Privacy Policy

Esta página es una traducción al inglés que ofrecemos como ayuda de lectura. La versión jurídicamente vinculante es la alemana: Datenschutzerklärung. ¿Tienes preguntas? Escríbenos a info@rewardrangers.com.

This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data when using the website rewardrangers.com as well as the “Reward Rangers” apps for Android and iOS (together: the “service”). Reward Rangers is a family app with which parents organise tasks, reward handovers, Savings, appointments, reminders, shopping lists and a family chat; children can follow their progress and arrange their sticker book.

The ranger family places a few selected app records into a protected archive chest while Erik guards the key.
Contents
  1. Controller
  2. Overview and core principles
  3. This website
  4. Parent account (app)
  5. Child profiles
  6. App data and storage (Supabase)
  7. Family chat
  8. Photos and voice messages
  9. Push notifications
  10. Subscription and payments
  11. App permissions
  12. Offline data on the device
  13. Storage period and erasure
  14. Your rights
  15. Right to lodge a complaint
  16. Changes to this policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data in connection with this service is:

Mike Fröse
Berliner Str. 12
58566 Kierspe
Deutschland
Email: info@rewardrangers.com

Data protection enquiries reach us by email at the address stated above or through the form on the contact page.

2. Overview and core principles

Reward Rangers is built on the principle of data minimisation. The most important principles up front:

  • Children need neither an authentication account of their own nor an email address. A six-digit one-time code connects the child device with the profile created by the parents; a contractual relationship exists exclusively with the parents.
  • Only what is strictly necessary is stored about children: a first name or nickname, optionally a date of birth (for birthday features) and optionally an avatar (emoji or a photo uploaded by the parents). Added to this are the usage contents created within the app (e.g. points, completed tasks).
  • No advertising and no disclosure to third parties: The service currently contains no advertisements and no advertising tracking. We do not sell data and do not pass it on to third parties. Should advertising be introduced in future, we will describe its nature and scope as well as any associated data processing here beforehand.
  • EU hosting of the core data: The website and the core app data are hosted on servers within the EU (see Section 3 and Section 6). With push notifications and app stores, processing outside the EU may occur; those cases are described separately in the respective sections.

3. This website

Hosting and server log files

The website rewardrangers.com is hosted by Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus. Delivery takes place from servers in Germany; server backups are held in France. Both locations lie within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with Hostinger.

When the website is accessed, technical server access data (log files) may be processed, as is customary for websites, in particular:

  • IP address of the requesting device,
  • date and time of access,
  • file/URL requested and volume of data transferred,
  • status code of the request,
  • browser type/version and operating system (user agent),
  • where applicable, the previously visited page (referrer).

Purpose: technical delivery, operational security and stability, defence against attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and functioning provision). Storage period: Log files are stored only for as long as is necessary for operation, security and error analysis, and are deleted or anonymised afterwards.

No cookies, no tracking

This website uses no tracking and no analytics or statistics services, and sets no cookies for the content pages and the contact form. Fonts and all further resources are delivered locally from our own server; no content is loaded from third-party servers.

A technically necessary session cookie is set exclusively on the confirmation pages for email links from the app (addresses below /de/auth/ and /en/auth/). It secures the one-time process against misuse, contains no identifier for advertising or recognition purposes and ends when the browser is closed. The legal basis for the storage is Section 25(2) no. 2 TDDDG, and for the processing Art. 6(1)(b) GDPR.

There is exactly one single entry in the local storage of your browser (localStorage): the key “rr-theme”, which stores the design setting you selected manually (light/dark). It is only set if you actively switch the design, contains no personal data and is not transmitted to us. This storage is strictly necessary for the function you have expressly requested (Section 25(2) no. 2 TDDDG); consent (a cookie banner) is not required for it.

Contact form

A contact form is available on the contact page. Its use is voluntary; an ordinary email to info@rewardrangers.com remains an equivalent route.

Data processed: Required are the selection of your concern, your email address and your message. Providing a name is voluntary and may also be a nickname. We do not ask for any further details, and the form does not accept file attachments. What you write beyond that in the message text is for you to decide. Please never send us passwords or the connection code of a child.

Process: The entries are processed on our web server and delivered immediately by email to the mailbox info@rewardrangers.com. Your email address is set as the reply address so that we can answer you. The website operates no database; your message is neither stored nor archived on the web server, and your IP address is not carried over into the email. As with every page view, an entry is created in the server log files (see above).

Purpose: receipt, assignment and answering of your concern including any follow-up questions. Legal basis: Art. 6(1)(b) GDPR insofar as your enquiry serves the initiation or the performance of a contractual relationship, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). If your enquiry concerns the exercise of a right under Section 14, the legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 12 GDPR.

Recipients: The web server is operated by Hostinger (see above). The mailbox info@rewardrangers.com is likewise kept at Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus; the mailbox servers are located in Frankfurt am Main (Germany) and therefore within the European Union. The provider is bound by our instructions as a processor pursuant to Art. 28 GDPR. We do not pass your enquiry on to any other third parties.

Protection against automated submissions: The form contains an invisible check field, uses a signed timestamp to check how quickly it was submitted, and limits the number of submissions per sender. For this limit the web server stores an irreversible check value (hash) of your IP address together with a counter and a timestamp for a maximum of 24 hours; the IP address itself is not stored for this purpose. A third-party service such as a captcha is not used: still no content is loaded from external servers and no cookies are set for the form. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing misuse and bulk sending).

Storage period: We keep your enquiry for as long as is necessary for handling it and for possible follow-up questions, and then delete it from the mailbox, at the latest after 24 months. Statutory retention obligations remain unaffected.

Provision: You are obliged neither by law nor by contract to provide us with this data. Without a message and without an email address, however, we cannot handle or answer your concern.

4. Parent account (app)

In order to use the app, a parent creates an account with an email address and password. Authentication takes place through the authentication system of our processor Supabase (see Section 6); passwords are not stored in plain text but exclusively in irreversibly encrypted form (hash).

A further parent can join the family by means of an invitation code and likewise creates an account of their own with an email address and password.

Inviting further parents

The family admin can invite a further parent. In doing so, the first name, surname and email address of the invited person, the family assignment, an invitation code that can be used once, the creator and the time of creation are processed. The app does not send an invitation itself and does not access the address book. The family admin copies or shares the code through an app of their own choosing; that target app is governed by its own privacy terms.

The invitation code can be used only once. After a successful join, the associated invitation record is deleted immediately. An open invitation expires 14 days after it was created. Expired invitations and invitations declined by the recipient or withdrawn by the family admin are deleted by the next daily cleanup after a 24-hour grace period, normally within 24 to 48 hours.

Purpose: provision of the account, sign-in, administration of the family and secure assignment of the invited person. Legal basis: Art. 6(1)(b) GDPR for the function requested by the family admin, and Art. 6(1)(f) GDPR for the processing of the invitation data and the protection against unauthorised joins. The storage period is described in Section 13.

5. Child profiles

Children have no authentication account of their own. Child profiles are created and administered exclusively by the parents. The admin can pause a child profile in the app or, after an explicit confirmation, permanently delete it together with the assigned data; deleting the family removes all child profiles. A six-digit one-time code connects a device with the profile and becomes invalid afterwards; an email address or telephone number of the child is not required for this. A date of birth is voluntary.

The following are processed for a child profile:

  • First name or nickname (freely selectable by the parents; it does not have to be a real name),
  • optionally a date of birth (entered by the parents; used for birthday features, e.g. the birthday gift in the app),
  • optionally an avatar (emoji or a photo uploaded by the parents),
  • the usage contents created within the app: points balance, completed and open tasks, reward requests and handovers, badges, stickers, levels, family-internal account balances and bookings as well as content created by the child (e.g. appointments, reminders, shopping items or chat messages).

Responsibility of the parents or legal guardians: The decision whether and to what extent a child uses the app is taken by the parents or legal guardians. They set up the profile, know and control the stored content and can determine for each child which functions it may use (e.g. creating its own appointments or reminders). Insofar as consent is required for individual processing operations in connection with the use by a child (cf. the legal principle of Art. 8 GDPR), the parents or legal guardians give that consent within the scope of setting up and enabling the profile. Legal basis otherwise: Art. 6(1)(b) GDPR (provision of the contractually agreed functions towards the parents).

6. App data and storage (Supabase)

The content created within the app is processed in the database and the storage of our service provider Supabase (database, authentication and file storage). This includes in particular tasks (“Missions”), reward requests and handovers, points and activities, family-internal accounts and bookings, appointments, reminders, shopping lists, chat messages as well as uploaded images and voice messages. The Savings function processes exclusively family-internal overview and learning values; no bank, account or payment data is collected in this context. External push delivery is described separately in Section 9.

  • Processing on our behalf: Supabase is bound by our instructions as a processor pursuant to Art. 28 GDPR.
  • Server location: EU (Frankfurt am Main). A transfer to third countries does not take place in regular operation.
  • Access protection: Access is secured on a per-family basis: each family can read and change only its own data; access rules enforce this directly at database level. Access from child profiles is additionally protected by device-side session tokens. Transmission is encrypted (TLS).

Purpose: provision of the app functions, synchronisation between the devices of the family. Legal basis: Art. 6(1)(b) GDPR.

7. Family chat

The family chat (“Radio Post”) is a closed channel exclusively for the members of one family. There are no public profiles, no contact search and no possibility to reach persons outside the family or to be reached by them.

  • Private one-to-one messages: messages between two people are visible only to those two participants. This protection is anchored technically on the server and applies towards other family members as well: parents, too, cannot read private messages in which they are not involved. The group chat is visible to all family members.
  • Automatic server-side erasure after 30 days: chat messages are automatically deleted on the server after 30 days, including the associated images and voice messages in the file storage.
  • Local history: every device stores its chat history locally (up to about 12 months) so that the family can keep its conversations despite the short server storage period. This local history remains exclusively on the respective device. After successful deletion of the family or a parent account, it is cleared on the device used; independently of that, individual messages of your own can be deleted in the app and the entire history by deleting the app data or uninstalling it (see Section 12).

Reports and moderation

Family members can report individual chat content in the app. We process the case only to review the report, protect affected persons, take any necessary measures and send the notices required by law.

  • Case data: case number, reporting and affected family member, reason for the report, optional note, time, and an evidence copy of the reported text, image, audio or poll.
  • Protected access: media evidence is kept in private storage. Only the operator can view it for a limited period to handle the case; access and the decision are logged.
  • Outcome: depending on the review, the content may be removed, a child’s chat access may be disabled or the family may be suspended. The reporting and affected persons receive the notice intended for their case. safety@rewardrangers.com is the dedicated point of contact for authorities and recipients.

Legal basis: depending on the case, Art. 6(1)(c) GDPR in conjunction with statutory notice and statement-of-reasons duties, in particular Articles 16 and 17 DSA, and Art. 6(1)(f) GDPR for secure handling and the prevention of misuse.

Legal basis: Art. 6(1)(b) GDPR (provision of the chat function); the short server storage period serves data minimisation at the same time (Art. 5(1)(c) and (e) GDPR).

8. Photos and voice messages

At several points users can voluntarily upload media of their own: images for tasks, rewards, appointments, reminders, shopping items and avatars as well as photos and voice messages (up to 60 seconds) in the family chat.

  • Images are reduced in size and compressed on the device already before they are uploaded; the original at full resolution is not transmitted.
  • Storage takes place in the file storage of our processor Supabase (EU, see Section 6); access is limited to the respective family.
  • Chat images and voice messages are subject to the 30-day erasure (see Section 7).

Legal basis: Art. 6(1)(b) GDPR. Camera and microphone access take place only after express approval through the operating system (see Section 11).

9. Push notifications

On request, Reward Rangers delivers push notifications about family-related events: for example when a child submits a task for review, requests a reward or confirms its receipt, when a parent marks a handover or a rejection, or when a new chat message arrives. For this we use Firebase Cloud Messaging (FCM) by Google. On Apple devices the message is forwarded by FCM to the Apple Push Notification Service (APNs).

  • Activation and data: push is only set up after the notification function has been called up in the app and the permission has been granted in the system dialogue of the device. Processed are in particular a pseudonymous installation or device token, the platform and the assignment to a parent account or child profile.
  • Content of the notification: transmitted are the token required for delivery, the type of event and a short notification text. Depending on the event, this text may contain the name of a child profile or a short preview of a chat message, but no photos, voice messages or complete chat histories. Depending on the device settings, the text may be visible on the lock screen; the preview can be restricted in the system settings.
  • Recipients: the token is stored in our Supabase database and transmitted for delivery to Google and, on iOS, additionally to Apple. Google processes FCM on global infrastructure; processing outside the EU, in particular in the USA, may take place in this context. The Firebase data processing terms and the respectively applicable safeguards under Chapter V GDPR apply.
  • Switching off and erasure: push can be deactivated in the app and at any time in the system settings of the device. The server-side token assignment is removed upon deactivation, sign-out, invalidity of the token or erasure of the family member. Individual chats can additionally be muted temporarily.

Legal basis: Art. 6(1)(b) GDPR for the notification function requested by the user. Insofar as a notification serves the secure and timely handling of family-related matters, Art. 6(1)(f) GDPR may apply in addition. The system permission can be withdrawn at any time with effect for the future.

10. Subscription and payments

Billing: A Premium subscription is purchased exclusively through Google Play or the Apple App Store and processed by the respective store operator.

Neither we nor RevenueCat receive bank details or credit card data. The means of payment remains with the respective store operator. To unlock and manage Premium, however, we process the purchase and subscription status as well as the store and transaction information described below. Legal basis: Article 6(1)(b) GDPR (performance of the subscription).

For the technical management, validation and restoration of in-app subscriptions, once the subscription feature is offered, we use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA, as our data processor. The data transmitted comprises the pseudonymous Supabase user ID of the signed-in parent as the App User ID, store, platform, product, transaction and entitlement identifiers, the Apple purchase receipt or Google purchase token, purchase and subscription history including status and timestamps, and technically required information about the app, device, operating system, SDK, language, country and currency. According to RevenueCat, the IP address is used only to determine the country and is then discarded.

We transmit to RevenueCat no names or email addresses, no data from child profiles, and no task, chat, calendar, image or audio data. RevenueCat processes and stores customer data in the United States and may use the subprocessors listed in the current data processing agreement. The EU Standard Contractual Clauses (Module 2: controller to processor) form part of the agreement for required restricted transfers. Further information: RevenueCat Privacy Policy and the RevenueCat Data Processing Addendum, including the current subprocessors.

The RevenueCat customer profile is generally processed for as long as necessary to manage the subscription and to comply with statutory evidence and retention obligations. Our in-app deletion routes remove or anonymise the personal RevenueCat assignment in our own database. The external RevenueCat deletion is durably queued, attempted automatically and retried after technical errors. If automatic processing cannot be completed, we handle a verified request separately with RevenueCat unless statutory obligations prevent this. Deleting a Reward Rangers account or the RevenueCat customer profile does not automatically terminate a store subscription; an active subscription must additionally be cancelled in Google Play or the Apple App Store.

When the app is obtained, Google and Apple process on their own responsibility in particular the store account, the download, the installation, updates and, in the case of a subscription, payment and subscription data. We have no complete influence on this; in addition, the data protection and contractual terms of the respective store operator apply.

Referral programme

When you recommend the app, no data about the recipient is collected. The app does not send any recommendation itself and does not access your address book; it merely provides a referral code and a link, which you pass on through an app of your own choosing. No email address, telephone number or other detail of the person you recommend is requested or stored. The data protection terms of the app you choose apply to that app.

Only data about your own family is processed: your family’s referral code, the link between the referring family and the referred family, the status of the credit and the number of credited days. Purpose: operating the programme and protecting it against abusive multiple crediting. Legal basis: Article 6(1)(b) GDPR for the function you requested and Article 6(1)(f) GDPR for protection against misuse. The storage period is described in section 13.

11. App permissions

The app requests system permissions exclusively when the associated function is used for the first time, in each case through the standard dialogue of the operating system. Without approval the app remains usable; only the respective function is then unavailable.

A parent ranger decides together with her child about camera, microphone, notifications and network access.
  • Camera / photos (optional): images of your own for tasks, rewards, appointments, reminders, shopping items, avatars and the chat.
  • Microphone (optional): voice messages in the family chat.
  • Notifications: push messages and ringing reminders.
  • Network status: detecting offline phases so that changes can be cached and sent on later.

12. Offline data on the device

To keep previously loaded content visible and retry supported changes that failed because of a network error, the app stores the following data locally on the device (app storage or local database, e.g. IndexedDB):

  • cached app data (e.g. tasks, rewards, points, accounts, appointments and shopping items) for the offline display,
  • a queue for changes made offline, which are sent on automatically at the next connection,
  • the local chat history (up to about 12 months, see Section 7),
  • the arrangement of the sticker book pages,
  • settings and sign-in status.

This data remains on the device. After successful deletion of the family or the user’s own parent account, the app clears the personal local app storage on the device used for the deletion, including the queue and local chat and media data. An ordinary sign-out removes the sign-in status and cached store data; local chat and media data may then remain until the app data is deleted or the app is uninstalled. Server-side deletion cannot immediately reach other devices that are currently offline. When changing or passing on such a device, please additionally delete the app data there and protect the device with a screen lock. Legal basis: Section 25(2) no. 2 TDDDG (storage strictly necessary for the function) as well as Art. 6(1)(b) GDPR.

13. Storage period and erasure

The ranger family empties its archive chest in a controlled way and thereby keeps control over its stored data.

The following storage and erasure periods apply to the processed data.

DataStorage period
Parent invitation including name, email address and codeopen for no more than 14 days; immediate deletion after a successful join; after expiry, rejection or withdrawal, deletion by the next daily cleanup following a 24-hour grace period (normally within 24 to 48 hours)
Referral code of the family, link to the referred family and credit daysuntil the family is deleted or an erasure has been initiated; no data about the recommended person is stored with the referral code
Chat messages as well as chat images and voice messages on the server30 days
Reports concerning chat content, including the evidence copy, handling decision and technical case datagenerally 90 days after the case is concluded; cases marked for an authority remain excluded from automatic erasure until the competent authority releases them
Historical task and reward activities and points bookingsuntil the assigned child profile or family is deleted, or a justified erasure request is made; no automatic 30-day erasure
Current points balance and current profile progress of a childuntil the child profile or family is deleted, or a justified erasure request is made
Active tasks, rewards, savings accounts, appointments, reminders and shopping itemsuntil the entry, the assigned profile or the family is deleted
Push token in the Reward Rangers databaseuntil deactivation, sign-out, invalidity or erasure of the family member
RevenueCat customer profile (pseudonymous App User ID, store receipt or purchase token, and purchase, subscription and entitlement history)for as long as required for subscription management and statutory obligations; the external deletion is durably queued, attempted automatically and retried after technical errors. If automatic processing cannot be completed, a verified request is handled separately with RevenueCat unless statutory obligations prevent this. This does not terminate an active store subscription; it must be cancelled separately in the respective store
Parent account and child profileuntil deletion of the user’s own parent account, the individual child profile or the entire family; these routes are available in the app depending on role and subscription assignment
Local chat historyup to about 12 months; deleted immediately on the device used for a successful family or parent-account deletion, otherwise together with the app data or on uninstallation
Website server log filesonly as long as necessary for operation, security and error analysis; erasure or anonymisation afterwards
Contact enquiries through the form and by email including message and sender addressuntil the matter has been concluded and for possible follow-up questions; erasure afterwards, at the latest after 24 months
Check value (hash) of the IP address for limiting form submissionsa maximum of 24 hours

Deletion of individual profiles, parent accounts and the family

The family admin can pause a child profile in the app or, after an explicit confirmation, permanently delete it together with the assigned data. An additional parent who is not the admin can permanently delete their own parent account in the app; the family and the other members’ accounts remain in place. If that parent account is assigned as the subscription payer, the subscription assignment must be resolved first. The family admin uses the family route for their own deletion. An informal request to info@rewardrangers.com or through the contact form remains available as a route without the app.

With “Delete family”, the family, parent and child records including the assigned app content are removed from the productive database and the parent sign-ins are deleted. Associated paths in file storage are placed in a durable queue before the database deletion, processed and retried after an error. RevenueCat identifiers that can be linked to a person in our database are removed or anonymised. The external RevenueCat deletion is durably queued, attempted automatically and retried after technical errors. If automatic processing cannot be completed, we handle a verified request separately with RevenueCat. Statutory retention obligations as well as technically unavoidable, time-limited backup copies held by service providers remain unaffected and are not used productively any further. An active store subscription is not terminated by the deletion and must be cancelled separately in the respective store.

After a successful family or parent-account deletion, the app clears its personal local storage on the device used for that deletion. Server-side erasure cannot immediately remove local data physically on another device that is temporarily offline; the notes in Section 12 apply there.

14. Your rights

Subject to the statutory requirements, you have the following rights:

  • access to the personal data processed (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
  • withdrawal of a consent given, with effect for the future (Art. 7(3) GDPR).

To exercise them, an informal email to info@rewardrangers.com or a message through the contact form is sufficient. For children, the parents or legal guardians exercise these rights. We answer enquiries as a rule within one month (Art. 12(3) GDPR). Automated decision-making including profiling does not take place.

15. Right to lodge a complaint

Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement (Art. 77 GDPR).

Supervisory authority responsible for the controller:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf

16. Changes to this policy

We adapt this Privacy Policy as soon as changes to the app, the website or the legal framework require it, for instance in the case of new functions or changes among the service providers used. The respectively current version published here applies.


Last updated: August 2026 · Related documents: Legal Notice · Terms · Contact