Privacy Policy
Protecting your personal data is a central concern for us. This Privacy Policy informs you about which data we collect when you use JH FamilySync, for what purpose we process it, and what rights you have. We process your data in accordance with the EU General Data Protection Regulation (GDPR) as well as the Swiss FADP (revDSG).
Last updated: 12 August 2026
This English version is a translation provided for your convenience. The legally binding version is the German original.
1. Data Controller
The controller responsible for data processing within the meaning of the GDPR and the Swiss FADP (revDSG) is:
JH Virtuell KollektivgesellschaftChlini Schanz 31, 8260 Stein am Rhein, Switzerland
Commercial register no.: CH-290.2.021.387-3 · UID: CHE-378.337.964
Represented by: Jermain Huber, Eugenia Ebel
Email: info@jh-virtuell.ch
For further details, see the Legal Notice.
2. Data We Collect
We collect and process only the data required to provide the app's functions:
2.1 Account Data
- Email address
- Display name (freely chosen)
- Encrypted password (managed by Firebase Authentication)
- Optional: profile picture
2.2 Family Data
Content that you and the members of your family actively create in the app:
- Appointments and calendar entries
- Occasions and events (member-assigned)
- Polls with options and members' votes (including appointments created automatically upon a majority)
- To-dos and lists
- Family members (name, role, colour)
- Attachments (files, images)
This data is stored in Cloud Firestore (region europe-west1, Belgium) or Firebase Storage (region europe-west1, Belgium).
2.3 Push Notifications
- FCM token (Firebase Cloud Messaging) for the delivery of push notifications
2.4 Technical Data
When you access the web app, our hosting provider Infomaniak (Switzerland) processes technical data in server logs (IP address, user agent, timestamp). This serves exclusively the security and stability of the service. The Infomaniak access logs are automatically deleted after 90 days; the access logs of Firebase Hosting (CDN edge) are anonymised or deleted after 60 days.
2.5 Payment and Billing Data
For a paid subscription, we record: Stripe customer ID, subscription status (active/cancelling/cancelled), billing history with date and amount, as well as the last 4 digits of the card for display in the portal. Card number, CVV and expiry date are processed exclusively by Stripe (PCI-DSS Level 1 certified).
2.6 Family Tree Data (optional)
If you use the optional family tree tool, you store information about persons in your family — including persons who do not use the app themselves (e.g. children or deceased relatives): names, dates of birth and, where applicable, dates of death, family relationships, nationality/nationalities and photos. Information about nationality does not, in itself, constitute special categories of personal data; only where, in an individual case, it reveals ethnic origin may Art. 9 GDPR or Art. 5 lit. c Swiss FADP (revDSG) be affected. This data is stored in Cloud Firestore or Firebase Storage (region europe-west1, Belgium) within your family. You are yourself responsible for entering data about third parties and warrant that you have the necessary authorisation to do so. Use is voluntary; the data can be deleted in the app at any time.
3. Purpose of Processing
We process your data for the following purposes:
- Provision and operation of the app's functions (account, family calendar, polls, lists)
- Synchronisation of data between family members and devices
- Sending push notifications (e.g. appointment reminders, new polls)
- Sending transactional emails (e.g. confirmation email upon account deletion)
- Reach measurement and improvement of the app (only where consent has been given)
- Ensuring technical operation and protection against misuse
- Handling of subscriptions, payments and invoicing — legal basis Art. 6 para. 1 lit. b GDPR
Legal bases: Art. 6 para. 1 lit. b GDPR (performance of a contract or pre-contractual measures), Art. 6 para. 1 lit. f GDPR (legitimate interest in secure operation) as well as the corresponding provisions of the Swiss FADP (revDSG) (Art. 31).
4. Processors
We use carefully selected service providers with whom we have concluded the legally required data processing agreements (DPA):
4.1 Google Firebase
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Firebase handles authentication, database (Cloud Firestore), file storage (Firebase Storage), push notifications (Firebase Cloud Messaging), server-side functions (Cloud Functions, europe-west1 Belgium and europe-west3 Frankfurt) as well as — where consent has been given — reach measurement (Firebase Analytics / Google Analytics 4) and the delivery of the web app and landing page (Firebase Hosting, CDN edge worldwide, access logs anonymised after 60 days). Storage location of the family data: EU (europe-west1, Belgium).
Transfer to third countries: Google LLC (Mountain View, USA) acts as an intra-group sub-processor of Google Ireland Limited. Although data processing physically takes place in the EU (europe-west1/west3), technical access by Google LLC in the context of support and security incidents is possible. Safeguarded by EU Standard Contractual Clauses (SCC) as well as the EU-U.S. Data Privacy Framework (DPF certification of Google LLC).
Privacy policy: firebase.google.com/support/privacy
4.2 Infomaniak Network SA
Rue Eugène-Marziano 25, 1227 Les Acacias (Geneva), Switzerland.
Hosting of the web app and the associated domain. In addition, we use the
Infomaniak SMTP delivery for transactional emails
(DKIM-signed via the domain jh-familysync.app), e.g. for the
confirmation email upon account deletion.
Privacy policy:
infomaniak.com/de/dsgvo
4.3 Sentry (crash and error telemetry)
Operator: Functional Software, Inc. (Sentry.io),
45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
We use Sentry to automatically capture crashes and unexpected errors in the app
so that we can fix them quickly.
Data categories: error stack traces, browser user agent,
app version, environment identifier (dev/prod) as well as — if signed in —
an anonymous, technically generated user identifier (Firebase UID).
Plain-text email addresses, IP addresses and cookie contents are removed
server-side before transmission (sendDefaultPii = false
as well as an additional beforeSend filter that discards the
request object entirely).
Legal basis: Art. 6 para. 1 lit. f GDPR
(legitimate interest in stable, secure operation of the app)
or Art. 31 para. 1 Swiss FADP (revDSG).
Retention period: 90 days; thereafter automatic deletion
by Sentry.
Transfer to third countries: The events are processed in an
EU region, provided Sentry supports this for the chosen
plan; otherwise processing takes place in the USA.
The transfer is safeguarded by the EU-US Data Privacy Framework as well as
by EU Standard Contractual Clauses (SCC).
Privacy policy:
sentry.io/privacy
4.4 Swisstopo / GeoAdmin API (address autocomplete)
Operator: Federal Office of Topography swisstopo,
Seftigenstrasse 264, 3084 Wabern, Switzerland.
When you enter a location for appointments, we offer you a
live suggestion service that accesses the official
GeoAdmin Search API of the Swiss Confederation.
Data categories: the search string currently
entered in the input field (e.g. street name, place name). No
account data, no appointment content and no
calendar IDs are transmitted. According to swisstopo, the
requests are not stored in a personally identifiable manner.
Legal basis: Art. 6 para. 1 lit. f GDPR
(legitimate interest in convenient address entry)
or Art. 31 para. 1 Swiss FADP (revDSG).
Transfer to third countries: None — swisstopo operates
the service in Switzerland.
Terms of use:
geo.admin.ch (terms of use)
4.5 Vertex AI Gemini (image recognition, only with active premium AI auto-fill)
Operator: Google Ireland Limited,
Gordon House, Barrow Street, Dublin 4, Ireland.
For the optional premium feature "Camera + AI auto-fill"
we use Vertex AI Gemini 1.5 Flash to automatically
extract event details such as title, date, time and
location from a photo actively uploaded by the user (e.g. flyer, invitation,
timetable).
Purpose: automatic pre-filling of the appointment form
from an image — exclusively upon explicit user action.
Data categories: only photos that the user
selects or takes for analysis via the camera button. No
images are transmitted to Vertex AI without active user
interaction.
Legal basis: Art. 6 para. 1 lit. b GDPR
(performance of the contract within the premium subscription) or
Art. 31 para. 1 Swiss FADP (revDSG).
Place of processing: EU region
europe-west3 (Frankfurt am Main, Germany). Photo data
does not leave the EU.
Retention period: The images uploaded for analysis
are stored briefly in the tempAnalysis path of Firebase Storage
and are automatically deleted once the analysis is complete.
No training-data sharing: Vertex AI is used in
enterprise mode — the transmitted images are demonstrably
not used to train Google models.
No automated decision-making: The result of the
image recognition merely pre-fills form fields as a suggestion. No
automated decision in an individual case producing legal effects
within the meaning of Art. 22 GDPR takes place; you review and
confirm every entry yourself.
Privacy policy:
cloud.google.com (Vertex AI Data Governance)
4.6 Stripe (payment processing)
For the processing of paid subscriptions, we use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
- Purpose: payment processing, fraud prevention, invoicing.
- Data categories: name, email, payment method data (the card number is not stored by us but transmitted directly to Stripe), IP address, Stripe customer ID, subscription status, transaction ID, billing history.
- Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract), Art. 31 para. 1 Swiss FADP (revDSG).
- Transfer to third countries: Stripe Inc. (USA) acts as a sub-processor. Safeguarded by EU Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF).
- Retention period: in accordance with the commercial-law retention period (10 years pursuant to Art. 958f CO / § 257 HGB), for payment data in accordance with Stripe's specifications.
- Stripe privacy policy: stripe.com/de/privacy
4.7 RevenueCat (management of in-app subscriptions, iOS/Android)
For the verification of purchase receipts and the management of in-app subscriptions in the native apps (Apple App Store, Google Play), we use RevenueCat, Inc., San Francisco, California, USA.
- Purpose: server-side verification of purchase receipts and management of subscription status (purchase, renewal, cancellation, expiry) via the app stores.
- Data categories: your anonymous Firebase user identifier (as app user ID), store transaction and original transaction IDs, product/subscription status, purchase timestamps. No payment method data (this remains with Apple or Google).
- Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract), Art. 31 para. 1 Swiss FADP (revDSG).
- Transfer to third countries: USA — safeguarded by EU Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF).
- Retention period: for the duration of the subscription or as long as necessary for billing and verification purposes.
- RevenueCat privacy policy: revenuecat.com/privacy
4.8 Photon / Komoot (address search outside Switzerland)
For address and location search for appointments outside Switzerland (fallback to the swisstopo API), we use the open geocoding service Photon, operated by komoot GmbH, Berlin, Germany (EU).
- Purpose: conversion of an entered address/location search into suggestions with coordinates.
- Data transmitted: the search string you enter as well as, for technical reasons, your IP address.
- Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in location search), Art. 31 para. 1 Swiss FADP (revDSG) — only upon your active input.
- Transfer to third countries: None — servers operated in the EU (Germany).
- Komoot privacy policy: komoot.com/privacy
5. Retention Period
We store your personal data for as long as your account exists or as long as it is required to perform the contract. After confirmation of your account deletion (see the section "Your Rights"), all associated data (profile, appointments, polls, lists, attachments, FCM tokens) is irrevocably removed from the production systems without delay, but no later than within 30 days. Statutory retention obligations remain reserved.
Commercial-law retention obligation: Invoices, proofs of payment and business records are retained for 10 years pursuant to Art. 958f CO (Switzerland) or § 257 HGB (Germany). This period exceeds the regular 30-day deletion following account deletion; only the payment-relevant records are affected (Stripe customer ID, invoice date + amount, subscription period), not the calendar content.
6. Your Rights
You have the following rights vis-à-vis us:
- Access to the data stored about you (Art. 15 GDPR / Art. 25 Swiss FADP (revDSG))
- Rectification of inaccurate data (Art. 16 GDPR / Art. 32 Swiss FADP (revDSG))
- Erasure of your data (Art. 17 GDPR / Art. 32 Swiss FADP (revDSG))
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR / Art. 28 Swiss FADP (revDSG)) — you can download your complete data yourself at any time as a machine-readable JSON file under Settings → App Info → Export my data
- Objection to the processing (Art. 21 GDPR)
- Withdrawal of consent given (e.g. for analytics cookies, see section 7) at any time with effect for the future
- Complaint to a supervisory authority (in Switzerland: the FDPIC; in the EU: the competent data protection authority of your country of residence)
Note on account deletion: A complete account deletion is possible directly in the app under Profile → Delete account. For security reasons, we use a two-step email confirmation procedure: after your request, we send you a confirmation email with a link valid for 24 hours. Only after you click this link are your account and all your data irrevocably deleted. If you were the last member of your family, the entire family — including all appointments, polls, lists, occasions and attachments — is deleted along with it as part of a cascade delete. Alternatively, you can submit an informal deletion request by email to info@jh-virtuell.ch; we will process it within 30 days.
7. Cookies and Analytics
JH FamilySync uses cookies as well as local storage technologies (localStorage, IndexedDB) of your browser. We clearly distinguish between technically necessary storage and optional analytics services, which are activated only with your consent.
7.1 Technically Necessary Cookies and Storage
The following storage is strictly required for the operation of the app and is set without consent (Art. 6 para. 1 lit. f GDPR / legitimate interest in secure operation):
- Firebase Authentication — sign-in and maintenance of the session
- App settings — e.g. theme (light/dark), language, selected view
- Service Worker — offline capability, PWA functionality, push registration
- Cookie consent — storage of your decision under the localStorage key
jhfs_cookie_consent
7.2 Google Analytics 4 / Firebase Analytics (only with consent)
To improve the app and for anonymous reach measurement, we use Firebase Analytics (based on Google Analytics 4). Among other things, the screens accessed, usage duration, device type and a technically generated pseudonymous identifier are recorded. The IP address is anonymised (IP anonymisation active), ad tracking and personalisation signals are disabled (allow_ad_personalization_signals = false, allow_google_signals = false).
Activation takes place exclusively after your explicit consent via our cookie banner (Art. 6 para. 1 lit. a GDPR, Art. 31 para. 1 Swiss FADP (revDSG)). The provider is Google Ireland Limited, Dublin. For integration, the Google Tag Manager (googletagmanager.com) is loaded; it serves only as a technical trigger and sets analytics signals only after your consent.
7.3 Google Consent Mode v2
We use Google Consent Mode v2 in default-denied mode: before your consent, all consent signals (analytics_storage, ad_storage, ad_user_data, ad_personalization) are set to denied. Only after active consent in the cookie banner is analytics_storage updated to granted. Advertising-related signals remain permanently set to denied even after consent, as we do not run any advertising.
7.4 Withdrawal of Your Consent
You can withdraw your cookie consent at any time. There are two ways:
- Delete the localStorage key
jhfs_cookie_consentin your browser's developer tools or clear the browser data for our domain — the cookie banner will reappear on your next visit. - Contact us informally by email at info@jh-virtuell.ch.
Marketing or advertising tracking cookies are not used.
8. Push Notifications
Push notifications are sent exclusively if you have agreed to the browser- or device-side permission request. For delivery, we use Firebase Cloud Messaging (FCM). For this purpose, a device-specific FCM token is generated and associated with your account.
You can withdraw the permission at any time in the settings of your browser or operating system. Upon logout, the associated FCM token is automatically deleted.
9. Minor Users
JH FamilySync is a family app. Two roles must be distinguished here: account holders who register themselves, and family members who are managed by an account. Adult or authorised account holders may create family members of any age — including children — and manage their data on their own responsibility; such a family member requires no account of their own and no separate registration.
A minimum age of 13 years applies to the
independent registration of one's own account. Since the
age of consent relevant under Art. 8 GDPR is up to
16 years in the EU depending on the member state, persons under
16 years of age may create their own account only with the consent or
authorisation of their parents or guardians (in Switzerland, the Swiss FADP (revDSG) or
the capacity of judgement applies). During registration, the age is requested,
accounts for those under 13 years of age are not permitted, and for minors
the required parental consent is pointed out and confirmed (stored with a
timestamp in the account record, ageConfirmed).
If we become aware that an account has been created contrary to this age limit and without parental consent, we will block the account and delete the associated data. Please send reports of this to info@jh-virtuell.ch.
10. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy in order to adapt it to changes in the legal situation or to changes in our service. The version available at the time of your use applies in each case. In the event of material changes, we will additionally inform you in the app or by email.
11. Contact
For questions about data protection, the exercise of your rights or the deletion of your account, please contact:
JH Virtuell KollektivgesellschaftEmail: info@jh-virtuell.ch