Last updated: April 2026
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Andreea Schmid
Hauptstraße 12
71334 Waiblingen, Germany
Email: info@coinatlas.eu
For all requests under the GDPR, such as access, rectification, deletion, and similar requests, the email address above is available.
This Privacy Policy applies to the use of the Coin Atlas website as well as the Android and iOS apps.
When you access our website, your browser automatically transmits the following data (server log files):
Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in the security and optimization of the service). The data is not combined with other data sources and is deleted after no more than 14 days.
When using the Android and iOS apps, technically necessary access data may be processed, in particular:
Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in the security, stability, and optimization of the service) and, insofar as processing is necessary for the use of the Service, on the basis of Art. 6(1)(b) GDPR.
No use for analytics, tracking, or advertising purposes takes place.
When creating a user account, we collect:
Alternatively, you can register and log in using a third-party service (Google or Apple). In this case, we receive the following data from the respective provider:
No password is collected when logging in via third-party providers.
Processing is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract).
When you add or edit content, we store:
When you create activity reports for machine locations, we store:
When you submit suggested changes to existing data, we store the suggestion together with your user ID in order to assign the suggestion and enable the review process.
When you report content (content reports), we store the report including the reason, time, and — if you are logged in — its assignment to your user account. Users who are not logged in may also report content; in this case, no assignment to an account takes place.
When you create personal lists or bookmarks (e.g., visited locations, collection entries), these are assigned exclusively to your account and are visible only to you, unless you actively share them.
Processing is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract).
The Android and iOS apps may access your current device location if you grant the corresponding permission. Location access is used exclusively to pan the map view to your current location.
The current device location is not stored, not processed on a persistent basis, and not linked to your user account or user profile. The device location is not used for analytics, tracking, or advertising purposes.
The location permission can be revoked at any time via your operating system settings. Without the location permission, the map can still be used; only the automatic panning of the map to your own location is then not possible.
Processing is carried out on the basis of Art. 6(1)(a) GDPR (consent), provided that you actively grant the location permission.
In order to make the service accessible to an international audience, content entered by users (names, descriptions) may be translated into other languages by machine. Translation is carried out exclusively on our own infrastructure in Germany; no data is transmitted to external providers (see also Section 5.6).
Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in providing content in multiple languages).
As part of the use of the service, we send transactional emails to the email address you provide. These include, for example:
The content of the emails depends on the respective process. Marketing emails or newsletters are not sent unless separate consent has been obtained for this.
Processing is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract).
The Service may in the future offer paid features or subscriptions. For purchases made through the Android or iOS app, payment processing is handled by the respective app store provider. In this context, the Operator processes only the information necessary to provide, activate, manage, and document the booked service, in particular purchase or subscription status, product identifier, term, and assignment to the user account.
Processing is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract) as well as, where necessary, Art. 6(1)(c) GDPR (statutory retention obligations).
We use your browser's local storage to provide technically necessary functions, in particular to store the login status, language setting, and the status of notices. Storage and access are carried out on the basis of Section 25(2) No. 2 TDDDG (German Digital Services Data Protection Act), insofar as they are necessary to provide the service expressly requested by the user. In addition, the processing of personal data is carried out on the basis of Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
In the Android and iOS apps, technically necessary data may be stored locally on the end device, in particular login status, language setting, and app settings. Such storage serves exclusively to provide the functions requested by the user. No local storage for analytics, tracking, or advertising purposes takes place.
We currently do not use cookies. Local storage is not used for analytics, tracking, or advertising purposes.
The technical operation of the service is provided by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. The servers are located within the European Union. A data processing agreement pursuant to Art. 28 GDPR exists with IONOS. IONOS's privacy policy is available at: https://www.ionos.de/terms-gtc/terms-privacy
On the website, we use MapTiler to display the interactive map. The provider is MapTiler AG, Zugerstrasse 22, 6314 Unterägeri, Switzerland.
In particular, IP address, requested map tiles, time of access, browser information, and approximate location/map section data may be processed. MapTiler's privacy policy is available at: https://www.maptiler.com/privacy-policy/
Use is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in displaying an interactive map).
As Switzerland is recognized by the European Commission as a third country with an adequate level of data protection, any transfer of personal data to Switzerland is based on the European Commission's adequacy decision pursuant to Art. 45 GDPR.
In the Android app, the native map service Google Maps is used to display the map. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When using Google Maps, personal data may be processed by Google, in particular IP address, device and operating system information, app information, map section and usage data, and — if you have granted the location permission — location data. Processing by Google takes place in accordance with Google's privacy policy: https://policies.google.com/privacy
The Operator has no full control over the data processing by Google Maps. Use is carried out to provide the map function on the basis of Art. 6(1)(f) GDPR (legitimate interest in displaying an interactive map). Insofar as the current device location is accessed, this only takes place after your prior authorization via the operating system and on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
In the iOS app, the native map service Apple Maps is used to display the map. The provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland; the parent company is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
When using Apple Maps, personal data may be processed by Apple, in particular IP address, device and operating system information, app information, map section and usage data, and — if you have granted the location permission — location data. Processing by Apple takes place in accordance with Apple's privacy notice: https://www.apple.com/legal/privacy/
The Operator has no full control over the data processing by Apple Maps. Use is carried out to provide the map function on the basis of Art. 6(1)(f) GDPR (legitimate interest in displaying an interactive map). Insofar as the current device location is accessed, this only takes place after your prior authorization via the operating system and on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
If you use the "Sign in with Google" function, the Google JavaScript SDK (Google Identity Services) is loaded. Data is transmitted to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google processes your data in accordance with its own privacy policy: https://policies.google.com/privacy
After successful login, we receive an ID token from Google containing your email address, name, profile picture URL, and a Google user ID.
The use of the Google SDK is based on Art. 6(1)(a) GDPR, provided that you actively select Google login. The processing of login data received from Google for the creation and management of your user account is based on Art. 6(1)(b) GDPR. The SDK is loaded only when you actively use Google login.
If you use the "Sign in with Apple" function, the Apple JavaScript SDK is loaded. Data is transmitted to Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. Apple processes your data in accordance with its own privacy policy: https://www.apple.com/legal/privacy/
After successful login, we receive an ID token from Apple containing your email address (where applicable, an Apple-generated relay address) and an Apple user ID. We receive your name only during the initial login, if you allow this. Please note: If you revoke the connection with Apple, logging in via Apple will no longer be possible.
The use of the Apple SDK is based on Art. 6(1)(a) GDPR, provided that you actively select Apple login. The processing of login data received from Apple for the creation and management of your user account is based on Art. 6(1)(b) GDPR. The SDK is loaded only when you actively use Apple login.
To send transactional emails (see Section 2.6) we use two service providers. Depending on availability, either one or the other provider is used to send a given message. In each case, your email address as well as the content and metadata of the respective message (e.g. sender, recipient, subject and headers) are transmitted to the provider used. Transmission is exclusively encrypted (TLS). Both providers process this data on our behalf on the basis of a data processing agreement (Art. 28 GDPR).
The legal basis for email sending is Art. 6(1)(b) GDPR (performance of the user contract) as well as Art. 6(1)(f) GDPR (legitimate interest in reliable email delivery).
Depending on availability, transactional emails are sent via Microsoft Azure Cloud. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Emails are sent from the "Germany West Central" region (Frankfurt am Main).
According to our configuration, processing generally takes place within the EU. If, in an individual case, a transfer to third countries or access from third countries cannot be excluded, this will only take place on the basis of appropriate safeguards, in particular the EU-US Data Privacy Framework, where applicable, or the EU Standard Contractual Clauses.
Depending on availability, transactional emails are sent via the email infrastructure service Postscale. The provider is DNScale OÜ, Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Estonia (registry code 16776331).
Postscale operates its infrastructure generally within the European Union (including providers in Germany and the EU) and uses subprocessors of its own. The subprocessors used are available at https://postscale.io/subprocessors. Further information on data processing by Postscale can be found in the privacy policy at https://postscale.io/privacy and in the data processing agreement at https://postscale.io/dpa.
If, in an individual case, a transfer to third countries or access from third countries cannot be excluded, this will only take place on the basis of appropriate safeguards, in particular the EU Standard Contractual Clauses.
Machine translation of user contributions (see Section 2.5) is carried out exclusively on our own infrastructure in Germany. No texts or other data are transmitted to external providers.
When downloading, installing, updating, and, where applicable, managing in-app purchases or subscriptions via the Android or iOS app, personal data is processed by the respective app store provider.
For the iOS app, this is Apple Distribution International Ltd. or Apple Inc. For the Android app, this is Google Ireland Limited or Google LLC. The Operator has no influence over these data processing operations. The privacy notices and terms of use of the respective app store provider apply.
For paid features or subscriptions purchased through the app, payment data is generally processed by the respective app store provider. As a rule, the Operator does not receive complete payment data, but only the information necessary to activate and manage the booked service, e.g., the status of a purchase or subscription.
When using MapTiler on the website, personal data may be transferred to Switzerland. Switzerland is recognized by the European Commission as a third country with an adequate level of data protection; the transfer is therefore based on the adequacy decision pursuant to Art. 45 GDPR.
Where personal data is transferred to the USA or other third countries, or where access from third countries cannot be excluded, when using Google Sign-In, Google Maps, Sign in with Apple, Apple Maps, or Microsoft Azure, this is carried out — insofar as the respective provider is appropriately certified — on the basis of the EU-US Data Privacy Framework. Otherwise or additionally, the transfer is carried out on the basis of the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Under the GDPR, you have the following rights:
To exercise your rights, simply send an informal message to the email address provided above.
The provision of the data required for registration and use is necessary for the creation and management of a user account and for the use of the associated functions. Without this data, a user account cannot be created or the service cannot be used in full.
Automated decision-making, including profiling pursuant to Art. 22 GDPR, does not take place.
You have the right to lodge a complaint with a data protection supervisory authority. In particular, the competent authority is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Email: poststelle@lfdi.bwl.de
Website: https://www.baden-wuerttemberg.datenschutz.de/
We use technical and organizational security measures to protect your data against manipulation, loss, destruction, and access by unauthorized persons. In particular, data transmission takes place via a TLS-encrypted connection (HTTPS). Passwords are stored only as cryptographic hashes.
We reserve the right to amend this Privacy Policy as necessary. Registered users will be informed by email of material changes. The current version is always available on this page.
Note: This is a machine translation of the original German Privacy Policy, provided for your convenience. In case of any discrepancies, the German version is legally binding and shall prevail.