Privacy Policy

Stand / Last updated: 2026-08-03

This is a courtesy translation. Only the German Datenschutzerklärung is legally binding.

1. Controller

Thomas Kraaibeek
Wilhelmstr. 20, 48149 Münster, Germany
Email: kontakt@cronloom.io
Phone: +49 1590 6269275
Further details in the Impressum.

We are not legally required to appoint a data protection officer and have not done so. Please direct all privacy questions to the address above.

2. Processing activities

2.1 Visiting the website

Our server processes technically necessary connection data (IP address, date and time, resource requested, volume transferred, status code, referrer, browser and operating system). Purpose: delivering the page, stability and security. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in secure, trouble-free operation. Retention: server logs are deleted after 14 days.

2.2 Account and use of the Service

For an account we process your name and email address and, depending on how you sign in, a password (stored only as a hash) or the identifier of your Google or GitHub account. In use, we process the content you enter: time entries, clients, projects, rates, budgets and settings. Purpose: performing the contract. Legal basis: Art. 6(1)(b) GDPR. Retention: until you delete your account, then erased within 30 days unless a statutory retention duty applies. Providing this data is necessary to conclude the contract; without an email address we cannot create an account.

2.3 Sign-in with Google or GitHub

If you sign in via Google or GitHub we receive your email address, name and a user identifier. Google and GitHub are independent controllers for the processing on their side. Legal basis: Art. 6(1)(b) GDPR.

2.4 Google Calendar connection (optional)

You can voluntarily connect your Google Calendar to turn appointments into time entries. We request read-only access to your calendars and store the access and refresh tokens issued by Google in order to maintain the connection. Legal basis: Art. 6(1)(a) GDPR (consent, given by granting access). Retention: until you disconnect it in the settings or delete your account. You may withdraw consent at any time with effect for the future; this does not affect the lawfulness of processing carried out beforehand.

Limited Use of Google user data: CronLoom’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use your calendar data solely to provide the features you asked for in CronLoom. We do not transfer it to third parties except as necessary to provide the service, for security purposes, or to comply with applicable law. We do not use it for advertising, and we do not allow humans to read it unless you have given explicit consent, it is necessary for security or to resolve a technical problem, or the law requires it. Calendar data is not used to train generalised AI models.

2.5 Email

We send contract-related email (password resets, running-timer reminders, weekly summaries, budget alerts) via the provider Scaleway (Transactional Email, Paris). Legal basis: Art. 6(1)(b) GDPR and, for summaries and alerts, Art. 6(1)(f) GDPR — our legitimate interest in keeping you informed about your tracking. Every such email contains an unsubscribe link and the preferences can be changed in your account at any time.

2.6 Reach measurement with Plausible

On our website we measure reach using Plausible Analytics, which we run on our own server in Germany (analytics.kraaibeek.tech); no data is transmitted to the vendor or any third party. We record the page requested, the referrer, an approximate country-level location, and coarse device and browser information. No cookies are set and no cross-device identifiers are created. To recognise repeat visits within a single day, a hash of IP address and browser signature is generated server-side; it rotates daily and cannot be reversed, and the IP address itself is not stored. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in privacy-preserving reach measurement without profiling. Retention: aggregated statistics only, no individual profiles.

2.7 In-app product analytics

Inside the application we currently run no product analytics and no automatic pageview tracking, so URLs containing access tokens — such as shared client reports — cannot enter an analytics system in the first place. Should we change that, we will update this policy beforehand.

3. Recipients and processors

Beyond this we disclose personal data only with your consent or where legally required. We do not sell data and use no advertising networks.

4. Transfers to third countries

No personal data is transferred to countries outside the European Union. Hosting (Hetzner, Germany) and email delivery (Scaleway, France) both take place entirely within the EU. Should that ever change, we will update this policy and name the Art. 46 GDPR safeguards together with how to obtain a copy of them.

5. Retention

We keep personal data only as long as necessary for the purposes described. Account and content data are deleted within 30 days of the contract ending. Once we issue invoices, the relevant records become subject to statutory retention periods — accounting records are kept for eight years under German tax law, running from the end of the calendar year in which the record arose. During that period processing is restricted to storage.

6. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to withdraw consent with effect for the future (Art. 7(3)).

Right to object under Art. 21 GDPR: You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6(1)(f) GDPR. This applies in particular to reach measurement and product analytics. We will then stop processing unless we can demonstrate compelling legitimate grounds that override your interests. An informal message, for example by email to kontakt@cronloom.io, is sufficient.

You can also export and delete your data yourself under Settings → Privacy & data.

You further have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.

7. Processing on behalf of our users

When you record data about your own clients in CronLoom, you are the controller and we act as processor under Art. 28 GDPR. We provide a data processing agreement free of charge on request at kontakt@cronloom.io.

8. Cookies

We set one strictly necessary session cookie for sign-in; it is essential for the service you requested and therefore requires no consent. We set no advertising or tracking cookies.

9. Changes to this policy

We update this policy when our processing or the legal situation changes. The version published on this page applies.