Privacy Policy

As of: May 25, 2026

This privacy policy explains what personal data we process on efoilmap.com, for what purposes, on what legal basis, and what rights you have.

1. Data Controller

The entity responsible for processing data on this website in accordance with the General Data Protection Regulation (GDPR) is:

Angelpower UG (limited liability)

Belvedereallee 5, 52070 Aachen, Germany

Represented by: Carlo Matic

Email: hi [at] efoilmap [dot] com

2. Processing of Personal Data (Purposes, Data Categories, Legal Bases)

We process personal data only to the extent necessary to provide the community platform and the interactive map. This includes:

  • 2.1 User Account and Registration (Magic Link)

    Processed data: Email address; profile details if applicable (username, bio); avatar image uploaded by you if applicable. Purposes: Registration/Login, account management, provision of community functions.

    Legal Basis: Art. 6 para. 1 lit. b GDPR (Contract/terms of use relationship).
  • 2.2 User Generated Content (Spots, Reviews, Content)

    Processed data: Content submitted by you such as spot coordinates, descriptions, amenities, reviews/ratings, photos if applicable, scheduled visits (including date, time, and optional description), coordination comments, and RSVP/attendance statuses. Purposes: Display and maintenance of the interactive community map, sharing and meetups in the community.

    Legal Bases: Art. 6 para. 1 lit. b GDPR (Provision of platform functions) and Art. 6 para. 1 lit. f GDPR (legitimate interest in the operation, quality, and integrity of community data).
  • 2.3 Technical Logfiles

    Processed data: Connection/access data (e.g. IP address, date/time, browser type, referrer URL). Purposes: Ensuring security and stability, error analysis, abuse/spam prevention.

    Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in secure operation).

3. Recipients / Data Processors and Third-Country Transfers

We use service providers who process personal data on our behalf (processors). Data processing agreements in accordance with Art. 28 GDPR have been concluded with them:

  • 3.1 Supabase (Database, Auth, Storage):

    We use Supabase for our database, authentication (including passwordless login via Magic Links/PKCE), and storage (e.g. for uploaded pictures). Account data, profile information, spots, reviews, comments, scheduled visits, RSVP statuses, and other uploads are stored/processed there.

  • 3.2 Mapbox (Map Tiles):

    We use Mapbox to display the interactive map. Mapbox is blocked by default and only loaded after your consent; upon consent, your IP address, among other data, is transmitted to Mapbox to fetch map content.

    Legal Basis: Art. 6 para. 1 lit. a GDPR (Consent via cookie banner).
  • 3.3 Google Translate (Translations):

    We integrate Google Translate on the client side to dynamically translate content (e.g. reviews/descriptions). The service is loaded only after user action (trigger).

4. Cookies / Local Storage

We exclusively store functional settings in Local Storage:

  • efoilmap-consent: Stores cookie banner choice
  • efoilmap-lang: Stores language selection
  • efoilmap-intro-dismissed: Flag indicating whether onboarding has been read

No third-party tracking pixels or behavior-based advertising scripts are active on this website.

5. Data Retention / Deletion

We generally store personal account data as long as your profile exists. If you decide to delete your profile, the following is triggered:

  • Profile fields, avatar images, reviews, coordination comments, scheduled visits, and participation/RSVP states are permanently and cascadingly deleted.
  • Spot entries you created remain intact but are anonymized (authorship is set to 'null') so that the community map remains functional.

6. Rights of Data Subjects

Under the GDPR, you have the following rights in particular:

  • Art. 15 GDPR: Right of access
  • Art. 16 GDPR: Right to rectification
  • Art. 17 GDPR: Right to erasure
  • Art. 18 GDPR: Right to restriction of processing
  • Art. 21 GDPR: Right to object
  • Art. 20 GDPR: Right to data portability
  • Art. 77 GDPR: Right to lodge a complaint with a supervisory authority

To exercise your rights, please contact us by email (see above).

7. Right to Lodge a Complaint with a Supervisory Authority

You can lodge a complaint with a data protection supervisory authority. Generally, the supervisory authority of your usual place of residence, workplace, or place of the alleged infringement is competent (Art. 77 GDPR).

8. Changes to this Privacy Policy

This privacy policy may be adjusted as the platform develops. The version currently published on the website applies (see date above).