Privacy Policy â Website & Online Services (LocalBob)
Controller pursuant to the DSGVO:
Flying Hamsters GmbH
WasserwerkstraĂe 17
66292 Riegelsberg
Local Court SaarbrĂŒcken HRB 19761
Managing Director: Marius Jungmann
VAT ID: DE279005373
Contact:
Eâmail: support@localbob.com
1. Principles
We process personal data in accordance with the DSGVO and TDDDG. This policy informs about the type, scope and purposes of processing when visiting our website, in the Checkout, in connection with contact enquiries, when using our B2B service and in connection with applications and participation in the LocalBob Partner program.
This privacy policy applies to this website and the online services described herein. Separate privacy notices apply to standalone landing pages or other domains with their own content, forms or tracking/analytics functions.
2. Server log files
When our website is accessed, we and our hosting provider process log data (IP address, date/time, user agent, referrer, requested resources) to ensure operation, stability and security (Art. 6 Abs. 1 lit. f DSGVO). The full IP address is stored only for the duration of error analysis or to defend against attacks and is generally deleted or anonymized no later than after 7 days.
3. Contact, communication and website chat
When you contact us by eâmail, telephone, website chat or via messengers/communication channels we provide, we process the senderâs details for handling the enquiry and communication (Art. 6 Abs. 1 lit. b and/or lit. f DSGVO).
If you contact us via external messengers such as WhatsApp, Telegram or comparable services, or actively connect such channels to your LocalBob user account as part of use, we process the communication data arising in this context to the extent necessary for handling your enquiry or providing the requested service. The respective messenger providers additionally process data under their own responsibility pursuant to their privacy terms. Please do not transmit special categories of personal data via such channels.
The chat on our homepage is conducted by our AI assistants Bob and Kim; they explicitly identify themselves as AI at the beginning of the conversation in their greeting message and are additionally labeled as AI assistants in the image descriptions for screen readers. Use is voluntary and possible without an account. Processed data comprise the messages you enter, the conversation history of the respective session, a randomly generated session identifier and the selected language. If you voluntarily provide a website address in the chat, we will retrieve publicly accessible basic information about that site (title and short description) once per session to tailor our responses to your company. For responding we use OpenRouter, Inc. (USA) as processor; OpenRouter forwards the request to the model operators we have configured, currently in particular Google and OpenAI. To prevent automated mass enquiries we additionally limit the number of chat requests per IP address; the IP address is retained as a counting key for up to 24 hours for this purpose. Your IP address and browser identifier are not transmitted to the model providers. Your chat inputs are not merged with account data and no profiling takes place. Transfers to third countries in this context are subject to section 9. The legal basis is Art. 6 Abs. 1 lit. b DSGVO for answering your enquiry and Art. 6 Abs. 1 lit. f DSGVO for the secure and functional operation of the chat. Chat histories are retained for abuse prevention and quality assurance and are deleted no later than after 90 days.
If other interactive input fields are answered using AI support, your inputs may be processed by integrated AI/model providers to respond to the enquiry. Further information on this can be found in section 6.
4. Cookies and similar technologies
Our website uses, as a rule, only such cookies and similar technologies as are necessary for the provision of a digitally delivered service explicitly requested by the user, for security, login/session control, language settings, abuse and fraud prevention, technical redirection or for a userâtriggered Checkout, partner, activation or referral function.
In the context of referral, partner or activation processes explicitly invoked or triggered by the user, firstâparty cookies or comparable storage mechanisms may be used to technically enable the desired attribution of benefits, trial periods, partner attribution or process steps within that flow. The cookie for attributing a referral expires no later than after 14 days; the cookie for partner attribution expires no later than after 90 days. These technologies are not used for general reach measurement, behavioral advertising or crossâsite tracking.
Optional analytics, marketing or retargeting cookies are not used on this website.
Where technical cookies or comparable technologies are set by embedded service providers in the context of a userâinitiated payment, login, partner or referral process, this is done solely to provide the respective function, for authentication or for fraud prevention.
5. Checkout, payment via Stripe
For Checkout, payment processing, invoicing processes, Customer Portal, where applicable Stripe Connect and fraud prevention we use Stripe (in particular Stripe Payments Europe, Ltd. and/or Stripe Technology Europe, Limited, Ireland). The legal basis is Art. 6 Abs. 1 lit. b DSGVO; with respect to security and fraud prevention measures additionally Art. 6 Abs. 1 lit. f DSGVO.
Stripe processes, among other things, identification and payment data (e.g. payment method, token, card/account data, IBAN, billing data), transaction data, risk and verification data as well as device and usageârelated information for payment processing, authentication, fraud prevention and service improvement. Where Stripe components or Stripe.js are loaded in a Checkout or comparable flow, Stripe may also use cookies or similar technologies as well as interaction and device data.
Further information can be found in Stripeâs privacy notices.
6. Registration and use of the service (B2B user account, thirdâparty platforms, messenger/social connections, AI functions)
We process account, contract, usage, content and communication data for provision of the service (Art. 6 Abs. 1 lit. b DSGVO).
During registration we retrieve publicly accessible company information based on the eâmail domain or website address you provide to prefill the registration form for you; the retrieval is performed once per provided eâmail domain or website address and is executed again if you change your input. For this purpose we evaluate the contents of the relevant website and match the derived company name or domain with the Google Places service of Google Ireland Ltd., which provides publicly available details such as company name, address and website; the information obtained in this way is structured by AI. All suggestions are mere pre-filled entries and can be changed or deleted before submission. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (performance of preâcontractual measures at your request).
For userâactivated OAuth/API integrations or other technical links with thirdâparty platforms, messengers or social media/content platforms we process the tokens, permissions, account identifiers, synchronization and metadata required for this purpose as well as the contents released by the user for use of the function. This concerns in particular connected platform, messenger and publishing functions. Such connections can be revoked or disconnected at any time in your user account, insofar as this is technically possible.
AI functions are provided via integrated AI/model and infrastructure providers. Personal data are processed only insofar as they are provided by the user in prompts, drafts, attachments, audio/text/image/video content, connected platform data or other content, or insofar as this is technically necessary for provision of the respective function. There is no obligation to use such functions.
7. Partner program, applications and activation processes
If you register for the LocalBob Partner program, brand ambassador/referrer program or comparable activation processes, request an interview link, use a website chat for this purpose or provide onboarding details on country, status, tax data, payout data, compliance or verification, we process these data for performance of preâcontractual measures, for the decision on participation, for the setup of the partner account, for commission settlement, for abuse and compliance checks and for payout (Art. 6 Abs. 1 lit. b, lit. c and/or lit. f DSGVO).
In particular contact, application, communication, status, qualification, billing, tax, KYC/verification and payout data may be processed. Where AIâsupported systems are used to provide interview, chat or support functions, section 6 applies additionally.
Where automated preâassessments, plausibility checks, scorings or risk checks are used in the partner program, these are generally used to prepare, prioritize, prevent abuse and control internal processes. A final decision on admission, rejection, blocking or payout is not normally made solely on the basis of automated processing. If, in exceptional cases, a decision in an individual case is made exclusively by automated processing and produces legal effects concerning you or similarly significantly affects you, we will inform you about this including the essential parameters of the decision and the expected consequences; in such a case you may request a subsequent human review, present your position and challenge the decision.
8. Processing on behalf; subâprocessors
Where we process personal data on behalf of the customer, the separate data processing agreement (AVV) pursuant to Art. 28 DSGVO applies. We use, among others, the following categories of recipients or subâprocessors:
- Cloud/hosting infrastructure
- Payment and payout services
- AI/model and API infrastructure
- Communication, support and security services
- Providers of connected thirdâparty platforms, where activated by the user
9. Transfers to third countries
For transfers to third countries we ensure an appropriate level of protection. Where recipients in the USA are certified under the EUâUS Data Privacy Framework (DPF), the transfer is based on the adequacy decision (Art. 45 DSGVO). Otherwise the transfer is based on appropriate safeguards, in particular standard contractual clauses (Art. 46 DSGVO), unless another permissible basis applies.
10. Storage periods
We store personal data only as long as required for the respective purposes or statutory retention periods apply. Contractual, invoicing, tax and commercial law relevant data are retained in accordance with legal requirements. Communication, chat, application and partner data are deleted once the purpose ceases to apply and no statutory retention or evidentiary obligations oppose deletion. Website chat histories are deleted in any event no later than after 90 days.
11. Rights of data subjects
You have, subject to the legal requirements, the right to access, rectification, deletion, restriction, data portability and to object to processing based on Art. 6 Abs. 1 lit. f DSGVO. Please contact datenschutz@localbob.de for this. In addition, you have the right to lodge a complaint with a supervisory authority.
12. Mandatory information; B2B and program notes
Provision of payment, contractual, tax, verification or payout data may, depending on the function used, be necessary for contract performance, for performance of preâcontractual measures, for abuse prevention or for billing.
Our feeâbased SaaS offering in the Checkout is addressed exclusively to businesses (B2B). Separate program, application or partner processes mayâdepending on country, status and activationâalso be accessible to natural persons of legal age.
13. Changes
We may adapt this privacy policy where necessary (e.g. in case of new features, new recipient categories or changes in law). The version published on the website at any given time applies.
As of: July 2026