Skip to content
unitee
Events
Events entdeckenBerlinBrandenburgHamburg
For familiesFor providers
Guides
About us
DE — Deutsch / EN — English
ContactGet the app
Events
Events entdeckenBerlinBrandenburgHamburg
For families
For providers
Guides
About us
Contact
DE — Deutsch / EN — English
Get the app

Privacy policy

Sections 1 to 14 match the privacy policy published in the Unitee app word for word. The sections after that apply in addition to this website.

Version
v1.3
Effective from
September 17, 2026
Operator
Joana Noack & Stefanie Schalitz GbR, Hosemannstr.22, 10409 Berlin
Applicable law
GDPR (EU) 2016/679, TTDSG/TDDDG requirements for device storage, and applicable German law
Version (website part)
v1.0
Website part effective from
22 September 2026

1. Controller and contact

Unitee is operated by Joana Noack & Stefanie Schalitz GbR, Hosemannstr.22, 10409 Berlin. If you have questions about privacy or want to exercise your rights, email us at hello@uniteeapp.de.

2. What this policy covers

Unitee is a mobile app that helps parents, guardians, and other family-oriented users discover family-friendly places, events, and support nearby. This policy explains what personal data we process, why we process it, where it is processed, and how long we keep it.

3. Guest use of the app

If you use Unitee as a guest, the app can request your device location to center the map around you. The GPS coordinates are used on the device only and are not written to Firestore or uploaded to our servers. The legal basis is Art. 6(1)(b) GDPR because the location is processed only to provide the map function you request.

Guest access currently also uses anonymous Firebase Authentication so the app can keep a temporary signed-in session and record your acceptance of the legal documents. We store a consent record in Firestore under your anonymous user account with the accepted privacy-policy version, terms version, app version, timestamp, and anonymous user ID. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is being able to prove that the legal documents shown in the app were accepted.

4. Registered accounts and profile data

When you register with email and password, Firebase Authentication processes your email address, password hash, and email-verification status. We do not store your password in Firestore. The legal basis is Art. 6(1)(b) GDPR because this processing is necessary to create and manage your account.

In Firestore we store your account profile under users/{uid}. This currently includes first name, last name, display name, email address, role, provider company or organization name where applicable, subscription status, city, optional postal code, country, reminder settings, push-token list, saved-events version number, optional deletion scheduling fields, and timestamps for creation or updates. The legal basis is Art. 6(1)(b) GDPR because this data is necessary to provide the account-based features of the app.

During sign-up, we ask you for your city. You can also optionally provide your postal code. We store this location information in your profile so we can understand where registered users are located and use that information when deciding which cities to support next. The legal basis is Art. 6(1)(b) GDPR for providing location-aware account features and Art. 6(1)(f) GDPR for our legitimate interest in product planning based on city-level demand.

If you register as a provider, we ask for a company or organization name. We use it to identify provider accounts, show submitted event ownership internally, and review provider-submitted events. The legal basis is Art. 6(1)(b) GDPR because this processing is necessary for the provider account and event submission feature.

5. Provider-submitted events and review workflow

Providers can create events in the app. Provider event documents are stored in the providerEvents collection and currently include provider ID, title, description, date and time, address and geocoding data, price/free status, age range, tags, image URL, website URL, Instagram URL, recurrence information, review status, and timestamps.

New or edited provider events are reviewed before they are published in the public events list. For review, our Cloud Functions queue an internal review email that includes provider name, provider company or organization name, provider email address, event title, description, age range, tags, website, Instagram, location, and secure approve/reject links. The legal basis is Art. 6(1)(b) GDPR because this review is necessary to provide the provider event submission feature and protect the quality and safety of the public event list.

Approved provider events are mirrored into the public events collection and become visible to app users. Rejected or pending provider events remain visible to the provider account but are not published in the public event list.

6. Saved events, reminders, and consent records

If you save an event, we store a document in users/{uid}/savedEvents containing the event ID, a saved flag, and an update timestamp. We also store a saved-version counter in your user document so the app can synchronize your saved list between devices. The legal basis is Art. 6(1)(b) GDPR.

If you enable push reminders, we store your reminder preference settings in Firestore together with one or more Expo push tokens in your user document so reminders can be delivered to your device. The legal basis is Art. 6(1)(a) GDPR because these reminders are optional and switched on by you. We no longer send reminders by email.

When you accept the Privacy Policy and Terms of Service, we store a consent record in a Firestore subcollection with the accepted versions, app version, and timestamp. For guest users, the anonymous account ID is also stored in that consent record. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is documenting acceptance of the legal texts and defending legal claims if needed.

7. Profile photos and Firebase Storage

If you upload a profile photo, the image is stored in Firebase Storage at users/{uid}/avatar.jpg and the download URL is saved in your Firebase Auth profile and Firestore profile. The legal basis is Art. 6(1)(b) GDPR because the upload is part of the profile feature you choose to use.

8. Emails, push notifications, and local device storage

We send service emails needed to run your account, such as email-verification messages and password-reset emails. The legal basis is Art. 6(1)(b) GDPR.

We also send or queue operational emails needed to run the provider review workflow, including internal review emails and, where implemented, provider notifications about approval or rejection. The legal basis is Art. 6(1)(b) GDPR.

Optional saved-event push reminders are sent only if you turn them on in the app. The legal basis is Art. 6(1)(a) GDPR. You can switch them off in the app settings at any time. On iOS or Android, push notifications also require device-level permission. We no longer send reminders by email.

The app stores a small amount of information locally on your device in AsyncStorage to make core features work. This currently includes event and place cache data, saved-event cache data, reminder-setting cache data, a cached Expo push token, consent-related ad state, and technical state used for guest access. We use this storage only for app functionality that you request. Where German device-storage rules apply, the storage is used because it is technically necessary to provide the app feature you chose to use.

9. Recipients, processors, and international transfers

We use Google Firebase as our main processor for authentication, database hosting, cloud functions, and file storage. Firestore data for this app is currently hosted in europe-west10. Profile photos in Firebase Storage are currently hosted in us-central1. Firebase Authentication and other Google infrastructure may process data outside the European Economic Area, including in the United States.

Email delivery is handled through our Cloud Functions and the email service provider Mailjet (Mailjet SAS, Paris, France, part of the Sinch group) acting as a processor. We transmit the recipient address together with the subject and body of the message to Mailjet. For account emails, the body contains your first name and a one-time verification or password link. Mailjet states that it processes email data in data centres in the European Union and relies on the EU Standard Contractual Clauses for intra-group transfers where required.

Emails that carry no security link are briefly stored as queue documents in the Firestore mail collection before delivery. Those documents are not readable by app clients and are deleted by a TTL rule. Emails containing verification or password links are deliberately kept out of that queue and sent directly, so the one-time link is never stored.

To prevent abuse of our email sending, we keep counters for verification and password email requests in the Firestore mailRateLimits collection. The email address and the requesting IP address are not stored in clear text; they only enter the document identifier as a cryptographic hash. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is preventing our app from being used to send bulk email to other people's mailboxes.

Verification and password links open a page we operate, served through Firebase Hosting. Opening it causes Firebase Hosting to process technically necessary connection data such as your IP address. The page itself communicates only with Google's Identity Toolkit API in order to redeem the link.

For ad delivery in the free version of the app (on Android and iOS), we may also use Google AdMob and Google's User Messaging Platform (UMP). On iOS we additionally ask for App Tracking Transparency (ATT) permission before any advertising identifier can be used; without your permission, ads are served non-personalized. These services may process advertising identifiers, consent signals, device information, and ad-request metadata to decide whether ads can be shown and whether they must be non-personalized. The legal basis is Art. 6(1)(a) GDPR where consent is required and Art. 6(1)(f) GDPR for strictly necessary anti-abuse and delivery operations where applicable.

For usage analytics, Google Ireland Limited acts as our processor for the event data described in section 13 in Google Analytics for Firebase. Processing outside the European Economic Area can occur here too, for which Google states it relies on the EU Standard Contractual Clauses.

Where personal data is transferred outside the EEA, Google states that it uses appropriate safeguards such as the EU Standard Contractual Clauses where required. You can read Google's Privacy Policy here: https://policies.google.com/privacy.

We do not sell your data. We do not share it with data brokers or social-media SDKs.

10. Retention periods

Device location used to center the map is processed only during the relevant app session and is not stored on our servers.

Local device cache data stays on your device until it is replaced, cleared, you sign out, or you remove the app, depending on the feature.

Account data in Firebase Auth, Firestore profile data, provider event submissions, saved events, reminder settings, push tokens, and profile photos are kept while your account remains active.

Provider event review tokens are temporary and are intended to expire after a short review window. Queued email documents, abuse-prevention counters in mailRateLimits, and reminder locks are deleted according to the configured Firestore TTL rules.

If you request account deletion in the app, your account is currently marked for deletion and then permanently deleted after 30 days unless you cancel the deletion during that period. You can also request deletion by email at hello@uniteeapp.de. We will delete or anonymize personal data unless we must keep it longer to comply with the law or to establish, exercise, or defend legal claims.

In Google Analytics for Firebase, event data is deleted automatically after 2 months and user-level data after 14 months. Aggregated report data that can no longer be traced to an individual device is not affected.

Consent records are kept for as long as needed to document acceptance of the legal documents and to defend legal claims, unless a shorter retention period is required by law.

11. Your rights under the GDPR

You have the right to request access to your personal data, rectification of inaccurate data, erasure of your data, restriction of processing, data portability, and to object to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR. Where processing is based on consent, you can withdraw that consent at any time with effect for the future.

You also have the right to lodge a complaint with a supervisory authority, especially in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. If you are in Germany, you can contact the competent state data-protection authority.

12. How to request deletion or other privacy actions

For access requests, corrections, deletion requests, data-export requests, objections, or questions about this policy, email hello@uniteeapp.de. To help us verify your request, please contact us from the email address linked to your account where possible.

13. Usage analytics and limited advertising

To improve the app we use Google Analytics for Firebase (Firebase Analytics, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). It measures in aggregate how the app is used: for example how many people open it, which areas are visited, and whether flows such as registration, a search, or saving an event are completed. The legal basis is your consent under Art. 6(1)(a) GDPR and, for the device storage this requires, Section 25(1) TDDDG.

Usage analytics is switched off by default. It only starts once you agree to the question "May we measure how the app is used?" in the app. That question is separate from advertising consent; agreeing to advertising does not switch usage analytics on. Without your agreement we collect no analytics data, including no automatically generated events. You can change your choice at any time with effect for the future, in the app settings under "Privacy" using the "Allow usage analytics" switch.

What is processed: a randomly generated app-instance ID, device and operating-system information, the app version, the approximate region derived from your IP address, and the events we define together with their parameters. Those parameters include the identifier of the event or place concerned, its category and city, the filter values you selected, and whether you use the app as a family or as a provider.

What is never sent to Firebase Analytics: name, email address, phone number, exact address, credentials, free-text profile content, information about children, precise location coordinates, and the terms you type into the search field. We set neither a user ID nor an advertising ID in Firebase Analytics. The analytics data is configured so that it is not used for advertising audiences or personalized advertising.

In the free version (Android and iOS), we may also show limited Google AdMob ads on discovery screens. Where consent is required, we request it before allowing personalized ad serving and default to non-personalized ads until that consent state is known. We do not sell behavioral data.

14. Changes to this policy

We may update this Privacy Policy if the app, our processors, or the law changes. If the changes are material, we will publish the updated version in the app before it takes effect.

15. Additional information for the uniteeapp.de website

The sections above describe the processing that takes place in the Unitee app. The following sections apply in addition to your visit to our website at uniteeapp.de. The controller is the entity named in section 1.

No account is required to use the website. We collect no registration, profile or location data there.

16. Hosting and server log files of the website

The website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA, and its European group companies as our processor. When a page is requested, Vercel processes technical connection data, in particular the IP address, the time of the request, the URL requested, the HTTP status code, the amount of data transferred, the referrer and browser and device details from the user agent.

This processing is necessary for the website to be delivered at all and also serves the stability and security of the service. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is the secure and uninterrupted operation of the website.

Processing outside the European Economic Area, in particular in the USA, may take place. Vercel bases those transfers on the EU standard contractual clauses. Details and the current list of sub-processors are published by Vercel at https://vercel.com/legal/privacy-policy.

17. Consent management on the website

On the website we obtain consent for analytics and advertising through Google’s consent message (Google Funding Choices, shown as "Privacy & messaging" in Google AdSense). That message is a consent management platform certified under the IAB Transparency and Consent Framework (TCF) and is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Until you have made a choice in that message, analytics and advertising storage are switched off. Technically we use Google Consent Mode for this: the signals ad_storage, ad_user_data, ad_personalization and analytics_storage are set to "denied" when the page loads and are only set to "granted" after your consent. Without your consent, Google Analytics and Google AdSense neither store nor read cookies or comparable identifiers on your device for analytics or advertising purposes.

To store your decision and the resulting TCF consent string, Google places entries on your device. That storage is necessary to apply and to evidence your choice. The legal basis is Art. 6 (1) (c) in conjunction with Art. 7 (1) GDPR and, as far as storage on your device is concerned, Section 25 (2) no. 2 TDDDG.

You can change your decision at any time with effect for the future. The footer of every page contains a "Privacy settings" item that reopens the consent message. The vendors involved under the TCF can be inspected in the message itself; the complete list is maintained by IAB Europe at https://iabeurope.eu/vendor-list-tcf/.

18. Audience measurement with Google Analytics 4 on the website

On the website we use Google Analytics 4 (property G-36EM3H2FRT) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as our processor, to measure in aggregate form how the website is used.

The data collected includes the pages and page titles requested, the time and duration of the visit, the referrer, approximate location derived from the truncated IP address, details about browser, operating system and device type, and the events triggered. Besides page views (page_view) we record the events click_app_store and click_google_play when you click one of our links to the App Store or Google Play; all that is recorded is where on the page the click happened and which store it pointed to.

IP anonymisation is enabled, so Google truncates your IP address and does not store it together with the analytics data. We transmit no names, email addresses or other direct identifiers to Google Analytics, and we do not combine the analytics data with account data from the app.

The legal basis is your consent under Art. 6 (1) (a) GDPR and, for the storage of and access to information on your device that this requires, Section 25 (1) TDDDG. Without consent no analytics using cookies or similar identifiers takes place. In Google Analytics, event data is deleted automatically after 2 months and user-level data after 14 months. Aggregated reporting data that can no longer be attributed to a device is not affected.

19. Advertising on the website with Google AdSense

We embed Google AdSense, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to fund the free service. The script it requires is loaded when the page loads, because it is also what displays the consent message described in section 17.

At the time this policy was last updated, our AdSense account is still under review by Google, so no ads are served on the website yet. Once ads are served, Google may use cookies and similar identifiers to select ads, cap their frequency, measure clicks and impressions and detect abuse. The data processed then includes advertising identifiers, your truncated IP address, browser and device details, the page requested and your consent signals.

Personalised advertising only takes place if you consented in the consent message. Without consent, no advertising cookies are set and any ads served are non-personalised. The legal basis is your consent under Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG.

Google processes part of the data from ad serving and audience measurement as a controller in its own right. Google publishes information about this at https://policies.google.com/technologies/partner-sites and https://business.safety.google/adscontrollerterms/.

20. Transfers to third countries when using the website

When Google Analytics, Google AdSense and the consent message are used, data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework; in addition, Google relies on the EU standard contractual clauses.

Despite those safeguards, access to transferred data by US authorities cannot be ruled out entirely. Your consent expressly extends to that risk, insofar as the processing is based on Art. 6 (1) (a) GDPR and the transfer on Art. 49 (1) (a) GDPR.

21. Storage in your browser when visiting the website

Beyond the consent, analytics and advertising purposes described above, we store no cookies for marketing or tracking purposes. Technically necessary storage is limited to applying your consent decision; the legal basis for that is Section 25 (2) no. 2 TDDDG.

Fonts and all other design assets of the website are served from our own servers, so no connection to external providers is made for them.

© 2026 Jofi Labs. All rights reserved.

unitee

More time together. Less time searching.

Instagram

Product

For familiesFor providersSupport us

Unitee

About usGuidesContact

Legal

PrivacyImprint

© 2026 Jofi Labs · Unitee