Privacy Policy â Website & Online Services (LocalBob)
Controller within the meaning of the DSGVO:
Flying Hamsters GmbH
WasserwerkstraĂe 17
66292 Riegelsberg
Local Court SaarbrĂŒcken HRB 19761
Managing Director: Marius Jungmann
VAT ID No.: DE279005373
Contact:
E-mail: support@localbob.com
1. Principles
We process personal data in accordance with the DSGVO and TDDDG. This policy informs about the nature, scope and purposes of processing when visiting our website, in the Checkout, in connection with contact inquiries, when using our B2B service and in connection with job applications and participation in the LocalBob Partner program.
This privacy policy applies to this website and the online services described herein. Separate privacy notices apply to standalone landing pages or other domains with their own content, forms or tracking/analysis functions.
2. Server log files
When our website is accessed, we and our hosting provider process log data (IP address, date/time, user agent, referrer, requested resources) to ensure operation, stability and security (Art. 6 Abs. 1 lit. f DSGVO). The full IP address is stored only for the duration of error analysis or to defend against attacks and is generally deleted or anonymized no later than 7 days after collection.
3. Contact, communication and website chat
When contacting us by e-mail, telephone, website chat or via messenger/communication channels we provide, we process the senderâs details to handle the inquiry and for communication (Art. 6 Abs. 1 lit. b and/or lit. f DSGVO).
If you contact us via external messengers such as WhatsApp, Telegram or comparable services, or connect such channels actively with your LocalBob user account, we process the communication data generated in this context to the extent necessary to handle your inquiry or to provide the requested service. The respective messenger providers process data on their own responsibility in accordance with their privacy terms. Please do not transmit special categories of personal data via such channels.
If the website chat or comparable interactive input fields are answered using AI, your inputs may be processed by integrated AI/model providers in order to respond to the inquiry. Further details are set out in Section 6.
4. Cookies and similar technologies
Our website generally uses only such cookies and similar technologies as are necessary to provide a digital service explicitly requested by the user, for security, login/session control, language settings, abuse and fraud prevention, technical redirection, or for a user-triggered Checkout, partner, activation or referral function.
As part of referral, partner or activation processes explicitly invoked or triggered by the user, short-lived first-party cookies or comparable storage mechanisms may be used to technically enable the desired attribution of benefits, trial periods, partner attribution or process steps within that flow. These technologies are not used for general reach measurement, behavioral advertising or cross-site tracking.
Optional analytics, marketing or retargeting cookies are not used on this website.
Where technical cookies or comparable technologies are set by embedded service providers in the context of a payment, login, partner or referral process explicitly initiated by the user, this is done exclusively to provide the respective function, for authentication or for fraud prevention.
5. Checkout, payment via Stripe
For Checkout, payment processing, invoicing processes, Customer Portal, where applicable Stripe Connect and fraud prevention we use Stripe (in particular Stripe Payments Europe, Ltd. and/or Stripe Technology Europe, Limited, Ireland). The legal basis is Art. 6 Abs. 1 lit. b DSGVO; insofar as security and fraud prevention measures are affected, additionally Art. 6 Abs. 1 lit. f DSGVO.
Stripe processes, inter alia, identification and payment data (e.g. payment method, Token, card/account data, IBAN, billing data), transaction data, risk and verification data as well as device- and usage-related information for payment processing, authentication, fraud prevention and service improvement. Where Stripe components or Stripe.js are loaded in a Checkout or comparable flow, Stripe may also use cookies or similar technologies as well as interaction and device data.
Further information can be found in Stripeâs privacy notices.
6. Use of the service (B2B account, thirdâparty platforms, messenger/social connections, AI functions)
We process account, contractual, usage, content and communication data to provide the service (Art. 6 Abs. 1 lit. b DSGVO).
For user-activated OAuth/API integrations or other technical links with thirdâparty platforms, messengers or social-media/content platforms, we process the necessary tokens, permissions, account identifiers, synchronization and metadata, as well as the content the user has authorized for use. This specifically concerns connected platform, messenger and publishing functions. Such connections canâwhere technically providedâbe revoked or disconnected at any time in your user account.
AI functions are provided via integrated AI/model and infrastructure providers. Personal data is processed only insofar as it is provided by the user in prompts, drafts, attachments, audio/text/image/video content, connected platform data or other content, or insofar as it is technically necessary to provide the respective function. There is no obligation to use such functions.
7. Partner program, applications and activation processes
If you register for the LocalBob Partner program, brand ambassador/referrer program or comparable activation processes, request an interview link, use a website chat for this purpose or provide information during onboarding about country, status, tax data, payout details, compliance or verification, we process these data to carry out pre-contractual measures, to decide on participation, to set up the partner account, for commission accounting, for abuse and compliance checks and for payouts (Art. 6 Abs. 1 lit. b, lit. c and/or lit. f DSGVO).
In particular, contact, application, communication, status, qualification, billing, tax, KYC/verification and payout data may be processed. Where AI-supported systems are used to provide interview, chat or support functions, Section 6 applies additionally.
Where automated pre-assessments, plausibility checks, scorings or risk assessments are used within the Partner program, these are in principle used to prepare, prioritize, prevent abuse and steer internal processes. A final admission, rejection, suspension or payout decision is generally not made solely on the basis of automated processing. Should an individual case exceptionally involve a solely automated decision that produces legal effects concerning you or similarly significantly affects you, we will inform you about this including the essential parameters of the decision and the expected consequences; in such a case you may request a human review, present your position and contest the decision.
8. Processing on behalf; subprocessors
Where we process personal data on behalf of the customer, the separate DPA (AVV) pursuant to Art. 28 DSGVO applies. We employ, among others, the following categories of recipients or subprocessors:
- Cloud/hosting infrastructure
- Payment and payout services
- AI/model and API infrastructure
- Communication, support and security services
- Providers of connected thirdâparty platforms, insofar as activated by the user
9. International transfers
For transfers to third countries we ensure an appropriate level of protection. Where recipients in the USA are certified under the EUâUS Data Privacy Framework (DPF), transfers are made on the basis of the adequacy decision (Art. 45 DSGVO). Otherwise transfers are made on the basis of appropriate safeguards, in particular Standard Contractual Clauses (Art. 46 DSGVO), unless another lawful basis applies.
10. Storage period
We retain personal data only as long as required for the respective purposes or statutory retention obligations exist. Contractual, billing, tax and commercially relevant data are retained in accordance with legal requirements. Communication, chat, application and partner data are deleted once the purpose ceases to exist and no statutory retention or evidential obligations prevent deletion.
11. Data subject rights
You haveâsubject to statutory prerequisitesâthe right to access, rectification, erasure, restriction, data portability and to object to processing based on Art. 6 Abs. 1 lit. f DSGVO. Please contact datenschutz@localbob.de for this purpose. You also have the right to lodge a complaint with a supervisory authority.
12. Mandatory information; B2B and program notes
Providing payment, contractual, tax, verification or payout data mayâdepending on the function usedâbe necessary for contract performance, the carrying out of preâcontractual measures, abuse prevention or billing.
Our paid SaaS offering in the Checkout is directed exclusively at companies (B2B). Separate program, application or partner processes mayâdepending on country, status and activationâalso be accessible to natural persons of legal age.
13. Amendments
We may adapt this privacy policy if required (e.g. in case of new functions, new categories of recipients or changes in legislation). The version published on the website at the relevant time shall apply.
As of: March 2026