Privacy Policy

Privacy Policy


1. Controller Information

The data controller responsible for processing personal data on this website under the General Data Protection Regulation (GDPR) is:
ILOVETERMIN, Loherstraße 116 58256 Ennepetal, Email: admin@ilovetermin.de


2. Data Collection and Processing

We process personal data based on high-level enterprise security standards:

  • Geo-Coding & Search: We map 5-digit PLZ codes to regions (Ort/Bundesland) to provide highly accurate, location-based search results.
  • Authentication: We store cryptographic TOTP secrets to mathematically verify 6-digit MFA tokens.
  • Billing Data: We process Stripe IDs and PayPal tokens. We do not store raw credit card numbers on our servers.


3. Third-Party Integrations

  • Google Calendar (OAuth 2.0): If a Business Owner or Staff member voluntarily enables Google Calendar Synchronization, we request strict offline read/write access. We dynamically pull "busy" slots to prevent double-booking and push new appointments directly to Google. We do NOT share, sell, or parse this calendar data for any other purpose.
  • Payment Gateways: Financial processing is handled via Stripe and PayPal under strict PCI compliance.


4. Cookies and Local Storage

  • Session Management: We use secure cookies to manage stateful session locks during registration and checkout.
  • MFA Bypass: A cryptographic `trusted_device_token` is stored locally for 30 days if you select "Remember this device."
  • Embedded Widgets: Our iframe booking widgets do not track cross-site behavior but utilize essential storage for cart and date/time selection.


5. GoBD Data Retention (Important)

Under strict German tax law (GoBD), we are legally required to retain immutable financial records (including PDF invoices, payment logs, and associated identifiers) for up to 10 years
For this reason, deleting your profile triggers a "Soft Delete" in our database. Your profile instantly vanishes from the public web, but financial ledgers remain securely archived to satisfy tax audits.



6. Your GDPR Rights

You have the right to request access, rectification, restricted processing, and (where legally permissible overriding GoBD) erasure of your data.