Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Picsure GmbH ("we") processes personal data when you use Fahrzeugschein24 (the "Service"), in accordance with the EU GDPR and the German Federal Data Protection Act (BDSG). Fahrzeugschein24 is a brand of Picsure GmbH; Picsure GmbH is the responsible controller.

1. Controller

Picsure GmbH, Heidenkampsweg 58, 20097 Hamburg, Germany. Represented by Enrico Bolloni. Email: support@fahrzeugschein24.de.

1a. Data protection officer

Our data protection officer is Florian Bischof. You can reach him at datenschutz@fahrzeugschein24.de, or by post at the address above marked "Datenschutzbeauftragter".

2. What data we process

3. Purposes & legal bases

We process data to provide the Service and perform our contract with you (Art. 6(1)(b) GDPR), to operate, secure and improve the Service and prevent misuse (legitimate interests, Art. 6(1)(f) GDPR), and to comply with legal obligations (Art. 6(1)(c) GDPR). Where we rely on consent, you may withdraw it at any time (Art. 6(1)(a) GDPR).

4. Documents you upload

Documents uploaded for extraction are processed to read and return the contained fields as structured data. Uploaded images are processed in memory only and are not written to disk; only the extracted data and log records are stored. If you enable the optional fraud detection, documents are additionally checked for manipulation; the cross-document duplicate check compares documents only within your own account and stores exclusively salted one-way hash values (SHA-256), not the documents themselves.

5. Processing on your behalf (DPA)

Where uploaded documents contain personal data, we act as processor and you as controller. A data processing agreement pursuant to Art. 28 GDPR governs that processing (/avv).

6. Hosting & location

The Service is hosted in Germany. Documents you upload for extraction are processed exclusively on servers within the European Union — text recognition runs against the EU regional endpoint of our OCR provider. Account and billing data, as well as operational logs and error reports, are additionally processed by providers in the United States (see sections 7, 7a and 7b); those transfers require appropriate safeguards under Art. 44 et seq. GDPR.

7. Disclosure & sub-processors

We do not sell personal data. We disclose data only to service providers acting on our instructions, where required by law, or with your consent. The sub-processors we currently engage are: Hetzner Online GmbH (Germany) — hosting of our servers (application and reach measurement); Google Cloud via its EU regional endpoint (EU processing location, US parent company) — text recognition on uploaded documents; Resend (USA) — transactional email; Lemon Squeezy (USA) — checkout, payment and invoicing; GitLab — source code, build and container registry (no customer data); Better Stack, Inc. (USA) — availability monitoring, status page, operational logs and error reports (see section 7b). Not part of this list is the optional sign-in with a Google account: there, Google does not act on our instructions but as a separate controller — see section 7a. We inform customers of intended changes to this list.

7a. Signing in with a Google account

You may optionally register and sign in with a Google account. This is voluntary: signing in with an email address and password remains fully available, and as long as you do not click „Sign in with Google“, no data is transmitted to Google.

When you do, we redirect you to Google. In doing so, Google learns your IP address, technical details of your browser, and the fact that you wish to sign in to Fahrzeugschein24. For that processing Google is a separate controller (Art. 13(1)(e) GDPR); there is no processor relationship for it. The contracting entity for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; a transfer to Google LLC in the United States may occur. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the European Commission (Art. 45 GDPR). Google’s own privacy policy applies in addition (policies.google.com/privacy).

After you confirm at Google, we receive from them a pseudonymous user identifier issued for Fahrzeugschein24 only, your email address together with an indication of whether Google considers it verified, and the name held there. Of these we store only the identifier, the email address at the time of linking, and the times of linking and of the last sign-in. We do not store access or refresh tokens. We neither request nor receive access to your email, contacts, calendar or files.

The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR) — you choose this sign-in method yourself — together with our legitimate interest in a secure sign-in and in preventing account takeover (Art. 6(1)(f) GDPR). We neither need nor obtain consent under Art. 6(1)(a) GDPR for this.

The flow sets a short-lived cookie that serves solely to secure the sign-in and expires afterwards. It is technically necessary to protect the process against tampering (Section 25(2)(2) TDDDG).

You can disconnect the link at any time in your account under Settings → Security; if it is your only sign-in method, set a password first. Deleting your account removes the link as well.

7b. Operations monitoring & error analysis

So that we notice and fix outages and errors quickly, we use services of Better Stack, Inc. (USA). Better Stack regularly calls our website, web app and API from outside to check that they are reachable, and hosts our status page at status.fahrzeugschein24.de. In addition, our servers send operational logs and error reports to Better Stack.

Operational logs contain the time, the requested address without parameters, the status code, response times and technical messages of the application. Before transmission we shorten IP addresses by their last byte and remove email addresses, access keys and tokens. Error reports contain the type of error, the error message, the affected place in the program and technical details of browser, operating system and server, but no form input, cookies or request headers. Both are filtered so that they contain no content of uploaded documents.

If an error occurs in your browser while you use the web app, your browser sends the error report directly to Better Stack. Your IP address is transmitted for technical reasons but is not included in the report. The website (fahrzeugschein24.de) sends nothing from your browser. When you open the status page, Better Stack as its host processes your IP address and technical details of your browser.

The data is stored in data centres in the United States. Better Stack is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the European Commission (Art. 45 GDPR), and in the alternative on standard contractual clauses (Art. 46(2)(c) GDPR). Operational logs are deleted after 3 days, error reports after 90 days. The legal basis is our legitimate interest in the secure and uninterrupted operation of the Service (Art. 6(1)(f) GDPR); you may object at any time (Art. 21 GDPR).

8. Retention

We retain personal data only as long as necessary for the purposes described here, for the duration of your account, and as required by statutory retention obligations. Uploaded document images are not retained at all — they exist only in memory for the duration of the request. Extraction records and log data are retained for the lifetime of your account.

9. Your rights

Subject to the conditions of the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21), and to lodge a complaint with a supervisory authority. Two of these you can exercise yourself at any time in your account under Settings → Security: download all your data as JSON (Art. 20) and delete your account (Art. 17). For everything else, contact datenschutz@fahrzeugschein24.de.

10. Security

We use appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, and continually review our safeguards.

11. Cookies, fonts & analytics

This website sets no cookies. The language follows from the page address (German without a prefix, English under /en), so nothing has to be stored on your device for it. Because we neither store nor read information on your device, no consent under Section 25 TDDDG — and therefore no cookie banner — is required. We use no advertising cookies, no third-party trackers and no cross-site tracking.

For reach measurement we use Umami, analytics software we host ourselves on our own server in Germany. Umami works without cookies and stores no data on your device. It records page views and interactions (for example which button was clicked), the referring page and the campaign parameters of the link you followed, plus technical data such as browser, operating system, screen size, language and — derived from your IP address — your country. Your IP address itself is neither stored nor passed on, and the data is not used to identify you personally. Nothing is transferred to third parties. The legal basis is our legitimate interest in the statistical evaluation and needs-based improvement of our website (Art. 6(1)(f) GDPR); you may object at any time (Art. 21 GDPR). We honour the "Do Not Track" setting of your browser: when it is enabled, no measurement takes place.

Web fonts are self-hosted on our own servers, so no data is transferred to third parties to display the site.

12. Changes

We may update this Privacy Policy to reflect changes to the Service or legal requirements. The current version is always available on this page.