Legal

Privacy Policy

Last updated: August 2026

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Julian Stock, Grace-Hopper-Straße 14, 23562 Lübeck, Germany

Email: datenschutz@digitalerbrillenpass.de

2. General information on data processing

We only process personal data of our users to the extent necessary to provide a functioning website and our content and services. Personal data is generally only processed with the consent of the user or on the basis of a legal permission (Art. 6(1) GDPR).

3. Creating a digital glasses prescription card

When you create a digital glasses prescription card using our form, we process the prescription data you enter (e.g. sphere, cylinder, axis, pupillary distance), your customer details, and optionally details about your optician, in order to generate a wallet card for Google Wallet or Apple Wallet and make it available to you via a link or QR code.

The legal basis for this is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of the contract requested by you through the form, or to take steps prior to entering into a contract. Transmission to our server is encrypted (TLS).

If you create the prescription card without an account, you receive a link, valid for 30 days, that lets you link it to a free account afterwards (see section 6). If you don't link it to an account within these 30 days, the data you entered is deleted automatically; you can also request earlier deletion at any time at datenschutz@digitalerbrillenpass.de.

4. Disclosure to Google or Apple (creation of the wallet card)

In order to generate a wallet card from your details, we transmit the data you entered – including your prescription data – via a secure interface to Google LLC or Google Ireland Limited ("Google"), or to Apple Inc. or Apple Distribution International Ltd. (Ireland) ("Apple"), depending on which wallet you create your prescription card for. Google or Apple processes this data to create the card and make it available for you to retrieve via a link or QR code.

Your prescription data may allow inferences to be drawn about a visual impairment and is therefore treated as health data within the meaning of Art. 4(15), Art. 9 GDPR. The legal basis for this processing and disclosure is therefore, in addition to Art. 6(1)(b) GDPR, your explicit consent under Art. 9(2)(a) GDPR, which you give separately before submitting the form. You may withdraw this consent at any time with effect for the future, for example by having your prescription card deleted or by contacting us at datenschutz@digitalerbrillenpass.de.

If you create your prescription card for Apple Wallet, your device also automatically registers with us when the card is added, so that the card updates automatically if you later change your prescription data: we store a device-generated identifier and a push token issued by Apple, which we use to ask Apple to send a silent notification to your device whenever your card changes (Apple Push Notification service); your device then retrieves the updated card directly from us. The legal basis for this is Art. 6(1)(b) GDPR (performance of the contract – automatic updates are not possible without this data); these two values have no health-data relevance. They are deleted once you remove the card from your Apple Wallet (your device reports this automatically) or deactivate the associated prescription card.

Google and Apple are headquartered in the USA. The transfer takes place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023, provided the respective provider is certified under it, and otherwise on the basis of EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Further information on data protection is available at https://policies.google.com/privacy (Google) and https://www.apple.com/legal/privacy/ (Apple).

5. Creating a prescription card as a PDF

If you choose the "PDF" option instead of Google Wallet or Apple Wallet when creating your prescription card, we generate a PDF document in credit-card format from the data you entered on every retrieval, for you to download and print.

Unlike Google Wallet or Apple Wallet (see section 4), your data is never transmitted to an external provider for this option. The data you entered – including your prescription data – remains exclusively on our own servers within the EU and is stored there so the PDF can be regenerated with the current values on every retrieval. The generated PDF document itself is never cached on our servers; it is freshly generated on every download.

The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and, since your prescription data is treated as health data within the meaning of Art. 4(15), Art. 9 GDPR (see section 4), your explicit consent under Art. 9(2)(a) GDPR, which you give separately before submitting the form and may withdraw at any time with effect for the future.

The same retention rules apply as for your other prescription cards: with an account, you can deactivate it in the dashboard at any time and then delete it permanently (see section 6, section 15 "Retention period"); without an account, the 30-day period from section 3 applies.

6. Login and management of your prescription cards in the dashboard

When you log in with your email address (magic-link login, no password), we permanently link the prescription cards created via the generator or the dashboard to an account identified by your email address. This allows you to view, edit or delete your prescription data at any time without having to re-enter it.

To log in, we send a one-time login link, valid for 15 minutes, to the email address you provide. After it is used, we set a session cookie (httpOnly, valid for 7 days) that recognises your browser as logged in for the duration of the session. Logging out invalidates all sessions issued for that account on the server side.

The legal basis for account management (email address, login) is Art. 6(1)(b) GDPR (performance of a contract). For the permanent, account-bound storage of your prescription data, Art. 9(2)(a) GDPR additionally applies – your explicit consent, which you give separately before creating your first prescription card in the dashboard and can withdraw at any time with effect for the future.

You can deactivate any of your prescription cards in the dashboard yourself at any time and subsequently delete them permanently; the associated prescription data is then irrevocably removed from our database. Your account (email address) remains in place until you ask us to delete it at datenschutz@digitalerbrillenpass.de (see the "Your rights" section); once it contains no active prescription cards, it no longer contains any health data.

7. Payment processing for the Pro subscription (Stripe)

If you take out a paid Pro subscription in the dashboard, we use the provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland ("Stripe") for payment processing. Your email address and the payment details you provide to Stripe (e.g. card or account details) are transmitted directly to Stripe and processed there – we ourselves never receive or store your complete payment details at any point.

To manage and cancel your subscription, we link you to a customer portal hosted by Stripe, where you can view your invoices, payment method and subscription status.

The legal basis is Art. 6(1)(b) GDPR (performance of the subscription contract). Stripe may also transfer data to the USA; this takes place on the basis of EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR or, where certified, the EU-US Data Privacy Framework. Further information on data protection at Stripe is available at https://stripe.com/privacy.

8. Server log files

When you access our website, our hosting provider automatically collects information in so-called server log files, which your browser automatically transmits to us. These are: browser type and version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, and IP address.

This data is not merged with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of the website.

9. Cookies and local storage

We only use technically necessary cookies, such as the session cookie set after logging in to the dashboard (see section 6). Under Section 25(2) No. 2 TDDDG, no consent is required for these, as they are strictly necessary to provide the service you have explicitly requested. Our web analytics (see section 11) runs without cookies. No tracking for advertising purposes or disclosure to advertising networks takes place.

In addition, your browser may store technical information in local storage or session storage in some cases, without setting any cookies: a random claim token that links an anonymously created glasses prescription card to your account once you subsequently log in; the billing interval you selected, if you continue the checkout only after logging in; and a flag indicating that you have dismissed the language-switch notice for the current session. These values are automatically removed once the respective process is complete or the session ends, and serve solely the technical functioning of the website. The legal basis is likewise Section 25(2) No. 2 TDDDG.

10. Explainer video (YouTube)

On our homepage we embed an explainer video hosted on YouTube (Google Ireland Limited, Ireland; Google LLC, USA). We use YouTube's privacy-enhanced mode ("youtube-nocookie.com"), which, according to Google, does not set cookies for advertising purposes merely by loading the page.

Initially, only a static preview image is shown, without any connection to YouTube being established. Only when you actively click on the video is the embedded YouTube video loaded; this transmits your IP address and potentially other technical information (e.g. browser type, page visited) to Google, where it is processed.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give by actively clicking on the video after having been informed of this beforehand. You can avoid the data transfer to Google by not playing the video.

Google is based in the USA. The transfer takes place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023, provided Google is certified for it, or otherwise on the basis of EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Further information on data protection at YouTube is available at https://policies.google.com/privacy.

11. Web analytics (Matomo)

This website uses Matomo (formerly Piwik), an open-source software for statistical analysis of visitor access. Matomo is operated on our own server; the data collected is not disclosed to third parties.

The following data is processed: truncated IP address (the last two octets are anonymised before storage), pages accessed, time spent, browser and operating system used, country of origin, and referrer URL. Matomo is deliberately configured on our site to set no cookies at all (cookieless tracking); to distinguish returning visits within the same day, an anonymised identifier derived from IP address and browser signature is used instead, which is not stored on your device.

Since no information is stored on or read from your device, no consent under Section 25(1) TDDDG is required for this analysis. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the anonymised analysis of usage behaviour to improve our offering). You can object to this collection at any time by enabling Do-Not-Track in your browser (Matomo respects this setting).

12. Error and incident monitoring (Sentry)

To detect and fix technical errors in our website and the associated API, we use the Sentry service provided by Functional Software, Inc. Sentry is operated exclusively in the EU region (Frankfurt am Main data centre).

In the event of an error, technical information such as error messages, stack traces, and metadata about the affected request (e.g. the requested URL, IP address) is transmitted. Cookies and authorization headers are automatically removed before transmission and are not shared with Sentry.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stable, error-free operation of our website and API). Further information on data protection at Sentry is available at https://sentry.io/privacy/.

13. Hosting

This website and its associated API are operated by a hosting provider with servers located within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider, ensuring that personal data is processed exclusively on our instructions and in compliance with the GDPR.

14. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content – such as the prescription data you send us via the generator – this site uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the padlock icon in your browser bar.

15. Retention period

Unless a more specific retention period is stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you delete your digital glasses prescription card or cancel your account, the associated data will be deleted, provided no statutory retention obligations apply.

16. Your rights

You have the right, at any time and free of charge, to obtain information about your stored personal data, its origin and recipients, and the purpose of the data processing (Art. 15 GDPR). You also have a right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and a right to object to processing (Art. 21 GDPR).

You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data.

17. Contact regarding data protection

If you have any questions about the collection, processing or use of your personal data, or about information, rectification, blocking or deletion of data, please contact: datenschutz@digitalerbrillenpass.de