Legal information
Privacy.
How we process personal data when you visit Crashline or contact us. Updated: 20 September 2026.
01 / Privacy
Data controller
The controller for personal data processed on crashline.org is Maximilian Mann, Am Waldrand 3, 29499 Zernien, Niedersachsen, Germany. For privacy enquiries, contact [email protected].
02 / Privacy
Website and hosting
Visiting this website involves processing technical connection data, including IP address, request time and URL, browser information, the referring page where provided, and status and error information. This allows us to deliver content, maintain availability and investigate faults and abuse. The basis is Article 6(1)(f) GDPR: our legitimate interest in a secure, functioning website.
The website and our self-hosted Payload CMS run on Railway Corporation, USA. Amsterdam was selected as the server region. Some images load directly from the CMS on a Railway address, which receives the connection data needed to deliver them. An EU server location does not mean all processing by the provider takes place exclusively within the EU.
03 / Privacy
Cloudflare: delivery and security
Cloudflare, Inc., USA, handles traffic to crashline.org for DNS, encrypted connections, caching and protection against attacks. It processes connection, request and security data, including IP addresses. The basis is Article 6(1)(f) GDPR: our legitimate interest in protecting the website and keeping it available.
Cloudflare operates a global network. Security checks may use necessary cookies, such as cf_clearance to record a completed check. Where access to a device is strictly necessary, it relies on section 25(2)(2) of the German TDDDG. Processing personal data additionally remains subject to the GDPR.
04 / Privacy
Cloudflare Web Analytics
We use Cloudflare Web Analytics to understand page views, visits and website performance. Only after your consent do we load JavaScript from Cloudflare to collect usage and performance metrics, such as pages viewed and loading measurements. We use these insights to understand which content is used and where the website can be improved.
According to Cloudflare, Web Analytics uses neither cookies nor localStorage for this purpose and does not fingerprint individuals for analytics. This is separate from processing required to establish connections and by other Cloudflare services.
Optional analytics relies on your consent (Article 6(1)(a) GDPR and, where applicable, section 25(1) TDDDG). You may withdraw it at any time for the future using Privacy settings in the footer. Withdrawal does not affect the lawfulness of earlier processing. The website works without consent.
We store your choice and its expiry for 180 days in your browser’s localStorage under crashline.analytics.v1. This entry contains no individual visitor identifier and is used only to respect your decision (section 25(2)(2) TDDDG). You can also remove it by clearing website data.
05 / Privacy
Website features
The public website currently has no visitor registration, comments or embedded payment form. The intro does not require persistent storage of a visitor identifier. The copy button writes the displayed email address to the clipboard only when pressed; it does not read existing clipboard contents.
The separate Payload administration area is intended for authorised operators. Login credentials, authentication and security data, and session cookies are processed to manage content and prevent unauthorised access. The basis is Article 6(1)(f) GDPR and, for necessary session cookies, section 25(2)(2) TDDDG. Ordinary visitors do not need to log in.
06 / Privacy
Email contact
When you write to [email protected], we process your sender address, name where provided, message, attachments and related communication data to respond to your enquiry. Email is provided through Apple iCloud Mail; Apple Distribution International Limited in Ireland is responsible for EEA users.
The basis is Article 6(1)(f) GDPR for general enquiries, or Article 6(1)(b) GDPR for an enquiry concerning a contract with you. Contacting us is voluntary; without the necessary information we may be unable to answer.
07 / Privacy
Support and external links
Ko-fi and PayPal are external links. Displaying our Support page does not load their payment forms. Opening a link takes you to that service, where its privacy notice applies. Ko-fi may process payments through PayPal or Stripe.
If you financially support Crashline, the service may provide us with payment information such as your name or display name, amount, date, transaction identifier and accompanying message. We use this to administer support and, where required, meet statutory record-keeping duties (Article 6(1)(f) or (c) GDPR). This website does not collect full payment card numbers. Supporter names and messages are not automatically published on the website.
08 / Privacy
Retention and recipients
We delete ordinary contact enquiries after resolution as soon as they are no longer needed. Where follow-up questions are expected, we retain them for that purpose for no more than three months after resolution. We delete spam and clearly unnecessary messages promptly. Payment records, agreements and documents concerning specific disputes are handled separately and retained only as required by statutory duties or specific evidential needs. Payment records subject to mandatory retention are kept for the applicable commercial and tax-law periods.
For application logs accessible in Railway, the provider specifies seven days during the trial and then three days on the Free plan. Cloudflare Web Analytics makes reports available for the preceding six months. These access periods do not constitute a blanket promise that all internal security, connection or backup data is deleted at the same time; the providers apply purpose-dependent retention periods to those data. Records of a specific security incident may be needed for longer to investigate or establish legal claims. Access is limited to the operator and relevant service providers; disclosure to authorities requires an appropriate legal basis.
09 / Privacy
Processing outside the EU
The international services of Railway, Cloudflare and Apple may involve processing outside the European Economic Area, including in the USA. Their privacy and contractual documents describe the safeguards used, which may include adequacy decisions and EU standard contractual clauses depending on the recipient and processing. You can request information and copies of applicable safeguards via [email protected].
10 / Privacy
Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction of processing and data portability. Where processing relies on consent, you can withdraw it at any time with future effect.
You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. Contact [email protected] to exercise your rights. We do not carry out automated decision-making producing legal or similarly significant effects.
You may lodge a complaint with a supervisory authority, particularly where you live, work or believe an infringement occurred. The State Commissioner for Data Protection of Lower Saxony is a point of contact for complaints concerning this operator.