Privacy Policy
Last updated: 19 September 2026
1. Introduction
Thank you for your interest in Moin.Zone. Moin.Zone is a link-in-bio service: you can create a public profile (“Zone”) and collect links, text and media in one place. This notice explains which personal data we process, for which purposes and on which legal basis.
It applies to the Moin.Zone website, dashboard, API and mobile app.
2. Controller
Where we determine the purposes and means of processing, the controller is:
auronet GmbH represented by the managing director Michael Mücke Labbéstr. 18 41169 Mönchengladbach Germany
Phone: +49 (2161) 29 89 221 Email: [email protected]
Further details are in the imprint.
We have not appointed a data protection officer. Privacy requests can be sent to the address above.
3. Our roles
Account, login, billing, moderation and notice procedures. For these we are the controller under the GDPR.
Visitor data on a published profile. If you use Moin.Zone for business, you are usually the controller towards visitors of your profile. We then process access data, security data and — where applicable — form submissions on your behalf (Art. 28 GDPR). You can conclude the data processing agreement in the dashboard.
Third-party embeds on your profile (for example maps or booking tools after a click) remain your responsibility. Section 6.13 explains how those embeds work technically.
4. Hosting and infrastructure
Cloudflare
Public pages and the dashboard are delivered through Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (Pages, Workers, CDN, DNS, bot protection). Cloudflare processes technical data (in particular IP address, browser and request information) to deliver the site and to defend against attacks.
Microsoft Azure
The backend, databases and file storage run on Microsoft Azure (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA). Server locations are in the European Union (West Europe region).
Microsoft and Cloudflare are certified under the EU-US Data Privacy Framework (DPF). We also rely on the European Commission’s Standard Contractual Clauses (SCCs) and have data processing agreements in place. Azure meets recognised security standards (ISO 27001, SOC 1/2/3).
Legal basis for hosting and security: Art. 6 (1) (f) GDPR (legitimate interest in a secure, available service) and, where the infrastructure performs the contract, Art. 6 (1) (b) GDPR.
5. Recipients and international transfers
We only share data where that is necessary for the purpose:
| Recipient | Purpose | Location / transfer |
|---|---|---|
| Cloudflare Inc. | Delivery (including custom domains), CDN, bot protection (Turnstile) | USA (DPF and SCCs) |
| Microsoft Corporation (Azure) | Hosting, databases, storage, error logs | Processing in the EU; group in the USA (DPF and SCCs) |
| Brevo (Sendinblue) | Transactional email (login codes, forms, moderation notices) | EU |
| Stripe Payments Europe, Ltd. (Dublin, Ireland) | Payments and subscriptions | EU; parent company Stripe, Inc. (USA, DPF / SCCs); card data stays with Stripe |
| Google, Apple, Microsoft, X, Meta | only if you sign in with that service or connect it | each USA (DPF / SCCs where applicable) |
Other services (for example Instagram, maps, booking tools) run only if you enable them on your profile or a visitor loads them after a click. Only with that click does the provider receive the visitor's IP address and browser data (section 6.13).
A transfer to the USA may mean that US authorities can request access under US law. We limit sharing to what is necessary and choose providers with DPF certification and/or SCCs.
6. What we process
6.1 Visiting the website (logs)
Browsers and networks automatically send technical data. Cloudflare and Azure keep server logs, in particular:
- browser type and version, operating system
- referrer URL, requested path
- time of the request
- IP address
Purpose: delivery, stability, abuse and attack detection. Legal basis: Art. 6 (1) (f) GDPR. We do not combine this with the account for advertising.
6.2 Account and profile
Registration requires at least an email address and a profile name (handle). We may also store display name, bio, avatar, zone domain, imprint, privacy policy, DPA signature, moderation status and the content you create (links, text, files, vCards, embedded media).
Legal basis: Art. 6 (1) (b) GDPR (user agreement) and, for statutory details such as an imprint, Art. 6 (1) (c) GDPR.
6.3 Sign-in
You can sign in with an email one-time code (OTP) or a magic link. We store the code briefly (a few minutes) and then delete it. You may also sign in with Google, Apple, Microsoft, X or Meta. Those providers send us the account data needed to log you in (typically email, name, provider ID).
After login, a JWT session token is stored on the device (dashboard: localStorage, mobile app: secure device storage). For some SSO providers we set short-lived, strictly necessary cookies (sso_pkce_*, sso_state_*, 10 minutes, HttpOnly, Secure, SameSite=Lax).
Legal basis: Art. 6 (1) (b) GDPR; for optional SSO connections Art. 6 (1) (a) GDPR (consent by using the button).
6.4 Instagram and Facebook connection
If you connect an Instagram or Facebook feed, we store access and refresh tokens, their expiry, the profile ID and the profile name for as long as the connection lasts. We remove them when you disconnect the feed or delete your account. Legal basis: Art. 6 (1) (b) and (a) GDPR.
We fetch the feed server-side and bake it into the published page; images are served through our image proxy (section 6.13). Your visitors' browsers never contact Instagram or Facebook for this.
6.5 Bot protection (Cloudflare Turnstile)
Sign-in, registration, requests for login codes and confirmation links, notices and appeals, the cancellation form, and the contact form on published profiles are protected by Turnstile.
On a published profile, Turnstile loads only once you click or type into the form. Simply viewing a profile triggers no request to Cloudflare. Turnstile checks whether a human submitted the request. It does not set tracking cookies for advertising. Legal basis: Art. 6 (1) (f) GDPR. No consent banner is required for this (§ 25 (2) TDDDG).
6.6 Email
We send transactional mail (login codes, confirmations, moderation and form messages) through Brevo. Legal basis: Art. 6 (1) (b) or (f) GDPR. We do not send a marketing newsletter.
6.7 Payments
Paid features (“PRO”) are billed by Stripe. We store customer and subscription IDs, plan and trial period. Card data is held by Stripe, not by us. Legal basis: Art. 6 (1) (b) GDPR and, for statutory records, Art. 6 (1) (c) GDPR.
6.8 Contact form on profiles
A contact form on a published profile collects name, email, optional phone and country, and the message, then forwards it by email to the profile owner. The email footer contains the sender’s IP address so abuse can be traced; it is therefore passed on to the profile owner.
We do not keep these submissions as our own inbox. The profile owner is usually the controller towards the sender. Legal basis for our technical forwarding: Art. 6 (1) (b) or (f) GDPR; in a processor relationship Art. 28 GDPR.
6.9 Notices and appeals (DSA)
Via /report, /appeal or [email protected] you can report illegal content or appeal a decision. We process the contact details you provide, the facts of the case and the handling status. We also store, for each notice, a hash of the reporting person's IP address computed with a secret salt, so we can detect abuse of the notice procedure; we do not store the IP address itself. Legal basis: Art. 6 (1) (c) GDPR (duties under the DSA/DDG) and Art. 6 (1) (f) GDPR.
6.10 Profile views (statistics for PRO)
When someone opens a published profile, we count the view on the server (Cloudflare Worker to our backend). The profile itself does not run an analytics script and we do not set a tracking cookie for this.
We store: time, path, approximate country and city (from request headers), browser, operating system, device type and language. The IP address is stored neither in the clear nor as a hash; it is only processed to answer the request and then discarded. The referrer does not enter the statistics either. Obvious bots and secondary pages (imprint, privacy policy, avatar) are not counted.
The last 30 days of this data are a PRO feature in the dashboard. Legal basis: Art. 6 (1) (b) GDPR (contract with the account holder) and Art. 6 (1) (f) GDPR (a secure, low-abuse measurement). Towards profile visitors we act as a processor where the account holder is the controller.
We do not use Google Analytics, the Facebook Pixel or comparable advertising trackers.
6.11 Error logs
In production, Azure Application Insights records technical errors. Telemetry that is not an error report is dropped, and the standard IP address field is set to 0.0.0.0.
We attach the request headers to an error report so the error stays traceable. Credentials (authorization, cookies, keys) and the IP address are redacted there; the browser identifier (user agent) can be included. Form content, such as the text of a message, is not written to the error logs. Only a small number of authorised people can access these logs. Retention: 30 days. Legal basis: Art. 6 (1) (f) GDPR.
6.12 Mobile app
The app is built with Expo (React Native) and uses the same API as the dashboard. The session token is stored in the device's secure storage (iOS Keychain or Android Keystore), not in localStorage.
For avatar and file uploads the app asks for access to photos or the camera. A selected image leaves the device only when you start the upload. We use no third-party analytics, advertising or crash-reporting SDKs in the app, and we do not send push notifications.
Distribution runs through the App Store (Apple) and Google Play. When you obtain the app, those stores process data as controllers in their own right, which is outside our influence.
6.13 Third-party embeds (click to load)
A published profile loads nothing from third parties when it opens. Embeds such as YouTube, Spotify and Apple Music, Google Maps, Podigee, Calendly, Microsoft Bookings, TikTok, Threads or X sit behind a click-to-load gate: until a visitor taps it, the page shows only a placeholder and no request reaches the provider.
Only on that click does the browser load the provider's content. The provider then learns the IP address, browser and device data, and can set its own cookies. The legal basis is the visitor's consent given by the click (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). The profile owner is the controller for that embed.
Images from connected services (for example Instagram thumbnails) are served through our own image proxy. The visitor's browser loads them from us rather than from the provider's CDN, so that server sees neither the visitor's IP address nor their user agent. Live applet data (tour dates, ratings, feeds) is fetched server-side when the page is published and stored in the finished page.
6.14 Protected and age-gated links
A link can be password-protected. The entry is sent to our API and compared with the stored value; we do not store the entry and we do not evaluate failed attempts in a personally identifiable way. Legal basis: Art. 6 (1) (f) GDPR (protecting the content behind the link).
A link can also carry an age prompt. That prompt relies on self-declaration and is not an age verification system within the meaning of § 4 (2) JMStV (section 13). The answer is neither transmitted to us nor stored.
6.15 Email capture on profiles
A profile can include a block that lets visitors leave their email address so the profile owner can contact them. If the account holder uses that block, we store the email address entered, the time and the reference to the link, and make it available in the dashboard.
The account holder is the controller towards the person who signs up; we process on their behalf (Art. 28 GDPR). Obtaining valid consent, documenting it and honouring a withdrawal are the account holder's responsibility. We neither message these addresses ourselves nor use them for any purpose of our own.
6.16 Cancellation form (cancellation button)
The cancellation button lets you terminate a paid contract without signing in. We process the type of termination (ordinary or extraordinary), the contract identifier you give (handle, account email or customer id), the email address for the confirmation, optionally your name and a note (such as a preferred date), the time of receipt and an automatically assigned reference number.
The declaration is stored before any email goes out: a termination takes effect when it arrives, so it must not fail because a mail provider is down. We then try to match it to an account and stop an active subscription at the end of the period already paid for. You receive a confirmation in text form. If the address you gave differs from the one on the account, we also notify the account address, so that a termination filed by someone else does not go unnoticed. A copy goes to [email protected]. The form is protected by Turnstile (section 6.5). This form deletes no profile data, files or accounts; that is section 9.
Legal basis: Art. 6 (1) (c) GDPR (§ 312k German Civil Code requires us to accept the declaration and to confirm its content and the time of receipt and of the contract ending, in text form) and Art. 6 (1) (b) GDPR (performance of the contract).
7. Cookies and local storage
We use no tracking cookies and no marketing pixel.
Strictly necessary storage (§ 25 (2) TDDDG) includes:
- short-lived SSO cookies during sign-in with an external provider (section 6.3)
- cookies Cloudflare or Turnstile may set for security
- the session token after login (
tokeninlocalStorageor in the app’s secure store) - preferences such as language, colour scheme and dismissing notices (also stored locally on the device)
- the case number of a notice you submitted, so the page can show you its status on your next visit
This storage is required for the service or for a step you explicitly requested. A tracking cookie banner is therefore not required.
8. Retention
We keep data only as long as needed for the purpose, legal duties or the establishment of claims.
| Data | Period |
|---|---|
| Account and profile content | until the account is deleted, plus short backups and restore points (database 7 days; files: soft-delete and previous versions 14 days) |
| Login codes (OTP) | a few minutes |
| Email confirmation links | 24 hours |
| SSO cookies | 10 minutes |
| Profile-view statistics | 90 days from the view; the dashboard reports on the last 30 days of those |
| Email capture on a profile | until the account holder deletes the entry or the account |
| Invitation codes (alpha phase) | code, time of redemption and the handle that redeemed it; the link to the handle is removed when the account is deleted |
| Error logs | 30 days |
| Notices and the moderation log (including the reporting person's IP hash) | until the case is closed, then 3 years for the record-keeping and reporting duties under the DSA; for permanently reserved handles (accounts closed for repeat infringement), for as long as the reservation stands |
| Terminations filed through the cancellation button | 3 years from the end of the year in which the termination took effect (evidence under § 312k (4) German Civil Code and limitation periods); billing-related details fall under the next row |
| Payment and invoice data | statutory retention (usually 10 years) |
| Handle reserved after account deletion | 90 days, so old links cannot be taken over by someone else; the reservation record itself (handle, time, reason) is kept as an audit entry |
9. Account deletion
You can delete your account yourself in the dashboard under Settings. That takes the published profile offline, removes stored profile data, related files, view statistics, scheduled posts and any addresses collected through an email-capture block, and ends an active subscription. The handle stays reserved for 90 days.
Where statutory retention or evidence duties apply (for example payment records or moderation cases), those data remain for that period.
10. Your rights
You have the right to
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR),
- withdraw consent with effect for the future (Art. 7 (3) GDPR).
Many details you can change in the dashboard yourself. For access, export or deletion beyond self-service, write to [email protected] or the address in the imprint.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestraße 2–4 40213 Düsseldorf Germany https://www.ldi.nrw.de
11. Required information
We cannot run an account without an email address and a handle. We cannot deliver the website without the technical data in section 6.1. Without a contract identifier and an email address we can neither match nor confirm a termination filed through the cancellation button. Other details are optional but may be required for individual features (imprint, payments, integrations).
12. No automated decision-making
We do not take decisions that produce legal or similarly significant effects based solely on automated processing (Art. 22 GDPR). Moderation decisions are taken by humans.
13. Children
Moin.Zone is not directed at children. You must be at least 16 years old to create an account; paid features require full legal capacity to contract (clause 3 of the Terms).
We do not operate an age verification system within the meaning of § 4 (2) JMStV. Individual links can carry an age prompt that relies on self-declaration (section 6.14). Pornographic and youth-endangering content is prohibited by the terms.
14. Changes
We will update this notice if the service or the law changes. The version published here, with the date above, is the one that applies.