Privacy

Privacy Policy

This privacy policy explains how personal data is processed in the OnAim app (iOS and Android) and on this website onaim.app under the EU General Data Protection Regulation (GDPR). The German version is legally binding; this is a courtesy translation.

1. Controller

The controller within the meaning of the GDPR is:

MAK C.E.T GmbH
Heidenfelder Str. 1
97525 Schwebheim
Germany

Represented by: Mr Michael Ali Kilic
Phone: +49 9723 93805-0
Fax: +49 9723 93805-129
E-mail: [email protected]

Registry: Amtsgericht Schweinfurt, HRB 6561
VAT ID (§ 27a UStG): DE287231582

2. Data protection officer

We are not legally required to appoint a data protection officer. For any privacy enquiries or to exercise your rights, please contact the controller named above.

3. Principles and storage location

OnAim is a companion app for sport shooting (IPSC and BDS): a personal shooting log, match calendar, training analysis and equipment management. We process personal data exclusively on servers located within the European Union.

4. Account and sign-in (passwordless)

Sign-in is passwordless and uses e-mail: you receive a one-time six-digit code (or a magic link). We process:

Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (legitimate interest in service security).
Retention: codes/tokens are valid for 15 minutes and single-use; expired records including IP and user-agent are deleted automatically within 7 days.

5. Profile data

We process the following in your profile:

We do not collect a date of birth or age.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete your account.

6. Equipment / firearm data (optional)

You may — voluntarily — store details about your sport firearm and equipment. This feature is disabled by default (opt-in). We process, among others:

These entries form a private record. They are visible only to you, are never displayed publicly, are not transmitted to authorities and are not fed into the National Firearms Register (NWR). Access is strictly user-scoped at the technical level (authorisation by your user ID on every query).
Legal basis: Art. 6(1)(a) GDPR (your consent) and Art. 6(1)(b) GDPR to provide the feature. You may withdraw consent at any time with effect for the future.
Retention: until you delete the entry or your account.

7. Shooting log and training data

To maintain your shooting log and training analysis we process the entries you record, in particular:

Where you enter third-party data (e.g. the range officer's), you are co-responsible for the lawfulness of that input. This data is not published.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete the entry or your account.

8. Target photos and automatic hit detection

In the training analysis you may voluntarily take a photo of your target, or pick one from your photo library. The image is transmitted to our server in the EU and evaluated automatically (detection of hit positions). The feature is optional — you can always enter your hits manually instead.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract — the evaluation is part of the feature you requested).
Retention without consent (default): the photo is deleted immediately after the evaluation. If you abandon the process without confirming the result, the photo is deleted automatically after 7 days at the latest. The derived coordinates and scores remain as part of your training entry.

8.1 Voluntary consent to model improvement

Additionally and separately, you may consent to your target photos and your corrections being used to improve the automatic hit detection. This consent is voluntary: without it the evaluation works exactly the same and in full.

Legal basis: Art. 6(1)(a) GDPR (consent).

9. Microphone (par-timer time measurement)

For time measurement during training you may enable the microphone so that the start of your run is detected automatically. This feature is off by default; the microphone permission is only requested once you switch it on.

Processing happens entirely on your device and in real time: only the point in time of a signal is determined. No audio recording is created, stored or transmitted. The audio data never leaves the device's native processing layer and reaches neither our servers nor any third party. Accordingly, no personal data is transmitted to us in this respect.
Legal basis: Art. 6(1)(b) GDPR, to the extent that any processing by us takes place at all.

10. Publication of results

Results are published (e.g. in rankings) only if you actively allow it; by default this is disabled / can be switched off (opt-out).
Legal basis: Art. 6(1)(a) GDPR.

11. E-mail delivery and international transfer (AWS SES)

To send transactional e-mails (sign-in codes) we use Amazon Simple Email Service (Amazon Web Services EMEA SARL, Luxembourg), region eu-central-1 (Frankfurt). Only your e-mail address and the one-time sign-in code are passed to the e-mail service — no names, federation, firearm, shooting-log or location data.

Because the parent company (Amazon.com, Inc.) is based in the USA, theoretical access under US law (in particular the CLOUD Act) cannot be fully excluded. We base the transfer on the EU Commission's Standard Contractual Clauses (Art. 46 GDPR) together with a Transfer Impact Assessment and supplementary measures (EU region pinning, TLS 1.3 encryption, minimal payload, short-lived single-use tokens). We do not rely primarily on the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(b) GDPR; transfer under Art. 46 GDPR.

11a. Subscription management and international transfer (RevenueCat)

To manage the paid OnAim Pro subscription we use RevenueCat, Inc., Brandon, Florida (USA), as a processor. RevenueCat maps the purchase, renewal and cancellation notifications from the App Store and Google Play to your OnAim account, and it delivers the content of the subscription screen.

This also affects you without a subscription: the content of the subscription screen (prices, texts, layout) is loaded at runtime from RevenueCat's content delivery network. As a result, merely opening that screen transmits your IP address to RevenueCat — even if you never subscribe and use OnAim free of charge indefinitely. The screen is loaded only when you open it yourself; no connection to RevenueCat is made when the app starts.

International transfer: RevenueCat is based in the USA and operates its systems on Amazon Web Services in the USA. The provider does not offer storage exclusively within the EU — unlike the e-mail delivery described in section 11, region pinning is technically not available here. RevenueCat in turn engages sub-processors, all of which are established in the USA. Access under US law (in particular the CLOUD Act and FISA 702) therefore cannot be excluded.

We base the transfer on the EU Commission's Standard Contractual Clauses (Art. 46 GDPR) together with a Transfer Impact Assessment and supplementary measures: pseudonymisation (no real names, no e-mail addresses), strict data minimisation, no advertising, attribution or marketing integrations, no collection of device advertising identifiers, and deletion of the record when you delete your account. We do not rely on the EU-US Data Privacy Framework.

The decision whether your account receives Pro features is made exclusively by our servers in the EU. For us RevenueCat is only a source of events, not the deciding party.
Legal basis: Art. 6(1)(b) GDPR (managing the subscription you entered into); transfer under Art. 46 GDPR.
Retention: for the duration of the subscription and for as long as required for tax and commercial accountability; when you delete your account, deletion at RevenueCat is additionally requested.

12. Server and security logs

For security, accountability (Art. 30 GDPR) and attack prevention we log security-relevant events (e.g. profile changes, failed sign-ins) together with your user ID, the timestamp and the IP address.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and integrity).
Retention: generally 90 days, then automatic deletion or anonymisation.

When you access this website, our hosting provider processes and briefly stores technically necessary access data (IP address, date/time, requested resource, user-agent) in server log files.

13. Storage on your device

The app also stores your data locally on the device (encrypted SQLite database) so it works offline. Your sign-in token (JWT) is stored in the operating system's secure storage (iOS Keychain / Android Keystore). Some settings (e.g. starred matches, notification and checklist preferences) remain on the device only and are not transmitted to our servers. Uninstalling the app deletes this local data.

14. Notifications

Reminders are generated as local notifications directly on your device. No push service (e.g. Firebase Cloud Messaging) is used and no push tokens are transmitted to any server.

15. Maps and match calendar

To display match locations, map tiles may be loaded from OpenStreetMap (OpenStreetMap Foundation). Your IP address is technically transmitted to the map service in the process. Match dates are aggregated from publicly available sources; for details see onaim.app/en/about/bot.
Legal basis: Art. 6(1)(f) GDPR.

16. No advertising or tracking services

OnAim uses no advertising or tracking services: no Google Analytics, no Firebase Analytics, no advertising identifiers (IDFA/AAID), no cross-app or cross-device tracking, no attribution or marketing networks and no profiling for advertising purposes. No data is processed for advertising or sold to third parties.

So that this statement stays accurate, we expressly delimit three points:

17. Fonts on this website

This website loads fonts via Google Fonts (Google Ireland Limited). When the fonts are loaded, your IP address is transmitted to Google. The provider is Google Ireland Limited; for more information see policies.google.com/privacy.
Legal basis: Art. 6(1)(f) GDPR (consistent, accessible presentation).

18. Recipients and processors

We share your data only with the processors required to provide the service (Art. 28 GDPR):

For the automatic hit detection (section 8), no external AI or image-analysis services are used; it runs on our own infrastructure within the EU. The sub-processors engaged by RevenueCat concern subscription management only and are described in section 11a.

We do not sell personal data.

19. Your rights

You have the following rights:

To exercise your rights, simply e-mail [email protected].

20. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

21. Minors

OnAim is intended exclusively for adult sport shooters (aged 18 and over) and is not directed at children or adolescents under 18. We do not knowingly collect personal data from anyone under 18; if we become aware of such data, we delete it.

22. Data security

We apply appropriate technical and organisational measures (Art. 32 GDPR): TLS 1.3 transport encryption, encryption of the database at rest, strictly user-scoped access control and storage of sign-in codes/tokens only as hashes (SHA-256).

23. Changes to this policy

We update this privacy policy when the scope of features or the legal situation changes. The current version published here always applies.