This policy explains what SAMTrek UG (haftungsbeschränkt) does with personal data when you use vaaii.com. We are the controller for that data under the General Data Protection Regulation (GDPR).
In short: we hold your account details and whatever you put in a listing. We do not run advertising trackers, we do not sell data, and we do not profile you. Your email address is shared with another member only when one of you deliberately sends the other a message.
Who is responsible
SAMTrek UG (haftungsbeschränkt)
Lerchenstr. 7
85630 Grasbrunn, Germany
Registered at Amtsgericht München, HRB 309076
Represented by Dr. Shahidul Alam
Email: info@sam-trek.com
We have not appointed a data protection officer, as we are not required to.
What we collect
When you create an account
- Your name and email address.
- An encrypted password, or, if you sign in with Google or Facebook, an identifier from that provider instead.
- The date you joined and the date you last signed in.
- A profile description, if you write one.
When you post a listing
- The cities and countries you are travelling between.
- Dates, weight, price and currency.
- The package categories you accept or are sending.
- Any notes you add.
Listings are public. Anyone visiting the site can see them, including search engines. Your first name and last initial appear on a listing. Your full name, email address and exact location are never shown publicly.
When you send a message
The name, email address and message text you enter. Your email address is passed to the recipient so they can reply to you directly.
Automatically
Our hosting provider keeps standard server logs, including IP address, browser type and the pages requested, for security and troubleshooting. We use one short-lived record of your IP address and email address to stop the contact form being abused, which expires after a minute.
What we do not do
- We do not run Google Analytics, Facebook Pixel, or any other analytics or advertising tracker. We have checked, and none are installed.
- We do not sell, rent or trade personal data.
- We do not build advertising profiles, and we make no automated decisions that have legal effects for you.
- We do not use marketing cookies.
Why we are allowed to hold it
| What | Why | Legal basis |
|---|---|---|
| Account details | To give you an account and let you sign in | Performance of a contract, Art. 6(1)(b) |
| Listings | To publish what you asked us to publish | Performance of a contract, Art. 6(1)(b) |
| Messages between members | To pass on a message you chose to send | Performance of a contract, Art. 6(1)(b) |
| Messages to us | To answer your enquiry | Legitimate interest, Art. 6(1)(f) |
| Server logs, anti-abuse | To keep the site secure and working | Legitimate interest, Art. 6(1)(f) |
Who else sees it
We share data only with the providers that make the site work. Each acts as our processor under a data processing agreement.
| Provider | What for | Where |
|---|---|---|
| Our hosting provider | Running the website and database | Stated in our hosting agreement |
| Brevo (Sendinblue GmbH) | Delivering email, including member messages | EU |
| Google Fonts | Serving the typefaces used on the site | See below |
| Google, Meta | Only if you choose to sign in with them | USA, under EU standard contractual clauses |
We also disclose data where the law requires it, for example a valid order from a court or public authority.
A note on fonts
This site currently loads its typefaces from Google’s servers, which means your IP address is transmitted to Google when a page loads. We are aware that German courts have held this requires consent, and we are moving to serving the fonts from our own servers so that no request to Google is made at all.
Cookies
We set no cookies at all if you simply browse the site while signed out. Once you sign in, WordPress sets session cookies that keep you logged in and protect forms against cross-site attacks. These are strictly necessary and cannot be switched off without breaking the login.
How long we keep it
- Account data: until you delete your account, then removed within 30 days.
- Listings: until you delete them, or until they have been expired for 12 months.
- Messages to us: up to 2 years, so we can follow up on a dispute.
- Server logs: as set by our host, typically a few weeks.
- Anti-abuse records: one minute.
Where German commercial or tax law requires longer retention, we keep only what those rules require and restrict its use to that purpose.
Your rights
Under the GDPR you can ask us to:
- Access the data we hold about you, and receive a copy (Art. 15).
- Correct anything inaccurate (Art. 16). Most of this you can do yourself from your account.
- Delete your data (Art. 17).
- Restrict how we use it (Art. 18).
- Receive it in a portable format (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time, where we relied on consent.
Write to info@sam-trek.com and we will respond within one month. There is no charge.
You also have the right to complain to a supervisory authority. In Germany this is the data protection authority for the state where we are established, or the authority where you live.
Keeping it safe
The site is served over HTTPS. Passwords are stored hashed, never in plain text. Access to the database is limited to people who need it. No system is perfectly secure, and we cannot guarantee absolute security, but we will tell you and the regulator without undue delay if a breach puts your rights at risk.
Children
Vaaii is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Changes
If we change this policy we will update the date at the top, and tell you by email where the change is significant.
Contact
Questions about your data go to info@sam-trek.com, or use our contact page.