Privacy Policy
Last updated: 22 August 2026
This notice describes what Budborn actually does with your data — not what would be customary. Where something is not deleted, that is stated here, with the reason. Where a commitment has limits, those limits are named.
1. Data Controller
The data controller for this website is:
Dennis Gorgs – Budborn
c/o flexdienst – #20475
Kurt-Schumacher-Strasse 76
67663 Kaiserslautern, Germany
Email: datenschutz@budborn.com
No data protection officer has been appointed; the conditions of § 38 BDSG are not met. Data protection enquiries go to the address above.
2. If you only visit the site
Hosting and server logs
The platform runs on servers of STRATO GmbH, Otto-Ostrowski-Strasse 7, 10249 Berlin, Germany. Strato processes data on our behalf under Art. 28 GDPR. Each page request produces server-side log data: IP address, timestamp, requested address, volume transferred, referrer, browser and operating system identifier. Legal basis is Art. 6 (1) lit. f GDPR — the legitimate interest in secure and reliable operation. These logs are kept by Strato and discarded per its retention periods; we do not analyse them by person and do not combine them with other data.
Age verification
Before access to the platform you are asked for your date of birth. The date of birth is not stored. The entry is only used to calculate whether you are of age; on success your session carries a "confirmed" flag and nothing else. The flag lasts seven days, then the prompt reappears. No separate cookie is set and no database record of the result is created.
Each attempt does record the IP address in a rate-limit table — otherwise the age could be guessed indefinitely. That entry is deleted after one hour. Legal basis: Art. 6 (1) lit. c GDPR together with youth protection law; for the rate-limit table Art. 6 (1) lit. f GDPR.
Cookies and local storage
We use only technically necessary cookies and technically necessary browser storage (session, language, units, form drafts). There are no tracking, advertising or analytics cookies and no tag manager. A full list with purpose and lifetime is in the Cookie Policy. Payment providers may set their own cookies on their own pages — see their notices.
3. Account, profile and community
| Data | Purpose | Legal basis |
| Username, email address, password (bcrypt hash only) | Creating and running the account | Art. 6 I b |
| Optional profile details: bio, location, favourite strain, experience, growing methods, social media handles, avatar and banner, status | Displaying your profile | Art. 6 I b |
| Posts, comments, messages, reviews, trade listings | Community features | Art. 6 I b |
| Experience points, badges, rankings, view counts (incl. daily rank snapshots, kept for up to 12 months — see ToS § 17a) | Platform progression system | Art. 6 I b |
| Grow diaries: strains, dates, measurements, photos, yields | Seed2Smoke / GrowBase | Art. 6 I b |
| Strain entries: effects, flavour, rating | StrainBase, including public averages | Art. 6 I b |
| IP address | Abuse prevention, rate limits, login attempts | Art. 6 I f |
"Art. 6 I b" refers to Art. 6 (1) lit. b GDPR (performance of the user agreement), "Art. 6 I f" to legitimate interests.
What others can see
Posts, comments, profile, uploads, StrainBase entries and grow reports set to public are visible to others — in part also to visitors who are not logged in, and therefore to search engines. That is the purpose of a community platform, but it is a publication: what you write here can only be pulled back to a limited extent. Private messages are not public, but they are not end-to-end encrypted either; access via the database would be technically possible and does not take place in normal operation.
4. Health data (Art. 9 GDPR)
In two places you can state what a strain helps with in your experience — in a StrainBase entry and in the smoke report of a grow. Such statements are health data and specially protected. The following therefore differs deliberately from the rest of this notice:
- The entry is optional and requires separate consent. Legal basis is your explicit consent under Art. 9 (2) lit. a GDPR — not the user agreement.
- The entries do not appear in the public grow report or the PDF. They are visible only to you.
- In StrainBase they only feed an aggregate, and only from three independent entries upwards. A single entry is never attributable to a person.
- You may withdraw consent at any time; the entry is then removed.
- On account deletion these entries are hard-deleted, not merely detached from your name — including where the rest of the entry is retained.
5. Stored location data (RootsBorn)
In the RootsBorn area you can record plantings, renaturation projects and geocaches. Coordinates are optional; only the country is required.
This section covers only locations you deliberately record. The location display on the respect map works entirely differently — nothing is stored and nothing is transmitted there. See section 11a.
The decisive control is the "share location" switch:
Without sharing, the coordinate is rounded to two decimal places before it is stored, i.e. to roughly 1.1 km. The precise value never reaches the database and therefore cannot leak. This is not reversible: if you enable sharing later, you must pick the point again.
With sharing, the precise coordinate is stored. It is still only displayed publicly in rounded form, with a radius of about 1 km.
Legal basis is your consent (Art. 6 (1) lit. a GDPR). The time of consent is recorded so that it can be demonstrated (Art. 7 (1) GDPR). Withdrawing consent on the edit page rounds the stored coordinate immediately.
Exception, geocaches: here the coordinate is always stored precisely — a geocache without a precise location would be pointless. The precise position is visible to you, to every user who has logged the find, and to moderators. On the public overview map a geocache also appears only to about 1.1 km.
6. Images and metadata
Uploaded images are resized to a maximum resolution and re-encoded in the process. Embedded metadata — in particular GPS coordinates, camera serial number and capture time — is removed. This applies to JPEG, PNG, WebP and GIF. For HEIC files (the default format of many phone cameras) the cleaning happens during conversion to JPEG.
Two limits, so the commitment is accurate: for PDF files that you can attach in disputes or order messages, metadata is not removed — author, producing application and timestamps remain. And for a GIF with a malformed structure the file is left untouched rather than damaged during cleaning; such a case is logged.
7. Connected measuring devices
You can connect climate and power sensors to your grow. To do so you provide the credentials of your manufacturer account. Polling runs roughly every 15 minutes from our server — so the manufacturer sees our server IP, not yours.
| Provider | What you provide | Location |
| AC Infinity | Email and password — the password is immediately exchanged for a token and is not stored | USA |
| VIVOSUN | Email and password, both stored permanently (encrypted) | USA |
| Mars Hydro | Email and password, both stored permanently (encrypted) | China |
| Pulse | API key only, no password | USA |
| Shelly | Server address and access key, no password | Bulgaria (EU) |
How the credentials are held: encrypted with XChaCha20-Poly1305, each row with its own key, which is in turn bound to a master key. The master key is stored outside the web directory. If it is missing, nothing is decrypted and nothing is stored in clear text. Your data export does not include the credentials — an export file gets forwarded by email, and they have no place there.
Measurements: temperature, humidity, vapour pressure deficit, CO₂, soil moisture, power and consumption. Raw values are deleted after 90 days. Before that they are condensed into hourly figures and written into your grow diary; those condensed figures remain until you delete the grow or the connection.
Transfers to third countries: connecting to AC Infinity, VIVOSUN and Pulse (USA) and to Mars Hydro (China) means your credentials leave the EU. For the USA there is an adequacy decision, but it only covers certified companies; we could not establish whether these providers are certified. For China there is no adequacy decision. These transfers may therefore lack a level of protection equivalent to European standards, and authorities in the receiving country may be able to access the data. The connection is entirely voluntary and only happens if you set it up; legal basis is your consent under Art. 49 (1) lit. a GDPR. With Shelly the data stays in the EU provided your account sits on a European server — that is determined by your Shelly account, not by us.
8. Orders, payment, shipping
| Data | Purpose | Legal basis |
| Name, delivery address, order items, amounts | Contract performance and shipping | Art. 6 I b |
| Invoice data | Commercial and tax law obligations | Art. 6 I c |
| SEPA mandate: IBAN, account holder, mandate reference | Direct debit on behalf of the seller | Art. 6 I b |
| Shop data: company name, address, tax number | Marketplace operation, provider identification | Art. 6 I b/c |
Card details are never stored with us — they are entered exclusively at the respective payment provider. There is one exception: with a SEPA direct debit mandate, IBAN and account holder are stored in our database, because the collection file for the seller's bank is generated on our server. They are not passed to third parties. On account deletion, IBAN and account holder are cleared; the mandate reference and date remain as evidence of the payment.
With advance payment you receive the seller's bank details and transfer the amount yourself; we collect no payment data.
When ordering from a third-party shop, your name and delivery address are transmitted to the seller so that delivery is possible. For the data the seller collects, the seller is an independent controller.
9. Emails
We distinguish three kinds, and they differ legally:
| Kind | Examples | Can you stop it? |
| Contractual Art. 6 I b | Address confirmation, password reset, order confirmation, shipping, invoice, dispute | No — part of the contract |
| Notification Art. 6 I b | New message, new follower, level-up, badge, task digest | Yes, in settings |
| Advertising § 7 (3) UWG | Reminder about an abandoned cart, request for a review | Yes — separate switch and unsubscribe link in every such email |
The third row is the reason for a separate switch: under German Federal Court of Justice case law, a request for a product review is advertising, even though it looks like service. We send it on the basis of § 7 (3) UWG to customers who have ordered from us — and every such email points out that you can object free of charge. If you object you do not lose your order confirmations; the two are separate.
Delivery runs through STRATO as mail provider. We log when which kind of email went to which account — for the anti-duplicate lock and to be able to follow up on queries. This log is deleted after 180 days.
10. Moderation and abuse prevention
A system called BudGuard checks posts for spam, insults and prohibited content and assigns a score. It records content excerpts (up to 500 characters), IP address and time. Legal basis is Art. 6 (1) lit. f GDPR — the interest in a usable platform and in meeting our obligations under the Digital Services Act.
On Art. 22 GDPR — automated decisions: BudGuard can withhold a post on submission, issue a warning and limit the number of actions per hour. No automated system ever decides about your account: a suspension always requires a human decision — the former automatic suspension mechanism has been removed from the program code, not merely switched off. Every measure is recorded in the moderation log. Warnings expire after a set period.
Objection. You may state your case against any measure and have it reviewed by a person — via the objection form. It is reachable without signing in, because a suspended account cannot sign in. You receive a case number and the outcome with reasons. Whoever issued the measure does not decide the objection. The deadline is 180 days from the measure. The route by email to kontakt@budborn.com remains open, as does approaching a supervisory authority or a court.
The moderation log is retained even when an account is deleted. It records which measure was taken and why, and must remain verifiable — both for you and towards authorities. The real name is no longer recorded in it.
11. Maps
All map pages load map tiles from OpenStreetMap (OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom). This covers the RootsBorn maps and the respect map. They are fetched directly from your browser, so OpenStreetMap learns your IP address and browser identifier. We transmit no data there. Legal basis is Art. 6 (1) lit. f GDPR. If you wish to avoid this, do not open the map pages; every other area works without a map.
The location data of the respect map (schools, playgrounds, nurseries, sports facilities, pedestrian zones, place names) also comes from OpenStreetMap, but is stored on our own server: we imported it once, and your browser only ever queries us. No user data reaches third parties during that import.
Map data © OpenStreetMap contributors, available under the Open Database License.
11a. Location on the respect map
The respect map has a „Where am I?" button. Only when you press it does your browser ask you to share your location — without that permission we receive no coordinate. The legal basis is your consent (Art. 6 (1) lit. a GDPR), which you can withdraw in your browser at any time.
Your position never leaves your browser. It is not transmitted to us, not stored, not logged and not written to your device. The check whether you are inside a zone happens in your browser — the zone data it needs was already loaded when you opened the map. Reloading the page discards everything.
11b. Respect zones — enquiries to institutions
Registered members can propose an institution as a respect zone and provide its publicly available contact address. A proposal triggers no automatic sending: it is first only stored with us and reviewed by a person. Only once that person releases the enquiry do we contact the address once and ask whether the institution wishes to appear on the map. The legal basis is our legitimate interest in a voluntary, verifiable marking (Art. 6 (1) lit. f GDPR). This is a factual enquiry, not advertising.
We store the institution’s name and location, the address provided, the username of the proposer and a random confirmation key. The zone appears on the map only if the institution itself clicks the link in that email.
The same email contains a „never contact again" link. If used, we add the address to a block list and will not write again — not even if another member proposes the same institution. The confirmation key is deleted once a decision is made; an unanswered proposal expires after 30 days. Erasure or objection at any time via the address in the imprint.
12. Recipients
Your data is not sold or rented. These parties receive data, and only what is listed:
| Recipient | What and when | Role |
| STRATO GmbH 10249 Berlin | Server operation and delivery of all emails — technically therefore every email including its content | Processor |
| Sendcloud B.V. 5611 DD Eindhoven, NL | Name, delivery address, email, order number, weight — when a seller creates a shipping label | Processor |
| sevdesk GmbH 77652 Offenburg | Name, address, invoice items, amounts — when an order is paid | Processor |
| PayPal (Europe) L-2449 Luxemburg | Amounts, order reference — PayPal collects name and address itself on its own page | Independent controller |
| Klarna Bank AB 111 34 Stockholm, SE | Name, address, email, amounts — when Klarna is selected at checkout | Independent controller |
| Mollie B.V. 1015 CW Amsterdam, NL | Amount and order reference, no name, no address | Independent controller |
| Sensor manufacturers see section 7 | your own credentials, when you connect a device | Independent controller |
| OpenStreetMap | your IP address when you open a map page | Independent controller |
| Authorities | only where legally required, e.g. by court order | Art. 6 I c |
What expressly does NOT go there: we use healthchecks.io and cron-job.org to monitor our maintenance runs; only a technical status message without any user reference is sent. A Telegram bot serves us internally as a note-taking tool; platform user data is not transmitted there. Shop operators can import their own product catalogue via Google Sheets — no customer data is involved. Fonts and all program libraries are hosted on our own server; there is no external script provider.
13. Retention and deletion
You can delete your account yourself in the settings. That deletion is the same one an administrator can trigger — both call the same routine. It takes effect immediately, not after a delay.
| What | What happens to it | Period |
| Account record | Every content field is cleared — username, email, bio, location, avatar, banner, status, favourite strain, experience, skills and the social media handles. The row itself remains as an empty shell because many references point to it. | immediate |
| Private data: messages, notifications, bookmarks, carts, grow diaries, location data, sensor credentials, blog posts | deleted, together with the associated files on the server | immediate |
| Health data (section 4) | deleted, including where the rest of the entry remains | immediate |
| Forum posts, comments, reviews, StrainBase entries, trade listings, breeding projects | remain, without your name. A conversation does not belong to one participant alone: removing your post makes the replies of others incomprehensible. Reviews remain so that a shop cannot make unwelcome ones disappear via account deletion. | — |
| Orders and invoices | remain in full — we are required to keep them (§ 147 AO, §§ 238, 257 HGB). Afterwards name, address and note are cleared; amounts and items remain. | 10 years |
| SEPA mandate | IBAN and account holder are cleared, mandate reference and date remain | immediate |
| Your shop | is closed, not deleted — the retention-bound orders refer to it | 10 years |
| Moderation log | remains, without real names (section 10) | — |
| Raw sensor values | discarded | 90 days |
| Abuse prevention log (with IP) | discarded | 90 days |
| Login attempts (with IP) | discarded | 24 hours |
| Rate counters, age check | discarded | 1 hour |
| Email log | discarded | 180 days |
| Expired confirmation links | discarded | 7 days after expiry |
| Browser session | expires | 7 days |
A word on accuracy: what remains above is pseudonymised, not anonymised. The account record keeps its identifier, and posts then carry the label "[Deleted]". That is a difference we do not want to blur: it would only be anonymous if every route back were excluded.
14. Your rights
Access (Art. 15) and portability (Art. 20): under "Settings → Export data" you receive a machine-readable file containing everything stored under your account. The export works on an inverted principle: it covers every table with a personal reference; whatever is deliberately omitted is listed in the file itself with a reason. Password hashes and access keys are excluded — they say nothing about you and do not belong in a file that gets forwarded by email.
Rectification (Art. 16): you can edit your profile and posts yourself. For anything else, a message suffices.
Erasure (Art. 17): "Settings → Delete account". What happens is set out in full in section 13.
Restriction (Art. 18) and objection (Art. 21): by message to the address above. You may object to advertising at any time free of charge — via the switch in settings or the unsubscribe link in the relevant email.
Withdrawal of consent (Art. 7 (3)): consents — health data, location sharing, device connection — can be withdrawn at any time. The lawfulness of processing up to withdrawal is unaffected.
No obligation to provide: for an account we need a username, email address and password; for an order, name and address. Everything else is voluntary; without it we simply cannot provide the respective service.
15. Complaint to the supervisory authority
You may lodge a complaint with a data protection supervisory authority at any time. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
Phone: +49 6131 8920-0
Email: poststelle@datenschutz.rlp.de
www.datenschutz.rlp.de
You may equally contact the supervisory authority of your place of residence or work.
16. Security
Passwords are stored as bcrypt hashes and never in clear text. Confirmation links exist only as SHA-256 hashes. All forms are protected against cross-site submission; login attempts and email sending are rate-limited. Credentials for device connections are stored encrypted (section 7). The connection to the site is encrypted throughout, and the site sets a content policy that prevents loading third-party scripts.
No system is completely secure. If you notice something, write to kontakt@budborn.com — reports of vulnerabilities are welcome and will not be treated as an attack.
17. Changes
This notice is updated when the platform changes. The version available here is authoritative; the date at the top states its status. For substantial changes we will point them out at your next login.