Privacy policy
Last updated: 24 September 2026
This policy informs you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process when you use the publicly accessible pages of this web application: sign-in, password reset and shipment tracking.
1. Controller
Stele Viktor KurierdienstOwner: Viktor Stele
Rheinstraße 7
63225 Langen
Germany
Phone: +49 6103-9880784
Email: info@stele-kurierdienst.de
We have not appointed a data protection officer, as we do not meet the thresholds of Section 38 of the German Federal Data Protection Act (BDSG). Please send any data protection questions to the contact details above.
2. Scope
This web application is our company's internal management system. Only the sign-in pages and shipment tracking are publicly accessible; we provide the tracking links to our customers and to the recipients of their shipments. Our company website has its own privacy policy. We inform our employees separately about how their data is processed within the system.
3. Hosting and server logs
The web application runs on Microsoft Azure (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). The application server is located in a data centre in the USA (region “West Central US”). The connection between your browser and the server is encrypted with TLS.
With every page request, the server necessarily processes the data your browser transmits:
- IP address,
- date and time of the request,
- requested address (URL) and response status,
- browser type and operating system (user agent).
We need this data to deliver the pages and to operate the application reliably and securely. This includes limiting sign-in and password requests: the server counts requests per IP address for 5 to 15 minutes in memory; the counters are not stored permanently.
For error analysis we use Microsoft's Azure Application Insights. It records technical information about page requests and errors. Your IP address is only used to determine your approximate country and city and is not stored afterwards. We log failed sign-in attempts together with the email address entered, in order to detect attacks on user accounts. The logs are deleted automatically after 90 days.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and error-free provision of the application.
Microsoft processes the data as our processor under Art. 28 GDPR (Microsoft Products and Services Data Protection Addendum). Because the server is located in the USA, data is transferred to a third country. Microsoft Corporation is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). In addition, our contract with Microsoft includes the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
4. Database and authentication service
We store the application's data, the user accounts and the tracking links with Supabase (Supabase, Inc.). The database is located in a data centre in Frankfurt am Main, Germany. Supabase also verifies passwords and sends the password reset emails. Supabase is our processor under Art. 28 GDPR. Where Supabase or its sub-processors can access data from third countries, the transfer is safeguarded by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). More information: supabase.com/privacy.
5. Cookies and browser storage
We only use technically necessary cookies. We do not use analytics, advertising or tracking cookies, which is why we do not ask for consent.
- Form protection (
.AspNetCore.Antiforgery.…): protects forms against forged requests (cross-site request forgery). Our web framework sets it on every page request, including shipment tracking. It only contains a random value and is deleted when you close your browser. - Sign-in (
.AspNetCore.Cookies): keeps you signed in. Deleted when you sign out or close your browser, and invalid after 8 hours of inactivity. - Sign-in with Microsoft
(
.AspNetCore.Correlation.…,.AspNetCore.OpenIdConnect.Nonce.…): only during sign-in via Microsoft; they protect the process against tampering and are deleted afterwards.
Within the internal system, your browser also keeps individual display settings, such as a collapsed sidebar, in its local storage. This information does not leave your device.
The legal basis for storing and reading this information is Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), because it is strictly necessary for the service you requested; for the related processing, Art. 6(1)(b) and (f) GDPR.
6. Sign-in
Sign-in is intended for our employees only. We process:
- Your email address and password. We forward the password in encrypted form to Supabase, which verifies it. Supabase stores it only as a cryptographic hash, never in plain text.
- Your user profile (name, email address, role and, where applicable, the link to your employee record) and the time of your last sign-in.
Sign-in with Microsoft: If you choose “Mit Microsoft anmelden” (sign in with Microsoft), we redirect you to Microsoft Entra ID (Microsoft Ireland Operations Limited, address in section 3). You sign in there with your company account, and Microsoft then sends us your name and email address. Access is only granted to people registered or invited as users by us. Microsoft's processing is governed by the Microsoft Privacy Statement.
While you are signed in, the server checks roughly every five minutes whether your user account is still active and which role it has.
The legal basis is Art. 6(1)(b) GDPR (performance of the employment relationship; the application is a work tool), and Art. 6(1)(f) GDPR for the security checks. We keep the account data for the duration of the employment relationship; afterwards we lock the account and delete it as soon as it is no longer needed for legal obligations or to keep records traceable.
7. Password reset
If you enter your email address under “Passwort vergessen?” (forgot password), we forward it to Supabase. If it belongs to a user account, you receive an email with a link for setting a new password. The link is only valid for a short time. To prevent misuse, the number of requests per IP address is limited (see section 3). The legal basis is Art. 6(1)(b) and (f) GDPR.
8. Shipment tracking
We provide our customers and the recipients of their shipments with links for following a shipment or a vehicle live. Each link contains a random code that cannot be guessed and is only valid for a limited time: vehicle links for between 1 and 24 hours, shipment links until one hour after the planned delivery, and at most 24 hours longer while the shipment is not yet completed.
What the page shows: the shipment status, the planned pickup time, the estimated time of arrival, the pickup and destination locations, the vehicle's current position on a map and its licence plate. We do not show the driver's name or photo. The vehicle position comes from our vehicles' telematics system.
What we store about you as a visitor: only the server logs described in section 3. For each link we also store the time it was last opened, but no IP address and no information about your device. Apart from the form protection cookie (section 5), the page does not set any cookies; the selected language is only part of the address.
Arrival time: To calculate the estimated time of arrival, our server sends the vehicle position and the destination to the Google Routes API (Google Ireland Limited, address in section 9) and, if it is unavailable, to openrouteservice (HeiGIT gGmbH, Heidelberg, Germany). No data about you as a visitor is transmitted in the process.
The legal basis is Art. 6(1)(b) GDPR where we provide tracking as part of an order, and Art. 6(1)(f) GDPR otherwise. Our legitimate interest is to give customers and recipients reliable notice of their shipment's arrival.
9. Google Maps
The tracking map is provided by Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you open the page, your browser loads the map directly from Google's servers. In doing so, Google receives your IP address, information about your browser, the address of our website and the map sections displayed. The data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR).
The map is the core of shipment tracking: you open the link to see where the vehicle is. We therefore load it without asking for separate consent. The legal basis is Art. 6(1)(f) GDPR and, where information is stored on or read from your device, Section 25(2) No. 2 TDDDG. If you do not want this, you can block content from Google in your browser. Status, arrival time and licence plate are still shown without the map.
We have no influence on Google's processing. For details, see Google's Privacy Policy and the Google Maps Additional Terms of Service.
10. Your rights
You have the right to
- access the data we hold about you (Art. 15 GDPR),
- have inaccurate data corrected (Art. 16 GDPR),
- have your data erased (Art. 17 GDPR),
- restrict processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
To exercise these rights, simply contact us using the details in section 1.
Right to lodge a complaint (Art. 77 GDPR): You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de.
11. Further information
You are not obliged to provide us with personal data. However, you cannot sign in without an email address and password or a Microsoft account. We do not use automated decision-making, including profiling (Art. 22 GDPR).
We update this policy when the application or the legal situation changes. The version published here applies. In case of doubt, the German version prevails.