Cookies & externe Inhalte

Schnitzelhunter verwendet notwendige Browser-Speicher für Sprache, Theme, Spielstände und Sicherheit. Externe Inhalte wie Karten, Ortssuche oder Audio-Einbettungen laden wir erst nach deiner Freigabe.

Notwendige Speicher

Theme, Sprache, Fortschritt, Sicherheits- und Consent-Einstellungen.

Immer aktiv
Optionale Reichweitenanalyse

Anonyme bzw. aggregierte Nutzungsstatistik mit Vercel Analytics. Admin-, Play-, Login-, Token- und Einladungsbereiche sind ausgeschlossen.

Externe Inhalte

OpenStreetMap/Nominatim, optionale Bildkarten, eingebettete Audio-/Video-Inhalte.

Verwendete Speicher: `schnitzelhunter-cookie-consent`, `schnitzelhunter-locale`, Theme-Auswahl sowie lokale Fortschritts- und Team-Namen-Speicher.
AGB & HaftungNutzungshinweise
DeutschEnglishEspañol

Schnitzelhunter

Privacy Policy

Information about the processing of personal data by Schnitzelhunter.

Last updated: 10 August 2026

Only enter data that is genuinely required to run the hunt. Do not publish sensitive or confidential information in hunt texts, images, AI prompts or player names.
1. Controller and contact2. Scope and organisers3. Hosting, access and security4. Login, creator account and sessions5. Hunts, content, players and progress6. GPS, location checks and camera7. Cookies, local storage and analytics8. Maps, place search and external media9. Optional AI assistant10. Payments, feedback and support11. Recipients, processors and international transfers12. Retention and deletion13. Public links and files14. Your rights15. Children and schools16. Changes to this notice

1. Controller and contact

The controller responsible for operating Schnitzelhunter is BYTENETICS Web & IT-Solutions e.U., Gutshofweg 1, 4310 Mauthausen, Austria. Email: info@schnitzelhunter.com, telephone: +43 677 990 17 917.

Privacy requests may be sent to datenschutz@schnitzelhunter.com. No data protection officer has been appointed where there is no statutory obligation to do so.

Legal basis: Article 6(1)(c) GDPR for statutory privacy obligations and Article 6(1)(f) GDPR for secure handling and documentation of requests.

2. Scope and organisers

This notice applies to the web app at app.schnitzelhunter.com and its creator, administration and play areas.

Creators decide the content, locations, player or team names and operation of a hunt. For school, professional, association or organisational use, the organiser may be a separate controller for participant data. Where Schnitzelhunter processes those data solely on the organiser’s instructions, it acts as a processor. Organisers must inform participants and collect only necessary data.

Legal basis: Article 28 GDPR for processing on behalf of organisers. Organisers select an appropriate Article 6 GDPR basis for their own processing.

3. Hosting, access and security

When the app is accessed, our infrastructure providers process necessary connection data, which may include IP address, time, requested path, referrer, browser, operating system, device, error and security information.

This is required to deliver and secure the service, diagnose errors and prevent abuse. Contractually requested functions rely on Article 6(1)(b) GDPR; security, error and abuse-prevention data rely on Article 6(1)(f) GDPR. Logs are retained only as long as required for these purposes or by law.

Legal basis: Article 6(1)(b) GDPR for requested functions and Article 6(1)(f) GDPR for security, error analysis and abuse prevention.

4. Login, creator account and sessions

Access to existing hunts uses an email address and a time-limited login code. An authentication record and server-side sessions are created, including email, user ID, session ID and creation/last-use times.

These data are required to authenticate creators and assign their hunts. Sessions may be revoked by logging out or using the privacy controls. Sessions and unused authentication records that are no longer required are deleted regularly.

Legal basis: Article 6(1)(b) GDPR to provide the creator account and contractual functions.

5. Hunts, content, players and progress

We store hunt settings and content such as title, icon, mode, start time, story, clues, tasks, answers, station data, images and access tokens. Participation may process player or team name, device identifier, membership, progress, station times and completion status.

This enables the selected hunt, progress display and live dashboard. Creators should use pseudonyms instead of real names. New player names are encrypted server-side in the database.

Legal basis: Article 6(1)(b) GDPR for creation and operation; for participant data in organisational hunts, Article 28 GDPR together with the organiser’s legal basis.

6. GPS, location checks and camera

In GPS mode, location is requested only after device permission. Several readings containing latitude, longitude, accuracy and timestamp are sent to the server. Distance, the last plausible location, check time and a suspicion counter may be retained briefly in the play session for plausibility and abuse checks.

Location data are used only to unlock location stations and prevent manipulation, not for advertising or movement profiles. They are removed no later than 24 hours after the play session was last used. Permission can be withdrawn in device settings, after which GPS stations will not work.

The QR scanner optionally requires camera access. Video frames are analysed locally in the browser and are not uploaded or stored as camera recordings. Only the recognised QR content is processed for gameplay.

Legal basis: Article 6(1)(b) GDPR where GPS is necessary, Article 6(1)(f) GDPR for manipulation prevention, or Article 6(1)(a) GDPR where consent is the applicable basis. Local QR analysis does not create a server-side camera recording.

7. Cookies, local storage and analytics

Necessary cookies and browser storage are used for language, display, sessions, device identification, progress recovery, security and your privacy choice.

Optional analytics loads only in accordance with the privacy choice. It may process filtered page paths, time, country/region, browser, operating system and device type. Admin, play, token and invitation information is excluded. Consent can be withdrawn at any time in cookie settings.

Legal basis: Article 6(1)(b) or (f) GDPR and section 165(3) TKG 2021 for strictly necessary storage; Articles 6(1)(a) and 7 GDPR plus section 165(3) TKG 2021 for analytics and optional device access.

8. Maps, place search and external media

After consent, map tiles from OpenStreetMap and imagery from Esri and the named imagery contributors can load directly in the browser. Providers receive data such as IP address, browser, referrer and requested map area. Place searches are proxied to Nominatim/OpenStreetMap and include the search term.

Optional YouTube content loads through youtube-nocookie.com. Google/YouTube may still process connection, device and usage data when content is played. External maps and media remain blocked without consent.

Legal basis: Article 6(1)(a) GDPR for external maps, satellite imagery and media loaded after consent.

9. Optional AI assistant

When explicitly used, data required for generation are sent to OpenAI. This may include hunt title, theme, tone, audience, story instructions, station names, clues, answers, puzzle parameters and image descriptions. Content may also be automatically moderated.

The transfer is limited to the requested generation and content safety. Do not submit names, contact details, confidential data or special categories of personal data. According to OpenAI, API content is not used to train general models by default; technical retention and controls depend on the API plan used.

Legal basis: Article 6(1)(b) GDPR to provide the expressly requested AI function.

10. Payments, feedback and support

Optional payments are processed by Stripe, including checkout/payment data, email, amount, currency, status and fraud-prevention data. Payment information may be retained longer than a creator account where commercial or tax law requires it.

Voluntary feedback may include rating, selected categories, language, hunt reference, optional text and user agent. It is used to improve the service and is generally deleted or anonymised after twelve months. Support requests are processed with the contact data and content required to resolve them.

Legal basis: Article 6(1)(b) GDPR for payments and support, Article 6(1)(c) for legal retention, Article 6(1)(f) for fraud prevention and Article 6(1)(a) for voluntary product feedback.

11. Recipients, processors and international transfers

Depending on use, we use Vercel for hosting, analytics and files; Supabase for database and authentication; Stripe for payments; OpenAI for optional AI; OpenStreetMap/Nominatim and Esri for maps; and Google/YouTube for optional media.

These providers may use affiliates and subprocessors outside the EEA. Where EU processing or an adequacy decision does not apply, transfers rely on safeguards such as EU Standard Contractual Clauses and additional measures where required. Current subprocessor information can be requested through the privacy contact.

Legal basis: The legal basis of the underlying purpose; Article 28 GDPR for processors and Articles 45 or 46 GDPR for international transfers.

12. Retention and deletion

Hunts are normally deleted 30 days after their scheduled start. Without a scheduled start, the period begins on creation. The deletion date is shown in the administration area. Creators may delete a hunt or their complete account earlier.

Deletion removes the hunt, stations, player/team progress, invitations, play sessions and associated files. Payment and accounting records required by law remain restricted for the statutory period. Protected backups are overwritten according to the provider backup cycle and are not restored to production except where recovery is required.

Legal basis: Article 6(1)(b) GDPR while providing the service, Article 6(1)(c) for statutory retention and Article 6(1)(f) for legal claims and protected backup cycles.

  • GPS anti-cheat data: no more than 24 hours after the play session was last used
  • expired play sessions: no more than 30 days after last use
  • expired creator sessions: no more than 30 days after last use
  • expired rate-limit data: no more than 24 hours after the window ends
  • feedback: generally twelve months
  • payment/tax records: applicable statutory period

13. Public links and files

Hunts are not publicly listed, but secret admin, play, team or invitation links grant access according to their type. Share them only with authorised people and revoke them if disclosed unintentionally.

Uploaded or generated images may be technically accessible through an unguessable public file URL until deleted. Do not upload confidential images or identifiable people without permission.

Legal basis: Article 6(1)(b) GDPR for the selected link function and Article 6(1)(f) for access protection and revocation of compromised links.

14. Your rights

Subject to legal conditions, you have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future without affecting prior lawful processing.

We may request information to verify identity and authority and generally respond within one month. You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.

Legal basis: Article 6(1)(c) GDPR to fulfil data subject rights and Article 6(1)(f) for secure identity and authority checks.

15. Children and schools

Schnitzelhunter may be used for activities involving children. Organisers should use pseudonyms, avoid unnecessary contact details and provide age-appropriate information to children and guardians. Where consent is required, the organiser must ensure it is validly provided by the authorised person.

GPS and camera functions should be voluntary and clearly explained. Organisers should provide an equivalent alternative for participants without a suitable device or permission.

Legal basis: The basis follows the relevant purpose; where consent applies, Article 6(1)(a) and, where applicable, Article 8 GDPR. Organisers must ensure valid representation and age-appropriate information.

16. Changes to this notice

We update this notice when functions, providers or legal requirements change. Material changes will be communicated appropriately in the app. The published version and date above apply.

Legal basis: Article 6(1)(c) GDPR for statutory information duties and Article 6(1)(f) for transparent product communication.

Send a privacy request