Website Privacy Policy
1.Overview
This policy explains what personal data crossroutes.de itself - the website you're reading this on - collects, why, and who else ever sees it. It's a separate, much shorter document than the app's own Privacy Policy, which covers the Android and iOS apps and their backend - this page covers only the marketing website itself.
This site is operated by Lennard Zirks as a sole proprietorship (trading as "Software-Entwicklung Lennard Zirks"), the same one person behind the app. It sets no cookies, includes no analytics or third-party scripts, and holds no user accounts.
A handful of paths on this domain (/p/…, /u/…, /c/…, /r/…, /.well-known/assetlinks.json, /strava/callback) are technically served by the app's backend, not this website - they're covered by the app's Privacy Policy instead, specifically its Strava section for the OAuth callback.
The web version of the app at web.crossroutes.de is likewise part of the app, not of this website: its files are delivered by Cloudflare, not by this site's server, and everything you do in it - signing in, your account, rides, notifications - is covered by the app's Privacy Policy, which has its own section on the web version.
2.Who is responsible for your data
The controller responsible for processing under this policy is:
Lennard Zirks
Trading as: Software-Entwicklung Lennard Zirks
Hirtenweg 63A
26180 Rastede
Germany
Email: [email protected]. Full legal notice: Impressum.
Crossroutes operates at a small, one-person scale. It does not meet any of the GDPR Article 37 thresholds that would require appointing a Data Protection Officer (no large-scale processing of special-category data, no large-scale systematic monitoring, no public-authority processing) - so requests and questions go directly to the address above, not to an intermediary.
3.Data we collect, and why
| Category | What it includes | Why we collect it |
|---|---|---|
| Server logs | IP address, requested page, timestamp, and browser type, recorded briefly for every request | Keeping the site running and detecting abuse |
What we deliberately do not collect: cookies, analytics, advertising, or social-media embed scripts of any kind, user accounts, or any persistent visitor data. Every font, stylesheet, and script on this site is served from this same domain - nothing is loaded from a third-party CDN, so no external service ever sees that you visited.
4.Legal bases for processing
- Legitimate interest (Art. 6(1)(f) GDPR): server logs, kept purely to operate this site securely and detect abuse. These logs aren't linked to any account (this site has none) and aren't used for analytics or profiling.
5.Who else sees your data
This site runs on infrastructure located in Germany, owned and operated by the site owner. All requests to reach it pass through Cloudflare, Inc. (USA) first - a reverse-proxy/content-delivery layer that handles DDoS protection and TLS/HTTPS termination for every request, and so sees the same request metadata described in section 3 (plus, technically, the content of the request itself, the same way any site behind a CDN works) in order to route traffic.
6.International transfers
Cloudflare, Inc. is based in the United States; the transfer relies on Cloudflare's own Data Processing Addendum, which incorporates the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) - the free plan used here has no EU-only data-routing option, which is an Enterprise-only add-on.
7.Our social media profiles
This policy is only about crossroutes.de itself. Our presence on Instagram, Threads, Facebook, TikTok, X, and Bluesky is a separate surface with its own narrower notices, since interacting with those profiles involves each platform's own processing, not this website's:
8.No cookies, no tracking, specifically
This website sets no cookies and includes no analytics, advertising, or social-media embed scripts of any kind. (Our social media profiles, linked in section 7, are a different matter, governed by their own platforms' cookies and tracking - see their respective notices.)
9.How long we keep data
Server logs (IP addresses, request metadata) are short-lived - not a permanent database. This site holds no accounts and no persistent visitor data of any kind, so there's nothing else to retain.
10.Your rights
Under the GDPR, you can ask to: access the personal data we hold about you, have inaccurate data corrected, have your data erased, restrict or object to processing, and receive your data in a portable format. Since this site holds no accounts and no persistent visitor data (see section 9), there's little to request access to or deletion of - but you're welcome to ask, at [email protected]. You can also lodge a complaint with the Landesbeauftragte für den Datenschutz Niedersachsen(external link, opens in a new tab).
11.Changes to this policy
If this policy changes in a way that meaningfully affects how your data is handled, we'll note that here. The "last updated" date at the top always reflects the current version.
12.Contact
Questions, requests, or concerns about your data: [email protected].