Skip to content
Crossroutes Crossroutes 0.0 km
Home About Pricing Deutsch Web app Get the App

Privacy Notice for Our Meta Profiles

Covers the Crossroutes presence on Instagram (@crossroutes.de), Threads (@crossroutes.de), and any Facebook Page we operate — all part of Meta's family of apps. Stand: 8 September 2026. This is a narrow, platform-specific supplement — the main App Privacy Policy and Website Privacy cover crossroutes.de and the app itself, not these third-party profiles.

Diese Erklärung ist auch auf Deutsch verfügbar. Beide Fassungen sind rechtlich gleichwertig.

1.What this notice covers

This page explains what happens to your data specifically when you visit or interact with Crossroutes' own profile on a Meta platform — Instagram, Threads, or Facebook. It does not describe how Meta itself runs Instagram, Threads, or Facebook as a whole — that's between you and Meta, governed entirely by Meta's own Privacy Policy(external link, opens in a new tab) (which also governs Threads, built on Instagram's account infrastructure). We link to this page from our profile's bio because German law (Impressumspflicht) requires it to be reachable in a couple of clicks from any commercial social presence — see Section 10.

Share only the personal data necessary for your request. Content posted, commented, or sent to us on these platforms is first processed via Meta's own infrastructure. To prevent Meta from processing a specific piece of personal information, use email instead: [email protected].

2.Who's responsible for what

Crossroutes is run by Lennard Zirks (business name: Software-Entwicklung Lennard Zirks), Hirtenweg 63A, 26180 Rastede, Germany — [email protected]. Full details: Legal Notice. Crossroutes is small enough that none of the Art. 37 GDPR thresholds requiring a Data Protection Officer apply (no large-scale processing of special categories, no large-scale systematic monitoring) — the same as the main App Privacy Policy already states, so requests go directly to the address above rather than to a separately named DPO.

For one narrow slice of data — the aggregate audience/engagement statistics Meta shows us about our own profile ("Insights") — we and Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) are joint controllers under Art. 26(1) sentence 1 GDPR. This applies to Instagram and Facebook, and, run through the same Instagram account infrastructure, to Threads as well. It follows from the CJEU's 2018 Wirtschaftsakademie Schleswig-Holstein ruling (C-210/16) and Meta's own published Controller Addendum(external link, opens in a new tab), which sets out exactly how that joint responsibility is split. Under that agreement, Meta is the designated single point of contact ("Anlaufstelle," Art. 26(1) sentence 3 GDPR) for exercising your rights regarding the Insights processing specifically — see Section 8. Everything else about the platform itself — its own cookies and tracking, its algorithmic feed, its ad system, account security, content moderation — is Meta's sole responsibility as controller, described in Meta's own Privacy Policy(external link, opens in a new tab) — this notice doesn't and can't change that.

3.What we actually see and do

Insights. Meta compiles statistics about our profile from the following categories of user action: viewing content (a post, story, video, or the profile itself); following or unfollowing the profile; reacting to, commenting on, or sharing a post; hiding a post or reporting it as spam; clicking a contact button (website, phone number, directions) or an event link; and starting a Messenger conversation with us. The data Meta provides to us from this is aggregated and anonymized; we cannot attribute any of it to an identifiable person.

Where the visitor is logged in to a Meta account at the time, Meta may derive additional context for its own aggregate reporting — for example an approximate time, location, device type, and age range. This context is not provided to us on a per-person basis and does not identify the visitor.

Comments and public replies: visible to us the same way they're visible to anyone viewing the post, exactly as the platform itself shows them.

Direct messages sent to our profile (Messenger, Instagram, or Threads DMs): read by us personally — the only recipient — and treated like any other inbound contact, used only to answer whatever you asked. We never add it to a marketing list, combine it with anything else we hold, or share it onward, except where legally required or with your consent. Meta does not currently guarantee that these DMs are fully end-to-end encrypted in every conversation. Do not send sensitive personal data via direct message; use email instead: [email protected].

We don't run ads on these profiles, don't use Meta's Pixel or Conversions API anywhere, and don't buy or combine Insights data with any other dataset we hold.

4.Legal basis

Maintaining a public brand presence on these platforms and responding to messages sent to it both rest on legitimate interest (Art. 6(1)(f) GDPR) — presenting Crossroutes and communicating with the people who use or might use it. The joint-controller Insights arrangement in Section 2 rests on Art. 26(1) sentence 1 GDPR on our side. Meta's own legal basis for generating Insights data in the first place is a mix of consent (Art. 6(1)(a)) and legitimate interest (Art. 6(1)(f)) — see Meta's own explanation of its legal bases(external link, opens in a new tab).

5.Cookies

Meta sets its own cookies on our Instagram, Threads, and Facebook profiles — that's entirely Meta's responsibility as sole controller, not ours, and not something this notice can change. See Meta's Cookie Policy(external link, opens in a new tab) for the details.

6.How long data is kept

On our side: we don't export or separately store Insights numbers — they're viewed live in Meta's own interface, not copied into a database we control. A direct message or comment is kept only as long as it's relevant to answering it, then deleted along with the rest of our message history on the platform.

On Meta's side, as sole controller, retention isn't a single fixed number — it depends on what the data is and why it was collected in the first place, generally lasting until Meta no longer needs it for the service or until the account behind it is deleted. Meta publishes its own worked examples of this if you want the specifics (its Privacy Policy, linked in Section 2, is the authoritative source) rather than us restating figures here that Meta could update independently of this page.

7.International data transfers

Meta Platforms Ireland Limited is the EU entity most Meta account relationships run through; any further transfer to Meta's US operations is governed entirely by Meta's own safeguards (Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework), described in Meta's Data Policy(external link, opens in a new tab). We ourselves only ever see the aggregate Insights numbers or message content described in Section 3 — nothing we hold separately leaves the EU on our end.

8.Your rights

For the joint-controller Insights processing specifically, Meta's Controller Addendum designates Meta itself as the single point of contact (Art. 26(1) sentence 3 GDPR) for exercising your Art. 15–21 rights and for any Art. 33/34 breach-notification duties relating to that processing — reach Meta's Data Protection Officer here(external link, opens in a new tab), or use Facebook's own rights-request form(external link, opens in a new tab). If you send that kind of request to us instead, we'll forward it to Meta without delay rather than try to handle it ourselves. For everything else Meta processes as sole controller (the platform itself, its cookies, its ad system), the same Meta contact points apply. For anything we hold ourselves (a message you sent us) or questions about this notice, write to [email protected]; we respond within 30 days. You can also complain to our supervisory authority, the Landesbeauftragte für den Datenschutz Niedersachsen(external link, opens in a new tab).

9.Legal Notice (Impressum)

German law requires an easily reachable Impressum for any commercially operated social media presence. Ours is the same one that covers crossroutes.de: Legal Notice.

10.Looking for the app or website policy instead?

This page is only about the Instagram/Threads/Facebook profiles themselves. If you're looking for how the Crossroutes app handles your data, see the App Privacy Policy. If you're looking for how crossroutes.de itself handles visitor data, see Website Privacy.

11.Changes to this notice

If a meaningful change to how these profiles are run affects this notice, we'll update it here — the "Stand" date above always reflects the current version.

12.Contact

Questions about this notice: [email protected].

On this page
  1. Scope
  2. Who's responsible
  3. What we see and do
  4. Legal basis
  5. Cookies
  6. Retention
  7. International transfers
  8. Your rights
  9. Legal Notice
  10. App / website policy
  11. Changes
  12. Contact
Crossroutes

An ad-free app for people who'd rather meet up than train alone.

Get it on Google Play
Privacy Policy Terms of Use Cookie Policy Website Privacy Legal Notice Security Accessibility

© 2026 Lennard Zirks. Crossroutes is an independent project, run from Germany.