Privacy Policy
최종 업데이트: 2026-09-07
이 법적 문서는 영어와 독일어로 제공되며, 선택하신 언어에 해당하는 버전이 표시됩니다. 불분명한 점이 있으면 언제든지 저희에게 문의해 주십시오.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
BeConcrete L.L.C-FZ
Meydan Grandstand, 6th floor, Meydan Road
Nad Al Sheba, Dubai
United Arab Emirates
E-mail: support@merke.me
2. Overview
merke.me is a learning platform for the German language. We process personal data only to the extent necessary to provide the service, to perform the contract, or to comply with legal obligations. We do not sell data and do not run third-party advertising.
3. Hosting and server log files
The platform runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (processing on our behalf under Art. 28 GDPR). When the pages are accessed, the web server automatically processes technical access data (IP address, date and time, requested URL, referrer, user agent). This data is required for the technical operation and security of the service (Art. 6(1)(f) GDPR) and is deleted after no more than 14 days unless it is needed to investigate specific cases of misuse. The country is also derived from the IP address to enforce regional availability (exclusion of the UAE, see Terms of Service) and to display prices in the local currency; the evaluation is at country level only and no location profile is stored. The country database used for this is identified in the Legal Notice.
4. Cookies and local storage
We use the following cookies:
- a session cookie for login,
- a cookie storing the chosen interface language (`locale`),
- a cookie holding the chosen colour scheme (`theme-resolved`, light or dark) so that the server can deliver the page in the right scheme instead of switching after it loads (storage period: 1 year),
- after sign-in, a cookie holding your browser's time zone (`tz`) so that daily deadlines such as the streak are calculated in your local time (storage period: 1 year),
- a cookie storing your choice in the cookie notice (`mm_consent`, see below),
- the two cookies described below, `mm_src` (campaign attribution, only with your consent) and `mm_placement` (handing over a placement test result).
The session cookie, the language cookie, `theme-resolved`, `tz` and `mm_consent` are technically necessary (Section 25(2)(2) of the German TDDDG) and are set without consent; they contain no identifier of your person. In addition, the application stores settings (e.g. colour scheme, dismissed dashboard cards) in your browser's local storage (localStorage). This data does not leave your device; only the colour scheme is additionally sent in the cookie named above.
Campaign attribution
When you reach us through an advertising or post link (short links of the form `/go/…` or links carrying campaign tags such as `utm_source`, e.g. from a newsletter or a partner site), we want to know whether that link later led to a registration. We use two methods for this:
- URL parameter `mm`: For advertised links, the link's code is carried from page to page as a parameter in the page address (`?mm=…`) and evaluated at registration. This attribution works without a cookie; the parameter contains only the link code and nothing about you.
- Cookie `mm_src` (only with consent): When such a short link is opened - or any page is opened through a link carrying campaign tags (`utm_…`) - we may additionally set a cookie containing the channel (e.g. "instagram"), the medium (e.g. "social"), the campaign, the link code (for post links, the identifier of the post) and the time of the visit - no identifier of your person. If such a cookie already exists, it is not overwritten. Its purpose is to attribute a later registration to the link through which you found us. Storage period: 60 days. This cookie is only set if you click "Accept" in the cookie notice. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). If you click "Decline" or make no choice, the cookie is not set and attribution relies on the URL parameter alone. The cookie is read only by us and only while your consent is in place; a cookie still present without consent is deleted on the next page load. There is no tracking across other websites. The content of the cookie is not passed on to third parties; for the separate reporting of a sign-up to Meta, see the next point.
- Reporting sign-ups to Meta (only with consent): Where we run ads on Meta (Instagram, Facebook), we transmit, for a registration attributed to an advertising or post link, the following to Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) via the Meta Conversions API: your e-mail address exclusively as a SHA-256 hash (Meta matches it against its user accounts), the link code and the time of registration. We do not transmit anything else (no name, IP address or browser identifier); no Meta pixel and no Meta script is loaded in your browser. The purpose is measuring and optimising our ads. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by clicking "Accept" in the cookie notice; without it nothing is transmitted, even where the attribution came about through the URL parameter. Meta may transfer this data to Meta Platforms, Inc. in the USA; Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework, and Standard Contractual Clauses apply in addition (see section 10). For ad measurement Meta processes the data as a joint controller with us (Art. 26 GDPR); details of Meta's processing are in Meta's privacy policy. Withdrawal is described under the cookie `mm_consent`.
- Cookie `mm_consent`: We store your choice in the cookie notice ("Accept" or "Decline") in this cookie so that we do not have to ask you again on every visit. It contains only the value of your choice. Storage period: 365 days. It is technically necessary to honour your choice (Section 25(2)(2) TDDDG; Art. 6(1)(c) and (f) GDPR). You can withdraw your consent at any time with effect for the future: "Cookie settings" in the footer of every page deletes `mm_consent` and `mm_src`, the cookie notice asks again, and no report is sent to Meta from that point on.
At registration we store these details (channel, medium, campaign, link code, time of the first visit) in the table `signup_attributions`, linked to your account. They are deleted together with the account.
Placement test without an account: When you take the public placement test, we store the result (the level determined, the number of questions asked and answered correctly, time, channel and link code) in the table `placement_results` - without IP address, without e-mail address and without any link to an account. The result can be viewed under a random, unguessable link that only you receive. At the same time, the cookie `mm_placement` is set, containing the identifier of this result, so that an account created later can take over your result (recommended level, matching starter decks) - a function you explicitly make use of by taking the test. Storage period: 60 days. If you create an account, the result is linked to that account; when the account is deleted, this link is removed. Results are deleted as soon as they are no longer needed for attribution.
5. Registration and user account
An account is required to use the learning features. We process: e-mail address, optionally name and profile picture, password (only as a hash), language settings, and your learning data (activated decks, progress, review statistics, achievements). The legal basis is performance of the contract (Art. 6(1)(b) GDPR). When an account is deleted, the associated data is deleted unless statutory retention obligations (e.g. for invoicing data) apply.
6. Sign-in with Google
Optionally, you can sign in with your Google account. In that case we receive from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) your name, e-mail address, profile picture and a Google account ID. The legal basis is performance of the contract (Art. 6(1)(b) GDPR); using Google sign-in is voluntary. Google's privacy notices apply in addition.
7. Payment processing (Stripe)
Paid subscriptions are processed via the payment provider Stripe (for customers in the EEA: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). The data required for payment (e-mail address, amount, payment method) is transmitted to Stripe. We neither collect nor store full payment details (e.g. card numbers). We store subscription status as well as invoicing and tax data. Legal bases: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (tax and commercial retention obligations).
8. E-mail delivery (SMTP)
To send e-mails (account verification, password reset and - which you can switch off - learning reminders and progress summaries) we use an SMTP service. The e-mail address and the content of the respective message are processed. Legal bases: Art. 6(1)(b) GDPR for transactional e-mails, Art. 6(1)(f) GDPR for learning reminders to existing users; every reminder e-mail contains an unsubscribe link, and you can disable delivery in your settings at any time.
9. Web analytics (self-hosted, cookieless)
To measure reach we use self-hosted analytics software (Umami). The analytics work without cookies, do not create cross-device profiles and do not store IP addresses permanently; only aggregated data such as page views, referrers and rough device information is evaluated. The data remains on our own servers in Germany. The legal basis is our legitimate interest in improving the service as needed (Art. 6(1)(f) GDPR).
10. Transfers to third countries
The controller is established in the United Arab Emirates (UAE) - a third country for which the EU Commission has not issued an adequacy decision. Where personal data is transferred to or processed in the UAE for administration, customer care, billing or support, we rely on appropriate safeguards within the meaning of Art. 44 et seq. GDPR, in particular the EU Commission's Standard Contractual Clauses supplemented by any necessary additional measures. A transfer to the USA by Stripe is possible; Stripe relies on Standard Contractual Clauses and the EU-US Data Privacy Framework. The same applies to the reporting of sign-ups to Meta described in section 4 (only with your consent): Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework, and Standard Contractual Clauses apply in addition. You can request a copy of the safeguards via the contact details above.
11. Storage period
We store personal data only for as long as necessary for the stated purposes: account data until the account is deleted; server log files for up to 14 days; invoicing and payment data for the duration of the statutory retention periods.
12. Recipients and processors
Recipients of personal data are solely the service providers named in this policy (Hetzner, Stripe, the SMTP/e-mail provider, and Google where Google sign-in is used) and - only with your consent and only in hashed form - Meta, for the reporting of sign-ups described in section 4. Contracts under Art. 28 GDPR are in place with processors.
13. Your rights
You have the following rights regarding your personal data:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- withdrawal of consent with effect for the future (Art. 7(3) GDPR).
To exercise them, a plain e-mail to support@merke.me is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
14. Data security
Transmission is encrypted (TLS/HTTPS). Passwords are stored only as a salted hash. Server access is limited to the necessary minimum.
15. Changes to this policy
We adapt this privacy policy when the service or the legal situation changes. The version published here at the time applies.