Skip to main content

Privacy policy

Which personal data Reunitems processes, why, and for how long.

Who is responsible

Reunitems is operated by Joachim Vanthomme, Grünecker Straße 4, 80805 München, Germany, [email protected]. For staff accounts, venue applications and running the platform, the operator is the controller.

For lost and found reports, the venue where you lost your item is the controller. Reunitems processes these reports on the venue's behalf under a data processing agreement (Art. 28 GDPR). You can contact the venue directly, for example by replying to our emails.

Reporting a lost item

When you report a lost item we store what you enter: category, description, the date and approximate time, an optional photo, your name, your email address and the time you gave consent. We don't ask for your address, phone number or location.

We use this only to match your report with items the venue finds and to email you about it. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by contacting the venue; your report is then deleted.

Your report gets a reference number and a private link. Anyone with the link can view the report, so don't share it. Items found by the venue are never shown to guests.

Reporting a found item

If you report an item you found, we store what you enter: category, description, the date, approximate time and place where you found it, an optional photo, whether you hand it in or keep it, your name, your email address and the time you gave consent. The venue uses this only to return the item to its owner and to email you about it; Reunitems doesn't pass your contact details on to the owner. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by contacting the venue.

Photos

Photos are resized in your browser and stored without metadata, such as the place where a photo was taken. They are kept in private storage that only the venue's staff can access.

Venue staff

Venue staff have accounts with an email address and a password (stored only as a secure hash). If two-factor authentication is turned on, a secret for the authenticator app is stored as well.

Staff notes, match decisions and security-relevant actions record which account made them. Legal basis: the contract with the venue and our legitimate interest in running the service securely (Art. 6(1)(b) and (f) GDPR).

Venue applications

If you ask to use Reunitems for your venue, we store the venue's name, city and website and your name, role, email address and message, to verify the venue and contact you (Art. 6(1)(b) GDPR).

Security and spam protection

To protect the forms against spam and abuse, your IP address is processed briefly in the server's memory to limit the number of submissions. It is not stored in the database and is forgotten after at most one hour.

All data is transmitted encrypted (HTTPS). Database rules make sure only the venue's own staff can access its reports.

Emails

We only send emails about your report or your account: a confirmation with your private link, and a message when the venue may have found your item. Emails are sent through Mailjet (part of Sinch AB, Sweden), with servers in the EU.

Service providers

We use these service providers, each under a data processing agreement (Art. 28 GDPR): Supabase (database, file storage and sign-in) and DigitalOcean (hosting), both with servers in Frankfurt, Germany, and Mailjet (sending emails; part of Sinch AB, Sweden), with servers in the EU.

Supabase Inc. and DigitalOcean, LLC are based in the USA. Your data is stored on their servers in Frankfurt, but access from the USA (for example for support or maintenance) cannot be ruled out. Both companies are certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR).

We don't sell data, don't show advertising and don't use analytics or tracking tools.

How long data is kept

Reports are deleted automatically 180 days after they are closed (each venue can choose between 30 and 365 days). Reports nobody has worked on for 180 days are closed automatically. Photos and staff notes are deleted together with their report.

Rejected venue applications are deleted after 30 days, approved ones after 90 days. The security log is kept for 730 days. Staff accounts are deleted when they are removed from their last venue.

Cookies

Guests only get one cookie that remembers the language they chose. Staff also get technically necessary cookies to stay signed in and to remember the selected venue. We don't use tracking, so no consent banner is needed.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and you can withdraw your consent at any time. For your lost item report, contact the venue (for example by replying to our email) or us at [email protected].

You also have the right to lodge a complaint with a data protection supervisory authority, for example the authority of the German state where you live.