Privacy policy
1. Data controller
The controller responsible for data processing under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR) is:
optinno GmbH, Schwarzseestrasse 114, 1716 Schwarzsee, Switzerland Email: support@travel.optinno.ch
2. What data we process
Account data: first name, optional last name, email address, password (stored encrypted/hashed, never in plain text).
Order data: shipping address (street, ZIP, city, country), ordered items, chosen payment method.
Payment data: we do not store card details ourselves. Card payments are processed exclusively by Stripe; Bitcoin Lightning payments run through a BTCPay server we operate ourselves; QR-bill payments are reconciled against the bank statement.
Emergency information (optional, for Emergency ID tags): blood type, allergies/medical conditions, emergency contact name and phone number. This is particularly sensitive health data. It is only ever visible when someone scans your physical Emergency ID tag, and remains entirely under your control.
Travel data: trips, flight details, accommodations, packing lists, and any travel documents you choose to upload (passport, visa, tickets, insurance proof).
Finder contact data: if someone finds a lost item and contacts you via the QR code/NFC tag, we process their message, an optional reply email address they provide, and a hashed IP address for abuse and spam prevention. Your own contact details (phone, email) are never disclosed directly to the finder — communication runs through an anonymized relay.
External Bluetooth tracker location data: only if you set up this feature yourself (latitude/longitude, timestamp).
3. Purpose of processing
We process your data to fulfill the contract (shipping tags, providing app functionality), to enable the Emergency ID feature, to relay messages between finders and owners, for fraud and spam prevention, and — only if you explicitly enable it — for the optional AI-assisted recognition of booking confirmations.
4. Recipients and third parties
Stripe, Inc. (USA) — only if you choose card payment as your payment method.
Anthropic (USA) — only if you use the optional, paid AI booking-scan feature; processes the booking confirmation you upload or forward.
Our email provider — for sending notifications and relay messages.
Metanet (Switzerland) — hosting and server operations.
We do not share your data for advertising purposes and do not sell your data.
5. International data transfers
When using Stripe or the optional AI feature (Anthropic), data may be transferred to the USA. These providers rely on standard contractual clauses or comparable safeguards for an adequate level of data protection.
6. Retention period
We retain account data until you delete your account. Order and payment records are retained in accordance with statutory retention obligations (generally 10 years under Swiss law).
7. Cookies
We use only a technically necessary session cookie for login. There are no tracking cookies, no advertising cookies, and no third-party analytics tools.
8. Your rights
You have the right to access, rectify, delete, restrict the processing of, port, and object to the processing of your data. Contact support@travel.optinno.ch for any of these requests.
You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
9. Data security
Data is transmitted encrypted (TLS). Passwords are stored only in hashed form. Emergency information is only visible when the physical tag is actively scanned. The private contact relay prevents finders from gaining direct access to your personal contact details.
10. Contact for privacy inquiries
support@travel.optinno.ch
