This is an English translation of the German-language "Datenschutzerklärung" provided for convenience. In the event of any discrepancy, the German original (available here) prevails.
The controller responsible for data processing is claim-app GmbH (i.G.), Magnolienpark 13, 4052 Basel, Switzerland, represented by Marcel Mutschler ("we", "us", "Claim") · Email: info@claim-app.com · see also our Legal Notice.
As a Swiss provider, we are primarily subject to the revised Swiss Federal Act on Data Protection (revFADP). Because Claim also addresses users resident in the EU/EEA and processes their data, the EU General Data Protection Regulation (GDPR) additionally applies to the extent its territorial scope is triggered under Art. 3(2) GDPR. We have not currently appointed a representative in the EU under Art. 27 GDPR: given the current scale of our EU user base during this testing phase, we consider our processing to be occasional, not to involve large-scale processing of special categories of personal data, and, taking into account the nature, context, scope and purposes of processing, unlikely to result in a risk to the rights of data subjects (exemption under Art. 27(2)(a) GDPR). We continuously review this assessment and will appoint and disclose an EU representative here as our EU user volume grows.
Email address, optionally name and city, preferred language and currency.
Photos of your vouchers, plus information automatically recognised from them (provider, value or service, expiry date, code, address where available).
Listing price, approximate location, offers made and received as well as instant purchases, purchase/sale history, mutual ratings, problem reports, and your referral code. We also automatically compare newly entered voucher codes for similarity (not only exact matches) with existing codes to detect duplicate sales caused by text-recognition errors – flagged matches are reviewed manually by a person internally, and this does not result in an automated decision with legal effect (see Section 9).
A customer/account identifier assigned by Stripe, plus transaction metadata (amount, time, status). We never see payment data such as card numbers – these are processed exclusively by Stripe.
The shipping address entered by the Buyer (name, street, postal code, city, country), as well as the Seller's country of residence to calculate the flat shipping fee. The address is shared only with the Seller for the purpose of executing the shipment.
A device-specific technical address used for delivery, which allows no inference as to content.
Your device location, processed only temporarily in your browser – never stored on our servers.
A simple signal indicating whether the app is currently open/visible – no recording of individual clicks or scrolling. In addition, we use anonymised, cookie-free visitor statistics on our website (see Section 8).
When a business's voucher is first listed on the Marketplace, we contact that business once using publicly available data (name, address, any published contact email), obtained via the Google Places API, by email or, failing that, by letter.
We process your data to provide the account and Wallet, for automatic text recognition, map display on the Marketplace, processing of offers, instant purchases, payments and optional mail delivery, the rating system, fraud prevention (including code similarity checks), handling of problem reports, sending notifications, a rough assessment of product usage, one-time outreach to businesses, and the operation and security of the app. We do not use your data for advertising purposes and do not sell it to third parties.
| Purpose | Legal basis (GDPR) |
|---|---|
| Account, Wallet, Marketplace transactions, payment processing, mail delivery | Art. 6(1)(b) (performance of a contract) |
| Fraud prevention, code similarity checks, security, rough usage measurement, anonymised web analytics | Art. 6(1)(f) (legitimate interest in preventing abuse and improving the product) |
| Push notifications | Art. 6(1)(a) (consent given by enabling notifications), combined with (b) for transaction-related notices |
| Business outreach using publicly available data | Art. 6(1)(f) (legitimate interest in marketplace growth); objection possible at any time |
| Retention of completed transactions for accounting/tax purposes | Art. 6(1)(c) (legal obligation) |
For users resident in Switzerland, the corresponding principles of good faith, proportionality and purpose limitation under the revFADP apply analogously.
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, login, file storage | Ireland, EU |
| Vercel | Hosting; also anonymised, cookie-free web analytics (page views, see Section 8) | EU/USA (Vercel infrastructure, depending on region) |
| Stripe | Payment processing (Marketplace sales incl. payout, Claim Premium subscription) | Ireland/USA |
| Anthropic (Claude) | Text recognition on voucher photos | USA |
| Resend | Sending of login, system and outreach emails | USA |
| Google (Places API, geocoding/OpenStreetMap) | Business data for outreach; addresses → map coordinates | USA/international |
| Pingen | Postal letters to businesses without a discoverable email address | Switzerland |
| Your device manufacturer's push service (Apple/Google) | Technical delivery of notifications | depends on manufacturer, typically USA/EU |
Standard data processing terms apply with all processors listed above; where legally required, we conclude separate agreements.
Certain providers (Anthropic, in part Stripe, Resend, Google, push services, in part Vercel) process data in the USA or other countries outside Switzerland/the EU. We rely on their contractual data protection safeguards, in particular the EU Standard Contractual Clauses (SCCs) or comparable mechanisms recognised by the Swiss FDPIC, as well as adequacy decisions where applicable.
We store your data for as long as your account exists. After deletion, your name, profile picture, location and Wallet entries are removed or anonymised. Vouchers that are part of a completed purchase or a problem report remain referenceable, without your name, for accounting and tax reasons (typically 10 years under Swiss law on obligations and taxation). Your login is permanently blocked. Data of businesses contacted as part of outreach is deleted no later than 24 months after the contact attempt.
Under Swiss data protection law (revFADP) and, where you are resident or present in the EU/EEA, additionally under the GDPR, you have the following rights:
Please direct requests to: info@claim-app.com. We respond to requests within one month; this period may be extended by a further two months for complex requests, of which we will inform you.
We do not use tracking or marketing cookies, only technically necessary, locally stored data (e.g. login status, language setting within the app). On our website (not within the app), we additionally set a technically necessary cookie (claim-geo, valid for 30 days) that contains only country, language and currency, used to automatically display prices in the appropriate language/currency; consent is not required for this, as it is a purely functional cookie not used for tracking purposes. For anonymous visitor statistics (e.g. number of page views, pages visited, approximate origin), we use Vercel Web Analytics, which according to the provider operates without cookies and does not collect or cross-reference personal data across devices.
We use automated processes for text recognition on voucher photos and for the similarity check of voucher codes (see Section 2.3). These processes support our internal review but do not replace it: flagged matches are always reviewed manually by a person before any account suspension or comparable measure. No automated decision producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR takes place.
Your voucher photos are stored in a private storage area accessible only to you – via short-lived, individual links rather than permanently public URLs. We never see payment data; this is processed exclusively by our PCI-DSS-certified payment provider, Stripe. Access to our database is technically restricted through role-based permissions (row-level security), so that users can generally access only their own data or data intended for the Marketplace.
Claim is not directed at persons under the age of 18. If we become aware of an account belonging to a minor, we delete it promptly.
We reserve the right to amend this Policy, in particular in connection with new features, new service providers or legal changes. We will notify you of material changes with reasonable advance notice, via the app or by email. The current version is always available here.
claim-app GmbH (i.G.), Magnolienpark 13, 4052 Basel, Switzerland · Email: info@claim-app.com. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Section 7).
This Privacy Policy was prepared with the greatest possible care for Claim's multilingual, cross-border operations and reflects common practice for Swiss providers with users in Switzerland and the EU/EEA. It does not replace individual legal advice, in particular before significant changes in volume, functionality or target markets. Further details about the provider: Legal Notice · see also Terms of Service.