Data Protection Statement

homeorganizer processes personal data in order to provide you with household management. This data protection statement informs you about which data is processed, for which purposes, and on which legal basis.

1. Controller

The controller responsible for data processing within the meaning of the GDPR and the revised Swiss Data Protection Act (revDSG) is:

  • Name / company: Philipp Heim
  • Postal address: Bachweistrasse 1B, 9011 St. Gallen, Switzerland
  • Data protection contact: service@homeorganizer.ch
  • Data protection officer: No data protection officer has been appointed.

2. Which data is processed?

Account data:

  • Email address (for login and notifications)
  • First and last name
  • Password (stored only as a secure hash)
  • Language settings, time zone, date format
  • Optional: two-factor authentication

Purpose: authentication, notifications, personalisation.

Household data:

  • Household name
  • Members and their roles

Purpose: multi-user household management.

Financial data:

  • Accounts (name, description, balance, currency)
  • Transactions (date, amount, description)
  • Categories for income and expenses
  • Payees

Purpose: core household accounting functionality.

Document data (if the documents module is used):

  • Documents, folders, tags

Purpose: document storage.

Subscription and payment data:

  • Subscription status, transaction metadata

Purpose: processing of premium subscriptions.

Processing is based on the following legal grounds (GDPR Art. 6 / revDSG):

  • Performance of a contract (provision of the app functions) – GDPR Art. 6(1)(b)
  • Legitimate interest (security, abuse prevention) – GDPR Art. 6(1)(f)
  • Legitimate interest (reach measurement with self-hosted Plausible, see section 8) – GDPR Art. 6(1)(f)
  • Legal obligation (retention of payment records) – GDPR Art. 6(1)(c)

4. How is your data protected?

  • Transport encryption via HTTPS (TLS)
  • Passwords are never stored in plain text, only as a secure hash
  • Particularly sensitive fields are additionally stored encrypted at the application level
  • Hosting on a dedicated server in Switzerland
  • Access restrictions and regular security updates

5. Third parties (processors)

To provide our services we work together with the following providers:

Provider Purpose Data category
Stripe Payment processing for premium subscriptions Payment information, transaction metadata (credit card data is processed directly by Stripe, not stored on our servers)
Microsoft 365 (Graph) Email delivery (verification, notifications) Email address of the recipient

These providers are subject to their own privacy policies and process data only in accordance with our instructions. To provide the service we use processors, including Stripe (payment processing; Stripe, Inc., USA) and Microsoft 365 / Microsoft Graph (email delivery). In doing so, personal data may be transferred to third countries (in particular the USA). Such transfers are based on appropriate safeguards (e.g. EU Standard Contractual Clauses or recognised adequacy/protection mechanisms).

Your data is not sold or used for advertising purposes.

6. Your rights

You have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and to withdraw a consent you have given. You also have the right to lodge a complaint with the competent supervisory authority.

  • You can view and export your data at any time within the app
  • You can delete your user account at any time (password confirmation)
  • You can delete your household (with an option to undo)

Competent supervisory authority: Swiss Federal Data Protection and Information Commissioner (FDPIC/EDÖB), Feldeggweg 1, 3003 Bern, Switzerland.

7. Retention / deletion periods

  • Active data is retained until the account or household is deleted
  • Upon deletion, all associated data is removed from the active systems; a limited retention may technically still persist within backups
  • Personal data is stored for as long as your user account exists. After the account is deleted, the data is deleted unless statutory retention obligations apply (e.g. commercial- or tax-law retention of payment/invoice records for the applicable periods).

8. Cookies and tracking

We do not use any tracking or analytics cookies. For sign-in we store only technically necessary session information in your browser.

For usage statistics we use Plausible Community Edition – self-hosted on our own infrastructure in Switzerland (analytics.homeorganizer.ch). This analytics is cookieless (no tracking cookie, no localStorage identifier) and data-minimising: the events store no directly identifying data – only masked page paths (templates in which, for example, IDs and tokens are replaced), no user ID and no household or finance context. IP addresses are not stored and are processed only transiently/anonymised (no personal profile). There is no transfer to third parties and no transfer to third countries, because the measurement runs entirely on our own infrastructure. The purpose is reach measurement to improve the service; the legal basis is our legitimate interest (GDPR Art. 6(1)(f) or the Swiss FADP).

9. Client-IP addresses at the Traefik edge (operational security)

For operational security and abuse prevention, our reverse proxy (Traefik) at the VM5 edge records the real public IP address of every request in structured access logs. These access logs are shipped via Promtail to our Loki instance on VM2 (in Switzerland) and are kept there for 720 hours (30 days), then deleted automatically.

  • Purpose: error diagnosis and per-client rate limiting.
  • CrowdSec processing: The client-IP addresses stored in the access logs are continuously assessed by our CrowdSec instance (which reads the Traefik access logs directly) against known abuse patterns. When abuse is detected, IP addresses are temporarily blocked. There is no permanent or profile-building analysis.
  • Legal basis: legitimate interest (GDPR Art. 6(1)(f) or the Swiss FADP).
  • No transfer to third parties, no transfer to third countries.
  • Retention: 720 hours from the request; automatically deleted afterwards by the Loki retention regime.

This processing is independent of the usage statistics (section 8): Plausible does not store IP addresses; the storage described here occurs in the Traefik access logs and serves operational and security purposes only.

10. Status of this statement

Last updated: 7 August 2026

If you have any questions about data protection, contact us at:
service@homeorganizer.ch

← Back to home