Datenschutzerklärung
Zuletzt aktualisiert: 2026-05-24
1. Wer wir sind
2. Welche Daten wir erheben
- Email address (required for waitlist, Magic Link auth, and campaign updates)
- Order and fulfillment information: name, email, phone, shipping address, order items, customization text, coupon code, and order notes collected during checkout.
- Payment information: payment provider, payment status, provider session / transaction identifiers, and limited payment metadata returned by the provider. We never receive or store your full card number, card security code, private wallet key, or seed phrase.
- Country (derived from IP via Cloudflare; not GPS or precise location)
- IP hash (SHA-256, irreversible) and device fingerprint (FingerprintJS) — used only for fraud detection
- Optional survey answers (preferred destination, source, role)
- Google OAuth profile data when you choose Google login: email address, Google account ID, display name, and profile picture if provided by Google.
- Passkey credentials: public key, credential ID, sign-in counter, device label, and transport hints. We never receive or store your fingerprint, face data, or device unlock secret.
- First-party anonymous behavior analytics: page views, referrer host, country, device type, section visibility time, image/video/game interactions, checkout funnel steps, and payment success events. We do not record checkout form contents, raw IP addresses, emails, phone numbers, shipping addresses, or typed messages in analytics.
- Photo wall uploads (only after explicit user submission, with moderation)
3. Wie wir Daten verwenden
- Sie benachrichtigen, wenn Kickstarter live geht
- Track referral conversions and issue digital / physical rewards
- Create orders, process payment status, arrange shipping, provide customer support, and handle order issues.
- Konten per E-Mail-Verifizierungscode, Google OAuth oder Passkey-Anmeldung authentifizieren.
- Send mission updates (drip emails) — unsubscribe at any time
- Aggregierte, anonymisierte Analysen zur Produktverbesserung
4. Rechtsgrundlagen der Verarbeitung
- Performance of a contract: checkout, payment status, shipping, account access, and order support.
- Consent: marketing emails, photo wall submissions, optional surveys, and non-essential advertising or third-party analytics tools if enabled later.
- Legitimate interests: fraud prevention, site security, abuse prevention, internal diagnostics, first-party anonymous behavior analytics, and improving our products.
- Legal obligations: tax, accounting, sanctions screening, and compliance recordkeeping where required.
5. Was wir NICHT tun
- Sell your data to third parties.
- Ihnen außerhalb eines kampagnenrelevanten Kontexts E-Mails senden.
- Track you across other websites.
- Share personal data for cross-site behavioral advertising.
- Profile minors. (We do not knowingly collect data from anyone under the age of 16, unless local law allows a lower age with valid guardian consent.)
6. Eingesetzte Drittanbieter
- Cloudflare — CDN, DDoS-Schutz, HTTPS
- Resend — Transactional email delivery
- Stripe — Kartenzahlungsabwicklung, wenn aktiviert
- PayPal — PayPal payment processing when enabled
- NOWPayments — Krypto-Zahlungsabwicklung
- Kickstarter — Campaign hosting; their privacy policy applies separately
- Etsy — External purchase of Starship and Card Holder products
- Google OAuth — Optional Google sign-in when enabled
- FingerprintJS — Device fingerprinting for fraud prevention
- Reown / WalletConnect — Wallet connection for crypto checkout; analytics are disabled in our app configuration.
7. Analytics
We use first-party anonymous behavior analytics to understand whether real visitors can find the product, which sections hold attention, which media gets opened or watched, and where the purchase funnel drops off. This analytics system runs on vokar.studio and is used for product improvement, security diagnostics, and checkout reliability.
We do not record checkout form contents, address fields, email fields, phone fields, card details, private wallet keys, raw IP addresses, full user-agent strings, keystrokes, screen recordings, or heatmap recordings. IP and user-agent values may be hashed for bot and abuse filtering only.
We do not currently use Google Analytics, Meta Pixel, TikTok Pixel, or cross-site advertising tracking. If we add advertising pixels or third-party non-essential analytics later, we will update this policy and request consent where required.
8. Internationale Verarbeitung
9. Datenspeicherung
- Verifizierte E-Mail-Konten: bis Sie die Löschung verlangen
- Pending (unverified) emails: 48 hours, then automatically purged
- Orders and fulfillment records: kept as long as needed for delivery, customer support, tax, accounting, chargeback, and compliance purposes.
- Payment provider identifiers and payment status: kept with the order record for reconciliation, support, refunds where applicable, and dispute handling.
- Email verification code records: 10 minutes until expiry; stored as a hash, not the plain verification code.
- Google OAuth temporary state cookies: 10 minutes, then deleted after callback or expiry.
- Anonyme Boarding-Pass-Vorschauen: 180 Tage
- Server access logs: 90 days
- Referral records: 5 years (audit/compliance)
10. Ihre Rechte
11. Cookies
We currently use only essential cookies and localStorage for login, language, preview access, referral attribution, cart, checkout continuity, and first-party anonymous behavior analytics. We do not currently use advertising pixels or third-party non-essential behavior analytics cookies. If we add them later, we will request consent where required.
vokar-user— Nutzerkonto-Sitzung, 60 Tagevokar-admin— Admin-Sitzung für interne Vorgänge, 30 Tagevokar-gate— private preview access gate, up to 1 year while preview mode is enabledvokar-goog-state/vokar-google-state— Google OAuth CSRF state token, 10 minutesvokar-goog-next— Google OAuth return path, 10 minuteslang— Spracheinstellung, 1 Jahrvokar-cart— localStorage cart data, kept on your device for checkout continuityvokar-analytics-session/vokar-analytics-anon— sessionStorage and localStorage anonymous analytics identifiers for first-party aggregate reporting