Privacy Policy
1. Overview
This Privacy Policy explains how Asemgo UG (haftungsbeschränkt) ("we", "us", or "our") processes personal data when you use the Wetterbaby mobile application (the "App") and the website wetterbaby.com including the web demo (the "Website"; together the "Services").
Wetterbaby is designed to be data-minimal:
- No user account is required or offered — we do not maintain accounts and do not identify individual users.
- Information about your child (first name, date of birth, optionally gender) and your settings are stored only locally on your device. The first name and date of birth are never transmitted to us or to any third party by the App; for product suggestions, our server receives only a coarse age group and, if you have entered it, the gender, without any identifier (Section 3.7).
- The App contains no third-party advertising, analytics, or crash-reporting SDKs and does not track you across apps or websites. Product suggestions in the App and on the Website may include clearly marked affiliate links and sponsored placements, whose reach we measure without personal reference and evaluate only in aggregated form (Section 3.6).
- We do not sell personal data and do not share it with advertisers.
2. Controller
The controller responsible for the processing of personal data described in this Privacy Policy is:
Asemgo UG (haftungsbeschränkt)
Pestalozzistraße 25
22305 Hamburg
Germany
Email: mail@asemgo.co
We are not legally required to appoint a data protection officer and have not appointed one; the controller can be reached directly at the address above for all data-protection matters.
3. Data processed in the App
3.1 Data that stays on your device
The following data is stored exclusively locally on your device and is not transmitted to us:
- your child's first name, date of birth, and optionally gender (used to calculate age-appropriate recommendations and to select suitable product suggestions);
- your preferences and settings (e.g. saved locations, stroller/carrier mode, room temperature, sleeping-bag TOG value, temperature sensitivity, units, day/night window, country for regional product suggestions);
- your subscription and trial status.
Because this data never reaches our systems in this form, we do not process it within the meaning of data-protection law. You can delete it at any time by deleting the App. Clothing recommendations are calculated locally on your device; no profile of you or your child is created on our servers. Section 3.7 describes the derived, coarse information the App sends to retrieve product suggestions.
3.2 Location data and weather retrieval
To show weather and recommendations, the App sends a request to our server containing:
- the geographic coordinates of the requested location (your device location, if you have granted the optional location permission, or a location you searched for and saved manually);
- the App version and your language setting (the location's time zone is derived from the coordinates on our server).
The request contains no user identifier, no account, and no advertising ID. We use the coordinates solely to retrieve the weather data for the requested location from our weather-data provider (Section 5.1) and to determine the applicable time zone. Coordinates are not linked to you and are not stored beyond short-term technical caching: weather responses are cached for currently up to 15 minutes, and place-search and geocoding responses for up to a few days — in each case keyed by location or search query, not by user or device.
Providing this data is neither legally nor contractually required; however, without the coordinates of a location we cannot show weather or recommendations for it.
Use of the device location permission is optional (foreground only; the App does not access your location in the background). You can revoke the permission at any time in your device settings and instead add locations manually via search.
Legal bases: Art. 6 (1) (b) GDPR (performance of the contract — providing the weather and recommendation service); for the device location permission additionally your consent given at operating-system level (Art. 6 (1) (a) GDPR), which you can withdraw at any time in your device settings.
3.3 Server logs and security
When the App or your browser communicates with our servers, our hosting infrastructure (Section 5.2) technically processes connection data, in particular your IP address, request time, and request metadata, in short-lived server logs. We use this data solely to provide the connection and to ensure the security, stability, and abuse prevention of our Services (Art. 6 (1) (f) GDPR — legitimate interest in secure and functional operation). Log data is not used to identify users and is retained only as long as required for the security purposes stated, after which it is automatically deleted.
3.4 Purchases
Purchases of Wetterbaby Plus are processed exclusively by the app store through which you obtained the App (currently Apple). The app store provider is responsible for processing your payment and account data under its own privacy policy; we receive no payment details and no identifying account data from the store. The App checks your entitlement (subscription or lifetime purchase) directly against the app store on your device.
3.5 Support and contact
If you contact us (e.g. by email), we process the data you provide (email address, content of your message) to handle your request (Art. 6 (1) (b) and (f) GDPR). Support correspondence is retained for a maximum of 12 months unless a longer retention period is required by law.
3.6 Affiliate links, sponsored placements, and product images
The Services may show product suggestions containing affiliate links (marked as such, e.g. with "*"), currently to Amazon. If you tap such a link, the retailer's store opens and the link contains a referral identifier that attributes the visit to Wetterbaby, not to you. From that point on, the retailer's own privacy policy applies. We ourselves transmit no personal data to affiliate partners and do not learn what you view or purchase; we receive only aggregated commission reports from the affiliate program.
Product images. The images of product suggestions are generally loaded directly from the servers of the respective retailer or affiliate program (currently Amazon), because its license terms prohibit us from storing copies of these images on our own servers. When an image is loaded, the retailer technically receives the connection data required for the retrieval (in particular your IP address and browser or app metadata), regardless of whether you tap a link. We transmit no further data in the process, in particular no information about you or your child, and we have no influence on the retailer's processing; the retailer acts as an independent controller under its own privacy policy. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in displaying current product images and in financing the Services through product suggestions); for transfers to third countries see Section 6.
Regional selection. So that product suggestions are available in your region, the App selects them based on the country of your app store account or your device region (the country code only, no location); the Website derives the country from your IP address. The country code is not linked to you and, apart from reach measurement, is not stored.
Reach measurement. The Services may also contain clearly marked sponsored product placements. For product suggestions we record impressions and clicks to determine their reach and report it to our partners. Per event we record only the product, the event type, the source (App or Website), the country code, the App version, and the time. No advertising identifiers, no cookies, no user or device identifiers, no user profiles, and no tracking across apps or websites are used; we store no IP address with these events (the connection data technically involved in the request is subject to Section 3.3). The events are therefore not linkable to you or your device and are evaluated only in aggregated form. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in financing the Services through non-personalized placements and in measuring their reach); where the law requires consent for specific measurement techniques, we will request it.
3.7 Retrieving product suggestions
To retrieve product suggestions, the App sends a request to our server containing:
- a coarse age group of your child (a range of months derived from the date of birth; the date of birth itself is not transmitted);
- your child's gender as selected in the App, if you have entered one (optional; without it, all products are shown);
- the country code for regional selection (Section 3.6), the App version, and your language setting.
The request contains no user identifier, no account, and no advertising ID. Our server uses this information solely to assemble the response to that one request; it is neither stored beyond the technical processing of the request nor linked to you or to earlier requests, and no profile is created. Entering the gender is voluntary. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in age- and region-appropriate product suggestions that help finance the Services); for the voluntarily entered gender additionally your entry in the App, which you can remove there at any time.
4. Data processed on the Website
4.1 Visiting the Website
When you visit the Website, connection data (in particular your IP address) is technically processed as described in Section 3.3.
4.2 Web demo
If you use the web demo and enter a city or location, the entered search terms and the resulting coordinates are processed to display example weather information and recommendations. As with the App, no account and no user identifier are involved.
4.3 Product suggestions on the Website
The pages for individual clothing pieces may contain product suggestions with affiliate links and sponsored placements. Section 3.6 applies accordingly: product images are loaded directly from the respective retailer, the country for regional selection is derived from your IP address and not linked to you, and reach measurement works without cookies and without identifiers.
4.4 Web analytics
On the Website (not in the App) we use Vercel Analytics, a privacy-focused analytics service that works without cookies and without cross-site tracking. It collects aggregated usage information — page views, country-level region, device type, and aggregated interaction events (for example, that a search was performed or a download button was clicked, without the content of your input); IP addresses are not stored and visitors are not persistently identified. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in understanding and improving our Website); where required by law, we will ask for consent instead.
5. Recipients and processors
We share data only as described below and do not share personal data with advertisers or other unauthorized third parties.
5.1 Weather, geocoding, and map data
To retrieve weather data, forecasts, and place search / geocoding results, the coordinates or search terms of the requested location are transmitted to our data provider, currently Apple Inc. (Apple Weather / WeatherKit and Apple Maps). These requests are made by our server on your behalf and contain no user identifier.
5.2 Hosting
Our server and the Website are hosted by Vercel Inc. (USA), acting as our processor under a data-processing agreement. Our server-side functions are executed in Vercel's Frankfurt region (fra1), so the server-side request processing described in this Policy takes place on servers located in Germany.
5.3 Communication providers
For handling support emails we use email service providers acting on our behalf.
5.4 Affiliate and sponsorship partners
We ourselves do not transmit personal data to affiliate or sponsorship partners; they receive only aggregated statistics from us (Section 3.6). When product images are loaded and when you follow a link to a partner, the respective retailer technically receives connection data and processes your data under its own responsibility and privacy policy (Section 3.6). Our affiliate partner is currently Amazon (Amazon Europe Core S.à r.l., 38 avenue John F. Kennedy, L-1855 Luxembourg, and its affiliated companies of the Amazon group).
5.5 Authorities and legal obligations
We disclose data to authorities or third parties only where we are legally obliged to do so or where necessary to establish, exercise, or defend legal claims (Art. 6 (1) (c) and (f) GDPR).
6. International data transfers
Our server-side processing runs in Frankfurt, Germany (Section 5.2). However, some of our providers (in particular Apple and Vercel) are companies based in the United States, and limited access to data from the USA (for example for support, administration, or analytics) cannot be ruled out. The servers from which product images are loaded (Section 3.6) may also be operated by companies of the Amazon group outside the EU/EEA. Where personal data (such as IP addresses) is transferred to countries outside the EU/EEA, we rely on an adequacy decision of the European Commission (including, where applicable, certification of the recipient under the EU–U.S. Data Privacy Framework) and/or on the EU Standard Contractual Clauses with additional safeguards.
7. Retention
We retain personal data only as long as necessary for the purposes described above:
- Weather requests / coordinates: not stored; weather responses are cached for a short period (currently up to 15 minutes) and place-search/geocoding responses for up to a few days, in each case keyed by location or search query only.
- Server logs: automatically deleted after a short period.
- Support correspondence: a maximum of 12 months, unless statutory retention obligations require longer.
- Analytics data (Website): stored only in aggregated form without personal reference.
- Product-suggestion requests (age group, gender if entered, country code): not stored; used only to answer the respective request.
- Impression and click events for product suggestions: collected without personal reference (Section 3.6) and evaluated only in aggregated form.
8. Children
The Services are directed at parents and caregivers, not at children, and we do not knowingly collect personal data of children on our servers. Information about your child that you enter in the App (first name, date of birth, optionally gender) remains on your device (Section 3.1); for product suggestions, our server receives only a coarse age group and, where entered, the gender, without any identifier and without storage (Section 3.7).
9. No automated decision-making
We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR. Clothing recommendations are generated locally on your device from weather data and your settings, without any server-side profile. Product suggestions are selected per request from the coarse information named in Section 3.7, without profiling and without storage.
10. Data security
We protect data through appropriate technical and organizational measures, in particular transport encryption (TLS/SSL) for all data transmissions, request validation for our API, data minimization by design, and strict access controls limited to authorized personnel and processors.
11. Your rights
Under the GDPR you have the right, subject to the respective legal conditions, to:
- Access (Art. 15 GDPR) — information about the personal data we process about you;
- Rectification (Art. 16 GDPR) — correction of inaccurate data;
- Erasure (Art. 17 GDPR) — deletion of your data;
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Objection (Art. 21 GDPR) — you may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 6 (1) (f) GDPR); we will then no longer process the data unless compelling legitimate grounds prevail;
- Withdrawal of consent (Art. 7 (3) GDPR) — at any time with effect for the future, without affecting the lawfulness of processing before withdrawal.
Please note: because we do not maintain user accounts and do not store identifying data about App users, we may not be able to link server-side data (such as short-lived logs) to you; in that case, Arts. 15–20 GDPR may not apply pursuant to Art. 11 GDPR. Data stored locally on your device is under your own control.
To exercise your rights, contact mail@asemgo.co.
You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence or place of work. The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.
12. Users outside the EU/EEA
If you use the Services from outside the EU/EEA (for example, from the United Kingdom, Switzerland, Norway, the USA, Canada, Australia, or New Zealand), the data practices described in this Privacy Policy apply equally, and you may have comparable rights under your local law (e.g. the UK GDPR, the Swiss FADP, the CCPA/CPRA in California, PIPEDA in Canada, or the Australian Privacy Act). We do not "sell" or "share" personal information within the meaning of the CCPA/CPRA and do not use personal information for cross-context behavioral advertising. You can exercise your rights via mail@asemgo.co.
13. Device permissions
The App requests the following optional permission:
- Location (while using the App): to determine the weather at your current location. The App does not access your location in the background. You can revoke this permission at any time in your device settings; the App remains usable with manually searched locations.
14. Changes to this Privacy Policy
We update this Privacy Policy when our Services or legal requirements change. The current version is always available in the App and on the Website; the date of the last update is shown above. In case of significant changes, we will inform you in an appropriate manner.
15. Contact
For any questions about data protection, contact us at mail@asemgo.co.
Further provider information can be found in our imprint.