Privacy policy
Last updated: 23 September 2026
This policy explains which personal data the HabenWir app and the pages at habenwir.avenzasoft.com process, why, on what legal basis and for how long — and what rights you have. The German version is the binding one.
In short
- HabenWir is an app where neighbours and businesses lend, rent out, give away and look for things. We process only what that needs.
- No advertising, no tracking, no analytics tools, no selling of data.
- Your exact pickup address is never public. Only your neighbourhood and a point moved by about 150 m are.
- The AI help when listing is optional and can be switched off.
- You can delete your account in the app at any time.
1. Controller
AvenzaSoft UG (haftungsbeschränkt), Pinneberger Str. 8a, 22880 Wedel, Germany, represented by its managing director Aymen Mokhtari.
E-mail: support@avenzasoft.com — more in the imprint.
We have not appointed a data protection officer because we are not required to. Write to the address above with any privacy question.
2. Account and sign-in
You sign in with a code we send to your e-mail address or, by SMS, to your phone number. There is no password.
- Data: e-mail address or phone number, when it was confirmed, your display name; optionally a profile photo, a short bio, your neighbourhood and city; the app's language.
- Home location (optional): if you set a place in your profile, we store its coordinates to calculate distances when your device gives no location. They are never public.
- Sign-in codes are valid for a few minutes. After you sign in, a session key is kept in your device's protected storage (Keychain or Keystore); the server keeps which sessions are valid.
- Purpose and legal basis: running your account and the contract of use (Art. 6(1)(b) GDPR); preventing abuse, for example by limiting how often codes can be requested (Art. 6(1)(f) GDPR).
Codes by e-mail are sent through our mailbox at IONOS, codes by SMS through Twilio (see section 13).
3. Business accounts
Businesses give their company name and address, and optionally a VAT ID, a website and a phone number. These details are public as the provider identification on the profile and listings, because businesses are legally required to show them (Art. 6(1)(b) and (c) GDPR).
4. Listings and photos
- Data: title, description, category, condition, brand and model, prices for rentals, a deposit (as information only — we handle no payments), availability, photos; optionally a phone number and — business accounts only — a link to the item on their own website.
- Visibility: listings are visible to everyone using the app, including your display name, profile photo and ratings. Phone numbers and links you add are part of the listing.
- Photos: on upload we re-encode every photo and remove all metadata, including the camera's GPS coordinates.
- Legal basis: Art. 6(1)(b) GDPR.
5. Location
- Pickup location: each listing has a pickup location. We keep the exact point and address private. Public are only the neighbourhood, the city and a point moved at random by about 150 m. Only the person whose request you accepted sees the exact address, and only while the loan is running.
- Your device's location: only if you allow it, the app sends your current location with a search to our server to calculate distances and show what is nearby. We do not keep it as a history.
- Legal basis: Art. 6(1)(b) GDPR; you can withdraw the location permission in your device settings at any time.
6. Search and map
- Search terms are used by the server for that search only; it does not store them. Your recent searches are kept on your device only and can be cleared in the settings.
- Place search: when you type a place (for example in the filters) or set your pickup location when listing, our server sends the text or the coordinates to Mapbox to find matching places, the neighbourhood and the city.
- Map tiles are loaded by your device directly from Mapbox, which thereby learns your IP address, details of your device and which map area you look at.
- Legal basis: Art. 6(1)(b) GDPR (search and map are part of the service).
7. Requests, loans and deposits
We store requests (the days wanted, your message), the steps of a loan with their times (acceptance, handover, return, completion), agreed pickup times and — as information only — rental price and deposit. Contracts to lend, rent or give something are made directly between you; payments do not go through us. Legal basis: Art. 6(1)(b) GDPR.
8. Messages
- We store messages on our server so they can be delivered and your history is available on all your devices. They are encrypted in transit (TLS); there is no end-to-end encryption.
- We do not read messages, except messages reported to us and where the law requires it.
- While the app is open it keeps a live connection so messages appear at once. That tells the server whether it also needs to send you a push notification.
- Legal basis: Art. 6(1)(b) GDPR; for reported content Art. 6(1)(c) GDPR (obligations under the Digital Services Act) and (f) (platform safety).
9. Ratings
After a completed loan, and after a real exchange in a chat, you can rate each other. Ratings are public with stars, text, date and the rater's name, and count towards the average on the profile. Legal basis: Art. 6(1)(b) and (f) GDPR (reliable assessment of the people you deal with).
10. Notifications
- In the app we store notifications in your account (Inbox › Updates).
- Push: if you allow them, the app registers your device with Firebase Cloud Messaging (Google). We store the device identifier ("token") to deliver notifications and delete it when you sign out.
- E-mail for new messages: only if you turn it on — at most one an hour, sent through IONOS. The e-mail contains the start of the message.
- You choose what reaches you under Settings › Notifications.
- Legal basis: Art. 6(1)(b) GDPR; for the e-mails your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by turning them off.
11. AI help when listing (optional)
Only when you tap the AI help while listing, the app sends your photos and the kind of listing to our server, which forwards them to Google's Gemini API. Google produces a suggestion for title, description, category and condition that you can check and change. We do not store the photos for this suggestion; only the photos you finally publish are stored. Using it is optional (Art. 6(1)(a) GDPR) and it can be switched off completely under Settings › Privacy & safety.
12. Reporting, blocking and safety
We store reports (reason, your details, the reported content) and blocks to handle abuse and protect you. We may remove content and suspend accounts; the person affected is told why. Legal basis: Art. 6(1)(c) GDPR (Digital Services Act) and (f) (safety of users and platform).
13. Recipients and processors
We pass data only to service providers who process it on our behalf and are contractually bound by our instructions:
- IONOS SE, Montabaur (Germany): the server, in a data centre in Berlin, holding all the app's data, and sending e-mails.
- Twilio Inc. (USA): sending and checking SMS sign-in codes — Twilio receives your phone number for that.
- Google Ireland Limited or Google LLC (Ireland/USA): Firebase Cloud Messaging for push notifications; the Gemini API for the optional AI help.
- Mapbox Inc. (USA): map tiles and place search.
Other users see what this policy describes as public. Authorities receive data only where the law requires it.
14. Transfers outside the EU
Twilio, Google and Mapbox may process data in the USA. We rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
15. Server logs
Our server logs the time, path, result and duration of each request — without the IP address. The web server in front of it stores IP addresses to fend off attacks and deletes these logs after 14 days. To limit how often requests can be made, we keep IP addresses briefly, for an hour at most. Legal basis: Art. 6(1)(f) GDPR (security and stability of the service).
These web pages set no cookies and load nothing from other servers.
16. How long we keep data
- Account: until you delete it. We then immediately remove your contact details, name, profile photo, bio, home location and a business's provider details, take your listings out of the app, delete their photos, exact pickup addresses, phone numbers and links, delete your notifications and end all sessions. Past loans, messages and ratings stay for the other people in them, without your name ("Deleted account").
- Sign-in codes: a few minutes.
- Web server logs: 14 days.
- Statutory retention obligations remain unaffected.
How to delete your account: Delete account.
17. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)). Write to support@avenzasoft.com.
Right to object: where we process data based on legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation.
You can also lodge a complaint with a data protection authority (Art. 77 GDPR), for example the one responsible for us: the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD) in Kiel.
18. No automated decisions
We make no decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). Sorting by distance or rating is not such a decision.
19. Minimum age
HabenWir is for people aged 18 and over.
20. Changes
When the app changes, we update this policy. The version with the date above applies.