Privacy policy (Datenschutzerklärung)

As of: 28/09/2026

This is a translation provided for convenience only. The legally binding text is the German version.

Warning: the operator details have not been filled in yet (environment variablesOPERATOR_*— see .env.example). The text below contains placeholders, not real company details. Do not publish this page in production until you have filled in the actual registration details.

1. Controller

⚠️ NOCH ZU ERGÄNZEN, ⚠️ NOCH ZU ERGÄNZEN, ⚠️ NOCH ZU ERGÄNZEN ⚠️ NOCH ZU ERGÄNZEN, Deutschland
Email for data protection enquiries: ⚠️ NOCH ZU ERGÄNZEN

2. Who we are and what this policy covers

Finanzigo is a SaaS platform for invoicing, quotes, expense management and tax overviews for German sole proprietorships (Gewerbe). This policy covers (a) visits to our website, (b) the use of the application by registered users, and (c) the personal data of our users' clients stored in the application (e.g. invoice recipients) — for these, you as the user are the controller under data protection law and we are the processor (see section 8, data processing agreement).

3. Hosting and server logs

When our website/application is accessed, our hosting provider automatically processes technical connection data (IP address, date/time, requested URL, user agent) in server logs in order to provide and secure the service technically. Legal basis: Art. 6(1)(f) GDPR (DSGVO) (legitimate interest in secure operation).

4. Cookies and local storage

We use only technically necessary cookies/storage — no tracking, no advertising or analytics cookies, which is why no cookie consent banner is required (legal basis: § 25(2) TTDSG or Art. 6(1)(f) GDPR):

  • Session cookie (sign-in/authentication, NextAuth)
  • Cookie for the active company (which business/view is currently selected)
  • Cookie for the selected interface language
  • Local storage of the theme preference (light/dark) in the browser

5. Registration and user account

When you register, we process your name, email address and a hashed password (bcrypt — the plain-text password is not stored) in order to give you access to the application. You can also enter personal tax details (federal state, Kirchensteuer, health insurance, marital status, etc.) to enable the tax calculation. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

6. Processing as part of use (invoices, clients, receipts)

As a user, you record in Finanzigo data about your own clients (name, address, USt-IdNr., payment history) as well as receipts/expenses in order to create GoBD-compliant invoices and accounting records. To verify a USt-IdNr., we transmit the country and number to the European Commission's VIES system. Invoice access links for your clients log openings/downloads (time, IP address, browser/device) as the legally required proof of immutability (GoBD) — automated bots/link previews (e.g. Slack, WhatsApp) are filtered out.

7. Payment processing

Card payments for invoices are processed via Stripe Connect — the payment is made directly between your client and your own Stripe account; we only receive status information (paid/failed) and, where applicable, our platform fee. Legal basis: Art. 6(1)(b) GDPR.

8. Data processing on your behalf

Since we process personal data of your clients on your behalf, we conclude a data processing agreement (AVV) with you in accordance with Art. 28 GDPR — available in your company settings. We use the following sub-processors:

ProviderPurposeLocation
Neon (PostgreSQL database)Storage of all application data (invoices, clients, user accounts).EU (eu-central region, Frankfurt) — confirm in the Neon dashboard for your project.
S3 object storage (https://3bb6d5c84485754add4ea1e163372610.eu.r2.cloudflarestorage.com)Storage of attachments (receipts, generated PDF documents).check the location with the provider (recommended: EU)
ResendSending transactional emails (invoices, reminders).USA/EU — check the current Resend DPA
European Commission — VIESVerification of clients' EU VAT numbers (USt-IdNr.) — only the country and VAT number are transmitted.EU

9. Retention period

We keep invoices, receipts and related evidence (event logs) for the statutory retention period of 10 years in accordance with § 147 AO / § 257 HGB (GoBD). Other data (e.g. your account profile) is kept for as long as your account exists and deleted when the account is deleted — except for the records mentioned above that must be retained by law, which then remain solely in your own GoBD export archive downloaded beforehand (see section 10).

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). In practice, we provide tools for this directly in the application: under Settings → Data export you can download a complete data export archive (documents, structured data, audit trail) at any time; under Settings → Delete account you can irrevocably delete your account together with all data (after the mandatory prior export). For all other requests, please contact ⚠️ NOCH ZU ERGÄNZEN.

11. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement.

12. Data security

Transmission is encrypted (TLS). Receipts/documents are stored content-addressed (SHA-256) and immutably. Passwords are stored only in hashed form (bcrypt).

13. Changes to this policy

We update this policy when our data processing or the legal situation changes. You will always find the current version at this address.