Hopsie Hopsie motorhome tracking
Legal information

Privacy

Controller

The controller within the meaning of the GDPR is Manuel Renner, Schützenstraße 14, 24626 Groß Kummerfeld, Germany. Email: info@hopsie.de.

Hosting and website provision

The website is operated on a virtual server provided by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Necessary connection data, including the IP address and HTTP communication data, are processed temporarily for delivery, stability, security, error analysis and abuse prevention (Art. 6(1)(f) GDPR; legitimate interest: secure and reliable operation). Caddy currently keeps no regular access log and the Node application does not log normal page visits. Reduced error or security logs are retained only while required for these purposes or legal claims.

Contact form

We process email address and message as required fields and name and subject as optional fields to receive, handle and answer enquiries and protect the form from abuse. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is handling incoming enquiries and operating a secure form. Without email address and message, an enquiry cannot be sent or answered. Details are not used for advertising or newsletters and are not stored in the Hopsie database.

Email service provider

The form is sent to the application on the IONOS VPS, validated there and handed over by encrypted SMTP connection to webgo GmbH, Wendenstraße 8–12, 20097 Hamburg, Germany. webgo makes the message available in the info@hopsie.de mailbox. Purpose and legal basis are those of handling the enquiry. Messages remain in the mailbox while needed, then are deleted unless another requirement, legal duty or legal claim applies.

Rate limiting and abuse prevention

When the form is submitted, client IP and timestamps are processed in memory for no more than 15 minutes to limit automated or abusive requests. At most five attempts are allowed within 15 minutes; data can disappear earlier when the app container restarts. The legal basis is Art. 6(1)(f) GDPR; legitimate interest is protecting the website and email infrastructure. A signed CSRF value protects against unauthorised submissions, is valid for no more than one hour and is not stored persistently. The invisible honeypot field detects automated input and is not stored.

Cookies and browser storage

No cookie is set during normal public page visits. We do not use analytics, marketing or advertising cookies, profiling or user analytics. The theme setting is stored as light or dark under hopsie-theme in localStorage until changed or browser data are deleted. It contains no user identifier, is not transferred to third parties and serves only the requested display (§ 25(2) no. 2 TDDDG).

Internal login

After a successful login, hopsie_session is set only for the protected internal area. It contains a signed session value, lasts 30 days and has HttpOnly, Secure and SameSite=Lax attributes. There is no server-side session table. The cookie is technically necessary for the explicitly requested login area (Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG; legitimate interest: access protection). Internal form drafts can be stored locally: sessionStorage generally lasts for the tab session, and localStorage until submission, manual deletion or browser-data deletion; these data are not transferred to external providers.

Map and external services

Leaflet resources are partly loaded automatically from the unpkg.com CDN. The browser connects directly to the CDN and transmits at least IP address and usual connection and browser metadata. On the homepage, map tiles are loaded directly from *.tile.openstreetmap.org; this can process IP address, browser and device information, operating system, referrer, time and requested map tiles. The recipient is the OpenStreetMap Foundation and its tile-server network in the United Kingdom. The legal basis is Art. 6(1)(f) GDPR; legitimate interest is providing a functional map. The European Commission has adopted an adequacy decision for the United Kingdom. See the OpenStreetMap Foundation privacy policy. We have no direct influence over retention at unpkg.com or OpenStreetMap.

External links and former guestbook

Manufacturer, product and YouTube pages are links only; a connection to them is made only after a deliberate click. The public guestbook is disabled, new entries are not accepted and earlier entries are not publicly displayed. Remaining earlier entries are retained internally only to document the former guestbook and are deleted once that purpose ends or a valid deletion request applies. Data subjects can contact info@hopsie.de.

Recipients and processing

Recipient categories are IONOS SE for hosting and server operation, webgo GmbH for email transport and mailbox, the OpenStreetMap Foundation and its tile-server network when the map loads, and CDN unpkg.com when Leaflet resources are requested.

Your rights

Subject to statutory requirements, you have rights of access, rectification, erasure, restriction of processing, data portability and withdrawal of consent for the future where processing is exceptionally based on consent. To exercise your rights, contact info@hopsie.de.

Right to object

Where processing is based on Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. Statutory requirements remain applicable.

Supervisory authority

You may lodge a complaint with a data protection supervisory authority, in particular the Landesbeauftragte für Datenschutz – Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein, Holstenstraße 98, 24103 Kiel, Germany. Information and complaint options: www.datenschutzzentrum.de. You may also contact another competent supervisory authority.

Automated decisions

No automated decision-making within the meaning of Art. 22 GDPR takes place.