Back

Legal

Privacy Policy

How we handle personal data on the Nami Club website at namiclub.de and in the Nami app for iPhone. Part A covers the website, Part B the app, Part C applies to both.

1. Controller

Nami Club UG (haftungsbeschränkt)
Wesendonkstraße 50
81925 München
Germany
Represented by: Sarah Blattmann, Geschäftsführer
Email: hello@namiclub.de

Part A: the website

2. Data we collect on the website

When you sign up for early access, we process the information you submit through the form:

  • Name
  • Email address
  • Submission timestamp, and the time you confirmed your address
  • Which form you came from (member early access or partner inquiry), so we send the right confirmation
  • The consent wording shown to you at the time, stored so we can show what you agreed to

Providing your name and email is voluntary. Without them, we cannot add you to the early-access list or send you launch updates. There is no other consequence to refusing.

3. Purpose of processing

We process this data to manage the Nami Club early-access list, send a one-time welcome confirmation, and contact you when launch communication is available. We do not use it for marketing unrelated to Nami Club.

4. Legal basis

The legal basis for processing is your consent under Art. 6(1)(a) GDPR, given by submitting the signup form. The consent wording sits directly above the submit button, and we store it with your entry so that what you agreed to stays reproducible even after we reword the form.

After signing up you receive one email asking you to confirm your address. We send nothing further unless you confirm, and an entry that is never confirmed is never used to contact you. This protects anyone whose address is entered by somebody else.

You can withdraw your consent at any time by writing to hello@namiclub.de or using the unsubscribe link in any email we send. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

5. Service providers for the website

We use the following processors to operate the website and the early-access flow. Each is bound by a data processing agreement under Art. 28 GDPR.

  • Vercel Inc. (United States), website hosting and serverless functions. The functions that handle your signup are pinned to Vercel's Frankfurt region.
  • Supabase Pte. Ltd. (Singapore), database hosting, running on infrastructure in the EU. Your entry is stored there.
  • Cloudflare, Inc. (United States), content delivery and bot protection in front of our database provider. Reached only by our own servers, not by your browser.
  • Resend, Inc. (United States), transactional email. Used to send the confirmation and welcome emails. Your name and email are passed to Resend strictly to deliver those messages.

Section 15 explains the legal basis for transfers to these providers outside the EU.

6. Server logs

When you visit the website, technical connection data such as IP address, request details, user agent, and timestamps may be processed in server logs. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR. The specific legitimate interest is to operate the website reliably, diagnose technical issues, prevent abuse such as automated signup attempts, and protect the service against attacks. These logs are held by our hosting provider under its own retention settings and then deleted; we do not evaluate them for any other purpose and do not store your email address in them.

7. Storage period for website data

Personal data submitted through the early-access form is stored until you ask us to delete it, or until the early-access program ends and we no longer need the list. Statutory retention obligations may require longer storage in specific cases.

8. Cookies

The website sets no tracking or advertising cookies, uses no analytics, and loads no third-party scripts. Our typefaces are served from our own servers, not from an external font provider. Strictly necessary cookies may be set by our hosting provider for technical operation; these do not require consent under § 25 Abs. 2 TDDDG.

Part B: the Nami app

9. What the app does with your data

The Nami app turns everyday movement into points you can redeem at partner cafés. To do that it needs an account, reads two health values from Apple Health, and stores your points and redemptions on our servers. Below is what we process, why, and on which legal basis. The app has no advertising, and none of the data described here is ever sold, used for advertising, or shared with advertisers or data brokers.

9.1 Account data

You can create an account with an email address and a password, or with Sign in with Apple. We store:

  • Your email address (with Sign in with Apple this may be the private relay address Apple generates for you, if you chose to hide your email)
  • Your name, if you shared it via Sign in with Apple or entered it in your profile. Apple sends the name only on the first sign-in; we store it in your profile so partners can greet you by name when you redeem
  • A password hash, never the password itself, for email sign-up
  • The time your account was created, your role (member or partner staff), and technical session data needed to keep you signed in

Legal basis: performance of the contract with you, Art. 6(1)(b) GDPR. Without an account the app cannot keep a points balance.

9.2 Health data from Apple Health

With your permission, the app reads two values from Apple Health (HealthKit) on your iPhone:

  • Your daily step count
  • Your daily Apple Exercise minutes (the green ring)

We read daily totals only, never individual workouts, routes, heart rate, or any other health category. The app sends the total for each calendar day to our servers, where it is stored per day together with the points it earned, capped at a fixed daily maximum. We keep the last few days so a walk on a day you did not open the app still counts, and so your activity streak can be computed.

We use health data for exactly one purpose: converting your movement into points and showing you your own activity and streak. We never use it for advertising or marketing, never sell it, never pass it to partner cafés or any other third party, and never use it to make decisions about you beyond the points calculation. Partner cafés see only that you redeem a reward, not how you earned it. Health data is stored in our database hosted by Supabase on infrastructure in the EU (Section 12) and is not sent to our analytics or crash-reporting providers.

Legal basis: your explicit consent, Art. 9(2)(a) and Art. 6(1)(a) GDPR, given when you grant the app access in the iOS Health permission dialog. Connecting Apple Health is voluntary; without it the app still works, but you cannot earn points from movement. You can withdraw the permission at any time in the iOS Settings app under Health, Data Access & Devices, Nami. From then on no new health data is read. Data already uploaded stays in your account until you delete it (Section 10) or ask us to.

9.3 Location

When you open the partner map, the app asks for permission to use your location while the app is in use. Your position is used only on your phone, to center the map on you and to show how far each partner café is. It is not stored and not sent to our servers or to anyone else. Legal basis: your consent under Art. 6(1)(a) GDPR, given in the iOS location dialog and revocable at any time in the iOS Settings app. Without it the map simply opens without your position.

9.4 Points, check-ins and redemptions

Every points change (earned from movement, awarded for a check-in at a partner, spent on a reward) is written to a ledger in your account, so you can see your history and we can answer questions about your balance. When you redeem a reward, the app shows a short code that the partner confirms. The partner sees your name and the reward being redeemed at that moment, and we store which reward was redeemed where and when. Partners cannot see your points balance history, your health data, or your email address. Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

9.5 Usage analytics (only with your consent)

During onboarding the app asks whether you want to help us improve it by sharing usage statistics. Only if you say yes does the app record which parts of it you use, for example that you completed onboarding, connected Apple Health or confirmed a redemption, together with your account ID, app version and device model. These events are stored in our own database in the EU (Section 12) and are not sent to any analytics provider. They never contain your step count, exercise minutes, location, email or name. If you say no, or say nothing, nothing is recorded. You can change your choice at any time in the app under Profile. Legal basis: your consent, Art. 6(1)(a) GDPR and § 25 Abs. 1 TDDDG.

9.6 Crash and error reporting

If the app crashes or hits an error, a report is sent to Sentry, our error-monitoring provider. A report contains the technical error, the part of the app it happened in, app version, iOS version and device model, and an IP address at the time of transmission. Reports do not contain health data or your location. We use them solely to find and fix bugs. Legal basis: our legitimate interest in running a stable app, Art. 6(1)(f) GDPR.

10. Deleting your account

You can delete your account yourself in the app under Profile, Delete account. Deletion is immediate and removes your account, profile, health data, points ledger, check-ins and redemptions from our database. Partner cafés keep an anonymous record that a redemption took place, without your name. Points cannot be restored afterwards. You can also ask us to delete your account by writing to hello@namiclub.de.

Deleting the account does not remove the Apple Health data on your phone, which stays under your control in the Health app, and does not withdraw Apple's own record of your Sign in with Apple, which you can manage in your Apple ID settings.

11. Storage period for app data

  • Account data, health data, points and redemptions: for as long as your account exists. Deleted when you delete your account.
  • Inactive accounts: we do not delete accounts automatically. You can delete yours in the app at any time, or ask us to.
  • Usage events: kept while your account exists. When you withdraw consent in the app, no further events are recorded; deleting your account deletes the ones already stored.
  • Crash reports at Sentry: deleted automatically after 90 days.

Statutory retention obligations may require longer storage in specific cases, for example for records of redeemed rewards that we have to keep for accounting.

12. Service providers for the app

We use the following processors to run the app. Each is bound by a data processing agreement under Art. 28 GDPR.

  • Supabase Pte. Ltd. (Singapore), database, authentication and file storage, running on infrastructure in the EU. Your account, health data, points and redemptions are stored there. Supabase does not access this data for its own purposes.
  • Functional Software, Inc. (Sentry) (United States), crash and error reporting (Section 9.6).
  • Apple Inc., for Sign in with Apple and App Store distribution, acting under its own privacy policy. Apple Health data is read locally from your phone; Apple does not receive it from us.

Part C: for the website and the app

13. Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). Where processing rests on your consent, you can withdraw it at any time with effect for the future. To exercise any of these rights, contact:

hello@namiclub.de

14. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Bavaria is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de

15. Transfers outside the EU

Transfers to the United States rest on the European Commission's adequacy decision of 10 July 2023 for the EU-U.S. Data Privacy Framework (Art. 45 GDPR), for those recipients certified under it: Vercel, Cloudflare and Resend. The transfer to Sentry rests on the EU Standard Contractual Clauses included in Sentry's data processing agreement, Art. 46(2)(c) GDPR. Supabase Pte. Ltd. is in Singapore, for which no adequacy decision exists, and is not certified under that framework; that transfer rests on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) under Art. 46(2)(c) GDPR. The data itself stays on Supabase's EU infrastructure; the clauses cover Supabase's support access from outside the EU. You can request a copy of those clauses from us at hello@namiclub.de.

16. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Converting steps and exercise minutes into points follows a fixed, published formula and produces no legal or similarly significant effect. We also do not have a statutory obligation to appoint a data protection officer; for any data protection question, write to hello@namiclub.de.

Last updated

26 August 2026