Privacy Policy
This privacy policy explains how personal data is processed in the OnAim app (iOS and Android) and on this website onaim.app under the EU General Data Protection Regulation (GDPR). The German version is legally binding; this is a courtesy translation.
1. Controller
The controller within the meaning of the GDPR is:
MAK C.E.T GmbH
Heidenfelder Str. 1
97525 Schwebheim
Germany
Represented by: Mr Michael Ali Kilic
Phone: +49 9723 93805-0
Fax: +49 9723 93805-129
E-mail: [email protected]
Registry: Amtsgericht Schweinfurt, HRB 6561
VAT ID (§ 27a UStG): DE287231582
2. Data protection officer
We are not legally required to appoint a data protection officer. For any privacy enquiries or to exercise your rights, please contact the controller named above.
3. Principles and storage location
OnAim is a companion app for sport shooting (IPSC and BDS): a personal shooting log, match calendar, training analysis and equipment management. We process personal data exclusively on servers located within the European Union.
- Hosting: Hetzner Online GmbH, Frankfurt am Main data centre (Germany), under a data processing agreement (Art. 28 GDPR).
- Database: PostgreSQL, operated in the same EU infrastructure.
- File storage (target photos): Hetzner Object Storage, Nuremberg data centre (Germany) — the same processor (Hetzner Online GmbH), a different service and location. See section 8.
- Transport: encrypted exclusively via TLS 1.3.
4. Account and sign-in (passwordless)
Sign-in is passwordless and uses e-mail: you receive a one-time six-digit code (or a magic link). We process:
- your e-mail address
- a cryptographic hash (SHA-256) of the code/token — the code itself is never stored in plain text
- your IP address and user-agent at sign-in time, solely for abuse and brute-force prevention (rate limiting)
Legal basis: Art. 6(1)(b) GDPR (performance of the contract)
and Art. 6(1)(f) GDPR (legitimate interest in service security).
Retention: codes/tokens are valid for 15 minutes and
single-use; expired records including IP and user-agent are deleted
automatically within 7 days.
5. Profile data
We process the following in your profile:
- e-mail address
- first and last name
- federation membership (e.g. BDS, DSB) and disciplines
- club name and an optional location hint (e.g. region)
- language preference and privacy settings (flags)
We do not collect a date of birth or age.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete your account.
6. Equipment / firearm data (optional)
You may — voluntarily — store details about your sport firearm and equipment. This feature is disabled by default (opt-in). We process, among others:
- make, model, calibre
- serial number, firearms ownership card (WBK) number and WBK position
- purchase date, round counter, notes, discipline tags
These entries form a private record. They are visible only to
you, are never displayed publicly, are not transmitted to authorities and are
not fed into the National Firearms Register (NWR). Access is strictly
user-scoped at the technical level (authorisation by your user ID on every
query).
Legal basis: Art. 6(1)(a) GDPR (your consent) and Art.
6(1)(b) GDPR to provide the feature. You may withdraw consent at any time with
effect for the future.
Retention: until you delete the entry or your account.
7. Shooting log and training data
To maintain your shooting log and training analysis we process the entries you record, in particular:
- date/time, range name, discipline and scoring
- firearm used, results/hit pattern, notes and weather data
- training metrics (e.g. distance, duration, group size)
- for match/proof entries, where applicable the name, licence number and signature of the range officer (RO)
Where you enter third-party data (e.g. the range officer's), you are
co-responsible for the lawfulness of that input. This data is not published.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete the entry or your account.
8. Target photos and automatic hit detection
In the training analysis you may voluntarily take a photo of your target, or pick one from your photo library. The image is transmitted to our server in the EU and evaluated automatically (detection of hit positions). The feature is optional — you can always enter your hits manually instead.
- Data processed: the image of the target, the hit coordinates and scores derived from it, your user ID and the time of the evaluation.
- Storage location: Hetzner Object Storage, Nuremberg data centre (Germany). The evaluation itself runs on our own infrastructure within the EU; no data is passed to third-party AI services.
- No automated decision-making: the result is a suggestion. It is shown to you for review and is fully editable; it is stored only once you confirm it. There is no automated decision within the meaning of Art. 22 GDPR.
- Please photograph the target only. Make sure no people and no third-party objects are captured in the frame.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract —
the evaluation is part of the feature you requested).
Retention without consent (default): the photo is
deleted immediately after the evaluation. If you abandon the
process without confirming the result, the photo is deleted automatically
after 7 days at the latest. The derived coordinates and
scores remain as part of your training entry.
8.1 Voluntary consent to model improvement
Additionally and separately, you may consent to your target photos and your corrections being used to improve the automatic hit detection. This consent is voluntary: without it the evaluation works exactly the same and in full.
- The data is stored and processed exclusively within the EU and enters our training data set in pseudonymised form.
- You may withdraw your consent at any time in the settings. After withdrawal, photos already collected are removed from the data set and deleted; the lawfulness of processing carried out up to that point remains unaffected.
- Every change to this setting is logged (demonstrability of consent).
Legal basis: Art. 6(1)(a) GDPR (consent).
9. Microphone (par-timer time measurement)
For time measurement during training you may enable the microphone so that the start of your run is detected automatically. This feature is off by default; the microphone permission is only requested once you switch it on.
Processing happens entirely on your device and in real time:
only the point in time of a signal is determined.
No audio recording is created, stored or transmitted. The
audio data never leaves the device's native processing layer and reaches
neither our servers nor any third party. Accordingly, no personal data is
transmitted to us in this respect.
Legal basis: Art. 6(1)(b) GDPR, to the extent that any
processing by us takes place at all.
10. Publication of results
Results are published (e.g. in rankings) only if you actively allow it; by
default this is disabled / can be switched off (opt-out).
Legal basis: Art. 6(1)(a) GDPR.
11. E-mail delivery and international transfer (AWS SES)
To send transactional e-mails (sign-in codes) we use Amazon Simple Email Service (Amazon Web Services EMEA SARL, Luxembourg), region eu-central-1 (Frankfurt). Only your e-mail address and the one-time sign-in code are passed to the e-mail service — no names, federation, firearm, shooting-log or location data.
Because the parent company (Amazon.com, Inc.) is based in the USA, theoretical
access under US law (in particular the CLOUD Act) cannot be fully excluded. We
base the transfer on the EU Commission's
Standard Contractual Clauses (Art. 46 GDPR) together with a
Transfer Impact Assessment and supplementary measures (EU region pinning, TLS
1.3 encryption, minimal payload, short-lived single-use tokens). We do not
rely primarily on the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(b) GDPR; transfer under Art. 46 GDPR.
11a. Subscription management and international transfer (RevenueCat)
To manage the paid OnAim Pro subscription we use RevenueCat, Inc., Brandon, Florida (USA), as a processor. RevenueCat maps the purchase, renewal and cancellation notifications from the App Store and Google Play to your OnAim account, and it delivers the content of the subscription screen.
- Data transferred: a pseudonymous user identifier (random UUID), the product purchased and its term, purchase, renewal, cancellation and refund events, the expiry date, the store (Apple/Google), country, IP address, plus device type, app version and language setting.
- Not transferred: your name, your e-mail address, federation and club details, firearm and equipment data, shooting-log and training data, target photos and location data. Without our database, your identifier at RevenueCat cannot be linked to a person.
- Neither we nor RevenueCat receive payment data. The purchase contract is concluded with the respective store operator and payment is handled exclusively there (see Terms of Use).
This also affects you without a subscription: the content of the subscription screen (prices, texts, layout) is loaded at runtime from RevenueCat's content delivery network. As a result, merely opening that screen transmits your IP address to RevenueCat — even if you never subscribe and use OnAim free of charge indefinitely. The screen is loaded only when you open it yourself; no connection to RevenueCat is made when the app starts.
International transfer: RevenueCat is based in the USA and operates its systems on Amazon Web Services in the USA. The provider does not offer storage exclusively within the EU — unlike the e-mail delivery described in section 11, region pinning is technically not available here. RevenueCat in turn engages sub-processors, all of which are established in the USA. Access under US law (in particular the CLOUD Act and FISA 702) therefore cannot be excluded.
We base the transfer on the EU Commission's Standard Contractual Clauses (Art. 46 GDPR) together with a Transfer Impact Assessment and supplementary measures: pseudonymisation (no real names, no e-mail addresses), strict data minimisation, no advertising, attribution or marketing integrations, no collection of device advertising identifiers, and deletion of the record when you delete your account. We do not rely on the EU-US Data Privacy Framework.
The decision whether your account receives Pro features is made
exclusively by our servers in the EU. For us RevenueCat is only a
source of events, not the deciding party.
Legal basis: Art. 6(1)(b) GDPR (managing the subscription
you entered into); transfer under Art. 46 GDPR.
Retention: for the duration of the subscription and for as
long as required for tax and commercial accountability; when you delete your
account, deletion at RevenueCat is additionally requested.
12. Server and security logs
For security, accountability (Art. 30 GDPR) and attack prevention we log
security-relevant events (e.g. profile changes, failed sign-ins) together with
your user ID, the timestamp and the IP address.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in
security and integrity).
Retention: generally 90 days, then automatic deletion or
anonymisation.
When you access this website, our hosting provider processes and briefly stores technically necessary access data (IP address, date/time, requested resource, user-agent) in server log files.
13. Storage on your device
The app also stores your data locally on the device (encrypted SQLite database) so it works offline. Your sign-in token (JWT) is stored in the operating system's secure storage (iOS Keychain / Android Keystore). Some settings (e.g. starred matches, notification and checklist preferences) remain on the device only and are not transmitted to our servers. Uninstalling the app deletes this local data.
14. Notifications
Reminders are generated as local notifications directly on your device. No push service (e.g. Firebase Cloud Messaging) is used and no push tokens are transmitted to any server.
15. Maps and match calendar
To display match locations, map tiles may be loaded from OpenStreetMap
(OpenStreetMap Foundation). Your IP address is technically transmitted to the
map service in the process. Match dates are aggregated from publicly available
sources; for details see
onaim.app/en/about/bot.
Legal basis: Art. 6(1)(f) GDPR.
16. No advertising or tracking services
OnAim uses no advertising or tracking services: no Google Analytics, no Firebase Analytics, no advertising identifiers (IDFA/AAID), no cross-app or cross-device tracking, no attribution or marketing networks and no profiling for advertising purposes. No data is processed for advertising or sold to third parties.
So that this statement stays accurate, we expressly delimit three points:
- Subscription screen: RevenueCat (section 11a) counts how often the subscription screen was shown and how often a purchase follows from it. This measurement relates to that single screen only and serves solely to assess it; it is not combined with your shooting-log, equipment or profile data. A/B testing and audience targeting are switched off and will not be enabled without first amending this policy.
- Error diagnostics: no crash-reporting SDK is embedded in the app (no Crashlytics, no Sentry). Our processors use their own diagnostic and logging tools to operate their own systems; that processing happens on their side and is part of the respective data processing agreement.
- Hit detection as described in section 8: a feature you actively trigger, not an analytics or tracking service. It involves no profiling and no advertising purpose.
17. Fonts on this website
This website loads fonts via Google Fonts (Google Ireland Limited). When the
fonts are loaded, your IP address is transmitted to Google. The provider is
Google Ireland Limited; for more information see
policies.google.com/privacy.
Legal basis: Art. 6(1)(f) GDPR (consistent, accessible
presentation).
18. Recipients and processors
We share your data only with the processors required to provide the service (Art. 28 GDPR):
- Hetzner Online GmbH — hosting (EU, Frankfurt)
- Hetzner Online GmbH — Object Storage for target photos (EU, Nuremberg); the same processor, an additional service
- Amazon Web Services EMEA SARL — transactional e-mail (eu-central-1)
- RevenueCat, Inc. — management of the Pro subscription (USA); for details and the international transfer see section 11a
For the automatic hit detection (section 8), no external AI or image-analysis services are used; it runs on our own infrastructure within the EU. The sub-processors engaged by RevenueCat concern subscription management only and are described in section 11a.
We do not sell personal data.
19. Your rights
You have the following rights:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR) — you can delete your account directly in the app (Settings → Delete account). The account is first marked for deletion and permanently deleted after 30 days; if you sign in again within this period, the deletion is automatically cancelled. This irreversibly removes your profile, firearm and shooting-log data. Instructions (including by email) are available at onaim.app/en/delete-account
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection (Art. 21 GDPR)
- withdrawal of consent (Art. 7(3) GDPR) with effect for the future
To exercise your rights, simply e-mail [email protected].
20. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
21. Minors
OnAim is intended exclusively for adult sport shooters (aged 18 and over) and is not directed at children or adolescents under 18. We do not knowingly collect personal data from anyone under 18; if we become aware of such data, we delete it.
22. Data security
We apply appropriate technical and organisational measures (Art. 32 GDPR): TLS 1.3 transport encryption, encryption of the database at rest, strictly user-scoped access control and storage of sign-in codes/tokens only as hashes (SHA-256).
23. Changes to this policy
We update this privacy policy when the scope of features or the legal situation changes. The current version published here always applies.