Language Versions
This privacy policy is also made available in other languages to make it easier to understand for users across Europe. Only the German version is authoritative and legally binding. In the event of any discrepancy or ambiguity between this translation and the German version, the German version shall prevail.
We have prepared this privacy policy (version 30 August 2026) to explain, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (in short, "data") we process as the controller — and the processors we engage (e.g. providers) — will process in future, and what lawful options are available to you. The terms used are to be understood as gender-neutral.
In short: We inform you comprehensively about the data we process about you.
Privacy policies usually sound very technical and use legal terminology. This privacy policy, however, aims to describe the most important things to you as simply and transparently as possible. Wherever it helps transparency, technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. We thus inform you in clear and simple language that, in the course of our business activities, we process personal data only where a corresponding legal basis exists.
If you still have questions, please contact the responsible party named below or in the legal notice ("Impressum"), follow the links provided, and look at further information on third-party sites. Our contact details can, of course, also be found in the legal notice.
This privacy policy applies to all personal data processed by our company and to all personal data processed by companies we engage (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data allows us to offer and bill for our services and products, whether online or offline. The scope of this privacy policy covers:
In short: This privacy policy applies to all areas in which personal data is processed in a structured manner within the company via the channels named above. Should we enter into a legal relationship with you outside these channels, we will inform you separately where applicable.
In the following privacy policy, we provide you with transparent information on the legal principles and provisions — that is, the legal bases of the General Data Protection Regulation — that enable us to process personal data. With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
Other conditions, such as tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, generally do not apply to us. Should such a legal basis nevertheless be relevant, it will be indicated at the appropriate point.
In addition to the EU regulation, national laws also apply:
Should further regional or national laws apply, we will inform you accordingly in the following sections.
Should you have questions about data protection or the processing of personal data, you will find the contact details of the responsible person or body below:
KRV Transporte und Dienstleistungen e. K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld
Germany
Email: kontakt@krvtd.com
Phone: +49 1578 5559857
Commercial register: HRA 27992, Düsseldorf Local Court
VAT ID: DE347700651
As a general rule, we only store personal data for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer applies. In some cases, we are legally required to continue storing certain data even after the original purpose no longer applies, for example for accounting purposes.
Should you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided there is no obligation to retain it.
We will inform you below of the specific duration of the respective data processing, where we have further information on this.
In accordance with Articles 13 and 14 GDPR, we inform you of the following rights to which you are entitled, in order to ensure fair and transparent data processing:
In short: You have rights — do not hesitate to contact the responsible party listed above!
If you believe that the processing of your data violates data protection law, or that your data protection rights have otherwise been infringed, you may lodge a complaint with the supervisory authority. In Germany, each federal state has its own data protection officer. The following local data protection authority is responsible for our company:
North Rhine-Westphalia Data Protection Authority
State Commissioner for Data Protection: Bettina Gayk
Address: Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Phone: +49 211/38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de/
We only transfer or process data in countries outside the scope of the GDPR (third countries) if you consent to such processing or if another legal permission exists. This applies in particular where processing is required by law or necessary for the performance of a contractual relationship. Your consent is, in most cases, the main reason we allow data to be processed in third countries.
The processing of personal data in third countries such as the USA, where many software providers offer services and host their servers, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, an adequate level of protection for data transfers to the USA currently exists where a US company processing personal data of EU citizens in the USA is an active participant in the EU-US Data Privacy Framework. More information can be found at: EU-US Data Privacy Framework
In addition, we use what are known as Standard Contractual Clauses (Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are template agreements provided by the European Commission designed to ensure that your data continues to meet European data protection standards even when transferred to and stored in third countries (such as the USA).
To protect personal data, we have implemented both technical and organisational measures. Wherever possible, we encrypt or pseudonymise personal data. This makes it as difficult as possible, within our means, for third parties to draw personal conclusions from our data.
Article 25 GDPR refers here to "data protection by design and by default", meaning that security is always considered — and appropriate measures taken — for both software (e.g. forms) and hardware (e.g. access to the server room).
TLS, encryption and HTTPS sound very technical, and they are. We use HTTPS ("Hypertext Transfer Protocol Secure") to transmit data over the internet in a way that cannot be intercepted.
This means that the entire transmission of all data from your browser to our web server is secured — no one can "listen in".
This gives us an additional layer of security and fulfils the requirement of data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the internet, we can ensure the protection of confidential data.
You can recognise the use of this secured data transmission by the small padlock symbol in the top left of your browser, to the left of the web address, and by the use of "https" (instead of "http") as part of our web address.
Cookies Summary
- Affected parties: Website visitors
- Purpose: depends on the specific cookie. More details below.
- Data processed: depends on the specific cookie used. More details below.
- Retention period: depends on the specific cookie, ranging from hours to years
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
Our website uses HTTP cookies to store user-specific data. Below we explain what cookies are and why they are used, to help you better understand the following privacy policy.
Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser sends this "user-related" information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to.
There are 4 types of cookies:
Essential cookies: These cookies are necessary to ensure basic functions of the website. For example, they are needed when a user adds a product to the shopping cart, continues browsing other pages, and only proceeds to checkout later.
Functional cookies: These cookies collect information about user behaviour and whether the user receives any error messages. They are also used to measure loading times and website behaviour across different browsers.
Targeting cookies: These cookies improve usability. For example, entered locations, font sizes or form data are stored.
Advertising cookies: These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. This can be very useful, but also very annoying.
Usually, when you first visit a website, you are asked which types of cookies you want to allow. And, of course, this decision is also stored in a cookie.
You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or only partially allow cookies.
You can manage cookies in your browser. Depending on your browser, this works slightly differently. Here you will find instructions for the most well-known browsers currently in use:
Since 2009, so-called "cookie guidelines" have existed. These stipulate that the storage of cookies requires your consent (Article 6(1)(a) GDPR). In Germany, the implementation of this guideline was largely regulated in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For strictly necessary cookies, even where no consent has been given, legitimate interests apply (Article 6(1)(f) GDPR), which in most cases are economic in nature. We want to give visitors to the website a pleasant user experience, and certain cookies are often strictly necessary for this.
Where non-essential cookies are used, this only happens with your consent. The legal basis for this is Art. 6(1)(a) GDPR.
Web Hosting Summary
- Affected parties: Website visitors
- Purpose: professional hosting of the website and securing its operation
- Data processed: IP address, time of website visit, browser used, and other data
- Retention period: depends on the respective provider
- Legal bases: Art. 6(1)(f) GDPR (legitimate interests)
When you visit websites nowadays, certain information — including personal data — is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only where justified.
By "website" we mean the entirety of all web pages on a domain, i.e. everything from the homepage to the very last subpage. By "domain" we mean, for example, example.com.
To view a website, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari.
To display the website, the browser must connect to another computer where the website's code is stored: the web server. Operating a web server is a complicated and demanding task, which is why it is usually handled by professional providers who offer web hosting and thus ensure reliable, error-free storage of website data.
The purposes of data processing are:
Even while you are visiting our website right now, our web server — the computer on which this website is stored — usually automatically stores data such as:
As a rule, the above data is stored for two weeks to two months and then automatically deleted. We do not pass this data on to third parties, but cannot rule out that it may be inspected by authorities in the event of unlawful conduct.
In short: Your visit is logged by our provider, but we do not pass on your data without consent!
The lawfulness of processing personal data in connection with web hosting arises from Art. 6(1)(f) GDPR (protection of legitimate interests), since the use of professional hosting with a provider is necessary to present the company on the internet in a secure and user-friendly manner, and to be able to pursue any attacks or claims arising from this where necessary.
We use Firebase Hosting, a web hosting and cloud service, for our website. The service provider is the American company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For the European region, the responsible company is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Firebase Hosting is part of the Google Cloud Platform and offers fast, secure hosting for web applications. The services include content delivery via a global Content Delivery Network (CDN) and SSL encryption.
When using Firebase Hosting, the following data is automatically processed:
By default, Firebase stores access logs for up to 30 days. After this period, the data is automatically deleted.
Google also processes some of your data in the USA. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Google also uses what are known as Standard Contractual Clauses (Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are template agreements provided by the European Commission designed to ensure that your data continues to meet European data protection standards even when transferred to and stored in third countries (such as the USA).
We have a legitimate interest in using Firebase Hosting in order to provide our online service. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We only use Firebase to the extent that we have taken the necessary security measures.
More information about Firebase and data protection can be found at https://firebase.google.com/support/privacy and in Google's general privacy policy at https://policies.google.com/privacy.
Communication Summary
- Affected parties: Everyone who communicates with us by phone, email or online form
- Data processed: e.g. phone number, name, email address, submitted form data
- Purpose: handling communication with customers, business partners, etc.
- Retention period: duration of the business matter and applicable statutory provisions
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
If you contact us and communicate with us by phone, email, or online form, personal data may be processed.
The data is processed to handle and process your inquiry and the related business matter. The data is stored for as long as required, or for as long as prescribed by law.
All those who seek contact with us via the communication channels we provide are affected by the processes described.
If you call us, the call data is stored in pseudonymised form on the respective end device and by the telecommunications provider used. In addition, data such as name and phone number may subsequently be sent by email and stored for the purpose of answering your inquiry. The data is deleted once the business matter has concluded and statutory provisions permit.
If you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and will be stored on the email server. The data is deleted once the business matter has concluded and statutory provisions permit.
If you communicate with us via an online form, data is stored on our web server and, where applicable, forwarded to one of our email addresses. The data is deleted once the business matter has concluded and statutory provisions permit.
Our website features a contact form through which you can send us messages. When you use this form, the following data is processed:
Processing takes place via Firebase Functions and Brevo for sending emails. After successful submission, you will receive an automatic confirmation email from noreply@krvtd.com.
The processing of data is based on the following legal bases:
We use Brevo (formerly Sendinblue) to send transactional emails (e.g. confirmation emails after a contact form submission). Brevo is a cloud-based email service provided by Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France.
When you use our contact form and we send you a confirmation email, the following data is processed via Brevo:
The legal basis for using Brevo is Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in ensuring reliable email delivery.
Brevo processes data primarily within the EU (server location: France) and is bound by European data protection standards.
More information can be found in Brevo's privacy policy: https://www.brevo.com/en/legal/privacypolicy/
Google Analytics Summary
- Affected parties: Website visitors
- Purpose: analysis of visitor information to optimise the website
- Data processed: access statistics, including data such as access locations, device data, access duration and time, navigation behaviour and click behaviour
- Retention period: individually configurable; by default, Google Analytics 4 stores data for 2 months
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use the analytics tracking tool Google Analytics 4 (GA4) from the American company Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) on our website. For the European region, the responsible company is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics collects data about your actions on our website.
Through a combination of various technologies such as cookies, device IDs and login information, you as a user can be identified across different devices. This allows your actions to be analysed across platforms as well.
With Google Analytics, we can measure how you interact with our website. For example, we can determine which pages are visited most frequently and where visitors come from. This helps us improve our offering and better respond to the needs of our users.
Google Analytics uses a tracking code to create a random, unique ID that is linked to your browser cookie. This is how Google Analytics recognises you as a new user, and a user ID is assigned to you. The next time you visit our site, you will be recognised as a "returning" user.
All collected data is stored together with this user ID, which is what makes it possible to evaluate pseudonymous user profiles.
To analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For every newly created property, the Google Analytics 4 property is the default. Depending on the property used, data is stored for different lengths of time.
Through identifiers such as cookies, app instance IDs, user IDs, or custom event parameters, your interactions are measured across platforms. Interactions are any type of action you take on our website. If you also use other Google systems (such as a Google account), data generated via Google Analytics may be linked with third-party cookies.
We have set the retention period for your user data in Google Analytics to 2 months. After this period, your user data is deleted. This setting only affects personal data linked to cookies, user recognition and advertising IDs. Aggregated statistics are retained for longer.
We use Google Consent Mode version 2 (Advanced Mode). This means:
Advanced Consent Mode allows Google to collect anonymised data — which cannot be attributed to any individual — even without cookies. This improves data quality without compromising your privacy.
You have the right, at any time, to access, rectify, erase, and restrict the processing of your personal data. You may also withdraw your consent to the processing of the data at any time.
You can manage, disable, or delete cookies in your browser. Please note, however, that this may impair certain functions of this website.
If you generally wish to disable, delete, or manage cookies, you will find the corresponding links to instructions for the most well-known browsers under the "Cookies" section.
The use of Google Analytics requires your consent, which we obtain via our cookie banner. This consent, under Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may occur when data is collected by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors in order to improve our offering both technically and economically. With the help of Google Analytics, we can identify website errors, detect attacks, and improve cost-effectiveness. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We only use Google Analytics to the extent that you have given consent.
Google also processes some of your data in the USA. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
Google also uses what are known as Standard Contractual Clauses (Art. 46(2) and (3) GDPR). The relevant Standard Contractual Clauses can be found at: https://business.safety.google/adsprocessorterms
More information about the data processed through the use of Google Analytics can be found in the privacy policy at https://policies.google.com/privacy
Google Tag Manager Summary
- Affected parties: Website visitors
- Purpose: organisation of the individual tracking tools
- Data processed: Google Tag Manager itself does not store any data. The data captured relates to the tags of the web analytics tools used
- Retention period: depends on the web analytics tool used
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use Google Tag Manager from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) on our website. For the European region, the responsible company is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). This tag manager is one of many helpful marketing products from Google. Through Google Tag Manager, we can centrally install and manage code snippets from various tracking tools that we use on our website.
Google Tag Manager itself does not set any cookies and does not store any personal data. It only enables the management and deployment of tags. Tags are small code snippets that, for example, record (track) your activities on our website.
Google Tag Manager helps us organise our website more effectively. Through Google Tag Manager, we can install and manage all tracking tags centrally via a single interface. Tags are small code snippets that, for example, record (track) your activities on our website. JavaScript code snippets are inserted into the source code of our page for this purpose.
Google Tag Manager itself does not store any personal data. However, personal data may be collected and processed via the tags it manages. In our case, Google Tag Manager is mainly used to integrate and manage Google Analytics 4.
The use of Google Tag Manager requires your consent, which we obtain via our cookie banner. This consent, under Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data that may occur through the use of Google Tag Manager.
In addition to consent, we have a legitimate interest in managing various tools as simply as possible and optimising our website's performance. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests). We only use Google Tag Manager to the extent that you have given consent.
Google also processes some of your data in the USA. Google is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data.
If you would like to learn more about Google Tag Manager, we recommend the FAQ at https://www.google.com/intl/en/tagmanager/faq.html
WhatsApp Summary
- Affected parties: WhatsApp users who communicate with us
- Purpose: communication with customers
- Data processed: contact details, messages, media
- Retention period: data is deleted after communication ends
- Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
We use the instant messaging service WhatsApp on our website to communicate with our customers. The service provider is the American company WhatsApp Inc., a subsidiary of Meta Platforms Inc. For the European region, the responsible company is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
We want to stay in touch with you, and WhatsApp is the fastest and easiest way to do so. The service is widely used and enables uncomplicated communication with you.
When you communicate with us via WhatsApp, various data may be processed:
Messages between you and us are end-to-end encrypted and therefore cannot be read by WhatsApp itself either.
WhatsApp only stores messages during delivery. Once delivery has succeeded, they are deleted from WhatsApp's servers. On your and our device, the messages remain stored until you or we delete them.
We only store communication data for as long as is necessary to process your inquiry.
The use of WhatsApp requires your consent, which is given by contacting us via WhatsApp. This consent, under Art. 6(1)(a) GDPR (consent), constitutes the legal basis for the processing of personal data.
In addition, we have a legitimate interest in responding to customer inquiries quickly and efficiently. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interests).
WhatsApp also processes some of your data in the USA. WhatsApp is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data.
More information about data processing by WhatsApp can be found in the Privacy Policy at https://www.whatsapp.com/privacy
The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of our mobile applications "KFZ Übergabe Protokoll start", "KFZ Übergabe Protokoll pro" and "KFZ Übergabe Protokoll plus" (collectively, the "App").
Note: The Apps are offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.
KRV Transporte und Dienstleistungen e.K.
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: mobility-solutions@krvtd.com
The App is used to create digital vehicle handover protocols. Depending on the app variant (start / pro / plus), only the data required for the following purposes is processed:
No automatic transmission to servers or third parties takes place. Data is only shared if the user actively shares a PDF (e.g. via email, messaging app, or cloud service).
Depending on which app variant is used, the following personal data may be processed:
Personal data of the parties involved in the handover:
Vehicle and protocol data:
Image and photo data:
All data is stored exclusively locally on the end device:
There is no cloud synchronisation, no server backup, and no automatic transfer to third parties.
The user can manually delete protocols at any time.
For the App to function, it requires the following system permissions:
Processing is based on:
The user is responsible for obtaining the consent of any persons photographed or signing.
Data is only shared if the user actively shares a PDF. Responsibility for such sharing lies with the user.
Data remains stored on the device until:
There is no automatic deletion function.
For all data stored in the App, the rights under the GDPR apply, in particular:
Since the data is stored locally only, these rights must be exercised by the user themselves (e.g. by deleting a protocol).
Data is stored exclusively locally and protected by the security mechanisms of the respective operating system:
There is no transmission to external systems.
The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of the mobile application "KRV Live-Tracking" and the associated web platform at tracking.krvtd.com (collectively, the "App").
Note: The App is offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.
KRV Transporte und Dienstleistungen e.K.
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: mobility-solutions@krvtd.com
The App allows users to share their real-time location via a link. Recipients of the link can follow the location in their browser without installing the App. Data is processed exclusively for the following purposes:
Account data:
GPS and tracking data (only during active tracking):
Usage statistics:
All data is stored in Google's Firebase Realtime Database (server location: europe-west1, Belgium). GPS data is transmitted and stored in real time only during an active tracking session. Once a tracking session ends, the position data is marked as inactive. Users can stop tracking data at any time by ending the tracking session.
Account data is stored until the user's account is deleted. Following account deletion, all personal data is irrevocably deleted within 30 days.
For the App to function, it requires the following system permissions:
Background location permission is used exclusively during a tracking session actively started by the user. No background location tracking takes place without an active tracking session.
GPS data is accessible, via the tracking link generated by the user, to anyone the user shares that link with. The user is solely responsible for who they share the tracking link with.
No further disclosure to third parties takes place, with the exception of the following technical service providers:
Processing is based on:
The user is responsible for ensuring that all persons whose location is shared have expressly consented. Unauthorised tracking of persons without their consent is prohibited and may be a criminal offence.
The data subject rights set out in this privacy policy under the GDPR apply. For requests regarding the deletion of your account or your tracking data, please contact: mobility-solutions@krvtd.com
The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of the mobile application "ApuDrive" (the "App").
Note: The App is offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.
KRV Transporte und Dienstleistungen e.K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: kontakt@krvtd.com
The App is used for private vehicle management. Only the data required for the following purposes is processed:
Account data: email address, password (encrypted), user ID
Vehicle data: make, model, year of manufacture, licence plate, colour, odometer reading, vehicle photo
Cost data: date, amount, category, fuel quantity, fuel price, odometer reading, notes, optional receipt photos
Maintenance data: maintenance type, date, odometer reading, garage, cost, notes, photos, due dates
Usage data: number of free scans used, unlocked in-app purchases
All data is stored in the Google Firebase Cloud (Firestore Database, server location: europe-west3, Frankfurt). Photos and receipt images are stored in Firebase Storage. Data is accessible only to the respective user and is protected by Firebase Security Rules.
The App uses the device camera to scan receipts. Text recognition (OCR) takes place entirely on the device via Google ML Kit — no receipt images are transmitted to external servers. Receipt photos are only stored in Firebase Storage if the user chooses to do so.
In-app purchases are processed via RevenueCat (1608 Bush St, San Francisco, CA 94109, USA). RevenueCat processes the purchase ID and purchase status. Payments themselves are processed via the Google Play Store. More information: revenuecat.com/privacy
No disclosure to third parties takes place, with the exception of the following technical service providers:
Data is stored until the user deletes their account or requests deletion. Deletion requests can be sent to kontakt@krvtd.com.
The following notices supplement the general privacy policy of KRV Transporte und Dienstleistungen e.K. and apply exclusively to the use of the mobile application "Meine Arbeitszeit" (the "App").
Note: The App is offered under the trading name "KRV Mobility Solutions". The legal entity and controller remains KRV Transporte und Dienstleistungen e.K.
KRV Transporte und Dienstleistungen e.K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld (Rhineland), Germany
Email: kontakt@krvtd.com
The App is used for private time tracking for jobs, clients and projects. Only the data required for the following purposes is processed:
No automatic transmission to servers or third parties takes place. Data (e.g. export files) is only disclosed if the user actively triggers this, for example by sharing a CSV/PDF file via email, messaging app, or cloud service.
Project data: project/client name, colour, target hours per week, break rules, standard working hours, rounding settings
Time tracking data: start/end times, break times, absence type (sick/holiday/public holiday), associated date
Achievements/statistics: unlocked achievements (purely local, with no personal reference beyond the device user)
Purchase data: purchase status of the "unlimited projects" in-app purchase (managed via Google Play, see below)
All of this data is entered by the user themselves; the App does not automatically collect any data in the background (no location, camera, microphone, or contacts).
All data is stored exclusively locally on the end device in a local database (Room/SQLite). There is no cloud synchronisation, no server backup, and no automatic transfer to third parties. Export files (CSV/PDF) are likewise only generated locally on the device and remain there until the user actively shares or deletes them.
The App does not request permissions for location, camera, microphone, or contacts.
The one-time in-app purchase to unlock unlimited projects is processed entirely via the Google Play Billing Library. Payment data is processed exclusively by Google; KRV Transporte und Dienstleistungen e.K. only receives information as to whether the purchase was unlocked. No payment data is processed or stored by the App itself.
More information: policies.google.com/privacy
No disclosure to third parties takes place, except for:
Data remains stored on the device until it is deleted by the user, the device is reset, or the App is uninstalled. There is no automatic deletion function and no server-side data store that would need to be separately deleted.
Since all data is stored exclusively locally on the user's device, the rights under the GDPR (access, rectification, erasure, restriction, data portability, objection) must be exercised by the user themselves, e.g. by deleting individual entries in the App or by uninstalling the App. For questions regarding the processing of the in-app purchase, please contact: kontakt@krvtd.com
Data is stored exclusively locally and protected by the security mechanisms of the respective operating system (e.g. device PIN, fingerprint, Face ID). No transmission to external systems takes place, except for communication with Google Play to process the purchase.
We hope we have been able to give you the key information about data processing on our website and in our apps.
If you would like to learn more about our data processing, or if you have any questions, please contact:
KRV Transporte und Dienstleistungen e.K.
Kevin Rüchel-Volkmann
Langforter Str. 19
40764 Langenfeld, Germany
Email: kontakt@krvtd.com
Phone: +49 1578 5559857
Version of this privacy policy: 30 August 2026
Last updated: 30 August 2026