Legal information
Privacy Policy
Last updated: 8 August 2026. This Privacy Policy explains which personal data is processed when you visit TeamCounter and when you use the native Android app.
1. General information
Protecting personal data is important to me. This Privacy Policy applies to the website teamcounter.net and to the native TeamCounter Android app.
This website is deliberately designed to minimise data use. On selected public website pages, the Google tag for Google Analytics 4 starts asynchronously immediately under Google Consent Mode v2 with all analytics and advertising consent signals initially set to denied. Full cookie-based Analytics measurement is enabled only after the corresponding choice through CCM19. Google Tag Manager, social media plugins, a newsletter, comments, user registration and a contact form are not used.
TeamCounter can be used free of charge. Google AdSense may be used on this website to finance its operation, hosting, security and further development. Details can be found in the “Online marketing” section of this Privacy Policy.
Cloudflare Web Analytics is used for privacy-friendly reach measurement and technical analysis of the website. According to the provider, Cloudflare Web Analytics is used without cookies, without LocalStorage and without individual fingerprinting.
2. Controller
The controller responsible for the processing described in this Privacy Policy on the website and in the app is:
Maximilian Holstein
Schmiededamm 9
25379 Herzhorn
Germany
Email: teamcounter@holsteinshops.de
Website: https://teamcounter.net
3. Hosting and technical provision
This website is hosted by STRATO.
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
When this website is accessed, STRATO processes technically necessary data in order to provide the website securely, reliably and in working order.
This may include the following data in particular:
- IP address
- date and time of access
- page or file accessed
- amount of data transferred
- browser used
- operating system used
- referrer URL, if transmitted
- status codes and technical access information
This data is processed in server log files. Processing takes place in order to provide the website technically, ensure the stability and security of the systems and detect possible attacks or disruptions.
According to STRATO, visitors’ IP addresses are stored for a maximum of seven days for the detection and prevention of attacks.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in providing this website securely, reliably and without technical errors.
Further information about data protection at STRATO is available at: https://www.strato.de/datenschutz/
4. Data processing on behalf of the controller
A data processing agreement pursuant to Art. 28 GDPR has been concluded with STRATO.
This is an agreement required under data protection law and is intended to ensure that STRATO processes the personal data of website visitors only in accordance with instructions and in compliance with the GDPR.
Where Cloudflare processes personal data as a processor in connection with the use of Cloudflare Web Analytics, this is done on the basis of Cloudflare’s contractual data processing terms. Cloudflare provides a Data Processing Addendum for this purpose.
Where Google services, Google Analytics 4, Google AdSense or the consent management solution provided by Google process personal data on behalf of the controller or as an independent provider, the provider’s respective privacy and contractual terms apply.
5. Use of cookies and comparable technologies
Technically necessary cookies or comparable technical storage may be used where they are required for the operation of the website, for example for technical provision, security functions or the WordPress administration area.
If you actively select the light or dark website design, this setting is stored exclusively in your browser under teamcounter_public_theme_v1. The selection is not transmitted to TeamCounter, is not used for advertising or tracking, and can be removed by deleting the local website data in your browser.
Google Analytics 4 may set the cookies _ga and _ga_* only after analytics consent has been given through CCM19. In addition, cookies, web beacons or comparable technologies may be used in connection with Google AdSense. Where consent is required, advertising technologies are controlled separately through the Google/AdSense consent banner provided.
According to Cloudflare, Cloudflare Web Analytics is used without cookies and without LocalStorage. Cloudflare also states that it does not fingerprint visitors by IP address, user agent or other characteristics in order to identify individual visitors.
5.1 Google/AdSense consent banner
Google may display a consent or privacy banner for Google AdSense. This banner is created and published in the Google AdSense account and is used to request and manage the consent required for advertising cookies, web beacons or comparable technologies.
Consent that has been given can be changed or withdrawn with effect for the future through the displayed Google/AdSense consent banner, through privacy settings provided by Google or by deleting the corresponding browser cookies. Personalised advertising technologies must not be activated without the required consent.
Further information is available in Google’s privacy information: https://business.safety.google/intl/en/privacy/ and https://policies.google.com/privacy.
5.2 Availability of Google consent management
Before advertising can be enabled, Google consent management must be configured and published independently of the disabled ad loader and tested on the approved pages. The website loads no ads while the applicable API is unavailable. It operates independently of the additional CCM19 consent manager used on the website.
The “Advertising privacy settings (Google)” link in the footer opens Google’s revocation flow once the applicable Google consent API is available. Until then, the link remains a normal link to this explanatory section of the Privacy Policy.
5.3 Android app notice and consent management with CCM19
The optional Android notice uses no event tracking. Hiding currently applies to this document only; no dismissal preference is read or stored. List data is not changed or sent to the store.
This website also uses the CCM19 consent management tool provided by Papoo Software & Media GmbH, Auguststraße 4, 53229 Bonn, Germany. CCM19 displays a consent banner and manages decisions concerning technologies that require consent.
To provide the banner, a script is loaded from cloud.ccm19.de. The visitor’s IP address is technically transmitted to the provider’s server. The consent decision may be stored in the browser together with technical evidence such as a timestamp, banner version and a randomly generated identifier.
The banner is used throughout the browser-based website, including list views, but not in the native Android app. Google Analytics uses Advanced Consent Mode: the Google tag starts asynchronously on eligible public pages without waiting for the banner, while analytics_storage, ad_storage, ad_user_data and ad_personalization initially remain denied. CCM19 controls the Analytics choice and may update analytics_storage accordingly. Analytics consent must never grant ad_storage, ad_user_data or ad_personalization; advertising consent remains separately governed by the Google/AdSense consent message and its TCF signals. The footer link “Analytics and cookie settings (CCM19)” can be used to change or withdraw the Analytics choice with effect for the future. Further provider information is available at https://www.ccm19.de/datenschutz/.
6. Online marketing
TeamCounter provides simple counting functions without registration and without paid access. To keep TeamCounter free to use in the long term, advertising may be displayed on TeamCounter pages through Google AdSense. The advertising helps to finance the ongoing costs of hosting, security, maintenance and further development of the website.
Use of the TeamCounter functions does not depend on consenting to personalised advertising. Where the consent banner is displayed, you can use it to give or refuse consent or to withdraw it later with effect for the future.
6.1 Google AdSense
Google AdSense is an advertising service provided by Google Ireland Limited, Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland. Ads help finance the free use, hosting, security, maintenance and further development of TeamCounter.
Retrieving the AdSense script establishes a technical connection to Google. Connection data such as the IP address, browser information and the URL of the requested page may therefore be transmitted even if the AdSense account has not yet been approved or no ad is displayed. Account approval and ad delivery are separate from this technical script request.
Google AdSense is prepared only for explicitly approved public guides and template pages. The central delivery switch remains off until account status, consent management and page exclusions have been verified. Analytics consent cannot authorize advertising.
The home page and tool entry pages, personal online lists, view and management links, local lists, My lists, the web dashboard, presentation, the app page, legal and contact pages, print, export and technical responses are excluded from website AdSense.
Private lists retain their indexing protection and are excluded from public sitemaps. There is no special advertising-crawler permission to read them. A view or management link remains an access key; noindex alone does not provide confidentiality.
AdSense may use cookies, web beacons or comparable technologies to provide and measure advertising. These processes take place only after the user has given the required consent pursuant to Art. 6(1)(a) GDPR through the Google/AdSense consent message where consent is required. Without the required consent, personalised advertising technologies must not be activated during the visit.
Google participates in the EU-U.S. Data Privacy Framework for relevant transfers to the United States. Further information is available at https://business.safety.google/intl/en/privacy/ and https://policies.google.com/privacy.
Third-party vendors, including Google, may place and read cookies in users’ browsers or use web beacons, IP addresses or other identifiers to serve and measure ads, support security and fraud prevention and – after the required consent – personalise ads based on prior visits to this website or other websites. Google’s use of advertising cookies enables it and its partners to serve ads based on users’ visits to this website and/or other sites on the Internet.
Beginning in August 2026, Google may use IP addresses in the EEA, the United Kingdom and Switzerland for ads measurement and ads personalisation, subject to the required consent and other legal requirements. The ad technology providers that may receive data are identified in the provider and purpose list of the Google/AdSense consent management solution shown to the user.
Users can opt out of personalised advertising through Google Ads Settings: https://www.google.com/settings/ads
Google explains how it processes data from sites and apps using Google services at: https://policies.google.com/privacy/partners
7. WordPress and WPCode
This website is based on WordPress. The WPCode plugin is also used to manage technical code customisations within WordPress.
WPCode may be used on this website to include custom technical functions, CSS, JavaScript or PHP snippets.
Cloudflare Web Analytics, the consent-controlled Google tag for Google Analytics 4 and Google AdSense may be integrated technically through WPCode, the TeamCounter snippet or a comparable integration in the page source.
The use of external services, scripts or comparable third-party technologies is described in this Privacy Policy.
If additional external services, tracking scripts, embedded content, marketing services or similar third-party technologies are integrated through WPCode in the future, this Privacy Policy must be updated accordingly.
8. Cloudflare Web Analytics
This website uses Cloudflare Web Analytics, a privacy-friendly web analytics service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
Cloudflare Web Analytics is used to better understand the use and technical performance of this website. The analysis helps in particular to determine which pages are accessed, whether the website works without technical errors and how the website performs in terms of loading times and performance metrics.
According to Cloudflare, Cloudflare Web Analytics is used without cookies, without LocalStorage and without individual fingerprinting. Cloudflare also states that it does not track individual end users across the different online services of its customers.
When Cloudflare Web Analytics is used, a JavaScript script is loaded from Cloudflare. This script is usually provided through the following address: https://static.cloudflareinsights.com/beacon.min.js
The script may process the following usage and performance data in particular:
- page accessed or URL path
- website hostname
- referrer, if transmitted
- country of access
- device type, for example desktop computer, smartphone or tablet
- browser used
- operating system used
- technical website performance metrics, for example loading times and Core Web Vitals
- technical information about the page view
Cloudflare Web Analytics is not used to identify individual visitors personally. No advertising profiles are created and no personal analysis of individual users takes place.
When the Cloudflare script is retrieved and measurement data is transmitted, Cloudflare may technically process connection data. This may include IP addresses or comparable technical access data where required to provide and secure the service.
Cloudflare states that it stores unsampled beacon data for seven days and then aggregates it for longer-term analysis.
The legal basis for the use of Cloudflare Web Analytics is Art. 6(1)(f) GDPR. The legitimate interest lies in data-minimising reach measurement, technical optimisation, error analysis and improving the user-friendliness of this website.
Where personal data is transferred to the United States or other third countries in connection with Cloudflare Web Analytics, Cloudflare states that this is done on the basis of appropriate data protection safeguards, in particular the Cloudflare Data Processing Addendum, the EU-U.S. Data Privacy Framework where applicable, and the European Commission’s Standard Contractual Clauses where required.
Further information about Cloudflare Web Analytics is available at: https://www.cloudflare.com/web-analytics/
Further information about data protection at Cloudflare is available at: https://www.cloudflare.com/policies/privacy/
Information about the Cloudflare Data Processing Addendum is available at: https://www.cloudflare.com/cloudflare-customer-dpa/
8.1 Google Analytics 4 and Google tag
On selected public website pages, TeamCounter uses Google Analytics 4 through the Google tag with measurement ID G-WLSPEK05NH. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google LLC in the United States may also act as parent company or technical service provider.
The purpose is consent-based reach measurement, understanding the use of public information and function pages, detecting technical problems and improving usability. Depending on the device and configuration, Google may process a generated client identifier, IP address and approximate location derived from it, browser, device, operating system, language, consent state, time of access and interaction or diagnostic events. Google states that IP addresses are not logged or stored in Analytics in full.
The Google tag is implemented in Advanced Consent Mode and is requested asynchronously immediately on eligible public pages. Before analytics consent is given, analytics_storage, ad_storage, ad_user_data and ad_personalization are set to denied; no artificial wait_for_update delay is used. In this denied state, Google may nevertheless receive cookieless consent-state and measurement pings together with technical request data such as the IP address, user agent and requested public URL. Analytics cookies and non-essential device storage are enabled only after consent. The legal basis for storing or accessing non-essential information on the device is consent under Section 25(1) TDDDG and, for the subsequent consent-based processing, Art. 6(1)(a) GDPR. Refusal has no effect on the TeamCounter functions.
Analytics is deliberately excluded from private list, management, view and presentation URLs, local/offline list pages, the web app and “My lists” areas, legal and contact pages, the native app, and export or print outputs. The measurement code transmits only a cleaned public page URL without query string or fragment and a technical route label; it suppresses the page referrer. List IDs, tokens, user-defined list names, list contents and browser-stored list links are not attached to Analytics events by TeamCounter.
Google signals and advertising-personalisation signals are disabled in the TeamCounter tag configuration. After Analytics consent, Google Analytics may use cookies such as _ga and _ga_* to distinguish visits and sessions. That Analytics choice updates only analytics_storage and does not constitute advertising consent. It can be changed or withdrawn at any time with effect for the future through “Analytics and cookie settings (CCM19)” in the footer. Cookies already stored can also be deleted in the browser.
The retention of event and user-level data depends on the retention setting actually configured in the Google Analytics property and must be checked there by the operator. Aggregated reports may remain available for longer. No fixed retention period is promised here without verification of that account setting.
Google may process data in third countries, in particular the United States. Where applicable, Google relies on the EU-US Data Privacy Framework and additional safeguards such as Standard Contractual Clauses. Further information is available at https://support.google.com/analytics/answer/11593727, https://business.safety.google/privacy/ and https://policies.google.com/privacy.
9. Google Search Console and Bing Webmaster Tools
Google Search Console and Bing Webmaster Tools may be used for technical search engine optimisation and to monitor how easily this website can be found.
Google Search Console is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Bing Webmaster Tools is a service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA, or by the applicable Microsoft entity.
These services help to monitor the website’s presence in search engines, identify indexing problems, check crawling errors and analyse search performance data. The following data in particular may be displayed or processed for this purpose:
- search queries through which pages on this website were found
- clicks, impressions, click-through rate and average position in search results
- affected page URLs
- indexing status, crawling errors and technical information
- information about sitemaps and search engine crawling
Google Search Console and Bing Webmaster Tools do not set their own analytics cookie or use their own tracking script on this website to analyse visitors. Website verification may be carried out technically through an HTML file, a DNS record or a meta tag.
Processing takes place on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in technical search engine optimisation, error analysis, discoverability and secure administration of the website.
Further information is available from Google at https://support.google.com/webmasters/answer/10268906 and in Google’s Privacy Policy at https://policies.google.com/privacy.
Further information about Bing Webmaster Tools is available at https://www.bing.com/webmasters/help/search-performance-c680da36 and in Microsoft’s Privacy Statement at https://privacy.microsoft.com/privacystatement.
10. Wordfence Security
This website may use the WordPress security plugin Wordfence Security. The provider is Defiant, Inc., USA.
Wordfence is used to protect the website against attacks, malicious code, unauthorised login attempts, brute-force attacks, suspicious bot traffic and other security-relevant access. For this purpose, Wordfence provides in particular a web application firewall, a malware scanner, login security functions, blocking functions and security logs.
For security purposes, Wordfence may process the following data in particular:
- IP address of the accessing device
- date and time of access
- URL accessed or file requested
- referrer URL, if transmitted
- browser, user agent, operating system and technical header information
- information about suspicious or blocked requests
- information about login attempts, for example user names used in failed login attempts
- technical security events, firewall hits, blocks and scan results
According to the provider, Wordfence must determine a visitor’s IP address in order to apply security functions such as firewall rules, blocks and brute-force protection correctly. Wordfence may also record server-side access in its “Live Traffic” function. This recording may include access that would not be recorded by analytics tools based solely on JavaScript, for example bot or crawler access.
Wordfence may set technically necessary cookies, in particular in connection with the firewall, the detection of logged-in WordPress users and login security functions. These cookies are not used for marketing or advertising, but to secure the website. For normal visitors without a WordPress login, these functions are generally relevant only to the extent necessary to detect and prevent security-relevant requests.
Wordfence may store security and Live Traffic data in the WordPress database. The storage period depends on the Wordfence settings and the relevant security purpose. According to Wordfence, Live Traffic can be limited by number of entries and by days; by default, the maximum retention period for Live Traffic data is 30 days.
As part of security functions, updates, firewall rules, malware signatures, IP reputation queries or similar Wordfence services, communication with Defiant servers may take place. Technical data such as IP addresses, website URL, plugin or system information or security-relevant access data may be processed where required to provide and secure the service.
The legal basis for using Wordfence is Art. 6(1)(f) GDPR. The legitimate interest lies in securing the website, defending against attacks, detecting malicious code, preventing abusive access and protecting data stored on this website.
Where personal data is transferred to the United States or other third countries in connection with Wordfence, this is done on the basis of appropriate data protection safeguards, in particular the Standard Contractual Clauses or data protection terms provided by Defiant, where required.
Further information about Wordfence and privacy is available at: https://www.wordfence.com/privacy-policy/
Wordfence information about the GDPR is available at: https://www.wordfence.com/help/general-data-protection-regulation/
Information about the Wordfence Standard Contractual Clauses is available at: https://www.wordfence.com/standard-contractual-clauses/
11. No other analytics, advertising or tracking services beyond the services listed
Apart from Cloudflare Web Analytics, consent-controlled Google Analytics 4, Google AdSense with Google’s consent controls, CCM19 for website consent management, the clearly labelled Amazon affiliate text links described in section 23, the CHECK24 and Temu affiliate text links described in sections 24 and 25 on the German benefits page, Google AdMob and UMP in the Android app, the search engine webmaster tools listed above and Wordfence as a security service, no other analytics, advertising or tracking services are used.
In particular, the following are not used:
- Google Tag Manager
- Meta Pixel
- Microsoft Clarity
- Matomo
- Hotjar
- other advertising networks apart from Google AdSense and Google AdMob
- affiliate tracking scripts
- social media tracking
12. No contact forms, comments or user accounts
This website does not provide a contact form.
Comments and public user registration are disabled. Visitors cannot create their own user accounts or publish comments on this website.
13. Use of TeamCounter functions
TeamCounter provides simple online functions for creating and using digital counters, tally lists or comparable lists.
Depending on how the service is used, users can enter their own labels, categories, counter values, list names or similar content. These entries may contain personal data if users enter real names or other information relating to people, for example.
Users are asked not to enter sensitive personal data. In particular, confidential, health-related, political, religious or other data requiring special protection should not be entered. Wherever possible, first names, initials or neutral labels should be used for simple counting processes.
When a tally list or one of the additional tools is created through TeamCounter, the list data required for it is stored in the WordPress database. Depending on the function used, this includes in particular:
- list ID or tool ID
- management token for the management link
- name or title of the list
- counter names, task labels, team names, personal names or participant names, where entered voluntarily
- counter values, starting values, optional target values and totals
- for scoreboards: teams or people, points, colours and winner marking
- for drinks lists: people, number of entries, price per entry and calculated totals
- for attendance lists: participants, attendance status, date and saved appointments or history entries
- for value counters: categories, value per click, number, period, note and calculated totals
- creation time, time of last edit and time of last activity
Where TeamCounter stores lists, counter values or similar content, this takes place to provide the function requested by the user, for example saving, sharing or subsequently retrieving a list.
Created lists cannot be found through a public overview. However, they are technically accessible to anyone who knows the corresponding link. The view link permits the list to be read. The management link also permits entries to be changed, counted and added. Users should therefore share management links only with people who are allowed to change the corresponding list.
Specific list URLs and private tool URLs are not intended to be publicly indexed. Where technically provided, such URLs are marked noindex,nofollow and are not intentionally included in public sitemaps. Absolute secrecy cannot be guaranteed for shared links, however, because anyone with the link can access the corresponding list.
The legal basis is Art. 6(1)(b) GDPR where processing is necessary to provide the function requested by the user. Processing may additionally be based on Art. 6(1)(f) GDPR. The legitimate interest lies in providing the online tool in a functional, secure and user-friendly manner.
TeamCounter currently does not delete lists automatically merely because a fixed inactivity period has expired. A list remains stored until it is permanently deleted through the management link, a justified deletion request is processed or a statutory deletion obligation is implemented.
Deletion can be requested informally by email to teamcounter@holsteinshops.de. Please initially provide the list/tool ID or view link so that the relevant list can be identified. A management link should be sent only if it is required for unambiguous identification after an explicit request; it allows changes and must be treated like a password.
14. Native Android app and local app area
TeamCounter is also provided as a native Android app through Google Play. The app does not display TeamCounter through a WebView, PWA or visible browser window. Its interface and navigation consist of native Android views. For current values of server-based lists, collaborative editing and the creation of those lists, the app communicates exclusively through encrypted HTTPS requests with the TeamCounter API on teamcounter.net. The local offline click counter does not require this API.
The app requires internet access and network-status access for online lists, consent management and advertising. The normal RECEIVE_BOOT_COMPLETED permission is used exclusively to reschedule already configured, token-free widget work after a device restart. Following an app update, the separate MY_PACKAGE_REPLACED system broadcast serves the same purpose. The scheduled work contains no token; for an expressly configured online update, the required management link is read from encrypted local storage only when the work runs. The AD_ID permission belongs to Google AdMob. Included Google and Android libraries may also add technical permissions for AdServices or Privacy Sandbox, basic phone state, wake locks and a WorkManager foreground service to the merged manifest. These permissions do not trigger a dangerous runtime permission dialog; TeamCounter does not request runtime access to the camera, microphone, precise location, contacts, call logs, telephony, SMS, calendar, photos, files or Bluetooth.
The app does not create a TeamCounter user account or a separate TeamCounter user profile. Content in server-based lists, such as list names, person or team labels, categories, values and counts, is processed on TeamCounter servers to provide the selected online function as described in section 13.
Depending on the online action deliberately selected, the app sends to the TeamCounter API in particular the list or tool ID, management or access token, title, list type, language, base URL, action, expected state and the required list or tool content. Technical request information includes the app version in the User-Agent, language, security nonce and connection information. This may also cause the server or hosting provider to process the IP address, time, requested endpoint, status code and other server-log data described in section 3.
The “My lists” area stores TeamCounter list links and associated convenience metadata locally on the device. This may include a management or view link, display name, list type, short summary, origin, and creation, modification and last-opened times. These records are encrypted using a key from the Android Keystore. Management links permit a list to be edited and should therefore be protected like a password.
An additional local feature store may contain, for each server-based list, favourite, archive, pinning, selected metric, view type, sorting and zero-value filter, as well as bounded local states for write operations, undo actions, sessions, rules, templates and recently loaded list data where those functions are expressly used. These local data support the native user experience; they do not replace the server-based list and are not synchronised between devices as a TeamCounter account. The respective payloads are encrypted using keys from the Android Keystore. For database operation and integrity verification, technical row identifiers, pseudonymous references and status, time and revision information are also kept unencrypted in the app's private database area; each row, including its encrypted payload, is authenticated with an HMAC.
Non-sensitive app settings, in particular the selected colour scheme, language, compact display, keep-screen-awake option and completion state of the introduction, are stored in private app storage. A widget configuration stores only the local identifiers and settings needed for the selected widget, such as widget ID, mode, list type and public list or item IDs, selected title, appearance and technical revision states. It contains neither a management link nor access token or its own shadow copy of list values. Following a deliberate user action, widget actions may update the relevant online list through the TeamCounter API.
The additional offline click-counter feature is technically separate and exclusively local. For each click counter, the selected name, current count, start or reset value, positive or negative step rule, and exactly the action and previous value required for the most recent undo are held in the encrypted payload. A random local ID, creation, modification and last-use times, and local revision are additionally kept as technical, unencrypted database fields in private app storage; the complete row is authenticated with an HMAC. Favourite and archive status are assigned locally according to the same principle. There is no unlimited tap-by-tap history.
Click-counter data are neither synchronised with TeamCounter servers nor sent as content to analytics or advertising services. Independently of this, the normal consent-dependent AdMob banner may trigger an ad request on the click-counter page; the name, count, start value, step rule and undo data are not attached to that request. Deleting a click counter removes only that local record and its local organisational state.
Android cloud backup and Android device transfer are disabled for the app; databases and Shared Preferences are additionally excluded by the corresponding backup rules. If the app is uninstalled or its storage is cleared, local links, click counters, settings and feature states are lost. This does not automatically delete the actual online lists on the TeamCounter server.
Sharing, copying and QR-code generation take place only following an explicit user action. The app marks a management link copied to the Android clipboard as sensitive and attempts to remove it after 60 seconds or when the Activity ends normally, provided that it is still there unchanged. The operating system and device manufacturer ultimately control the clipboard, so automatic removal cannot be guaranteed if the process ends abruptly. A QR code contains only the validated view link, is stored temporarily in the private app cache, and can be passed to a user-selected app or storage location only after a further choice. QR files older than 24 hours are cleaned up when another QR code is generated; the operating system may remove cache files independently. After a deliberate transfer, the privacy terms of the selected destination app or storage provider also apply.
“Enjoying TeamCounter?” is only a menu item that the user can open manually. “No” and “Later” close the dialog without storing a rating status. Only “Yes” opens the Google Play app or, as a fallback, the canonical Play webpage with the public package ID and no TeamCounter tracking parameters. Further processing is then performed by Google Play or the selected browser.
“Contact support” opens the installed email client with teamcounter@holsteinshops.de as the recipient only after a deliberate choice. TeamCounter does not send a message at that point and does not add any list or counter data. Only if the user sends the email in the selected client will the relevant email provider and recipient process the submitted information under their terms and section 15.
Local storage is used for app functions expressly selected by the user. Where information is stored on or read from the device for this purpose, this constitutes technically necessary or expressly requested storage within the meaning of Section 25(2) No. 2 TDDDG. Where personal data is involved, processing takes place to provide the requested function on the basis of Art. 6(1)(b) GDPR and additionally Art. 6(1)(f) GDPR; the legitimate interest is a secure, fast and user-friendly app experience.
Users can remove individual locally stored links, click counters and other local states through the provided app functions or clear app storage through Android. Removing an item from “My lists” deletes only the local reference on this device and not the actual TeamCounter server list. A server list is permanently deleted only through the separate delete function using the management link or following a justified deletion request.
14a. Google AdMob / advertising in the Android app
The native Android app contains the Google Mobile Ads Next-Gen SDK and the Google User Messaging Platform (UMP). The app displays advertising through Google AdMob to help finance its operation, maintenance and further development. A single responsive ad banner may appear above the permanently visible app navigation on main app views. On “My lists”, this applies only while the local overview is confirmed to be empty. As soon as at least one valid list has been saved, the lower banner is no longer shown there. If at least one saved list is visible on the first results page, a native ad card clearly labelled “Ad” may appear instead in the scrollable content: directly after the last list card when one or two lists are visible, and directly after the third list card when three or more lists are visible. The banner and native ad card are never shown at the same time on “My lists”. No interstitial, full-screen, app-open or rewarded ad is requested.
At the beginning of a newly created app or Activity session, the app updates the required consent information before Google Mobile Ads is initialised and the first ad for that session is requested. In the production build, the SDK is initialised and a banner or native ad is requested only if UMP permits ad requests. If at least one valid saved list exists, exactly one native ad may be prefetched in memory after this consent gate so that it is ready more quickly when “My lists” is opened. List contents, TeamCounter links, access tokens, and names and counts of local click counters are not sent to Google as ad content for this purpose. A prefetched ad older than one hour is discarded before it can be used. The relevant ad objects are discarded when consent changes, ad eligibility or placement ends, the final valid saved list is removed, or the Activity is finally destroyed. During a short interruption or while the app is in the background, loaded or in-flight ad objects may temporarily remain in memory but are made fully invisible so that no ad is displayed there. No ad is shown in the tutorial, dialogs or consent forms, or in the widget and its configuration. The lower banner is hidden while the on-screen keyboard is visible.
The provider of Google Mobile Ads / AdMob is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Technical processing may also be carried out by Google LLC in the United States as the parent company or a technical service provider.
According to Google's information, the GMA Next-Gen SDK automatically collects and shares, for advertising, analytics and fraud-prevention purposes, the IP address, from which a general location may be estimated; user product interactions such as app launches, taps and video views; diagnostic information such as app launch time, hang rate and energy usage; and device and account identifiers. These identifiers may include the Android advertising ID, app set ID and, where applicable, other identifiers relating to accounts signed in on the device. The SDK also provides a publisher first-party ID that is enabled by default and, according to Google, can support more relevant and personalised advertising using data from the app. Device, app, consent and Privacy Sandbox information as well as ad views and interactions may also be processed. Which identifiers are actually transmitted depends in particular on consent, the operating system, Limited Ads and advertising configuration, and any required age treatment. Google states that these SDK data are encrypted in transit using TLS.
Google's current information about these data categories and the publisher first-party ID is available at https://developers.google.com/admob/android/next-gen/privacy/play-data-disclosure and https://developers.google.com/admob/android/next-gen/privacy/strategies.
Purposes may include displaying advertising, ad measurement, fraud prevention, technical provision and improvement of ad delivery, and analysis of advertising performance. In the EEA, the United Kingdom and Switzerland, personalised advertising, access to the advertising ID or comparable tracking technologies may be used only after the required consent has been given. Without consent, only limited or non-personalised ads may be served where this is technically and legally permitted.
At the beginning of a newly created app or Activity session, the app uses UMP to update whether consent is required and, where necessary, to display a consent form. The visible “Privacy options” area in the app makes the Google privacy form available again as soon as Google reports that privacy options are required. Consent and regional opt-out choices can be changed or withdrawn there with effect for the future where the corresponding message has been published in the AdMob account and Google requires it for the user.
Users can also reset their advertising ID in their device’s system settings or restrict personalised advertising where the operating system provides these options. Where consent is required, advertising processing and access to information on the device that is not technically necessary take place exclusively on the basis of Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Consent can be withdrawn at any time with effect for the future through the privacy options provided in the app. Technical consent management and the implementation of statutory data protection requirements take place on the basis of Art. 6(1)(c) GDPR and additionally Art. 6(1)(f) GDPR; the legitimate interest lies in demonstrable and privacy-compliant control of the advertising services.
TeamCounter does not sell personal data for money. Terms such as “sale”, “sharing” or “targeted advertising” may, however, be defined more broadly by individual US state laws; transmitting or making technical advertising data available to Google or advertising partners for personalised advertising may fall within those definitions. Where required by law and published in the AdMob account, Google's US state message can record an opt-out from sale, sharing and targeted advertising. Google may process corresponding GPP or Global Privacy Control signals and apply restricted data processing. Users may also exercise their rights by emailing teamcounter@holsteinshops.de.
Information about Google's support for US state privacy signals is available at https://developers.google.com/admob/android/next-gen/privacy/us-states and https://support.google.com/admob/answer/14125907.
Google may also process data in third countries, in particular the United States. Where applicable, Google bases such transfers on the EU-US Data Privacy Framework and additionally on appropriate safeguards such as Standard Contractual Clauses. Further information is available from Google Business Data Responsibility (https://business.safety.google/privacy/) and in Google’s Privacy Policy (https://policies.google.com/privacy).
To verify authorised advertising partners, TeamCounter provides an app-ads.txt file on the developer website. This file supports advertising transparency and fraud prevention and does not contain personal user data.
14b. Possible future use of Firebase Analytics in the Android app
The current Android app version described in this Privacy Policy does not use Firebase Analytics. This website change neither installs nor activates Firebase in the app. The following information applies only if a separately developed, tested and published future app version expressly states that Firebase Analytics is included. Before such a release, the actual implementation, consent flow, Google Play data disclosures and this section must be checked against the released build.
In such a future version, Firebase Analytics would be provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC in the United States may also act as parent company or technical service provider. Its intended purposes would be consent-based measurement of app launches, sessions, screens and feature areas, technical stability and diagnostics, version adoption and improvement of app usability.
Depending on the future implementation and device configuration, the service may process an automatically generated app-instance identifier, app version, operating-system version, device model or category, language, country or approximate location derived from the IP address, session and interaction events, and technical diagnostic information. An advertising identifier may also be accessible depending on the Firebase/Google SDK and advertising configuration; before release it must either be technically disabled where it is not needed or accurately disclosed and covered by the applicable consent.
TeamCounter must not attach list names, person or team labels, counter values, list links, access or management tokens, offline click-counter content or a custom TeamCounter user ID to Firebase Analytics events. The future app implementation must keep Analytics collection disabled by default until the required app consent has been given and must provide an effective withdrawal option for future collection.
Where consent is required, access to non-essential device information would be based on Section 25(1) TDDDG and subsequent personal-data processing on Art. 6(1)(a) GDPR. Google may process data in third countries, in particular the United States, using the transfer mechanisms described by Google, including the EU-US Data Privacy Framework where applicable and Standard Contractual Clauses.
The retention period must be taken from and verified against the Analytics retention setting actually configured for the future Firebase project before release. Aggregated reports may remain available for longer; no fixed period is promised before that configuration has been completed. Further information is available at https://firebase.google.com/docs/analytics, https://firebase.google.com/docs/analytics/android/configure-data-collection and https://policies.google.com/privacy.
15. Contact by email and phone
If you contact us by email or phone, the personal data you provide is processed in order to handle your enquiry.
This may include the following data in particular:
- email address
- phone number, if transmitted or displayed
- name, if provided
- content of the message or conversation, where documented for handling the enquiry
- time of contact
The legal basis is Art. 6(1)(b) GDPR where the contact relates to pre-contractual or contractual measures. In all other cases, processing takes place on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in processing and responding to incoming enquiries.
The data is deleted as soon as it is no longer required to handle the enquiry and no statutory retention obligations prevent deletion.
16. SSL or TLS encryption
For security reasons, this website uses SSL or TLS encryption. An encrypted connection can be recognised by the HTTPS prefix at the beginning of the browser address bar.
Encryption prevents data transmitted between the visitor’s browser and the website from being read easily by third parties.
17. Recipients of personal data
Personal data is disclosed only where this is required for the technical operation of the website or app, the function requested by the user, advertising in accordance with the privacy choice, handling an enquiry, or a statutory obligation.
As part of technical provision, STRATO processes personal data as the hosting provider.
As part of consent management for Google AdSense, Google may process the data required to request and implement advertising consent.
When Cloudflare Web Analytics is used, Cloudflare may process technical usage and performance data.
When an eligible public website page is requested, Google may receive the denied consent state and the cookieless technical request data described in section 8.1. After analytics consent has been given, Google may additionally process the usage, device and connection data described there for full Google Analytics 4 measurement.
When Google AdSense is used, Google may process personal data for the purposes described in the “Online marketing” section, provided the corresponding consent has been given.
Within the native Android app, Google may process through UMP and Google Mobile Ads consent signals and the technical device, usage, diagnostic and advertising data listed in the AdMob section, insofar as permitted by the consent status and configuration.
Only after a future app version with Firebase Analytics has actually been released and the required app consent has been given may Google additionally receive the app analytics data described conditionally in section 14b.
When server-based lists are used, STRATO as hosting provider processes the list, token, content and connection data sent to the TeamCounter API. Where users deliberately invoke a sharing, QR or storage function, the app, platform or storage provider they select also receives the data expressly handed over. For support and ratings, TeamCounter specifies the support email address or the public TeamCounter page on Google Play as the destination; users decide in each case whether they actually open the external app or platform and transmit data. The relevant recipient's privacy terms additionally apply to subsequent processing.
Amazon receives technical request and referral information only if a user deliberately opens an Amazon affiliate text link as described in section 23. Merely loading a TeamCounter page or list does not transmit data to Amazon through this text link.
When Google Search Console and Bing Webmaster Tools are used, Google or Microsoft may process and provide search engine, crawling and website performance data.
When Wordfence Security is used, Defiant may process security-relevant technical data where required for firewall, scanning, login protection and attack detection functions.
18. Storage period
Personal data is stored only for as long as required for the relevant purposes or for as long as statutory retention obligations apply.
According to STRATO, visitors' IP addresses are stored for a maximum of seven days for the detection and prevention of attacks. Other server-log elements are retained only for as long as required for the relevant operational and security purpose or by law; no broader fixed seven-day period is promised for those elements.
The storage period for consent information in connection with Google AdSense depends on Google’s privacy, cookie and account settings and the applicable browser settings.
Cloudflare states that it stores unsampled beacon data for seven days and then retains it in aggregated form for longer-term analysis.
The retention of event and user-level data in Google Analytics 4 depends on the retention setting actually configured in the Analytics property; the operator must verify that setting. Aggregated reports may remain available for longer.
The storage period for data processed in connection with Google AdSense depends on Google’s privacy and retention rules and the applicable consent and account settings.
The storage period for consent, device, diagnostic and advertising data processed through UMP and Google Mobile Ads depends on Google’s applicable retention rules, consent status, ad configuration and device or account settings. TeamCounter does not store any additional personal advertising profiles from UMP or AdMob in its own list database.
If Firebase Analytics is introduced in a future app release, its event and user-level retention must be verified against the setting actually configured in the Firebase/Analytics property before release; section 14b does not activate or predetermine that storage.
Wordfence security data is stored depending on the Wordfence settings and the relevant security purpose. According to Wordfence, Live Traffic data can be limited by number of entries and days; by default, the maximum retention period for Live Traffic data is 30 days.
Tally lists, scoreboards, drinks lists, attendance lists and value counters created by users are currently stored without a fixed automatic inactivity deletion period. They remain in place until they are permanently deleted through the management link, a justified deletion request is processed or a statutory deletion obligation is implemented. Existing lists are neither deleted nor reset as a result of this clarification.
Locally stored list links, app settings, display choices, widget configurations, templates, click counters and associated local feature states generally remain on the device until the user removes them through the provided function, clears app storage or uninstalls the app. Technical maintenance rules bound individual journals, queues and caches. A QR cache artifact older than 24 hours is cleaned up when another QR code is generated; a copy deliberately stored or shared externally is then outside TeamCounter's control.
Data from email and phone enquiries is deleted as soon as the enquiry has been handled conclusively and no statutory retention obligations prevent deletion.
19. Objection to processing based on legitimate interests
Where personal data is processed on the basis of Art. 6(1)(f) GDPR, data subjects have the right to object to this processing at any time on grounds relating to their particular situation.
An informal message to teamcounter@holsteinshops.de is sufficient to exercise the right to object.
20. Rights of data subjects
Where the GDPR applies to processing by the controller established in Germany, data subjects have these rights regardless of where they live. Comparable rights may additionally or instead arise under the applicable law in the United Kingdom, Switzerland and other jurisdictions. These include in particular:
- right of access to stored personal data
- right to rectification of inaccurate personal data
- right to erasure of personal data
- right to restriction of processing
- right to data portability
- right to object to certain processing
- right to withdraw consent that has been given with effect for the future
An informal message to teamcounter@holsteinshops.de is sufficient to exercise these rights.
When requesting deletion of a specific TeamCounter list, the list/tool ID or view link should be provided first. Please send a management link only after an explicit request.
20a. Additional rights in other countries and regions
Depending on where a person lives and whether local privacy law applies, additional or different rights may exist. This Privacy Policy does not restrict those statutory rights.
In US states with comprehensive privacy laws, these may include – where the relevant law applies to TeamCounter – rights to confirmation; access to or knowledge of categories, sources, purposes and recipients; correction; deletion; and portability, as well as an opt-out from sale, sharing or processing for targeted advertising. Where applicable, there may also be rights to limit sensitive-data processing, non-discrimination, use of an authorised agent, and appeal or review of a denied request.
In Brazil, the LGPD may provide, among other rights, confirmation, access, correction, anonymisation, blocking or deletion of unnecessary or unlawfully processed data, portability, information about recipients and consequences of consent, and withdrawal of consent. In Canada, Australia, New Zealand, Singapore, India, Japan and other countries, rights may include access, correction, deletion or withdrawal and a complaint to the competent privacy authority where provided by the applicable law.
Requests can be sent to teamcounter@holsteinshops.de. TeamCounter may request information reasonably necessary to verify identity and authority securely, but will not request additional data that are unnecessary for that purpose. Requests are handled within the period prescribed by the applicable law; no single worldwide 30-day deadline is promised. Where required by law, no person will be disadvantaged for exercising a privacy right, and reasons for denial and available appeal options will be provided.
Where data are stored only locally on the device, TeamCounter cannot technically view or delete their content remotely. Those data can be removed through the app functions, by clearing app storage or by uninstalling the app. A specific server-based list generally requires the corresponding link or list/tool ID for secure identification.
21. Right to lodge a complaint with a supervisory authority
Data subjects have the right to lodge a complaint with a privacy supervisory authority if they believe that the processing of personal data infringes applicable privacy law.
For the controller in Schleswig-Holstein, the competent authority is, in particular, the Independent Centre for Privacy Protection Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany; information is available at https://www.datenschutzzentrum.de/. Data subjects may also contact the privacy authority at their habitual residence, place of work or the place of the alleged infringement, or the body competent under their local law.
22. Automated decision-making and advertising profiling
TeamCounter does not use list content, click-counter data or support enquiries to make its own solely automated decision that has legal or similarly significant effects on a person. TeamCounter does not create its own advertising profile from that content.
Google and participating advertising partners may automatically select, measure and, where permitted, personalise ads depending on consent, region, device or account settings and advertising configuration; this may constitute profiling under privacy law. This ad selection is not used by TeamCounter to make decisions with legal or similarly significant effects about users. Users can use the consent, opt-out and device settings described in section 14a.
22a. Children and minors
TeamCounter is a general-purpose organisation and counting tool and is not specifically designed for children. The app does not ask for a date of birth and does not perform its own age verification. The current Android version does not use a neutral age screen and does not set its own child-directed or under-age-of-consent treatment for ad requests. It is therefore not intended for independent use by people for whom parental or guardian consent is required under the law of their place of residence.
Minors may use TeamCounter only in accordance with applicable local law and, where required, with the consent and supervision of a parent or guardian. No personal or sensitive information about children should be stored in lists or click counters. If you believe that a child's data have been processed without the required authorisation, please contact teamcounter@holsteinshops.de so that the matter can be investigated and any required deletion arranged.
23. Amazon affiliate links (affiliate advertising)
TeamCounter displays a clearly labelled text link to coupon offers on Amazon.de on the German public benefits page at /vorteile/. Since 24 August 2026 this advertising link is no longer shown on list views – online, offline/local, personal or private. The link contains the Amazon partner tag teamcounter-21. If a user follows the link and makes a qualifying purchase, the website operator may receive a commission from Amazon. This does not increase the price for the user.
No Amazon script, product module, iframe, tracking pixel or other Amazon content is embedded for this link. Merely opening a TeamCounter page therefore does not establish a connection to Amazon through the affiliate text link. Only after the link is deliberately selected does the browser open Amazon.de. Amazon may then receive the IP address, time of access, browser and device information, the referring page and the parameters contained in the partner link, and may use cookies or similar technologies under its own responsibility.
The link is provided on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in the transparent, commission-based financing of the free website service. Users are free not to open the external link. Further information about processing by Amazon is available in the Amazon.de Privacy Notice.
The native Android app, its data processing and its advertising configuration are not changed by these website links.
24. CHECK24.net partner programme (affiliate advertising)
The German public benefits page at /vorteile/ displays clearly labelled text links to CHECK24 tariff comparisons (electricity, gas, DSL and mobile). The website operator participates in the CHECK24.net partner programme. If a user concludes a contract through one of these links, or if CHECK24 derives a lead or a sale from it, the website operator may receive advertising cost reimbursement. This does not increase the price for the user.
No CHECK24 iframe booking forms, scripts, comparison calculators, tracking pixels or other CHECK24 content are embedded in the page. Merely opening the benefits page therefore does not establish a connection to CHECK24. Only after a link is deliberately selected does the browser open the redirect address a.check24.net and then the CHECK24 offer. CHECK24 may then receive the IP address, the time of access, browser and device information, the referring page and the parameters contained in the partner link (partner, creative and category identifiers), and may use cookies or similar technologies under its own responsibility.
The links are provided on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in the transparent, commission-based funding of the free website. Users are free not to open the external links. Further information on data use is available in the privacy policy of CHECK24.net.
25. Temu partner programme (affiliate advertising)
The same page displays a clearly labelled text link to offers from Temu, together with a discount code. If a user follows the link and makes a qualifying purchase, the website operator may receive a commission. This does not increase the price for the user. The conditions, validity and availability of the discount code are determined solely by Temu.
No Temu script, product module, iframe, tracking pixel or other Temu content is embedded. Merely opening the page therefore does not establish a connection to Temu. Copying the discount code happens exclusively in the local browser through the device clipboard; no data is transmitted to the website operator or to Temu in the process.
Only after the link is deliberately selected does the browser open the redirect address temu.to and then the Temu offer. Temu may then receive the IP address, the time of access, browser and device information, the referring page and the parameters contained in the partner link, and may use cookies or similar technologies under its own responsibility. Temu belongs to the PDD Holdings group of companies; processing outside the European Union and the European Economic Area, in particular in the USA and in China, is therefore possible and falls within Temu's own responsibility.
The link is provided on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in the transparent, commission-based funding of the free website. Users are free not to open the external link. Further information is available in the Temu privacy policy.
The native Android app, its data processing and its advertising configuration are not affected by the website links described in sections 24 and 25.
26. Neutral operator reference
Public website footers may contain one neutral link labelled “A project by HolsteinShops.de” to HolsteinShops.de. This is neither an advertisement nor an affiliate link and does not load scripts, iframes, tracking pixels or other content from HolsteinShops.de when a TeamCounter page is opened. Data is transmitted only after the link is actively selected.
27. Changes to this Privacy Policy
This Privacy Policy may be updated if there are technical, legal or content-related changes to the website or app.
The version applicable to the app is available within the app; the current online version is also available on the website.