Privacy policy
Protecting your personal data matters to us. This privacy policy explains which personal data is processed when you use DearPigeon, for what purposes, and what rights you have.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Friedjof Noweck
Email: datenschutz@dearpigeon.de
2. Providing the website and server log data
When you access DearPigeon, technically necessary information that your browser transmits to our server is processed. This can include, in particular, your IP address, the date and time of access, the address accessed, browser and operating system information, and technical error information.
This processing takes place to provide the website reliably and securely, to detect errors, and to prevent misuse or attacks.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of DearPigeon.
Server log data is generally deleted after [X] days, unless longer storage is required in an individual case for security reasons or due to legal obligations.
Hosting provider
[HOSTING-ANBIETER]
To the extent the hosting provider processes personal data on our behalf, this is done under a data processing agreement.
3. Cookies and local storage
DearPigeon does not use analytics or marketing cookies.
We only use technical storage mechanisms that are necessary for the functions you request. This can include, in particular, session information, security information, your language selection, and locally stored drafts from the postcard designer.
To the extent information is stored on or retrieved from your device, this is done, where applicable, on the basis of § 25(2) no. 2 TDDDG (the German implementation of the ePrivacy Directive), to the extent strictly necessary to provide a function you have explicitly requested.
To the extent personal data is processed in doing so, the legal basis is additionally determined by the respective processing described elsewhere in this privacy policy.
4. User account and magic-link sign-in
If you use a user account or sign in via a magic link, we process, in particular, your email address as well as technically necessary login, token, and session information.
We use this data to provide your account, authenticate you securely, and give you access to your drafts and orders.
The legal basis is Art. 6(1)(b) GDPR.
We use the following provider to send sign-in emails:
[SMTP-/MAIL-ANBIETER]
In doing so, your email address in particular is transmitted to the email provider, to the extent necessary for delivery.
5. Local processing of images and drafts
While you design a postcard, selected images are first processed locally in your browser.
This includes, for example, cropping, resizing, image preparation, and converting an image into lines or pen strokes for the preview.
This processing generally takes place on your device while you’re designing. The source image is not automatically transmitted to our servers merely because it was edited.
Drafts and related data may be stored locally in your browser, for example in IndexedDB or comparable technically necessary browser storage, so your current progress is preserved.
Transmission to DearPigeon only happens once a feature requires it — in particular when you submit a postcard for review or ordering.
6. Submitting and ordering a postcard
When you submit or order a postcard, we process the data required to handle, produce, and ship it.
This can include, in particular:
- your email address,
- your order and customer data,
- the message text you entered,
- the handwriting style and design you chose,
- images and graphics that are part of the postcard,
- line and production data generated from them,
- a preview of the postcard,
- the recipient’s name and postal address,
- options and add-ons you selected,
- order, review, production, and shipping status,
- payment information and payment status.
This processing takes place to handle your order and to produce and ship the postcard you designed.
The legal basis is Art. 6(1)(b) GDPR.
7. Data of postcard recipients
For a postcard order, we receive the recipient’s personal data not directly from that person, but from the person sending the postcard.
This concerns, in particular:
- name,
- postal address,
- any further details that are part of the postcard, where applicable.
This data comes from the sender and is used to produce the requested postcard, address it correctly, and deliver it.
[LEGAL BASIS FOR RECIPIENT DATA — TO BE FINALIZED BEFORE LAUNCH]
Recipient data is not used for advertising, profiling, or our own marketing purposes.
8. Content review and moderation
To prevent DearPigeon from being misused for impermissible content, submitted message texts can be automatically checked against certain content categories.
We use the following provider for this:
TypeSafe AI, Inc. (“TypeSafe”)
In doing so, the message text — or a version of it prepared for moderation — may be transmitted to TypeSafe.
The purpose of this processing is, in particular, to detect impermissible threats, serious harassment, and other content that violates our content rules, and to route submitted cards to manual review where necessary.
Legal basis:
[LEGAL BASIS — TO BE FINALIZED BEFORE LAUNCH]
TypeSafe processes the submitted customer data, according to its own statements, as a processor. The service is operated in the United States. For international data transfers, the contractually agreed data protection safeguards apply.
DearPigeon only transmits the information necessary for content review to TypeSafe, and in particular no payment data or recipient address, unless required for moderation.
9. Manual content review
For quality assurance and to check compliance with our content rules, submitted postcards may be viewed by authorized personnel before production.
Access only takes place to the extent necessary for review, customer support, or production.
For handling orders and reviews, we use a self-hosted instance of Zammad. Data is processed within our own infrastructure or at our hosting provider.
10. Email communication and support
If you contact us by email, or we send you messages related to an order, we process the data transmitted in doing so, in particular your email address and the content of the communication.
For communication related to an order, this processing is based on Art. 6(1)(b) GDPR.
For other inquiries, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in handling and responding to inquiries.
Email provider: [SMTP-/MAIL-ANBIETER]
11. Storage period
We only store personal data for as long as necessary for the respective purpose, or as required by statutory retention obligations.
In particular, the following internal deletion periods apply:
Server logs: [X]
Rejected submissions: [X]
Production files, images, and stroke data after shipping: [X]
Support communication: [X]
Order, invoice, and payment records are stored in accordance with statutory retention obligations.
After the respective periods expire, the data is deleted or anonymized, unless statutory or other legitimate reasons require further storage.
12. Recipients of data
Personal data is only shared with third parties to the extent necessary for the purposes described.
This can include, in particular:
- our hosting provider,
- our email service provider,
- our content moderation service provider,
- shipping and postal service providers,
- authorities or other bodies, to the extent we are legally obliged to do so.
To the extent providers process data solely on our behalf, we enter into the necessary data processing agreements.
13. Transfers to third countries
Some of the service providers we use may process personal data outside the European Economic Area.
Such a transfer only takes place if the data protection requirements for it are met — for example, on the basis of an adequacy decision or suitable safeguards such as the European Commission’s Standard Contractual Clauses.
Which providers this affects is set out in the respective sections of this privacy policy.
14. Security
We take appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access, and other unlawful processing.
This includes, in particular, encrypted transmission via HTTPS as well as access and authorization concepts for internal systems.
15. Your rights
Subject to the statutory requirements, you have in particular the following rights:
- the right to access your personal data (Art. 15 GDPR),
- the right to rectification of inaccurate data (Art. 16 GDPR),
- the right to erasure (Art. 17 GDPR),
- the right to restriction of processing (Art. 18 GDPR),
- the right to data portability (Art. 20 GDPR),
- the right to object to certain processing (Art. 21 GDPR).
To the extent processing is based on your consent, you can withdraw that consent at any time with effect for the future.
To exercise your rights, you can contact us at datenschutz@dearpigeon.de.
16. Right to lodge a complaint
You also have the right to lodge a complaint with a data protection supervisory authority.
The authority responsible for us is, in particular:
[ZUSTÄNDIGE DATENSCHUTZAUFSICHT]
[ADRESSE / WEBSITE]
You may generally also contact any other supervisory authority responsible under Art. 77 GDPR.
17. Changes to this privacy policy
We may update this privacy policy if DearPigeon, the service providers we use, or legal requirements change.
The version published on this page at any given time applies.
Last updated: September 2026