Legal
Privacy Policy
Last updated: August 2026
1. Controller
The controller responsible for data processing is: JustInVentures GmbH, Pfarrer-Brendel-Platz 7, 97274 Leinach, place of business: Theresienstraße 152, 80333 Munich. Email: hello@boosterlounge.com, phone/WhatsApp: +49 177 5201612. A data protection officer is not legally required and has not been appointed.
2. Hosting and Server Log Files
Our website is hosted by Vercel Inc. When the site is accessed, access data (IP address, date/time, page requested, browser/device data) is automatically processed in server log files. The legal basis is our legitimate interest in secure and stable provision (Art. 6(1)(f) GDPR). Vercel acts as a processor; a data processing agreement is in place.
3. Cookies and Consent
Technically necessary cookies are used on the basis of Art. 6(1)(f) GDPR. All non-essential processing (in particular the reach measurement under section 4) takes place only after your explicit consent via our consent banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You may withdraw your consent at any time with effect for the future.
We store the consent together with the time and the version of the information provided. After twelve months we ask again; the same applies if what we inform you about changes. A withdrawal takes effect for the future and does not affect the lawfulness of processing carried out until then (Art. 7(3) sentence 3 GDPR). Upon withdrawal we additionally delete every entry on your device that was created only because of the consent; measurement records already collected remain until the periods stated in section 18 expire.
This website loads NO content, fonts, maps, videos or tools from third-party servers. Everything your browser requests comes from our own address. The complete overview of what is stored in or read from your device — name, form, purpose and duration — is set out below:
Strictly necessary (no consent required)
These entries are required for the service you requested (§ 25(2) no. 2 TDDDG). Without them sign-in, cart, language choice or storing this very decision would not work. They are set even if you decline in the banner.
sb-<projekt>-auth-token (samt Teilstücken und -code-verifier)
- Form:
- Cookie
- Duration:
- until sign-out, at most until the session expires
- Purpose
- Your signed-in session for the customer account (Supabase Auth). Server-readable only (httpOnly), transmitted encrypted.
Contains personal details.
bl-admin-auth-token
- Form:
- Cookie
- Duration:
- until sign-out, at most until the session expires
- Purpose
- Separate admin-area session. Created only for staff and independent of the customer session.
Contains personal details.
bl-signout-attempt
- Form:
- Cookie
- Duration:
- a few minutes
- Purpose
- Records a started sign-out so an interrupted sign-out is completed on the server. Contains no personal details.
bl-pwreset
- Form:
- Cookie
- Duration:
- 15 minutes
- Purpose
- Proof of an ongoing password reset. Server-readable only (httpOnly); carries the session markers of the reset link.
Contains personal details.
bl-session-signal
- Form:
- Web storage (persistent)
- Duration:
- overwritten with every signal; not meaningfully persistent
- Purpose
- Signal between multiple open tabs so a sign-out in one tab reaches the others. Contains only “signed in” or “signed out” plus a timestamp.
bl-oauth-resume
- Form:
- Web storage (tab)
- Duration:
- until return, at most 15 minutes; ends with the tab at the latest
- Purpose
- When you sign in with Google the page briefly leaves the tab. So you can continue at exactly the same point (cart contact step or chosen appointment), the intermediate state is stored here — for guest orders including the contact details you entered. It is read exactly ONCE on return and deleted in the process.
Contains personal details.
bl-cart
- Form:
- Web storage (persistent)
- Duration:
- until you empty the cart or complete the order
- Purpose
- Your cart (chosen services, appointments, quantities). Written only once you add something — merely browsing creates no entry.
bl-cart-resume
- Form:
- Web storage (tab)
- Duration:
- until return, at most 15 minutes; ends with the tab at the latest
- Purpose
- When you move to payment your appointments are already booked and therefore removed from the cart. If you cancel the payment, those bookings are released again, so you do not have to start over, your selection (services and appointment times, no contact details) is kept here in the meantime. It is read exactly ONCE on return and deleted in the process.
bl-cart-booking-lock
- Form:
- Web storage (persistent)
- Duration:
- until checkout or until the cart is emptied
- Purpose
- Prevents the same appointment being added to the cart twice. Contains appointment identifiers only.
bl-wallet-sweep
- Form:
- Cookie
- Duration:
- a few minutes
- Purpose
- Short-lived marker so newly acquired credit is applied to your account exactly once. Contains no amount and no personal details.
bl-locale
- Form:
- Cookie
- Duration:
- 12 months
- Purpose
- The language you CHOSE (German or English). Written only if you switch language or arrive via an English URL — a default is not stored.
bl-locale (zweite Ablage)
- Form:
- Web storage (persistent)
- Duration:
- until you clear browser storage; does not expire on its own
- Purpose
- The same language choice a second time, so it still applies if the cookie has expired or been deleted. Contains only “de” or “en”.
bl-consent
- Form:
- Cookie
- Duration:
- 365 days; after that we ask again
- Purpose
- The short form of your decision in the consent banner: one position for our own measurement (reach, usage and loading time together), one each for the vote on future boosts and, where offered, for Google Analytics, Google Ads and the Meta Pixel, plus the version you were informed about. This entry carries no timestamp. Without it we would have to ask again on every visit.
bl-consent (zweite Ablage)
- Form:
- Web storage (persistent)
- Duration:
- stays until you clear browser storage; after 365 days it no longer counts and we ask again
- Purpose
- The same decision a second time, in more detail: a yes or no for each purpose (reach, usage, loading speed, voting), plus the time and the version of the information given. This is how we know what you agreed to back then — even if the cookie is missing.
bl:navCount
- Form:
- Web storage (tab)
- Duration:
- ends with the tab
- Purpose
- Counts how many steps you took within this site so the back button does not lead out of it. Never leaves the browser.
bl-softwall-seen
- Form:
- Web storage (tab)
- Duration:
- until the end of the session (closing the tab)
- Purpose
- Remembers that you already saw the note about ordering without an account, so it does not reappear before every payment step.
bl:widerruf:<vorgang>
- Form:
- Web storage (tab)
- Duration:
- ends with the tab
- Purpose
- Remembers, per transaction, that your withdrawal declaration was already sent (or why the last attempt failed), so reloading the page does not trigger a second withdrawal.
bl-staging-unlocked
- Form:
- Cookie
- Duration:
- until the end of the session
- Purpose
- Preview addresses only: unlocks a not-yet-public version of the site. This entry is not created on the public address.
bl-consent-zeit
- Form:
- Web storage (tab)
- Duration:
- ends with the tab
- Purpose
- When the decision in the banner was last made, as far as this tab saw it. After a reload this tells the site that you withdrew in another tab in the meantime, so it deletes the visit identifier and the markers this tab created for our own measurement.
| Name | Form | Purpose | Duration |
|---|---|---|---|
| sb-<projekt>-auth-token (samt Teilstücken und -code-verifier)personal data | Cookie | Your signed-in session for the customer account (Supabase Auth). Server-readable only (httpOnly), transmitted encrypted. | until sign-out, at most until the session expires |
| bl-admin-auth-tokenpersonal data | Cookie | Separate admin-area session. Created only for staff and independent of the customer session. | until sign-out, at most until the session expires |
| bl-signout-attempt | Cookie | Records a started sign-out so an interrupted sign-out is completed on the server. Contains no personal details. | a few minutes |
| bl-pwresetpersonal data | Cookie | Proof of an ongoing password reset. Server-readable only (httpOnly); carries the session markers of the reset link. | 15 minutes |
| bl-session-signal | Web storage (persistent) | Signal between multiple open tabs so a sign-out in one tab reaches the others. Contains only “signed in” or “signed out” plus a timestamp. | overwritten with every signal; not meaningfully persistent |
| bl-oauth-resumepersonal data | Web storage (tab) | When you sign in with Google the page briefly leaves the tab. So you can continue at exactly the same point (cart contact step or chosen appointment), the intermediate state is stored here — for guest orders including the contact details you entered. It is read exactly ONCE on return and deleted in the process. | until return, at most 15 minutes; ends with the tab at the latest |
| bl-cart | Web storage (persistent) | Your cart (chosen services, appointments, quantities). Written only once you add something — merely browsing creates no entry. | until you empty the cart or complete the order |
| bl-cart-resume | Web storage (tab) | When you move to payment your appointments are already booked and therefore removed from the cart. If you cancel the payment, those bookings are released again, so you do not have to start over, your selection (services and appointment times, no contact details) is kept here in the meantime. It is read exactly ONCE on return and deleted in the process. | until return, at most 15 minutes; ends with the tab at the latest |
| bl-cart-booking-lock | Web storage (persistent) | Prevents the same appointment being added to the cart twice. Contains appointment identifiers only. | until checkout or until the cart is emptied |
| bl-wallet-sweep | Cookie | Short-lived marker so newly acquired credit is applied to your account exactly once. Contains no amount and no personal details. | a few minutes |
| bl-locale | Cookie | The language you CHOSE (German or English). Written only if you switch language or arrive via an English URL — a default is not stored. | 12 months |
| bl-locale (zweite Ablage) | Web storage (persistent) | The same language choice a second time, so it still applies if the cookie has expired or been deleted. Contains only “de” or “en”. | until you clear browser storage; does not expire on its own |
| bl-consent | Cookie | The short form of your decision in the consent banner: one position for our own measurement (reach, usage and loading time together), one each for the vote on future boosts and, where offered, for Google Analytics, Google Ads and the Meta Pixel, plus the version you were informed about. This entry carries no timestamp. Without it we would have to ask again on every visit. | 365 days; after that we ask again |
| bl-consent (zweite Ablage) | Web storage (persistent) | The same decision a second time, in more detail: a yes or no for each purpose (reach, usage, loading speed, voting), plus the time and the version of the information given. This is how we know what you agreed to back then — even if the cookie is missing. | stays until you clear browser storage; after 365 days it no longer counts and we ask again |
| bl:navCount | Web storage (tab) | Counts how many steps you took within this site so the back button does not lead out of it. Never leaves the browser. | ends with the tab |
| bl-softwall-seen | Web storage (tab) | Remembers that you already saw the note about ordering without an account, so it does not reappear before every payment step. | until the end of the session (closing the tab) |
| bl:widerruf:<vorgang> | Web storage (tab) | Remembers, per transaction, that your withdrawal declaration was already sent (or why the last attempt failed), so reloading the page does not trigger a second withdrawal. | ends with the tab |
| bl-staging-unlocked | Cookie | Preview addresses only: unlocks a not-yet-public version of the site. This entry is not created on the public address. | until the end of the session |
| bl-consent-zeit | Web storage (tab) | When the decision in the banner was last made, as far as this tab saw it. After a reload this tells the site that you withdrew in another tab in the meantime, so it deletes the visit identifier and the markers this tab created for our own measurement. | ends with the tab |
Only with your consent
These entries are created only if you accept the respective purpose in the banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Since 09 Aug 2026 you decide about them separately: “Reach”, “Usage” and “Load time” share one visit key, Boost voting has its own. Upon withdrawal they are deleted immediately — not merely no longer used, and only those of the withdrawn purpose.
bl-visit
- Form:
- Web storage (tab)
- Duration:
- ends with the tab; deleted immediately upon withdrawal
- Purpose
- Random identifier grouping the page views of ONE visit (reach measurement, section 4). Not traceable to you and not recognisable across visits.
bl-conv:<vorgang>
- Form:
- Web storage (tab)
- Duration:
- ends with the tab; deleted immediately upon withdrawal
- Purpose
- Remembers that an already counted completion (e.g. a paid order) is not counted again if you reload the page. Contains the transaction identifier of the payment or confirmation.
bl-boost-voter
- Form:
- Web storage (persistent)
- Duration:
- until withdrawal; deleted then
- Purpose
- Random identifier for voting on future Boosts, so the same vote is not counted twice. On the server it becomes an irreversible check value; the plain value never leaves your device.
bl-boost-votes
- Form:
- Web storage (persistent)
- Duration:
- until withdrawal; deleted then
- Purpose
- Which future Boosts you already voted for on this device, so the button shows the right state.
| Name | Form | Purpose | Duration |
|---|---|---|---|
| bl-visit | Web storage (tab) | Random identifier grouping the page views of ONE visit (reach measurement, section 4). Not traceable to you and not recognisable across visits. | ends with the tab; deleted immediately upon withdrawal |
| bl-conv:<vorgang> | Web storage (tab) | Remembers that an already counted completion (e.g. a paid order) is not counted again if you reload the page. Contains the transaction identifier of the payment or confirmation. | ends with the tab; deleted immediately upon withdrawal |
| bl-boost-voter | Web storage (persistent) | Random identifier for voting on future Boosts, so the same vote is not counted twice. On the server it becomes an irreversible check value; the plain value never leaves your device. | until withdrawal; deleted then |
| bl-boost-votes | Web storage (persistent) | Which future Boosts you already voted for on this device, so the button shows the right state. | until withdrawal; deleted then |
4. Reach Measurement (our own, without third parties)
For reach measurement we use NO third-party services. In particular, Google Analytics, Google Tag Manager and analytics or marketing tools from Meta (Facebook pixel, Conversions API) are not embedded on this website — neither before nor after consent. Consequently there is no joint controllership and no transfer to a third country. Should we use such a service in future, we will obtain a new, separate consent beforehand and update this policy; a consent already given expressly does not cover such use.
In addition, with your consent we carry out our own first-party reach measurement. NO third-party service is loaded and nothing is transmitted to third parties; the data stays in our own database (Supabase, see section 16). We process: the page viewed (as a page type, without booking numbers, invoice numbers or access links), the language, a device class (phone, tablet, computer, TV), the window width rounded to 20 pixels, the country (derived from the IP address, which itself is NOT stored), the referring internet domain (the domain only, never the full address), the campaign identifiers from the link (utm_source, utm_medium, utm_campaign, utm_content) and whether the address called up contained an advertising click identifier (such as gclid or fbclid) — the VALUE of that identifier is expressly NOT stored, because it is an identifier belonging to the respective advertising platform, time on page and scroll depth, steps reached in booking and purchase flows, the opening and reading time of our information windows (effect, procedure and ingredients of the individual Boosts), and technical loading times. To group a visit we store a random identifier generated in your browser in session storage (sessionStorage, key „bl-visit“); it contains no information about you as a person, is discarded when the tab closes and is deleted immediately if you withdraw consent. No profiles are created and no advertising audiences are built. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); you may withdraw it at any time via the consent banner. You decide SEPARATELY about three purposes, and each takes effect on its own: “Reach” (which page, device class, language, country, origin), “Usage” (time on page, scroll depth, steps reached, reading time of the information windows) and “Load time” (technical loading times). Whatever you do not allow never leaves your browser. Individual records are deleted after 90 days (see section 18).
4a. Voting on future Boosts
On the website you can indicate which not-yet-offered Boosts you would like (“thumbs up”). So the same vote is not counted twice, your browser generates a random identifier and stores it on your device (web storage, name “bl-boost-voter”; in addition “bl-boost-votes” records which cards you voted for on this device). What is transmitted to us is not this identifier itself but an irreversible check value computed from it using a secret addition. This check value cannot be traced back to you; it serves solely to detect a second vote from the same device.
In addition, we record anonymous usage figures per card (how often it was shown, opened and read, the reading time, and whether a vote was cast or withdrawn). These records contain NO identifier — not even the check value; they cannot be linked to your vote. The purpose is to decide which Boosts we add to our offering.
The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); it is precisely the consent you give under “Boost voting” in the banner — a separate purpose you can switch on and off independently of reach measurement. If you withdraw it, we delete both entries on your device immediately. The votes themselves are deleted after 12 months, the anonymous usage figures after 90 days, and free-text wishes (see section 9) after 24 months.
5. Appointment Booking
For bookings we use the SimplyBook.me booking system. The data required for scheduling (name, contact details, chosen service, appointment) is processed. The legal basis is the initiation and performance of the contract (Art. 6(1)(b) GDPR). SimplyBook.me acts as a processor; a data processing agreement is in place.
6. Health Data (Medical History)
Before a treatment, we offer you a medical history form in paper form, which you are free to complete. If you complete it, we process the health data contained therein (e.g. pre-existing conditions, medications, pregnancy) solely for the purpose of safely performing the treatment. The legal basis is your explicit consent (Art. 9(2)(a) GDPR). The forms are stored exclusively in paper form, under lock, on our premises, and are accessible only to the treating staff and our Heilpraktiker (alternative health practitioners). They are retained for a period of ten years, in line with the period customary for treatment documentation. You may withdraw your consent at any time with effect for the future.
7. Well-being Questionnaire
Before an appointment, we may offer you a short, voluntary well-being questionnaire (e.g. by SMS, email, or WhatsApp). This serves solely to provide a non-binding picture of mood and well-being (e.g. questions about tiredness, workload, or concentration) and is expressly not directed at any medical diagnosis or advice. No health data within the meaning of Art. 9 GDPR is collected through it; in particular, we do not ask here about pre-existing conditions, allergies, medications, or pregnancy. The legal basis is your consent (Art. 6(1)(a) GDPR); participation is voluntary and may be refused without disadvantage. When sent via WhatsApp (Meta Platforms Ireland Ltd.), processing of data outside the EU cannot be excluded. You may withdraw your consent at any time with effect for the future.
8. Payment and Online Purchases
Payments are processed via the payment service provider Stripe (Stripe Payments Europe Ltd.). This includes both the registration of a means of payment to secure bookings and the processing of online payments, in particular for advance payment of a treatment as well as for the purchase of vouchers, Booster Packs, or comparable services. For processing, we handle the order and payment data required for this (e.g. chosen service, amount, payment status) and associate it with your booking or customer account. The registered means of payment is charged for cancellation fees only in accordance with our GTC. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in protection against appointment no-shows (Art. 6(1)(f) GDPR). Stripe acts as a processor; a data processing agreement is in place.
If you select a third-party payment method during checkout, the data required for the payment (in particular name, email address, amount, and order reference) is transmitted to that provider. This concerns PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg), Klarna (Klarna Bank AB (publ), Sweden), and, for Apple Pay and Google Pay, Apple Inc. and Google Ireland Limited respectively. These providers process the data for handling the payment method you selected as independent controllers under their own privacy policies, and may carry out their own identity and fraud checks. We have no influence over this processing. The legal basis for the transfer is performance of the contract (Art. 6(1)(b) GDPR). The transfer only takes place if you actively select the respective payment method.
If we issue an invoice to a company or cooperation partner, we process the details required for it (company, contact person, address, VAT ID where applicable, and email address) in order to perform the contract (Art. 6(1)(b) GDPR) and because of the statutory obligation to issue invoices (Art. 6(1)(c) GDPR, Section 14 of the German VAT Act); they are subject to the same retention periods as invoices and payment records (section 18).
8a. Gift Vouchers and Credit
When a gift voucher is purchased, we process the buyer's details (email address and the payment data described in section 8) and — depending on the chosen delivery route — the recipient's name and email address, an optional personal message, and the desired delivery day. We use this information solely to create, deliver, and redeem the voucher. The legal basis is performance of the contract (Art. 6(1)(b) GDPR); for the recipient's details, additionally our legitimate interest in delivering the gift (Art. 6(1)(f) GDPR). The voucher code is not stored in plain text in our database but as an irreversible check value.
So that a voucher delivered to you is visible in your customer account, when you sign in or open your customer account we match your confirmed email address once against open voucher deliveries and automatically assign a voucher delivered to that address to your account. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). After delivery, or once the recipient has claimed the voucher, the buyer of a gifted voucher can only see the order and delivery status — not the current remaining value and not how the voucher is used.
We remove the personal details on the voucher (name, email address, personal message) 90 days after the voucher expires. The redemption history is retained without these details as an accounting basis (section 18).
Occasionally we give away vouchers ourselves, for example as a prize in a giveaway or as a goodwill gesture. In that case we process your name, your email address and, where provided, a personal message solely to deliver the voucher to you and to redeem it; no purchase contract arises, and therefore no receipt and no right of withdrawal. The legal basis is our legitimate interest in running the campaign (Art. 6(1)(f) GDPR); for redemption and for the deletion of your details 90 days after expiry, the preceding paragraphs of this section apply accordingly.
8b. Discount Codes (Promotional Codes)
If you redeem a discount code when booking, we store, for each appointment concerned, the fixed discount amount, the booking number and a transaction bracket (it links the appointments of one booking transaction). Instead of your email address we store a pseudonymous identifier: an irreversible check value of the email address given at booking, computed with a secret key. The address cannot be derived from this check value; no link to your customer account is stored in the process.
The fixed discount amount is the basis for the remaining payment, the invoice, any cancellation fee and refunds; the legal basis is performance of the contract (Art. 6(1)(b) GDPR). The pseudonymous identifier enforces the per-person redemption limit and prevents circumvention of campaign conditions; the legal basis is our legitimate interest in preventing misuse (Art. 6(1)(f) GDPR) — it replaces storing your email address in plain text.
In the event of a cancellation, the redemption is voided but not deleted; the code's redemption quota becomes available again. The pseudonymous identifier also remains after an account deletion, because redemption limits could otherwise be circumvented any number of times by creating and deleting accounts. The redemption rows form part of the accounting records and are retained like invoice and payment records (section 18).
9. Contact and Withdrawal Function
Via the contact forms on our website (general enquiries, enquiries regarding collaboration and franchise, and enquiries for Boost at Home) we process the information you provide in order to handle your request. Depending on the form, this comprises your name, your email address, your telephone number, your address, a preferred appointment time, and the content of your message. The notification is sent to us via our transactional service provider (see section 11). The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to the conclusion or performance of a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.
If you contact us by telephone, we process the information you provide during the call for the same purposes and on the same legal basis.
If you contact us via WhatsApp, Meta Platforms Ireland Ltd. processes your message and your telephone number; processing in the USA cannot be excluded. If you use the WhatsApp button on our website following a form enquiry, a message is prepared containing your first and last name so that we can match your message to your enquiry. No further information from the form is transmitted to WhatsApp. You may edit or delete the prepared text before sending it. Using WhatsApp is voluntary; you can also reach us via our contact forms and by telephone.
Please do not send us any health data or other sensitive information via WhatsApp. We discuss health-related matters with you in person on site.
Via the electronic withdrawal function provided on our website, we process the information you submit in order to handle and confirm your withdrawal, and we keep a withdrawal journal as proof of receipt (Art. 6(1)(b) and (c) GDPR). If you book an appointment from a Booster Pack credit, we additionally record, as proof, the time and the version of your express request that the service begin before the withdrawal period expires (Art. 6(1)(b) and (c) GDPR). Both records are deleted after the periods stated in section 18.
In addition to the email, we store one statistics row per enquiry that contains NO information about you as a person: the type of enquiry (general question, collaboration, Boost @ Home, boost wish), the chosen topic, for home visits the lead-time class (today, short notice, with lead time) and the first TWO digits of the postcode, the language, a device class and the processing status. Neither your name, email address, phone number nor address is stored there; those details exist only in the email. The purpose is handling open enquiries and operational planning; the legal basis is our legitimate interest in a functioning enquiry process (Art. 6(1)(f) GDPR). These rows are deleted after 24 months (see section 18). Your message text is not stored there either — with ONE exception: for a Boost wish, the wish text you enter is itself the request. It is therefore stored (max. 500 characters), without any contact details and without a link to any identifier, and deleted after 24 months.
10. Newsletter
If you sign up for our newsletter, we process your email address on the basis of your consent (Art. 6(1)(a) GDPR). You can sign up via the registration form on our website or via the settings in your customer account.
Where you sign up via the form, registration uses the double opt-in procedure. The confirmation email required for this is sent via our transactional service provider (see section 11); it contains no tracking pixel and no click-tracking redirect. Where you activate the newsletter via your customer account, your email address has already been confirmed by signing in to that account.
To demonstrate your consent, we record the time at which it was given. Where you sign up via the form, we additionally record your IP address, your browser type, and the wording of the consent declaration.
The following applies in addition as of 30 July 2026: you may also give your consent when creating a customer account. In that case we add you to the distribution list only once you have confirmed your email address via the confirmation link for your account; you will not receive a separate newsletter confirmation email.
We record the time, the wording of the consent declaration, your IP address and your browser type (user agent) for all of the sign-up routes named above, including activation via your customer account and consent given during registration. Where consent is given during registration, the IP address and browser type relate to the confirmation of your email address. This information is used solely to demonstrate consent pursuant to Art. 7(1) GDPR.
Dispatch of the newsletter is handled via Brevo (Sendinblue GmbH, Berlin); processing takes place within the EU. Brevo is used exclusively for sending the newsletter and not for sending transactional emails (see section 11). Brevo acts as a processor; a data processing agreement is in place.
Performance measurement. Our newsletters contain a tracking pixel as well as links that are routed via Brevo's servers. This allows us to identify whether and when a newsletter has been opened and which links within it have been clicked. This analysis serves to tailor the content of our newsletter to the interests of its recipients and to improve its design. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and, insofar as information on your terminal equipment is accessed, § 25(1) TDDDG. Consent to performance measurement forms part of your consent to receive the newsletter; it cannot be withdrawn separately. You may object to performance measurement by unsubscribing from the newsletter. Many email programs also suppress the loading of images by default, in which case no open measurement takes place.
You may unsubscribe from the newsletter at any time, for example via the unsubscribe link in every newsletter email or via the settings in your customer account. Unsubscribing from the newsletter has no effect on your receipt of transactional emails that are necessary for the use of your customer account and our services.
11. Transactional Emails
To send transactional emails, meaning those emails that are necessary in connection with the use of your customer account and our services (in particular sign-in and confirmation links, registration confirmation, password resets, the issuing and confirmation of gift vouchers, confirmation of account deletion, and replies to enquiries submitted via our contact form), we use the Transactional Email service provided by Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, France.
The data processed comprises the recipient's email address, their name where applicable, the content of the respective email, and technical metadata relating to delivery (in particular the time of sending, the delivery status, and error messages returned by the receiving server). We use this metadata solely to ensure the deliverability of our emails and to identify delivery failures.
Since 23 August 2026, our delivery journal additionally records a pseudonymous recipient identifier for every email sent. It is derived from your email address using a key stored exclusively on our database server and cannot be reversed into the address without that key; the email address itself is not stored in the journal. Using this identifier, our staff can check in the customer file (section 13a) which emails we have sent you in the last 90 days and whether they were delivered — for example, if you ask us why a confirmation has not arrived. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in reliable delivery and in answering your enquiries (Art. 6(1)(f) GDPR). The journal is deleted after 90 days (section 18). Entries that are less than 90 days old at the time of an account deletion remain until that period expires; the last entry evidences delivery of the deletion confirmation.
The legal basis is Art. 6(1)(b) GDPR, as sending these emails is necessary for the performance of the contract or for taking steps prior to entering into a contract, and Art. 6(1)(f) GDPR based on our legitimate interest in reliable and secure delivery.
Processing takes place exclusively within the European Union; no personal data is transferred to a third country in this context. Scaleway acts as a processor; a data processing agreement pursuant to Art. 28 GDPR is in place.
These emails contain no tracking pixels and no click-tracking redirects. Open rates and click rates are not measured. No unsubscribe option is provided for these emails, as they are necessary for the performance of the contractual relationship; this does not affect your right to delete your customer account at any time.
In addition, we send a security notification to the address stored in your account whenever that account's password has been changed. It states the time and the way the change was made and explains what to do if you did not make the change yourself. The legal basis for this is Art. 6(1)(f) GDPR; our legitimate interest is the security of processing under Art. 32 GDPR, that is, your ability to notice an unauthorised takeover of your account at all. For the same reason this notification cannot be unsubscribed from while the account exists.
12. Customer Account and Sign-in
To manage your bookings, you can create a customer account. Authentication and account management are handled via Supabase. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). Supabase acts as a processor; a data processing agreement is in place.
Optionally, you can also sign in with your Google account (“Continue with Google”). If you choose this option, the data required for sign-in is exchanged between Google (Google Ireland Ltd.) and us; in particular, we receive the email address associated with your Google account in order to set up and assign your customer account. The legal basis is the performance of the sign-in procedure you have chosen and performance of the contract (Art. 6(1)(b) GDPR) or your consent (Art. 6(1)(a) GDPR). A transfer to the USA cannot be excluded; for the legal basis, see section 17. Google’s privacy terms additionally apply.
13. Loyalty Programme
If you participate in our loyalty programme, we process the data required for this, in particular the number of your fully paid treatments and the resulting claim to a free service, and associate it with your customer account. The legal basis is the operation of the loyalty programme within the framework of the existing contractual relationship with you (Art. 6(1)(b) GDPR) and our legitimate interest in correct processing and the prevention of misuse (Art. 6(1)(f) GDPR). We store this data for the duration of your participation or for as long as a claim may exist.
13a. Customer File and Internal Analysis
To run the lounge, we bring the information we hold about you together in one place: your appointments from the booking system (section 5), your orders and receipts (section 8), your vouchers and credit and, where one exists, your customer account (section 12). The link is your email address. The purpose is to be able to answer a question on site or by phone without searching four separate systems, and to run the business (capacity, outstanding receipts, unredeemed credit). The legal basis is the performance of the existing contractual relationship with you (Art. 6(1)(b) GDPR) and our legitimate interest in orderly operations (Art. 6(1)(f) GDPR).
From this information we additionally calculate how long ago your last visit was, whether you come regularly, and to what extent guests from a given month return later. These analyses serve planning purposes and allow us to remind you, where appropriate, of existing credit or an expiring voucher. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). NO automated decision within the meaning of Art. 22 GDPR is made: the analysis proposes nothing and triggers nothing, it is read by people. You may object to this processing at any time under Art. 21(1) GDPR; an informal message is sufficient (section 19).
This view is accessible only to our staff in the protected administration area and requires a separate sign-in. Revenue, balance-sheet and liability figures are additionally reserved for management. No new data about you is collected there and no additional data is stored: the view reads what already exists under sections 5, 8, 11, 12 and 13, and the retention periods stated there apply. For technical reasons, the information read from the booking system is cached on our server for up to five minutes. For day-to-day work, our staff can download lists from this view as a file; such files contain the information displayed, then reside on a work device and are deleted once the reason for them has passed.
14. Security and Abuse Prevention
To protect our website and systems against misuse (e.g. automated attacks or spam), we use technical security measures. In doing so, security-relevant events may be logged, such as a shortened (anonymised) IP address, information about the browser used, and the function accessed. The legal basis is our legitimate interest in the security and integrity of our service (Art. 6(1)(f) GDPR). These security logs are deleted regularly, at the latest after 30 days, unless, in an individual case, the investigation of a specific instance of misuse exceptionally requires longer storage.
Separately from this, we log every change our staff make in the protected administration area, for instance cancelling or rescheduling an appointment, creating a booking, or changing an internal appointment note or a setting. Recorded are the time, the acting person with their work email address, the type of change and a summary; that summary may contain your name and the appointment concerned. The sole purpose is to demonstrate who initiated a change. The legal basis is our legitimate interest in the traceability of changes to your bookings and our accountability obligation (Art. 6(1)(f), Art. 5(2) GDPR). After twelve months we remove names and note texts from these entries; what remains is only who made what type of change and when. After ten years we delete the entry entirely. We deliberately do not delete this log upon account deletion, because a record that can remove itself on request would be worthless as a record (Art. 17(3)(e) GDPR).
15. Social Media
Our website contains links to our profiles on Instagram, TikTok, and Facebook. These are simple links; data is transmitted to the respective providers only when you actively click on them and access the relevant platform. The privacy policies of the respective providers apply to processing there.
16. Recipients and Processing
Data processing agreements pursuant to Art. 28 GDPR are in place, where required, with the service providers we use. These are: Vercel (hosting, section 2), Supabase (database and customer account, sections 4 and 12), SimplyBook.me (appointment booking, section 5), Stripe (payment, section 8), Scaleway (transactional email, section 11), Brevo (newsletter dispatch, section 10) and Microsoft (Microsoft Ireland Operations Ltd.; our business mailbox, in which all emails are processed that you send to us or that we receive via our contact forms). Beyond that, we use Google solely for signing in with a Google account (section 12; for the Google Pay payment method see section 8 and the paragraph below), and Meta solely in the context of communication via WhatsApp (sections 7 and 9). We use no third-party services for reach measurement; Google Analytics, Google Tag Manager and analytics or marketing tools from Meta are not embedded (section 4).
By contrast, the providers of the payment method you select (PayPal, Klarna, Apple, Google) act as independent controllers rather than processors; their own privacy policies apply (see section 8).
17. Transfer to Third Countries
Where services transfer personal data to countries outside the EU/EEA (in particular the USA), this is done only on the basis of an adequacy decision (for certified US recipients, the EU-US Data Privacy Framework) and/or appropriate safeguards within the meaning of Art. 46 GDPR, in particular the EU Standard Contractual Clauses. If one of these bases ceases to apply, we base the transfer on the remaining appropriate basis.
18. Retention Period
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods. Invoices and payment records are kept for 10 years due to commercial and tax law obligations (§ 147 AO, § 14b UStG, § 257 HGB); after an account deletion they are retained separately in pseudonymised form (name and email removed) and deleted once that period ends. After that, a retained record can only be linked to a person via a pseudonym; name, email and phone number are removed on deletion and are not kept separately. Medical history data is kept for 10 years. Security logs are deleted at the latest after 30 days (see section 14). Individual records of the reach measurement (section 4) are deleted after 90 days, the enquiry statistics rows without contact details and free-text wishes (section 9) after 24 months; the delivery journal of our emails (section 11) is deleted after 90 days. For voting on future Boosts (section 4a): the votes are deleted after 12 months, the anonymous usage figures after 90 days. All these periods run automatically every day; the decisive point is the time of collection in each case.
The following periods additionally apply: entries in the administration log (section 14) lose names and note texts after twelve months and are deleted after ten years. Details of a registered payment guarantee (section 8) lose the address and card characteristics no later than 400 days after the matter is settled; a means of payment you registered is removed 540 days after its last use. The withdrawal journal and the record of an express request (section 9) are retained for three years from the end of the year in which they arose and are then deleted automatically. We remove the personal details on gift vouchers 90 days after the voucher expires (section 8a); fixed discount redemptions (section 8b) are retained as part of the accounting records like invoice and payment records. We deliberately keep only one single list without a time limit: the suppression list for email delivery. It contains addresses to which we must permanently stop sending, for instance after permanent non-delivery or a complaint. Deleting that list would mean resuming delivery to precisely those addresses; it exists solely in order NOT to send. For the appointment data held in the booking system (section 5) we deliberately state no automatic period, because we cannot delete it there automatically; on your request we delete it there manually.
19. Your Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21 GDPR). You may withdraw consent given at any time with effect for the future (Art. 7(3) GDPR).
To exercise these rights, an informal message to hello@boosterlounge.com or to the postal address given in section 1 is sufficient.
20. Right to Complain
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
21. Currency
We update this Privacy Policy as soon as our data processing changes.
Consent to the Processing of Health Data (Medical History Form)
Consent to the processing of health data: I expressly consent to the health data provided in this form being collected for the purpose of safely performing the treatment, stored in paper form for a period of ten years, and made accessible only to the treating staff and our Heilpraktiker (alternative health practitioners) (Art. 9(2)(a) GDPR). This consent is voluntary and may be withdrawn at any time with effect for the future; further information is contained in our Privacy Policy.