Privacy Policy

Deutsche Fassung →

Convenience translation. This English version is provided for information only — the German version is the authoritative one.

In short: this website sets no cookies and builds no user profiles. Reach measurement is cookie-less and server-side from our host's access logs; no tracking script is loaded. If you arrive via a campaign link, your browser remembers the campaign parameters from the address bar for the lifetime of the tab in session storage (section 2). Fonts are self-hosted.

1. Controller

Jhael Tabrizi (BrauMo, sole proprietorship)
Knaackstr. 68, 10435 Berlin, Germany
Email: hello@braumo.com

2. Cookies, browser storage & tracking

This website uses no cookies. No profiling takes place. Fonts (Manrope) are delivered from our own server; no Google Fonts or other external CDNs are loaded.

Exactly one item is stored on your device: if you open the website via a campaign link, that is with utm parameters or ref in the address bar, a script on this website stores precisely those parameters in your browser's session storage under the key bm_attr. Only the campaign parameters themselves are stored (e.g. "source: Reddit post"), no identifier, no IP address and nothing about your browsing behaviour; no profile is created from it. The entry belongs to this website alone (first party), is not transmitted to any third party, and is deleted by your browser as soon as you close the tab. Its only purpose is to recognise, on a later purchase, which campaign brought you to us (section 5). The website works exactly the same without that entry; you can remove it yourself at any time by closing the tab or clearing your browser storage.

For reach measurement we use the server-side statistics feature of our hosting provider Netlify (Netlify Analytics). Only the server access logs that arise anyway when the website is requested are evaluated (see section 3); no analytics script is loaded in your browser, no cookies are set and no user profiles are created. We receive only aggregated figures (e.g. page views, visitor counts, country of origin, most-visited pages). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly, cookie-less reach measurement).

3. Server log files

When you visit the website, our hosting provider processes technically necessary access data (e.g. IP address, date and time, page requested, browser type) to deliver the website and ensure security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). This data is deleted after a short time.

Hosting provider: Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. Delivery takes place via a worldwide CDN (including EU locations). A data processing agreement including EU Standard Contractual Clauses for third-country transfers is in place with Netlify. Details: netlify.com/privacy.

4. Contact

If you contact us by email, we process your details solely to answer your enquiry; we do not pass them to third parties. To operate our mailbox we use Microsoft Ireland Operations Ltd. (Ireland) with Microsoft 365 / Exchange Online as a processor; all incoming and outgoing email runs through that service. The legal basis is Art. 6(1)(b) and (f) GDPR. You can object to this use at any time by email.

5. Purchase & checkout (Polar)

When you buy BrauMo, you leave this website: the purchase is handled by the payment provider and seller (Merchant of Record) Polar Software Inc. (USA), which is independently responsible under data protection law for payment processing, invoicing, taxes and delivery of the license key; personal data may be processed in the USA in the course of this. Polar's privacy notice applies: polar.sh/legal/privacy. Clicking "Buy" first calls a redirect function on our hosting that opens a checkout session at Polar without any entry of personal data (section 3 on server logs applies). We receive order data from Polar (e.g. name, email address, billing country, product purchased) to manage your license and provide support.

We receive this order data automatically via signature-verified server notifications from Polar (webhooks) and store it on our own server at Hetzner Online GmbH (Gunzenhausen, Germany — server location Germany; data processing agreement per Hetzner's AVV). The purpose is managing your license, support, our order overview and checking the regional price tier (matching the purchased tier against the billing country; a mismatch never leads to an automatic block, only to personal contact). The legal basis is Art. 6(1)(b) GDPR (performance of contract).

To measure which of our content and campaigns lead to purchases, the origin of your session (so-called utm parameters, e.g. "source: Reddit post") is additionally stored with the order at purchase. Those parameters come from your browser's session storage (section 2) and are appended to the checkout session when you click "Buy"; they are then stored and evaluated on our own server. No cookies, pixels or third-party tracking are involved; no profile of your browsing behaviour is created. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in cookie-less measurement of our marketing effectiveness). You can object to this processing at any time by email.

When handling this order data we use AI-assisted automation: to prepare and send our welcome and trial-phase emails, the order data mentioned above (email address, billing country, order date, product purchased) is processed by our technical service provider Anthropic PBC (San Francisco, USA); the third-country transfer is based on EU Standard Contractual Clauses. Those emails are then sent through our mailbox at Microsoft (Microsoft 365 / Exchange Online, see section 4). Data from your brewery installation is not affected — it never reaches us (see section 7). The legal basis is Art. 6(1)(b) GDPR (support during the trial phase) and Art. 6(1)(f) GDPR (efficient customer communication); you can object to this processing at any time by email.

We delete raw server-notification data after 12 months; we store order data for the duration of the business relationship plus statutory retention and limitation periods.

6. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority.

7. The BrauMo software

BrauMo is self-hosted: the application and all brewery data run on the respective brewery's hardware. This privacy policy covers this marketing website only, not the self-hosted software.

Two technical connections of the installed software touch our infrastructure or Polar: the app fetches an update notice from braumo.com once a day (a simple file request without identifiers; section 3 on server logs applies), and in licensed versions it validates the license key directly with Polar (transmitting the license key and a device label, never brewery data). Brewery, production or HACCP data never leaves the installation.

As of: July 2026 · English convenience translation of the German privacy policy