Kleiner Landwirt

Courtesy translation. This English version is provided for information purposes only. Only the German version is legally binding. In case of any discrepancy, the German version prevails.

Version: August 2026

Privacy Policy

Your privacy matters to us. Here is how we handle your data.

1. Controller

The controller responsible for data processing on this website is:

Kleiner Landwirt UG (haftungsbeschränkt)
Schohasberger Weg 8
27751 Delmenhorst
Germany

Email: info@kleinerlandwirt.de
Phone: +49 176 80762726

2. What data we collect

When you visit the website

When you access our website, your browser transmits technically necessary information to our hosting providers (see Section 4). This includes IP address, date and time of access, page accessed, referrer URL, browser and operating system. Depending on the service, technical details such as response status, requested API function and country code may also be logged. We do not combine these logs into usage profiles. Technical retention depends on the infrastructure plan: Vercel currently retains different log types for a few hours up to a maximum of 30 days; Supabase project-log retention is plan-dependent. We do not create a permanent separate copy. The legal basis is our legitimate interest in secure, stable operation (Art. 6 (1) (f) GDPR).

When you register

When you register on our platform, we collect name, email address, password (stored only as a non-reversible hash), address and optionally your phone number; for farm operator, association, sponsor and institution accounts additionally the company or institution details. To evidence your consent, we store the time and version of the confirmed Terms/Privacy Policy (Art. 7 (1) GDPR). The legal basis is contract performance (Art. 6 (1) (b) GDPR).

For farm-operator business accounts, we also record the mandate to create customer invoices as an instructed third party in the farm's name and for its account and, if separately agreed, the self-billing procedure for sponsorship payouts. The proof contains the organisation UUID and the acting profile UUID as pseudonymous identifiers, the server-defined wording, version and hash, language, and the server time of each acceptance or withdrawal event. The legal bases are performance of the platform contract and our legitimate interest in reliable contractual and accounting evidence (Art. 6 (1) (b) and (f) GDPR).

For administrative changes

If support or a platform administrator corrects a record, we log the acting account UUID, the type and time of the change, the target type and UUID, the reason, and the affected before-and-after fields. We do not store an additional plain-text email address of the acting account in this audit record. This logging supports secure and accountable platform administration and, for payment and accounting corrections, compliance with evidence and retention duties (Art. 6 (1) (c) and (f) GDPR).

For bookings and requests

For bookings we process booking details (date, offer, number of participants, where applicable the birthday child’s name and age), payment information (see Section 5) and the communication between you and the farm operator. The respective farm receives the data it needs to carry out the visit. The legal basis is contract performance (Art. 6 (1) (b) GDPR).

For applications (internships & jobs)

If you apply for an internship or a position via the platform, we process your application details and – if uploaded – your CV and forward them to the advertising farm. Uploads not linked to an application are deleted automatically. We delete application data and related documents no later than six months after acceptance, rejection or withdrawal; the upload cleanup then removes the CV once it is no longer linked. The legal basis is the initiation of a contractual or employment relationship (Art. 6 (1) (b) GDPR, Section 26 BDSG).

For contact and complaint requests

For requests via our forms, we process your details to handle the matter; for complaints additionally uploaded evidence (e.g. photos). The legal bases are contract performance and our legitimate interest in responding (Art. 6 (1) (b) and (f) GDPR).

3. Purposes of processing

Your personal data is processed for the following purposes:

  • Providing and improving our platform
  • Managing your user account
  • Processing bookings and payments
  • Communication between users and farm operators
  • Sending booking confirmations, invoices and important information
  • Preventing misuse and ensuring security

4. Hosting & infrastructure

Our website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA); database, authentication and file storage run on Supabase, Inc. The primary Supabase project is operated in the Stockholm EU region; individual edge and infrastructure services may be provided globally. Both providers process data on our behalf under the applicable data processing agreement. Third-country transfers are based in particular on the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.

The legal basis is our legitimate interest in secure and efficient provision (Art. 6 (1) (f) GDPR) and contract performance (Art. 6 (1) (b) GDPR).

Externally embedded images

Individual editorial articles or example displays may load images from external image URLs, currently in particular from Unsplash, Inc. When an image is fetched, the provider technically receives in particular the IP address, browser/device information, referrer and time of access. The legal basis is our legitimate interest in presenting our offering clearly (Art. 6 (1) (f) GDPR). Our own images and images uploaded by farms are served from our Supabase storage.

5. Payment processing (Stripe)

We process online payments via Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin, Ireland). Stripe receives in particular name, email address, payment instrument, amount, booking/order details, internal transaction identifiers and technical fraud-prevention data. Your full card details never reach our servers. In Stripe Connect onboarding, farm operators additionally provide business, representative, bank and identity evidence directly to Stripe. Stripe acts partly as our processor for payment handling and as an independent controller for its own legal tasks, particularly fraud prevention, KYC/AML, payment-network and retention duties. Transfers to Stripe, LLC and other Stripe entities in the USA are based in particular on the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.

The legal basis is contract performance (Art. 6 (1) (b) GDPR); Stripe’s own statutory checks are additionally based on Stripe’s applicable legal duties. Details: stripe.com/privacy

6. Email delivery & receipts

For sending all emails (booking confirmations, invoices, notifications, newsletter) we use Plus Five Five, Inc. (Resend) in the USA as a processor. Resend receives recipient address, subject, email content and technical delivery information. Email content and delivery data are generally retained for up to 30 days under the configuration applicable to our account. The transfer is based on the data processing agreement with EU Standard Contractual Clauses or the EU–US Data Privacy Framework.

Invoices and receipts are generated as PDFs via PDFShift (S.A.S.U. PDFShift, France); the data contained on the receipt (name, billing address, line items) is transmitted there for conversion and not permanently stored there. The legal basis is contract performance (Art. 6 (1) (b) GDPR).

7. Maps & address search

Google Maps (only after click)

Maps on farm pages and in the farm search only load after you have expressly agreed via “Load map”. Only then is data (including your IP address, browser/device information, referrer, API/project identifier, requested Maps function and response status) transmitted to Google Ireland Ltd. or Google LLC (USA). Google may set or read its own cookies or comparable device identifiers. The legal basis is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG); you can revoke it at any time in the cookie settings. Revocation prevents future loading; entries already set by Google can be deleted in your browser settings. Google’s Privacy Policy and the Google Maps Terms also apply.

Address and radius search

Address suggestions and postcode search run via our own server proxy: your browser only sends the search query to us; our server then queries the geo-services Nominatim (OpenStreetMap Foundation, UK) and Photon (Komoot GmbH, Germany). Your IP address does not reach these services. The legal basis is our legitimate interest in a working search (Art. 6 (1) (f) GDPR).

We only request your device location upon your active request (“Use my location”) via the browser; it is used solely for distance sorting and is not stored.

8. Newsletter

If you subscribe to our newsletter, we process your email address, the times of subscription, confirmation and, where applicable, unsubscription, as well as the subscription source (e.g. blog or newsletter page). The newsletter is usually published once a month.

You may voluntarily provide your postal code when subscribing. We derive your federal state from it in order to send you regional content (e.g. day-trip ideas and events near you). Without it you simply receive the newsletter without a regional focus – there is no disadvantage. If you are registered with a user account, we may instead derive the federal state from your account data (the postal code of your profile). The legal basis is again your consent (Art. 6 (1) (a) GDPR).

Subscription uses the double opt-in procedure: you first receive a confirmation email, and only after you click the confirmation link do we send you the newsletter. The legal basis for processing is your consent (Art. 6 (1) (a) GDPR); logging the (un)subscription process serves as evidence of consent (Art. 6 (1) (f) in conjunction with Art. 7 (1) GDPR).

You can revoke your consent at any time with immediate effect – via the unsubscribe link at the end of every newsletter email or by emailing info@kleinerlandwirt.de. The lawfulness of processing carried out before revocation remains unaffected. Upon unsubscription we delete the operational subscriber row, including postcode/ regional data, tokens and personal delivery copies. For three years, only a SHA-256 value of the normalised email address together with withdrawal and deletion time is retained as evidence; this proof is then deleted automatically. Unconfirmed subscriptions are deleted after 30 days at the latest.

9. Cookies & web analytics

We ourselves only use technically necessary or functional cookies and storage entries (e.g. login session, favourites, saved settings), and no advertising cookies. Only after your express Google Maps consent may Google set or read its own browser entries (see Section 7). A complete overview can be found in the cookie settings.

Web analytics with Plausible (no cookies)

For reach measurement we use Plausible Analytics, a privacy-friendly web analytics service by Plausible Insights OÜ (Västriku tn 2, 50403 Tartu, Estonia). Plausible uses no cookies and stores no personal data: IP address and browser identifier are only processed transiently to detect returning visits within one day and are not stored; no cross-device profile is created. All data is processed exclusively on servers in the EU.

The legal basis is our legitimate interest in statistical analysis and improvement of our offering (Art. 6 (1) (f) GDPR). We collect page views, referrer source, country, device type and browser as well as anonymous events such as registration (with role), booking (with booking type, guest status and source), application, newsletter signup and contact request. We do not send names, email addresses, booking/user IDs or tokens to Plausible. You can object to the counting at any time in the cookie settings.

QR code and short link statistics

If you open the platform via a farm flyer’s QR code or short link, we count this visit for the farm (which material, QR or link, time) – without IP address, device or browser data. If you complete a booking or application in the same visit, it is attributed to the material so the farm can measure the success of its flyers. The legal basis is our – and the farm’s – legitimate interest in simple success measurement (Art. 6 (1) (f) GDPR).

10. Reviews

If you review a farm after your visit, your review is displayed publicly on the farm page – with a shortened name (e.g. “Anna M.”) and, if provided, your town. We point this out before you submit. You can request deletion of your review at any time via our contact form or by emailing info@kleinerlandwirt.de. Your reviews are also deleted when your account is deleted. The legal basis is use of the review feature within the user agreement (Art. 6 (1) (b) GDPR).

If you report a review for examination, we process the reason for the report, your message, the handling status and decision, timestamps and – while the case remains open – your user ID and any contact details you provide voluntarily. The legal basis is our legitimate interest in a safe platform, accountable moderation and handling possible infringements (Art. 6 (1) (f) GDPR). Once the report is closed, we remove the user ID and contact details; the remaining moderation record is deleted no later than three years afterwards.

11. Disclosure of data

We only pass on your personal data to:

  • Farm operators whose offers you book or request (to the extent required for performance)
  • Processors pursuant to Sections 4–9 (in particular Vercel, Supabase, Resend, PDFShift and Plausible; Stripe where Stripe acts as our processor)
  • Independent controllers where required for the relevant function (in particular Stripe for regulatory payment/KYC purposes, Google after consent and external image providers when an image is fetched)
  • Authorities, where a legal obligation exists
  • other recipients only with your express consent or to enforce our rights

12. Retention & account deletion

We only store personal data for as long as necessary for the respective purpose:

  • Account data: until you delete your account
  • Completed booking data and tax or commercial accounting records and invoices: generally eight years from the end of the calendar year in which the booking was financially completed or the record was issued or received (Section 14b UStG, Section 147 AO and Section 257 HGB); books, annual accounts and any other records subject to a statutory ten-year period are retained for that longer period where applicable
  • Proof of the invoicing mandate and of any separately agreed sponsorship self-billing procedure: generally until three years after the mandate ends or is withdrawn; where proof is linked to a record or settlement subject to statutory retention, no longer than the retention period applicable to that transaction, normally eight years from the relevant year-end
  • Application data and documents: for the duration of the process and no more than six months after acceptance, rejection or withdrawal; unlinked uploads are then deleted automatically
  • Newsletter data: until revocation; thereafter only the minimised hash proof for 3 years; unconfirmed subscriptions max. 30 days
  • Contact cases: ongoing requests until completion; general and review-deletion requests for no more than 12 months thereafter, DSA notices and withdrawal cases as procedural evidence for no more than 3 years
  • Review reports: until completion with the user ID and any voluntary contact details; those direct identifiers are removed when the report is closed and the remaining moderation record is deleted no later than 3 years afterwards
  • Complaint case files, including the description, witness details, messages, uploaded evidence and case PDF: until completion and for no more than 3 years thereafter; invoices and correction records required under tax or commercial law remain separately retained for the statutory periods
  • Administrative audit records: general correction and support records for no more than 3 years; narrowly scoped payment, invoice and settlement records are minimised after 3 years to the required status, amount and document fields and deleted no later than 8 years from the relevant year-end
  • Requests to farms: platform archive for no more than 12 months; when an account is deleted, its account-linked archive copies are deleted immediately
  • Infrastructure logs: depending on provider, log type and plan, a few hours up to 30 days at Vercel; Supabase project logs for the plan-bound technical retention period
  • Accounts whose email address has not been confirmed: automatic deletion after 7 days; this does not apply to the later manual platform approval of an already confirmed farm-operator business account

Where booking, invoice or settlement records, proof of an invoicing mandate or complaint case files are required for an ongoing tax audit, appeal, court or enforcement proceeding, or to establish, exercise or defend specific legal claims, their regular deletion is suspended by a documented legal hold. The hold is reviewed regularly and lifted once its reason ceases to apply; the applicable regular deletion period then resumes. The fixed periods stated above apply to the other categories of data listed there.

You can delete your account at any time in the account settings. Your account, reviews and personal data no longer needed for ongoing matters or retention purposes are then deleted. Completed general contact cases and review-deletion requests are removed immediately, as are account-linked platform copies of your requests to farms. Ongoing contact cases as well as DSA notices, withdrawal cases and complaint cases still within their three-year period remain as case files separated from the account for the period stated above. Operational booking data is separated from your account. Invoices and records subject to statutory retention remain unchanged and access-protected for the retention period. We delete technically erasable Stripe Customer records; Stripe may retain payment, fraud, KYC/AML and accounting data under its own legal duties. Stripe Connect accounts are handled separately in the operator deletion process. Target-linked general administrator and support records are removed when the account is deleted. Where a payment or document audit record is required for the statutory period, we remove the acting account UUID, reason and free text at that point; only the required structured status, amount and document fields remain until the deletion date stated above. Proof of the invoicing mandate remains separated from the deleted contact profile for the limited period stated above. Unless it is linked to a record subject to statutory retention or covered by a documented legal hold, it is deleted no later than three years after the mandate ends or is withdrawn. After account deletion it contains no contact details, only the pseudonymous organisation and actor UUIDs, wording, version, hash, language and server time of the legal act. Farm, association and institution accounts are deleted on request via the contact form once all events, bookings and settlements have been completed.

13. Your rights

You have the following rights at any time:

  • Access to your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Revocation of consent given (Art. 7 (3) GDPR)

To exercise your rights, please contact: info@kleinerlandwirt.de

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen), Prinzenstraße 5, 30159 Hannover, lfd.niedersachsen.de.

14. Data security

We use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. Our security measures are continuously improved in line with technological developments.

Questions about data protection?

For questions about the collection, processing or use of your personal data, you can reach our data protection contact at any time at:

Email: info@kleinerlandwirt.de