.

10. Google Maps and Location

The Services use Google Maps for mapping and, where applicable, location-based functions.

If you grant location permission, the App may use location data to provide location-based content or features. The specific technical implementation determines which location information is transmitted to Google Maps. Before publication, the operator should verify whether and when precise device location is transmitted to Google and which Google privacy settings are used.

11. Payments

Where payments are offered, they are processed through Stripe and, depending on the platform and purchase, through Apple or Google in-app purchases.

Stripe may process payment and transaction data. For in-app purchases, information necessary for the transaction is processed by the relevant platform. The applicable privacy information of Stripe, Apple and/or Google may also apply.

We do not store full payment card details unless the specific technical implementation expressly collects such information.

12. Push Notifications

Firebase Cloud Messaging (Google Firebase) is used for push notifications.

Technical identifiers and/or push tokens and app/device-related information may be processed to deliver notifications. Notification permissions can be managed through device settings.

13. AR and QR Features

Unity AR Foundation is used for augmented-reality functionality. The App may require camera access for these features. QR functionality may use the camera to scan QR codes.

AR Foundation is not treated in this Privacy Policy as an independent analytics or crash-reporting service. According to the operator, no analytics or crash-reporting services are used. Whether camera frames or other AR data leave the App/device should be confirmed against the production build.

14. Cookies and Similar Technologies

The Website may use technically necessary cookies or similar technologies. Under Section 25 TDDDG, storing information on an end user's device or accessing information already stored there generally requires consent unless a statutory exception applies.

Non-essential cookies or similar technologies will only be used where the required consent has been obtained. Technically necessary technologies may be used without consent where the statutory requirements are met.

15. Account Deletion

If the App allows users to create an account, users may request deletion of their account and associated personal data.

Account-deletion contact: info@pfk-coaching.de

A technical deletion mechanism is available. The URL of that mechanism is intentionally not published in this Privacy Policy at this time.

Certain information may be retained where required by law or necessary for outstanding transactions, fraud prevention, security, or the establishment, exercise or defence of legal claims.

16. Data Retention

Personal data is retained only for as long as necessary for the relevant purpose or as required by law. Specific retention periods depend on the type of data and the purpose of processing.

17. International Data Transfers

Some services used by the App or Website may process personal data outside the EU/EEA. Where required, transfers are made in accordance with Articles 44–49 GDPR, for example on the basis of an adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses.

18. Data Security

We implement appropriate technical and organisational measures designed to protect personal data against loss, destruction, unauthorised access, alteration or disclosure. No electronic system can be guaranteed to be completely secure.

19. Your Data Protection Rights

Subject to applicable law, you may have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent.

To exercise your rights: info@pfk-coaching.de

20. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data protection supervisory authority.

The competent German data protection supervisory authority should be confirmed based on the controller's actual registered location and regulatory jurisdiction. The authority mentioned in earlier client documentation should not be carried over without verification.

21. Children's Privacy

MyCre provides experiences for children and families. Because children may participate in activities, processing involving children must be designed carefully.

We do not knowingly process children's personal data in violation of applicable law. Where parental/guardian consent or other safeguards are required, these must be implemented.

22. Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects, unless a specific feature is expressly described otherwise.

23. Contact

Vonhöne GmbH
Katja Vonhöne
Kleehof
67305 Ramsen
Germany
Email: info@pfk-coaching.de

For privacy, access, correction, deletion or other data-protection requests: info@pfk-coaching.de

MyCreBooking: https://mycrebooking.com

24. Changes to This Privacy Policy

We may update this Privacy Policy when our Services, technology, legal requirements or processing activities change. The “Last Updated” date at the beginning will be updated accordingly.

25. Last Updated

August 12, 2026.

Pre-Publication Verification

  • IONOS product and data-processing configuration verified.
  • Google Maps implementation and location-data flow verified.
  • Stripe processing and applicable DPA verified.
  • Apple and Google in-app purchase implementation verified.
  • Firebase Cloud Messaging token/data flow verified.
  • AR Foundation camera processing verified.
  • No analytics or crash-reporting SDKs are included in the production build.
  • Account deletion tested; deletion URL remains non-public.
  • Competent German supervisory authority confirmed.
  • Apple App Privacy and Google Play Data Safety declarations match the production app.

This document is a drafting template and does not constitute legal advice or a certification of GDPR compliance.