PK Spot - Privacy Policy
Last Updated: 29 July 2026
Your privacy is important to us. This Privacy Policy explains how PK Spot and its legal owner and operator, Lukas Bühler ("PK Spot," "we," "us," or "our"), collect, use, share, and protect your personal data under applicable data protection law, including the Swiss Federal Act on Data Protection, the EU GDPR, and the UK GDPR and Data Protection Act 2018.
1. Data Controller
The controller responsible for processing personal data through the PK Spot website, applications, and related services is Lukas Bühler, Switzerland.
Full contact details required under data protection law are available on our Impressum page.
2. Information We Collect and How We Use It
We collect and process data in the following situations:
- When you create an account or post content: We collect personal data you provide, such as your username and email address, to manage your account and display your content.
- When you upload media: Uploaded images and videos may be processed by automated safety systems and trusted service providers before publication. This helps us detect prohibited content, prevent abuse, and protect users and the service.
- When you visit our website: We automatically collect technical data (e.g., IP address, browser type) for security and operational purposes.
- When you report a concern, make a complaint, or appeal: We collect the case details, the item concerned, your contact email or account identity, correspondence, and our review record. We also collect limited network, device, authentication, and App Check information to protect the channel from spam and malicious reports. Reporter identity and contact details are private and available only to authorised moderators and service providers needed to operate the case process.
- When you interact with specific features: Services like our interactive maps require processing of technical data to function.
- When we choose an initial map area after consent: After you have accepted our terms and privacy flow, we may use an approximate country or region hint derived from the hosting/network request context or from coarse browser signals such as locale or time zone to choose the first default map area. This is used only to improve the initial map experience, does not determine your precise location, is not used for advertising or profiling, and does not override a map position you have already saved in your browser.
3. Legal Basis for Processing
We process your data based on the following legal grounds:
- Performance of a Contract: To provide the services you request when you create an account (Art. 6(1)(b) EU GDPR and UK GDPR).
- Legitimate Interests: To ensure the security and functionality of our website, analyze traffic with privacy-respecting tools, and protect against spam (Art. 6(1)(f) EU GDPR and UK GDPR). In particular, we use PostHog Analytics on the basis of our legitimate interests in measuring the reach and performance of our website and in improving the user experience. PostHog is configured with privacy-friendly settings: we use the EU data center (eu.i.posthog.com), respect the browser's "Do Not Track" setting, use localStorage instead of cookies, and only create person profiles for identified (logged-in) users. You can object to processing based on legitimate interests at any time by contacting us (see Impressum). If your browser or device blocks analytics or has strict tracking prevention enabled, we respect that.
- Consent: For specific optional processing where we ask for your freely given consent (Art. 6(1)(a) EU GDPR and UK GDPR). You may withdraw consent at any time without affecting processing that occurred before withdrawal.
4. Cookies, Local Storage, and Third-Party Services
To provide our services, we use various technologies. Here is a transparent overview:
| Service / Technology | Provider | Purpose |
|---|---|---|
| Approximate Start Region | PK Spot (us) | After consent, we may use a coarse country or region hint from the request context or browser settings (for example locale or time zone) to choose the initial map area. We do not use this feature to determine precise location, we do not store raw IP addresses for this feature, and we do not use it for advertising, profiling, or sale of personal data. |
| No first-party tracking cookies | PK Spot (us) | We do not set our own tracking/advertising cookies. |
| Consent Memory | PK Spot (us) | We use `localStorage` in your browser—not a cookie—to remember that you have accepted our terms, so we don't show you the welcome message on every visit. |
| Authentication session | Firebase (Google) | To keep you signed in, Firebase Auth stores tokens in IndexedDB/localStorage (not cookies). For optional Google sign-in, the Google Accounts domain may set temporary cookies to complete the OAuth flow. These are essential for sign-in and not used for advertising by us. |
| Website Analytics | PostHog (EU) | To measure website traffic and improve our services. PostHog is configured with privacy-friendly settings: data is stored in the EU, we respect "Do Not Track" browser settings, use localStorage instead of cookies, and only create person profiles for identified (logged-in) users. |
| Interactive Maps | Google Maps API | To display interactive maps. This service is essential for core website features. Google may set its own third-party cookies to ensure functionality. |
| OpenStreetMap amenity markers | PK Spot cache; OpenStreetMap data via public Overpass API instances operated by VK Maps or FOSSGIS | To show public toilets and drinking-water points, your device sends the requested coarse map tile to our Firebase backend. Firebase processes the normal technical and App Check information needed to secure that request. If the public map data is not already cached, our server requests that tile from Overpass using a fixed PK Spot application identifier. We do not forward your IP address, browser user agent, cookies, account information, or App Check token to Overpass. Overpass receives only the requested tile area and PK Spot's server details. Cached records contain public OpenStreetMap content and cache timestamps, not visitor records. |
| Security and abuse protection | Firebase App Check and Google reCAPTCHA Enterprise | After you accept our terms and privacy flow, we use these services to protect PK Spot, our forms, and our Firebase backend from spam, automated abuse, and unauthorized requests. They may process technical information about your browser, device, app, network, and interactions to assess risk and verify that requests come from a legitimate PK Spot app or website. reCAPTCHA may set necessary cookies for this security analysis. This site is protected by reCAPTCHA. |
| Media safety checks | Google Cloud Vision API and related Google Cloud services | When you upload images or videos, we may send them to Google Cloud services for automated safety checks, such as detecting explicit, violent, or otherwise prohibited content before publication. We use these checks to operate the service safely, enforce our rules, and handle reports or legal obligations. |
| Sign in with Google (optional) | If you choose to sign in with a Google account, the Google Accounts service may set necessary cookies on accounts.google.com to manage the login process. These are outside our control and are used solely to authenticate you. |
For more information on how Google processes data, please read Google's Privacy & Terms.
Note: Embedded third-party content (e.g., external videos or social media posts) may set their own cookies when you view or interact with them. We avoid such embeds where possible and load them only when necessary.
5. Data Sharing
We do not sell your personal data. We only share data with the essential third-party service providers listed above to operate our website.
6. International Data Transfers
Our service providers (PostHog, Google) may process data outside of Switzerland, the EEA, or the United Kingdom. PostHog is configured to use servers in the EU (eu.i.posthog.com). Where personal data is transferred internationally, we use a lawful transfer mechanism applicable to the transfer, such as an adequacy decision or regulation, the Swiss-U.S. Data Privacy Framework or UK Extension to the EU-U.S. Data Privacy Framework where the recipient participates, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, and any required transfer risk assessment and supplementary measures.
You may contact us using the details in our Impressum to request further information about the safeguards relevant to your personal data.
7. Data Retention and User Rights
We retain your personal data for as long as your account is active or as needed to provide the Service, meet our legal obligations, resolve disputes, enforce our agreements, and protect users and the Service. Retention periods vary by the type of data and the reason we hold it. When data is no longer required, we delete or anonymize it unless law requires longer retention.
Safety reports, complaints, appeals, evidence, correspondence, and decision records are retained while needed to investigate the case, protect users, demonstrate how we handled it, address repeat abuse, and meet legal obligations. We do not automatically delete a case merely because it is resolved. Volatile security metadata collected by the safety channel, such as raw IP address, IP hash, user agent, origin, and app identifier, is removed after 90 days unless it must be preserved for an active incident, legal obligation, or legal claim. One-time access links, private case sessions, and rate-limit records expire separately.
Depending on the law that applies to you, including the UK GDPR, you may have the following rights regarding your personal data:
- The right to access a copy of your personal data.
- The right to rectify inaccurate personal data.
- The right to erasure ("right to be forgotten").
- The right to restrict processing.
- The right to object to processing based on legitimate interests or for direct marketing.
- The right to data portability.
- The right to withdraw consent at any time where consent is the legal basis.
These rights may be subject to legal conditions and exceptions. To exercise them, please contact us at the email address provided on our Impressum page. We may need to verify your identity before completing a request.
You have the right to object at any time to processing based on our legitimate interests. If we ever use personal data for direct marketing, you may object to that use at any time.
8. Children and Minors
PK Spot is not directed to children under 13. If you are under 13, or are not old enough to consent to online services under the laws that apply to you, you may use PK Spot only with consent from a parent or legal guardian. In the United Kingdom, a child must be at least 13 to provide their own consent to consent-based processing for an online service. Where we rely on consent for a child under 13, we require authorization from a person with parental responsibility and take reasonable steps to verify it.
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a competent data protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC) (www.edoeb.admin.ch). In the United Kingdom, you may complain to the Information Commissioner's Office (ICO) (ico.org.uk). We would appreciate the opportunity to address your concern first.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data. However, no method of transmission over the Internet is 100% secure.
11. Changes to This Privacy Policy
We may update this policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date.
12. Automated Decision-Making
We may use automated tools to flag spam, abuse, or potentially prohibited media. We do not use solely automated decision-making that produces legal or similarly significant effects on you. Where appropriate, moderation decisions can be reviewed by a person.