← Back Deutsch

Privacy Policy

Claim · Last updated: 31 July 2026 · applies across all language and usage regions of the app

This is an English translation of the German-language "Datenschutzerklärung" provided for convenience. In the event of any discrepancy, the German original (available here) prevails.

Contents
  1. Controller and Applicable Law
  2. What Data We Collect
  3. Purposes and Legal Bases of Processing
  4. Third-Party Service Providers (Processors)
  5. International Data Transfers
  6. Retention Period
  7. Your Rights
  8. Cookies and Tracking
  9. Automated Individual Decisions and Profiling
  10. Data Security
  11. Protection of Minors
  12. Changes to this Policy
  13. Contact and Right to Lodge a Complaint

1. Controller and Applicable Law

The controller responsible for data processing is claim-app GmbH (i.G.), Magnolienpark 13, 4052 Basel, Switzerland, represented by Marcel Mutschler ("we", "us", "Claim") · Email: info@claim-app.com · see also our Legal Notice.

As a Swiss provider, we are primarily subject to the revised Swiss Federal Act on Data Protection (revFADP). Because Claim also addresses users resident in the EU/EEA and processes their data, the EU General Data Protection Regulation (GDPR) additionally applies to the extent its territorial scope is triggered under Art. 3(2) GDPR. We have not currently appointed a representative in the EU under Art. 27 GDPR: given the current scale of our EU user base during this testing phase, we consider our processing to be occasional, not to involve large-scale processing of special categories of personal data, and, taking into account the nature, context, scope and purposes of processing, unlikely to result in a risk to the rights of data subjects (exemption under Art. 27(2)(a) GDPR). We continuously review this assessment and will appoint and disclose an EU representative here as our EU user volume grows.

2. What Data We Collect

2.1 When creating an account

Email address, optionally name and city, preferred language and currency.

2.2 When scanning vouchers (Wallet)

Photos of your vouchers, plus information automatically recognised from them (provider, value or service, expiry date, code, address where available).

2.3 On the Marketplace

Listing price, approximate location, offers made and received as well as instant purchases, purchase/sale history, mutual ratings, problem reports, and your referral code. We also automatically compare newly entered voucher codes for similarity (not only exact matches) with existing codes to detect duplicate sales caused by text-recognition errors – flagged matches are reviewed manually by a person internally, and this does not result in an automated decision with legal effect (see Section 9).

2.4 For payments

A customer/account identifier assigned by Stripe, plus transaction metadata (amount, time, status). We never see payment data such as card numbers – these are processed exclusively by Stripe.

2.5 For optional mail delivery of the original voucher

The shipping address entered by the Buyer (name, street, postal code, city, country), as well as the Seller's country of residence to calculate the flat shipping fee. The address is shared only with the Seller for the purpose of executing the shipment.

2.6 When push notifications are enabled

A device-specific technical address used for delivery, which allows no inference as to content.

2.7 For the map feature

Your device location, processed only temporarily in your browser – never stored on our servers.

2.8 For a rough assessment of app usage

A simple signal indicating whether the app is currently open/visible – no recording of individual clicks or scrolling. In addition, we use anonymised, cookie-free visitor statistics on our website (see Section 8).

2.9 As part of our business outreach (does not concern app users)

When a business's voucher is first listed on the Marketplace, we contact that business once using publicly available data (name, address, any published contact email), obtained via the Google Places API, by email or, failing that, by letter.

3. Purposes and Legal Bases of Processing

We process your data to provide the account and Wallet, for automatic text recognition, map display on the Marketplace, processing of offers, instant purchases, payments and optional mail delivery, the rating system, fraud prevention (including code similarity checks), handling of problem reports, sending notifications, a rough assessment of product usage, one-time outreach to businesses, and the operation and security of the app. We do not use your data for advertising purposes and do not sell it to third parties.

PurposeLegal basis (GDPR)
Account, Wallet, Marketplace transactions, payment processing, mail deliveryArt. 6(1)(b) (performance of a contract)
Fraud prevention, code similarity checks, security, rough usage measurement, anonymised web analyticsArt. 6(1)(f) (legitimate interest in preventing abuse and improving the product)
Push notificationsArt. 6(1)(a) (consent given by enabling notifications), combined with (b) for transaction-related notices
Business outreach using publicly available dataArt. 6(1)(f) (legitimate interest in marketplace growth); objection possible at any time
Retention of completed transactions for accounting/tax purposesArt. 6(1)(c) (legal obligation)

For users resident in Switzerland, the corresponding principles of good faith, proportionality and purpose limitation under the revFADP apply analogously.

4. Third-Party Service Providers (Processors)

ServicePurposeLocation
SupabaseDatabase, login, file storageIreland, EU
VercelHosting; also anonymised, cookie-free web analytics (page views, see Section 8)EU/USA (Vercel infrastructure, depending on region)
StripePayment processing (Marketplace sales incl. payout, Claim Premium subscription)Ireland/USA
Anthropic (Claude)Text recognition on voucher photosUSA
ResendSending of login, system and outreach emailsUSA
Google (Places API, geocoding/OpenStreetMap)Business data for outreach; addresses → map coordinatesUSA/international
PingenPostal letters to businesses without a discoverable email addressSwitzerland
Your device manufacturer's push service (Apple/Google)Technical delivery of notificationsdepends on manufacturer, typically USA/EU

Standard data processing terms apply with all processors listed above; where legally required, we conclude separate agreements.

5. International Data Transfers

Certain providers (Anthropic, in part Stripe, Resend, Google, push services, in part Vercel) process data in the USA or other countries outside Switzerland/the EU. We rely on their contractual data protection safeguards, in particular the EU Standard Contractual Clauses (SCCs) or comparable mechanisms recognised by the Swiss FDPIC, as well as adequacy decisions where applicable.

6. Retention Period

We store your data for as long as your account exists. After deletion, your name, profile picture, location and Wallet entries are removed or anonymised. Vouchers that are part of a completed purchase or a problem report remain referenceable, without your name, for accounting and tax reasons (typically 10 years under Swiss law on obligations and taxation). Your login is permanently blocked. Data of businesses contacted as part of outreach is deleted no later than 24 months after the contact attempt.

7. Your Rights

Under Swiss data protection law (revFADP) and, where you are resident or present in the EU/EEA, additionally under the GDPR, you have the following rights:

Please direct requests to: info@claim-app.com. We respond to requests within one month; this period may be extended by a further two months for complex requests, of which we will inform you.

8. Cookies and Tracking

We do not use tracking or marketing cookies, only technically necessary, locally stored data (e.g. login status, language setting within the app). On our website (not within the app), we additionally set a technically necessary cookie (claim-geo, valid for 30 days) that contains only country, language and currency, used to automatically display prices in the appropriate language/currency; consent is not required for this, as it is a purely functional cookie not used for tracking purposes. For anonymous visitor statistics (e.g. number of page views, pages visited, approximate origin), we use Vercel Web Analytics, which according to the provider operates without cookies and does not collect or cross-reference personal data across devices.

9. Automated Individual Decisions and Profiling

We use automated processes for text recognition on voucher photos and for the similarity check of voucher codes (see Section 2.3). These processes support our internal review but do not replace it: flagged matches are always reviewed manually by a person before any account suspension or comparable measure. No automated decision producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR takes place.

10. Data Security

Your voucher photos are stored in a private storage area accessible only to you – via short-lived, individual links rather than permanently public URLs. We never see payment data; this is processed exclusively by our PCI-DSS-certified payment provider, Stripe. Access to our database is technically restricted through role-based permissions (row-level security), so that users can generally access only their own data or data intended for the Marketplace.

11. Protection of Minors

Claim is not directed at persons under the age of 18. If we become aware of an account belonging to a minor, we delete it promptly.

12. Changes to this Policy

We reserve the right to amend this Policy, in particular in connection with new features, new service providers or legal changes. We will notify you of material changes with reasonable advance notice, via the app or by email. The current version is always available here.

13. Contact and Right to Lodge a Complaint

claim-app GmbH (i.G.), Magnolienpark 13, 4052 Basel, Switzerland · Email: info@claim-app.com. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Section 7).


This Privacy Policy was prepared with the greatest possible care for Claim's multilingual, cross-border operations and reflects common practice for Swiss providers with users in Switzerland and the EU/EEA. It does not replace individual legal advice, in particular before significant changes in volume, functionality or target markets. Further details about the provider: Legal Notice · see also Terms of Service.