Leihnachbar
Borrow Lend How it works Safety Sustainability
List an item
EN
DE Deutsch EN English
DE Deutsch EN English
Log in Sign up

Privacy Policy

Version: 2026-08-30

1. Controller

The controller responsible for processing personal data in connection with Leihnachbar is:

Grundwerk Technologies UG (haftungsbeschränkt) Bretonischer Ring, 4-6a
85630 Grasbrunn
Deutschland Geschäftsführer: Grigorii Budakov-Shetelia
Email for privacy enquiries: datenschutz@leihnachbar.de

hereinafter “Leihnachbar”, “we”, “us” or “our”.

This Privacy Policy explains what personal data we process when you use https://leihnachbar.de, why we process it, to whom it may be disclosed and what rights you have.

2. General principles

We process personal data only where necessary to operate Leihnachbar, perform bookings, protect the marketplace, comply with legal obligations or pursue the other purposes described in this Privacy Policy.

Depending on the processing activity, we rely in particular on:

  • Article 6(1)(b) GDPR – performance of a contract or steps taken prior to entering into a contract;
  • Article 6(1)(c) GDPR – compliance with a legal obligation;
  • Article 6(1)(f) GDPR – legitimate interests; and
  • Article 6(1)(a) GDPR – your consent.

Where information is stored on or accessed from your terminal device, we additionally comply with section 25 TDDDG.

Leihnachbar is intended exclusively for adults.

3. Website access and server logs

When you visit our website, technically necessary information is processed. This may include:

  • IP address;
  • date and time of access;
  • requested URL;
  • referrer;
  • browser type and version;
  • operating system and device information;
  • HTTP status code;
  • amount of data transmitted; and
  • security-related technical events.

We use this information to deliver the website, investigate technical errors and identify and defend against attacks or abusive activity.

Legal basis: Article 6(1)(f) GDPR.

Our legitimate interest is the secure, stable and reliable operation of Leihnachbar.

Ordinary server logs are generally retained for up to 14 days. They may be retained longer where a specific security incident, suspected misuse or legal obligation requires this.

Hosting and infrastructure services are provided by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur.

4. Registration and user accounts

When you create an account, we may process:

  • name;
  • display name or masked name;
  • email address;
  • mobile telephone number;
  • password only in an appropriately secured or hashed form;
  • registration and confirmation timestamps;
  • account status;
  • language preferences;
  • neighbourhood or general location where applicable;
  • verification status;
  • ratings and account history; and
  • security-related account information.

For Business Lenders we may additionally process:

  • legal or trading name;
  • legal form;
  • business address;
  • authorised representatives;
  • registration authority and registration number;
  • VAT identification or other tax information;
  • business contact information; and
  • payout and verification information.

The data is used to create and administer your account, provide marketplace functionality and communicate with you.

Legal basis: Article 6(1)(b) GDPR.

Where account information is additionally used for fraud, misuse or security prevention, the processing is based on Article 6(1)(f) GDPR.

5. Location, search and nearby results

Leihnachbar is a local marketplace. In order to show you nearby items, we may process:

  • locations, neighbourhoods, postcodes or addresses entered by you;
  • geographic coordinates derived from them;
  • selected search radius;
  • search terms and filters; and
  • a spatially reduced or rounded location for internal marketplace statistics.

For internal supply-and-demand analysis, geographical accuracy is generally reduced to approximately one kilometre or used in aggregated geographical areas.

Location information is used to:

  • show nearby items;
  • calculate distances;
  • rank search results;
  • understand local supply and demand; and
  • improve the marketplace.

Legal basis for search and nearby functionality: Article 6(1)(b) GDPR.

Legal basis for aggregated marketplace analysis: Article 6(1)(f) GDPR. Our legitimate interest is improving and managing the marketplace.

We do not create a permanent movement profile and do not continuously track your location.

If we introduce optional browser-based location detection, it will only be accessed where you actively use the feature and grant the relevant browser permission.

6. Listings and publicly visible information

Where you list an item, we process and publish information including:

  • listing title;
  • description;
  • category;
  • price;
  • Security Deposit;
  • availability;
  • photographs;
  • approximate location or area;
  • Private or Business Lender status;
  • masked display name;
  • ratings; and
  • other information you choose to publish.

The following are not normally made publicly visible:

  • your private email address;
  • your private telephone number;
  • identity documents;
  • payment information; or
  • the precise agreed handover location.

Public listings may be indexed by search engines and other publicly accessible internet services.

Legal basis: Article 6(1)(b) GDPR.

7. Bookings, messages, handover and return

For a booking we may process:

  • Lender and Renter;
  • booking number;
  • booked item;
  • rental period;
  • prices, fees and Security Deposit;
  • payment status;
  • booking messages;
  • agreed handover and return times;
  • agreed handover or pick-up location;
  • one-time codes and handover/return confirmations;
  • photographs documenting the item's condition;
  • cancellations;
  • damage reports;
  • statements and supporting evidence in disputes; and
  • technical timestamps.

We use these data to perform and document the booking, process Security Deposits, facilitate communication between the parties and deal with problems.

Legal basis: Article 6(1)(b) GDPR.

Where required for damage documentation, fraud prevention or the establishment, exercise or defence of legal claims, processing is additionally based on Article 6(1)(f) GDPR.

8. Information shared between Lender and Renter

Leihnachbar applies the principle of data minimisation.

Before a confirmed booking, users are normally identified only through their masked or platform display name.

Once a booking has been accepted and paid, each party may receive information necessary to perform that particular rental. This includes in particular the agreed handover or pick-up location for the relevant appointment.

Private telephone numbers and private email addresses are normally not disclosed to the other party.

This does not prevent disclosure where it is:

  • necessary for the establishment, exercise or defence of specific legal claims;
  • necessary and lawful for the investigation of fraud or criminal activity;
  • required by law or a public authority; or
  • required in the case of a Business Lender by statutory information obligations.

Legally required business and contact details of a Business Lender may therefore be displayed to Consumers.

9. Payment processing through Stripe

We use Stripe to process payments, Security Deposits and payouts.

For users in the European Economic Area, Stripe services are provided in particular by Stripe Payments Europe Limited, Ireland.

Depending on the payment method, Stripe may process:

  • name and contact details;
  • payment information;
  • card or bank account information;
  • billing information;
  • amount and currency;
  • transaction information;
  • IP address and technical information;
  • fraud-prevention information; and
  • payout account information where applicable.

Complete card information is normally processed directly by Stripe and is not stored in Leihnachbar's own database.

Stripe provides us with information including:

  • payment status;
  • transaction identifier;
  • amount;
  • refunds;
  • Security Deposits;
  • payouts; and
  • limited information concerning the payment instrument.

The processing is required to process payments and perform bookings.

Legal basis: Article 6(1)(b) GDPR.

Where Stripe processes information to comply with its own legal obligations or for anti-money laundering, sanctions or independent fraud-prevention purposes, Stripe may act as an independent controller in respect of that processing.

10. Identity verification through Stripe

For certain bookings, in particular where the booking value including Security Deposit exceeds EUR 100, for Business Lenders or where particular security or fraud risks exist, identity verification may be required.

Identity verification is performed using Stripe Identity.

Stripe may process, among other information:

  • photographs of identity documents;
  • information extracted from the document;
  • name and date of birth;
  • document number;
  • address;
  • selfie or camera images;
  • technical device data;
  • IP address; and
  • the verification result.

Leihnachbar does not normally store copies of identity documents or selfies in its own application systems.

Our systems principally store:

  • verification status;
  • verification timestamp;
  • a technical verification reference; and
  • status information required for risk management where applicable.

Authorised Leihnachbar administrators may technically be able to access additional verification information within Stripe where necessary to investigate a particular verification, security incident or legal requirement.

Legal bases: Article 6(1)(b) GDPR where verification is necessary for the relevant platform or payment service; Article 6(1)(f) GDPR for fraud and misuse prevention; and, where applicable, Article 6(1)(c) GDPR for legal obligations.

Stripe may separately process certain identity information for its own legal, security and fraud-prevention purposes.

11. Email through Resend

We use Resend, operated by Plus Five Five, Inc., United States, to deliver emails.

Transactional and service emails

These may include:

  • email verification;
  • booking confirmations;
  • booking acceptance or rejection;
  • payment information;
  • handover and return reminders;
  • security notifications;
  • Security Deposit or dispute messages; and
  • material account notifications.

We may send Resend your email address, name or display name, relevant booking information and the content of the particular service message.

Legal basis: Article 6(1)(b) GDPR and, for security notifications where applicable, Article 6(1)(f) GDPR.

Optional marketing email

Newsletters, product updates and other promotional email are sent only where an appropriate legal basis exists, in particular your consent.

Legal basis: Article 6(1)(a) GDPR.

Consent may be withdrawn at any time for the future, for example through the unsubscribe link in the email or your account settings.

12. SMS through Twilio

We use Twilio, in particular Twilio Ireland Limited, for telephone-number verification and, where applicable, security- or booking-related SMS.

This may involve processing:

  • mobile number;
  • SMS content;
  • time sent;
  • delivery status; and
  • technical communications information.

Legal basis: Article 6(1)(b) GDPR where the SMS is necessary for account verification or contract performance and Article 6(1)(f) GDPR for security-related measures.

This processing does not automatically result in your mobile number being used for SMS marketing.

13. Geocoding using OpenStreetMap/Nominatim

To convert a location entered by a user or an agreed handover/pick-up location into geographic coordinates, we use OpenStreetMap data and, where applicable, the public Nominatim service operated by the OpenStreetMap Foundation.

The location or address to be geocoded is transmitted to Nominatim.

We do not transmit the user's name, email address or telephone number as part of the geocoding request.

The request is made server-side by Leihnachbar so that Nominatim does not need to be directly embedded in the user's browser for this purpose.

The location supplied is either:

  • a location selected by the user for a search; or
  • the handover or pick-up location for a particular booking.

Legal basis: Article 6(1)(b) GDPR where geocoding is required for the location or booking functionality requested by the user.

14. Optional AI features using OpenAI

Photo Studio

Leihnachbar may provide an optional function allowing a user to automatically prepare or improve a listing photograph.

Only where you actively use this feature is the selected photograph sent to the OpenAI API.

For users in the European Economic Area, the provider is in particular OpenAI Ireland Ltd., Ireland.

The processing may include:

  • the listing photograph selected by you;
  • the technical instruction required for the requested image processing; and
  • technical API metadata.

Leihnachbar does not intentionally transmit your name, email address, telephone number or other contact information to OpenAI for this purpose.

Purpose: providing the image processing requested by you.

Legal basis: Article 6(1)(b) GDPR.

We use the OpenAI business API. Under the applicable OpenAI API terms, API inputs and outputs are not used to train OpenAI's models by default.

You should not use the Photo Studio to upload images that unnecessarily show individuals, identity documents, private correspondence or other personal information not required for the listing.

Listing suggestion

When listing an item that is not in the catalogue, you may optionally enter a device name and have the title, brand, category, price, description, uses, accessories and a safety note pre-filled for you.

Only where you actively use this feature is the device name you entered sent to the OpenAI API. That text is the only thing sent.

Your name, email address, telephone number, location and any other account or item details are not sent.

The suggestion is a draft. It is shown to you in the form and is published only when you submit the listing yourself.

Purpose: making it easier to create a listing.

Legal basis: Article 6(1)(b) GDPR.

15. Google Analytics 4

15.1 Only with consent

We use Google Analytics 4 only after your explicit consent.

Until you consent:

  • the Google Analytics script is not loaded;
  • no Analytics connection to Google is initiated by us; and
  • no Analytics cookies or comparable Analytics identifiers are stored on your device.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

15.2 Purpose

We use Google Analytics to understand:

  • how users find Leihnachbar;
  • which search engines, websites or AI assistants refer visitors;
  • which public pages are used;
  • how visitors navigate the website;
  • which features are used; and
  • where technical or content improvements may be appropriate.

We do not use Google Analytics to personally monitor individual registered users.

15.3 Data processed

Depending on your use, this may include:

  • page visited;
  • timestamp;
  • referrer;
  • technical browser and device information;
  • language and screen parameters;
  • website events;
  • approximate geographical region;
  • Analytics identifiers or cookie IDs; and
  • consent status.

We do not send names, email addresses, telephone numbers, precise handover locations, message content or listing photographs to Google Analytics.

Our systems must also be configured so that such information is not contained in URLs, page titles or Analytics event parameters.

15.4 IP addresses

Google technically uses IP addresses during data collection, including to determine an approximate geographical region.

According to Google, individual IP addresses of users in the EU are not logged or stored by Google Analytics 4 and are discarded before being logged.

15.5 Settings

We have disabled in particular:

  • Google Signals; and
  • personalised advertising / ads personalisation.

We do not use Google Analytics for personalised advertising.

15.6 Legal bases

Storage of or access to information on your device is based on your consent under section 25(1) TDDDG.

Subsequent processing of personal data is based on Article 6(1)(a) GDPR.

15.7 Retention

User-level and event-level data in our Google Analytics property is configured for a 14-month retention period.

Aggregated statistical reports that no longer allow a direct link to an individual may remain available independently of this period.

15.8 Withdrawal

You may withdraw your consent at any time for the future.

A function such as “Change/withdraw analytics consent” is available through the website footer or privacy settings.

Withdrawing consent is as easy as giving it.

16. Cookies and similar technologies

We use cookies and comparable technologies such as Local Storage only where required for the relevant function or where you have given prior consent.

Technically necessary storage

This may include:

  • session and login information;
  • security and CSRF information;
  • language preferences;
  • location or search preferences you have requested us to remember;
  • booking state; and
  • your Analytics consent choice.

Where the storage or access is strictly necessary to provide a digital service expressly requested by you, consent is not required under section 25(2) TDDDG.

Associated personal-data processing is based, depending on the function, on Article 6(1)(b) or Article 6(1)(f) GDPR.

Non-essential technologies

Non-essential Analytics or comparable technologies are activated only after consent.

17. Fraud prevention, security and abuse detection

To protect users and the platform, we may process information to identify:

  • duplicate accounts;
  • unusual login attempts;
  • payment failures;
  • abusive chargebacks;
  • suspicious booking patterns;
  • review manipulation;
  • platform circumvention;
  • fraudulent listings; or
  • other security risks.

For this purpose, we may analyse account, booking, payment-status, device, IP, verification and usage signals together.

Legal basis: Article 6(1)(f) GDPR.

Our legitimate interests are protecting our users, preventing fraud, enforcing our Terms and maintaining marketplace security.

Where a measure has a material effect on a user, it should not be based solely on an automated decision within the meaning of Article 22 GDPR. Users may request review of such a decision.

18. Reviews and moderation

For reviews, content reports and moderation proceedings we may process:

  • affected users and listings;
  • review content and rating;
  • associated booking;
  • reason for a report;
  • statements;
  • evidence;
  • moderation decision; and
  • complaint information.

The processing is used to maintain marketplace functionality and safety and to handle unlawful or Terms-violating content.

Legal bases: Article 6(1)(b) and Article 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPR.

19. Recipients

Personal information is disclosed only where required for the relevant purpose.

Recipients may include:

  • the other party to a particular booking;
  • Stripe for payments, payouts and identity verification;
  • Resend for email delivery;
  • Twilio for SMS;
  • OpenStreetMap/Nominatim for geocoding;
  • OpenAI only where you actively use the Photo Studio or the listing-suggestion feature;
  • Google only where you have given Analytics consent;
  • our hosting and infrastructure providers;
  • IT, security and support providers;
  • accountants, lawyers and other professional advisers;
  • banks and payment institutions; and
  • public authorities and courts where legally required or necessary for legal claims.

Where a provider acts as a processor, we use it on the basis of Article 28 GDPR where required.

20. Transfers outside the EEA

Some service providers or their subprocessors may process personal information outside the European Economic Area, particularly in the United States.

Such transfers take place only where the requirements of Articles 44 et seq. GDPR are satisfied.

Depending on the recipient, safeguards may include:

  • an adequacy decision of the European Commission;
  • the EU-U.S. Data Privacy Framework where the relevant recipient is validly certified; or
  • Standard Contractual Clauses adopted by the European Commission under Article 46 GDPR, together with additional safeguards where appropriate.

This may in particular be relevant to Stripe, Resend, Twilio, OpenAI, Google and their respective subprocessors.

You may contact us for further information or a copy of the safeguards applicable to a particular transfer.

21. Retention periods

We do not retain personal data longer than necessary for the relevant purpose.

The following periods generally apply.

Server and security logs

Ordinary server logs are normally deleted after 14 days unless needed to investigate a security incident.

Incomplete registration

Accounts that have not been verified or completed may generally be deleted after 30 days.

User account

Account information is generally retained while the account exists.

Following account deletion, publicly visible profile information is removed and no longer used for normal platform operation.

Some information may continue to be retained where required for legal obligations, outstanding bookings, payments, fraud prevention or legal claims.

Messages, condition photographs and handover/pick-up locations

Booking messages, condition photographs and specific handover and return information are normally deleted or anonymised 365 days after completion of the relevant booking.

Where there is an outstanding damage, Security Deposit, fraud or other dispute, the required information may be retained until final resolution and, where necessary, for the applicable limitation period.

Booking and payment records

Invoices, accounting records and other information subject to statutory commercial or tax retention obligations are retained for the periods prescribed by law.

Invoices and accounting vouchers are generally subject to an eight-year retention period calculated in accordance with the applicable legal rules.

Other commercial or tax records may be subject to six- or ten-year statutory retention periods.

Legal claims

Information required for the establishment, exercise or defence of legal claims may be retained for the applicable limitation period.

The ordinary civil limitation period in Germany is generally three years and normally begins at the end of the year in which the statutory conditions are fulfilled.

Identity verification

Leihnachbar retains the verification status and required evidence information only for as long as necessary for the account, security, payment processing or legal claims.

Identity information held directly by Stripe is additionally subject to Stripe's own retention rules.

OpenAI

The original or processed photograph is stored by Leihnachbar in accordance with the normal lifecycle of the corresponding listing.

A device name entered for a listing suggestion is not separately stored by Leihnachbar; suggested values you keep become part of the listing and share its lifecycle.

Information processed by the OpenAI API is additionally subject to the retention and security settings applicable to our API account.

Google Analytics

User- and event-level data is retained for 14 months. Aggregated statistics may remain available for longer.

Consent records

Information recording when consent was given or withdrawn may be retained for as long as necessary to demonstrate compliance with data-protection requirements.

22. Account deletion

You can initiate deletion of your account through your account settings.

Following account deletion:

  • the account is disabled for ordinary use;
  • public listings and the public profile are removed; and
  • personal information that is no longer required is deleted or anonymised.

Immediate deletion of all information is not possible where individual records are still required for:

  • statutory retention obligations;
  • outstanding bookings or payments;
  • Security Deposit or damage cases;
  • fraud prevention;
  • legal claims; or
  • other legal obligations.

Such information is restricted and used only for the applicable retention purpose.

23. Your rights

Subject to the statutory conditions, you have in particular the following rights:

  • access – Article 15 GDPR;
  • rectification – Article 16 GDPR;
  • erasure – Article 17 GDPR;
  • restriction of processing – Article 18 GDPR;
  • data portability – Article 20 GDPR;
  • objection – Article 21 GDPR; and
  • withdrawal of consent – Article 7(3) GDPR.

You can exercise your rights by contacting the privacy address specified in section 1.

24. Right to object

Where we process personal information on the basis of Article 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation.

We will then cease processing the information unless:

  • we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms; or
  • the processing is required for the establishment, exercise or defence of legal claims.

You may object to processing for direct marketing at any time without providing reasons.

25. Withdrawal of consent

You may withdraw consent at any time for the future.

Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before withdrawal.

Analytics consent may be changed through the relevant link in the website footer or privacy settings.

Marketing emails can be disabled through the unsubscribe link in the relevant message.

26. Right to complain

You have the right to lodge a complaint with a data-protection supervisory authority.

For private-sector organisations established in Bavaria, the competent authority is generally:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach Germany

You may also contact another supervisory authority competent under Article 77 GDPR.

27. Data security

We implement appropriate technical and organisational measures to protect personal information against:

  • loss;
  • unauthorised access;
  • unauthorised alteration;
  • unauthorised disclosure; and
  • other unlawful processing.

Depending on the system, measures include encrypted transmission, secure password storage, access restrictions, role-based permissions, security logging and regular technical updates.

28. No solely automated decisions producing significant effects

Leihnachbar does not currently use solely automated decision-making within the meaning of Article 22(1) GDPR that produces legal effects concerning a user or similarly significantly affects a user.

Automated signals may nevertheless be used to assist fraud, security and moderation processes.

Decisions with material consequences may be subject to human review.

29. Changes to this Privacy Policy

We may update this Privacy Policy where the platform, our providers or legal requirements change.

The current version is available at /en/datenschutz.

Where changes are material, registered users will additionally be informed in an appropriate manner.

Leihnachbar

Borrow equipment from your neighbourhood – instead of buying it.

Borrow

  • Rotary hammer
  • Carpet cleaner
  • Tools
  • Cleaning equipment
  • Moving equipment
  • All categories
  • Projects
  • Post a request

Lend

  • How lending works
  • List a device
  • What can I earn?
  • Earnings
  • Sustainability

Safety

  • Safety
  • Secure payment
  • Deposit
  • Identity verification
  • Prohibited items

Help & legal

  • How it works
  • Frequently asked questions
  • Ranking
  • Imprint
© 2026 Leihnachbar · Munich Privacy · Terms · Withdrawal Policy
Borrow Lend Messages Profile