Privacy policy

Learn what data is processed, why it is needed and what rights you have.

Last changed: 20 September 2026

If the versions differ, the German version prevails. The English translation is provided for guidance.

1. Controller

The operator identified below is responsible for processing personal data.

Address
Deutschland
Contact
Not settled yet.
Competent supervisory authority
Not settled yet.

2. Principles

The application limits data collection to what is needed for accounts, bookings and secure operation.

  • No analytics or advertising trackers are included. Fonts, images and application scripts are served through the application.
  • Personal booking details, exact stay addresses and issuing-authority information are stored encrypted. The provider account email address is stored for sign-in.
  • Passwords are hashed with Argon2id and are not stored in plain text.
  • Cryptographic comparison values are used for certain lookups without exposing the original content.
  • Booking pages and appointment details instruct search engines not to index them. This does not replace access controls.

3. A provider's account

Provider and guest accounts are separate. We store an email address, a secure password hash, confirmation timestamps and expiring sessions. Guests additionally confirm registration and password sign-in with a one-time email code stored only as a verification hash. Guests can save personal booking links and link their own appointments.

  • An email address for sign-in and notifications, and a password hash.
  • An encrypted setup key if two-factor authentication is enabled.
  • Display name, introduction and an optional portrait.
  • Offers with descriptions, durations and prices.
  • Availability, breaks and blocked periods.
  • Tour stops with city, dates and time zone. Exact addresses are stored encrypted and shared after a confirmed booking according to booking settings.

The legal basis is Art. 6(1)(b) GDPR: the processing is necessary for the user agreement. Without these details no account can be kept.

4. Verification

The following verification information is processed before an account is approved:

  • Identity check: verification service, reference number, result and timestamp.
  • Registration under section 3 ProstSchG: issuing authority, issue date and validity. The authority is stored encrypted.

A registration under the Prostitute Protection Act says something about a person's sex life and is therefore data under Art. 9 GDPR. It is processed solely on the basis of explicit consent under Art. 9(2)(a) GDPR, given when it is entered and revocable at any time with effect for the future. Without it no activation is possible; the account remains but takes no appointments.

Identity document images remain with the external verification service. To establish ownership, we compare confirmed name and birth details with the private submission on the server. Legal name, date of birth, address, contact information and professional documents are stored securely and encrypted for review; they are not part of the public profile.

5. Bookings by customers

The following information is processed for a reservation:

  • An encrypted email address for confirmation, reminders and any cancellation notice.
  • An optional name and phone number, also stored encrypted.
  • Appointment time, selected offer, duration and payment status.
  • The timestamp of consent to the immediate start of the reservation service.

Processing to carry out the booking is based on Article 6(1)(b) GDPR. The relevant provider can view the appointment, offer and contact details in their private workspace.

6. Payment

A fee of ten euros is specified per reservation. When a payment service is connected, it processes the payment. The application stores the reference number and payment status, not card details.

Payment service provider
Payments are currently simulated. No money is transferred and no payment details are collected.

Appointment management and calendar exports

Questions, change requests and replies are encrypted and associated with the relevant booking. They are accessible to the provider and the person with the valid appointment link. Their content and associated delivery copies are removed when the booking’s configured retention period expires. The preference for email reminders is also saved with the booking.

A calendar download only includes a neutral title and the appointment’s start and end times. Providers can create a private calendar link and voluntarily subscribe to it through Google, Microsoft, Apple or another calendar service. Anyone with the link can retrieve these appointment times. Replacing or disabling the link does not delete copies already stored by the calendar service. Further processing depends on the settings and terms of the chosen calendar service.

Password recovery and email confirmation use expiring, single-use links. The database stores a verification hash of the link; the message prepared for delivery is encrypted. A password reset ends existing sessions. Account exports contain personal profile settings and may include tour addresses, and should be stored securely.

The selected gender, including a custom description where provided, is required and public on provider profiles. Sexual orientation is optional, stored encrypted, and published only when the separate visibility switch is enabled. Without that switch, the selection is not sent to guests.

7. Sending mail

Email addresses are passed to the mail service for confirmations, reminders and cancellations. These messages contain no advertising or tracking pixels.

Delivery route
Not settled yet.

8. Serving the site

To deliver and secure the website, the hosting service processes technical data such as IP address, time, requested address and browser identifier. The legal basis is Article 6(1)(f) GDPR.

Serving
Vercel Inc., Vereinigte Staaten
Name resolution and routing
Cloudflare, Inc., Vereinigte Staaten

Both services are based in the United States. The transfer relies on the European Commission's adequacy decision of 10 July 2023 for the EU-US Data Privacy Framework, supplemented by the Commission's standard contractual clauses.

9. Cookies

The following cookies support sign-in, language selection and age confirmation. They are not used for advertising or cross-site tracking.

  • lt_session — Maintains sign-in to the provider area. Duration: until sign-out, at most thirty days
  • lt_guest_session — Authentication in the private guest area Duration: until sign-out, at most thirty days
  • lt_guest_pending — Protected pending state until the email code is entered Duration: 10 minutes
  • lt_login_pending — Links the current sign-in attempt between password and second-factor verification. Duration: a few minutes
  • lt_totp_setup — Supports the current two-factor setup process. Duration: a few minutes
  • lt_operator — Maintains sign-in to the operator area. Duration: eight hours
  • lt_age — Records age confirmation for booking pages. Duration: thirty days
  • lt_age_embed — Records age confirmation in the embedded booking form. Duration: thirty days
  • NEXT_LOCALE — Remembers the chosen language. Duration: one year

Strictly necessary cookies do not require separate consent under section 25(2)(2) TDDDG.

10. Audit log

Security-relevant events, including sign-ins, account changes, approvals, suspensions and payment responses, are logged. Entries can be added but not subsequently edited or deleted.

Passwords, session keys, setup keys and one-time codes are excluded from logging.

11. How long things are kept

  • Personal booking data is deleted 30 days after the appointment by default. Providers can change this period in their settings.
  • Unpaid reservations expire after the configured payment window.
  • Rate-limiting entries are deleted after 24 hours.
  • Account data is kept until the provider account is deleted. Related records are removed with it.
  • Security logs are retained for audit purposes and contain no real names.

12. Your rights

You may exercise the following rights in particular against the controller:

  • Access to the data stored about you (Art. 15 GDPR).
  • Rectification of incorrect data (Art. 16 GDPR).
  • Erasure (Art. 17 GDPR).
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR).
  • Objection to processing based on legitimate interests (Art. 21 GDPR).
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR).

You may also complain to a data protection supervisory authority, particularly in your usual place of residence.

13. Obligation to provide data

Required information is needed for accounts and bookings. The relevant feature cannot be used without it. Other information is optional.

A person decides whether to approve an account. No automated individual decision-making, including profiling under Article 22 GDPR, takes place.

14. Changes

This notice is updated when relevant changes are made to the application. The date above identifies the current version.