Skip to main content

Last updated: 2026-08-01

Privacy notice

This notice explains how personal data is processed when using the Tiggy marketplace for tool rentals in Germany. It covers accounts, listings, messages, bookings, payments, deposits, claims, support and Tiggynator.

1. Controller

CloverTree Technologies UG (haftungsbeschränkt) Scharnhorststr. 17 80992 München, Deutschland E-Mail: info@clovertreetech.com Datenschutzanfragen: support@tiggy.eu

No data protection officer is currently appointed. Privacy requests are handled by the controller through the contact above. An internal privacy coordinator is not a formally appointed data protection officer.

2. Data we process

  • Account and profile data: name, email address, encrypted credentials, roles, language and settings.
  • Owner data: private/trader status, address, required identity, business, register and tax details, safety evidence, payout status and Stripe Connect account. Identity documents are processed directly by Stripe where possible.
  • Contract and transaction data: requests, rental dates, prices, fees and payment, refund, deposit, transfer and payout identifiers.
  • Communications and content: messages, reviews, support requests, listings, photos, condition reports, claim evidence and decisions.
  • Technical data: IP address, timestamps, device/browser data, security, error and access logs, and cookie/consent status.
  • Location data: entered address, search area or—after consent—device location for local results.
  • AI inputs: content voluntarily submitted to Tiggynator and generated responses.

3. Purposes and legal bases

  • Contract, account, marketplace intermediation, payment, deposit, claims and support: GDPR Article 6(1)(b).
  • Tax, commercial, payment and authority obligations: GDPR Article 6(1)(c).
  • Fraud prevention, security, abuse prevention, legal claims, quality assurance and technically necessary platform improvement: GDPR Article 6(1)(f). Our interests are a secure, functional and viable marketplace; conflicting rights are assessed in advance.
  • Google Analytics, other non-essential technologies and precise device location: GDPR Article 6(1)(a) and section 25(1) TDDDG. Consent is voluntary and can be withdrawn prospectively at any time.
  • At launch, Tiggy does not send advertising emails, marketing SMS or marketing push notifications. Transactional, security and support notices are not advertising and are necessary to perform the contract.
  • Social login is used at the user’s request for sign-in/account linking: GDPR Article 6(1)(b); optional additional processing requires consent.

4. Recipients and service providers

We disclose data only as necessary for the relevant purpose. Processors are contractually bound under GDPR Article 28 before production use. Some recipients, particularly Stripe when performing its own regulatory obligations, process certain data as independent controllers.

  • Hetzner (backend hosting) and Amazon Web Services using RDS and S3 (production database and file storage in region eu-central-1, Frankfurt).
  • Vercel (frontend hosting and delivery).
  • Stripe (payments, deposit authorisations, refunds, Connect and payouts). Tiggy does not store full card details.
  • Microsoft (business email).
  • Google (social login and—only after consent—Google Analytics).
  • Meta/Facebook (social login at the user’s request).
  • Geoapify (address search, geocoding and location-based results).
  • OpenAI (Tiggynator/AI features; users should not submit unnecessary sensitive information).
  • Grafana and Prometheus (operations, security and performance monitoring).
  • Other users where required to arrange and perform a contract; public profile/listing data according to selected settings.
  • Authorities, courts, advisers and insurers where legally required or necessary for legal claims.

5. Internal access and confidentiality

Employees and managing directors do not receive blanket access to user data. Access is role-based and limited to what is necessary for support, payment reconciliation, fraud and security review, claims, resolving a specific production incident or legal obligations. Particularly extensive access is time-limited, linked to a case and logged. Real production data is generally not copied to development or test systems. Authorised persons are bound by instructions and confidentiality.

6. International access and transfers

A managing director of the German controller works from the United States at times. Such internal access is solely on behalf of the German company, subject to instructions and technical safeguards; it does not disclose data to a separate US business. Some service providers may also have parent companies, support or subprocessors outside the EEA. Before such a transfer, we assess GDPR Articles 44 et seq. and rely in particular on an adequacy decision, including the EU-US Data Privacy Framework where certification is valid, or EU Standard Contractual Clauses with required supplementary measures. Information on safeguards can be requested from the privacy contact.

7. Retention

  • Incomplete registrations are generally deleted after 30 days and rejected or unverified applications after 90 days unless documented security reasons require otherwise.
  • Account data is kept during active use. After account closure, profile data no longer needed is generally deleted or anonymised within 30 days; open bookings, claims and legal obligations take priority.
  • Booking, contract, message, condition and claim records are retained to perform the contract and generally until ordinary statutory limitation periods expire; pending proceedings extend retention.
  • Invoices and booking records are generally retained for eight years, commercial correspondence for six years and company records subject to a ten-year obligation for ten years.
  • Ordinary support cases are generally deleted twelve months after closure; security-related matters may be kept until applicable claims expire.
  • Technical and security logs are generally retained for up to 90 days unless a specific incident, abuse or legal evidence requires longer retention.
  • Consent and legal-document evidence is kept during use and generally until applicable evidence and limitation periods expire.

8. Data-subject rights

Where applicable, individuals have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent. Requests: support@tiggy.eu. A complaint may also be lodged with a data-protection supervisory authority, in particular the Bavarian State Office for Data Protection Supervision.

9. Automation and AI

Tiggynator assists with search, recommendations and guidance. AI output can be incorrect and does not replace professional, legal or safety advice. Claim decisions are not made solely by automated means. If a future decision with legal or similarly significant effects is made solely by automated means, we will provide specific information and applicable safeguards.

10. Sources, required data and minors

We receive data from users, the other rental party, Stripe and social-login providers, technical systems and, where verification is necessary, public registers. Tiggy is intended only for persons aged 18 or over. Information marked as required for an account, contract, payment or owner verification is necessary; without it, the relevant function cannot be provided.

11. Cookies

Essential cookies support sign-in, language, security and preferences. Google Analytics and comparable non-essential technologies are activated only after consent. Details and controls are available at /en/cookie-policy.

12. Security and changes

We use risk-appropriate technical and organisational measures, including access restrictions, individual accounts, multi-factor authentication for privileged access, encryption in transit, logging, backups and recovery procedures. This notice is updated when processing, providers or the law materially change. Data already collected remains subject to the applicable lawful basis; material changes are communicated appropriately.