Privacy Policy
T. Stephan
Kookamp 40
46354 Südlohn
E-Mail: info@exoda.de
Phone: +49 171 3833568
Last updated: March 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
T. Stephan
Kookamp 40
46354 Südlohn
E-Mail: info@exoda.de
Phone: +49 171 3833568
2. Overview of Processing
We process personal data of our users only to the extent necessary to provide the app "Cable Configurator" (Exoda Cable Configurator) and our services. Processing is based on the GDPR and the German Federal Data Protection Act (BDSG).
3. Data Collected
3.1 When Using the App
The following data is automatically collected when using the app:
- Firebase installation ID (anonymous device identifier)
- App version
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical provision and security of the app).
3.2 During Cable Configuration
The options you select in the configurator (cable cross-section, colour, length, connectors) are processed for order fulfilment.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.3 During Ordering and Payment
For order processing and payment we process:
- Name, address, e-mail address, phone number (billing and delivery address)
- Payment data (processed directly by Stripe, see Section 7)
- Order details (configured products, prices, order time)
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.4 Push Notifications
With your consent, we send you push notifications for the support chat. For this purpose, a device-specific FCM token (Firebase Cloud Messaging) is stored.
Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time in your device settings.
3.5 Support Chat
When using the integrated support chat, the following data is processed:
- Your entered name
- Chat messages and optionally sent images
- A randomly generated customer ID (UUID) to associate your chat sessions
- FCM token for push notifications about new messages
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(a) GDPR (consent for push notifications).
3.6 Device and Other IDs
The app collects the following device and other IDs:
| ID Type | Purpose | Storage Location |
|---|---|---|
| Firebase Installation ID | Technically required for Firebase services | Firebase (automatic) |
| FCM Token | Push notifications in support chat | Firebase Firestore |
| Customer UUID | Association of chat sessions | Device (local) + Firestore |
| Stripe Customer ID | Payment processing | Stripe (server-side) |
These IDs are not used for advertising or tracking and are not shared with third parties (except with Stripe for payment processing).
4. Local Data Storage
The following data is stored locally on your device (SharedPreferences):
- Billing and delivery address (to simplify future orders)
- Support chat customer ID and name
- App settings
This data is automatically deleted when the app is uninstalled.
5. Data Storage and Deletion
(1) Order data is stored for the duration of legal retention obligations (generally 10 years pursuant to §§ 147 AO, 257 HGB — German fiscal and commercial law).
(2) Shopping basket data is stored only locally on your device and deleted when the app is uninstalled.
(3) Chat data is automatically deleted after the chat is closed and a configurable retention period.
(4) Other personal data is deleted as soon as the purpose of processing ceases and no legal retention obligations apply.
(5) You can request deletion of your data at any time: Request data deletion
6. Firebase (Google)
We use services of Google Firebase (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for the following purposes:
- Firebase Core – App initialisation
- Cloud Firestore – Storage of article data, price configurations, and chat data
- Firebase Storage – Storage of chat images
- Cloud Functions – Server-side payment processing and e-mail dispatch
- Firebase Messaging – Push notifications
- Firebase Remote Config – Configuration parameters
Google processes data on servers within the European Union (EU/EEA). No transfer to third countries takes place.
Google's privacy policy: https://policies.google.com/privacy
7. Stripe (Payment Processing)
For payment processing we use Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland).
The following data is transmitted directly to Stripe during payment:
- Payment data (credit card number, expiry date, CVC)
- Transaction amount and currency
- E-mail address
- Device information for fraud prevention
We do not store credit card data ourselves. Payment data is processed directly by Stripe and transmitted in encrypted form. Stripe is PCI DSS Level 1 certified.
Stripe processes payment data primarily on servers within the European Union (Stripe Payments Europe, Ltd., Ireland). Stripe may in individual cases transfer data to its US parent company; this is done on the basis of standard contractual clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Stripe's privacy policy: https://stripe.com/privacy
8. TikTok Business SDK (Conversion Tracking)
We use the TikTok Business SDK by TikTok Technology Limited (10 Earlsfort Terrace, Dublin, D02 T380, Ireland) in our app to measure the effectiveness of our advertisements on TikTok (conversion tracking).
8.1 Data Processed
The TikTok SDK collects the following data:
- Device identifiers (IDFA on iOS, provided you have consented to tracking)
- App events (e.g. "Added to cart", "Checkout started", "Purchase completed")
- Transaction values and currency
- Device and operating system information
- IP address (processed by TikTok for attribution purposes)
8.2 Purpose of Processing
The data is used to:
- Measure the success of TikTok advertising campaigns (attribution)
- Optimise advertisements and serve more relevant ads
- Build target audiences for advertisements
8.3 App Tracking Transparency (iOS)
On iOS devices (version 14.5 and above), we ask for your permission in accordance with Apple's App Tracking Transparency (ATT) framework before the SDK may access the advertising identifier (IDFA). Without your consent, TikTok cannot perform cross-device attribution. Basic event capture (without IDFA) is based on our legitimate interest.
8.4 Data Transfers to Third Countries
TikTok may transfer collected data to servers outside the EU/EEA, in particular to TikTok Inc. in the USA. Transfer is based on standard contractual clauses (Art. 46(2)(c) GDPR).
8.5 Legal Basis
- With consent (IDFA access): Art. 6(1)(a) GDPR
- Without IDFA (basic event capture): Art. 6(1)(f) GDPR (legitimate interest in measuring advertising effectiveness)
8.6 Opt-Out
You can stop tracking at any time:
- iOS: Settings → Privacy & Security → Tracking → Disable tracking for the app
- Android: Settings → Google → Ads → Opt out of personalised ads
TikTok's privacy policy: https://www.tiktok.com/legal/privacy-policy-eea
9. Google Ads & Conversion Tracking (Website)
On our website we use Google Ads and its associated conversion tracking tag (Google Tag, gtag.js) provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).
9.1 Data Processed
The Google Tag automatically collects the following data when you visit our website:
- IP address (anonymised)
- Page URL and referrer
- Date and time of visit
- Browser type and operating system
- Interactions on the website (e.g. clicks on the App Store or Google Play button)
- Information about previous interactions with Google ads (cookie-based)
9.2 Purpose of Processing
Conversion tracking allows us to measure the success of our Google Ads campaigns. We can thereby recognise whether users visited our website after clicking an ad or performed a specific action (e.g. clicked the download link).
9.3 Legal Basis
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the success of our advertising campaigns). Where consent is required under § 25 TTDSG (German Telecommunications-Telemedia Data Protection Act), processing is based on your consent (Art. 6(1)(a) GDPR).
9.4 Data Transfers
Data collected by the Google Tag is transmitted to Google servers, which may be located within the EU but also in the USA. For transfers to the USA, the EU-US Data Privacy Framework applies (EU Commission adequacy decision of July 2023).
9.5 Opt-Out
You can prevent Google Ads from collecting your data:
- By installing the browser add-on to disable Google Analytics/Ads: https://tools.google.com/dlpage/gaoptout
- Via the Google Ads settings: https://adssettings.google.com
- By disabling interest-based advertising at: https://www.youronlinechoices.eu
Google's privacy policy: https://policies.google.com/privacy
10. Apple Pay & Google Pay
If you use Apple Pay or Google Pay as a payment method, your payment data is processed directly by Apple or Google. We do not have access to your full payment data.
11. Your Rights
Under the GDPR you have the following rights:
- Access to your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR) — Request erasure
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of granted consent (Art. 7(3) GDPR)
To exercise your rights, please contact: info@exoda.de
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority depends on your place of residence. A list of authorities can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
13. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy as necessary to keep it in line with current legal requirements or to reflect changes to our services. The updated policy will apply to your next visit.