Privacy Policy
Last updated: September 16, 2026
1. Data Controller
The data controller responsible for processing personal data on this website is:

2. General Notes and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations (in particular the GDPR and the German Federal Data Protection Act, BDSG) as well as this Privacy Policy.
When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This Privacy Policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission over the Internet (e.g., when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
No Tracking / No Analytics Tools
This website is purely informational. As of the current status, we do not use any analytics or tracking tools (e.g., Google Analytics), marketing pixels, or social media plugins.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as inquiries you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
3. Hosting (Oracle Cloud / OCI)
This website is hosted on Oracle Cloud Infrastructure (OCI). For technical reasons, connection data is processed when the website is accessed in order to deliver the website and ensure security and error analysis.
Processed Data (Server Log Data)
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- IP address
- Date and time of the request
- Requested page/file (URL/path)
- Referrer URL (the previously visited page)
- Browser type and version and operating system used
- HTTP status code
This data is not merged with other data sources.
Purposes of Processing and Legal Basis
The collection of this data is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the technically error-free presentation and optimization of our website – for this purpose, the server log files must be recorded. The server log data is stored for a maximum of 7 days and is then automatically deleted. Longer storage only occurs in exceptional cases, provided this is absolutely necessary to investigate specific security incidents (e.g., in the event of a cyberattack). In this case, the data will be kept until the respective incident has been finally clarified.
Data Processing Agreement and Third-Country Transfer
We have concluded a Data Processing Agreement (DPA) with Oracle Cloud Infrastructure (Oracle Corporation). This is a contract mandated by data protection law, which guarantees that Oracle processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
Insofar as data is transferred to the USA or other third countries when using Oracle Cloud, this is based on the adequacy decision of the EU Commission (EU-US Data Privacy Framework) or on standard contractual clauses (SCCs) of the EU Commission.
4. Cookies and Similar Technologies
As of the current status, this website does not set cookies for analytics, tracking, or marketing purposes.
Depending on the technical design of the hosting (e.g., load balancers, DDoS/WAF protection, CDN), technically necessary cookies or similar technologies may be used, which are strictly required for the secure operation of the website.
The storage of these technically necessary cookies or access to them takes place on the basis of Section 25 (2) No. 2 of the German Telecommunications-Digital Services Data Protection Act (TDDDG). The subsequent processing of personal data is based on Art. 6(1)(f) GDPR (legitimate interest in providing the website). Such cookies are not used to create user profiles.
If you do not see a consent prompt (cookie banner) on this website, this means that we currently do not use any tracking or marketing technologies that require consent.
5. Contacting Us by E-Mail or Telephone
If you contact us by e-mail or telephone, your inquiry, including all resulting personal data (name, e-mail address, telephone number, content of the inquiry), will be stored and processed by us for the purpose of processing your request. We do not pass this data on without your consent.
Legal Basis
The processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of the inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested.
Storage Duration
The data you send to us via contact requests will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods (e.g., under the German Commercial Code (HGB) or the German Fiscal Code (AO)) – remain unaffected.
6. External Links
This website contains links to external third-party websites. If you follow an external link, the processing of your data there is the sole responsibility of the respective provider.
7. Your Rights
Under the GDPR, you have the right at any time and free of charge to:
- Information about your stored personal data, its origin, recipients, and the purpose of data processing (Art. 15 GDPR)
- Rectification of incorrect data (Art. 16 GDPR)
- Erasure of this data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
Right to Object (Art. 21 GDPR):
If data processing is based on Art. 6(1)(e) or (f) GDPR (legitimate interest), you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation.
You also have the right to lodge a complaint with a competent data protection supervisory authority (Art. 77 GDPR).
8. RenoStack – App and Web Application
This Privacy Policy also applies to our app RenoStack (iOS, Android) and the associated web application at renostack.stagworks.de. The app and the web application use the same user account and the same project data. RenoStack lets you manage renovation projects with budgets, contractors, quotes, tasks, appointments, receipts and expenses, and share projects with partners.
8.1 Data Processed
- Account data: name, e-mail address and an encrypted credential upon registration. When signing in with "Sign in with Apple" or "Google Sign-In", we receive a user identifier, the released e-mail address and, where available, the display name from the respective provider.
- Guest mode (app only): without an account we only create an anonymous technical identifier; project data then remains exclusively on the device.
- Project data: projects, budgets, contractors, quotes, phases, tasks, appointments, diary entries, planned costs and expenses, including amounts and cost splits between project members.
- Receipts and attachments: photos and documents attached to expenses, quotes or as project documents. In the app they are stored on the device; with RenoStack Pro (and when uploaded via the web application) they are additionally stored in Firebase Cloud Storage (Google) so they are available on all devices and can be shared with project partners. We store the file itself plus its name, size, type, category, upload time and project assignment; attachments are only accessible to members of the respective project. If Pro access lapses, attachments already uploaded are retained and remain accessible; they are deleted as soon as the attachment, the associated entry, the project or the account is deleted.
- Invitations: when sharing a project we generate an invite link with a random token and store the project name, the inviter's user identifier and – once accepted – the invited person's user identifier. Invitations expire after 14 days.
- Purchase data (RenoStack Pro): when purchased in the App Store or on Google Play, we process through RevenueCat the user identifier, e-mail address, display name, product purchased (monthly, annual or lifetime), start, expiry, renewal and cancellation status, and a pseudonymous transaction identifier assigned by the store. We do not receive payment details (card or bank data); they remain with Apple or Google. The resulting Pro status (yes/no, expiry date) is stored in the user profile. Purchases are currently not possible in the web application.
- Login state: authentication tokens stored locally in the browser or on the device (technically necessary).
- Crash reports and usage statistics (app only, consent only): see 8.4.
8.2 Purposes and Legal Bases
- Provision and management of the user account, storage and synchronisation of project data across devices and the web application, sharing projects with invited members, processing and managing RenoStack Pro purchases: Art. 6(1)(b) GDPR (performance of a contract).
- Device access in the app (camera, photo library, files, calendar, local notifications): only at your initiative; Art. 6(1)(a) and (b) GDPR. No push token is transmitted to us or third parties; appointment reminders are scheduled locally on the device.
- Hosting of the web application and abuse protection (see 8.3): Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation).
- Crash reports and usage statistics: Art. 6(1)(a) GDPR (consent).
Sharing a project makes its data – budgets, costs, expenses, documents and the names of the members – visible to all invited members. An account's Pro status is written to the user profile server-side by a Cloud Function (Google Cloud Functions) whenever RevenueCat notifies us of a purchase, renewal or expiry.
We do not sell your data and do not share it for advertising purposes.
8.3 Service Providers and Recipients
- Google Ireland Limited / Google LLC – Firebase Authentication, Cloud Firestore (database), Cloud Storage (attachments), Cloud Functions, Firebase Crashlytics and Firebase Analytics (consent only, app only).
- RevenueCat, Inc. – management of purchase entitlements for RenoStack Pro in the app and the web application.
- Apple Inc. / Google LLC – sign-in via "Sign in with Apple" or "Google Sign-In" and processing of purchases through the App Store or Google Play.
- Oracle Cloud Infrastructure (Oracle Corporation) – hosting of the web application renostack.stagworks.de. The information on server log data and retention in section 3 applies.
- Google reCAPTCHA Enterprise – abuse protection (Firebase App Check) in the web application. Your IP address and browser characteristics are transmitted to Google; a technically necessary cookie may be set for this.
We have Data Processing Agreements pursuant to Art. 28 GDPR with these providers. Where data is transferred to the USA, this is based on the EU Commission's adequacy decision (EU-US Data Privacy Framework) or on Standard Contractual Clauses.
8.4 Crash Reports and Statistics (Consent Only)
On first launch, the app asks whether Firebase Crashlytics (crash reports) and Firebase Analytics (usage statistics) may be enabled. Without your consent both remain disabled. You can change your decision at any time in your profile under Privacy; a withdrawal takes effect from the moment of the change. We use no analytics or tracking tools in the web application.
8.5 Retention and Deletion
We store account and project data for as long as the account exists. Delete account in your profile (app and web application) permanently removes the account, user profile, projects, invitations and attachments stored in the cloud; shared projects you own can be handed over to another member or deleted for everyone. Alternatively, you can request deletion at stagworks.de/delete-account. Data stored locally on the device is removed by signing out or uninstalling the app. Export data in your profile lets you download your project data as a JSON file at any time. Purchase records held by RevenueCat and the stores are subject to their retention periods; statutory retention obligations remain unaffected.
9. Changes to this Privacy Policy
We may adjust this Privacy Policy if the website or legal requirements change. The version published on this page at the given time applies.