Privacy Policy
Last updated: 2026-08-26
1. Privacy at a Glance
General Information
The following notices provide a simple overview of what happens to your personal data when you visit our website or use our browser-based "Urban Quest Adventures" quest app. Personal data is any data that can personally identify you.
Data Collection at Urban Quest Adventures
Data Controller:
Urban Quest Adventures
Max Köhler
Pöllatstr. 10
81539 Munich, Germany
Email: privacy@urban-quest-adventures.eu
What data do we collect?
- Contact information (email address for purchase and access)
- Payment information (processed through Stripe)
- Quest progress and quest data
- Location data (only for on-map orientation while you play — never stored)
- Photos you choose to share (group selfies, with your consent)
- Device information and usage data
- Cookie data on the website
What do we use your data for?
- Providing our quest services
- Synchronizing quest progress between participants
- Payment processing
- Improving our quests based on pseudonymized usage data
- Featuring shared photos publicly as social proof, and showing them in your group's completion email (only with your consent)
- Customer support
- Marketing (only with your consent)
2. General Notices and Mandatory Information
Data Protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
Note on the Responsible Party
The responsible party for data processing is:
Urban Quest Adventures
Max Köhler
Pöllatstr. 10
81539 Munich, Germany
Email: privacy@urban-quest-adventures.eu
Storage Duration
We store your personal data only as long as necessary to fulfill the purposes for which it was collected or as required by law. Tax-relevant data is stored in accordance with legal retention periods (typically 10 years).
Your Rights
You have the following rights:
- Information about your data stored with us (Art. 15 GDPR)
- Correction of incorrect data (Art. 16 GDPR)
- Deletion of your data ("right to be forgotten") (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of given consent (Art. 7 para. 3 GDPR)
Right to Complain to Supervisory Authority
If you believe that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority (Art. 77 GDPR).
3. Data Collection at Urban Quest Adventures
3.1 Purchase and Quest Access
When you purchase a Quest, we collect:
- Email address (for order confirmation and Quest access)
We do not create traditional user accounts. Quest access is provided via a secure link sent to your email address. No password or username is stored.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)
3.2 Location Data
While you play, the quest app can show your position on the map to help you orient yourself between the points in the story. This happens only if you allow location access in your browser, is used solely for on-map orientation, and is processed live on your device — we do not store, record, or transmit your location to our servers. Your position is never used to lock or unlock any part of the adventure; the story and its challenges are digital content you can reach regardless of where you are.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
3.3 Quest Progress and Analysis
We collect the following information:
- Quest progress for synchronization between participants
- Pseudonymized event data (e.g., "Challenge XYZ, 2 hints used")
- This data contains no personal information
- Used exclusively to improve our quests
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
3.4 Payment Data
Payment processing is handled exclusively through Stripe. We do not store credit card data. We receive from Stripe:
- Transaction ID
- Purchase date and amount
- Last 4 digits of credit card (for identification purposes)
For more information, see Stripe's privacy policy: https://stripe.com/privacy
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)
3.5 Multiplayer Expeditions
If you book a Quest as a group, the buyer can invite other adventurers to share the Quest. The room that coordinates this group — what we call an expedition — collects a small set of additional data so that everyone can join, see who is present, and play together.
When the buyer sends an invitation, they enter the email address of each adventurer they want to invite. When you open an invitation link, you enter your own name. If you request to join a group via a shared link, you enter your own name and email address.
During the expedition, we record presence events (joins, leaves, invitations sent, invitations expired) and quest interaction events (hints used, challenges completed, chapters reached) together with your adventurer identifier and a timestamp. These events drive the real-time updates other adventurers see in the same group. The content of your answers and your private notes is never stored. We do not collect location data on this surface — location data is only used during active quest play, as described in section 3.2.
We keep the expedition record after the Quest is complete so that the buyer can revisit the result with friends. You can request deletion of your data from an expedition at any time by emailing privacy@urban-quest-adventures.eu; we will remove your name, email address, and event history from the expedition.
The welcome screen of an expedition includes a separate, opt-in checkbox for occasional letters from the Chronicler. This is a distinct, express opt-in, independent of any consent given at purchase; the general consent and withdrawal model for marketing messages is described in section 6. You can withdraw it at any time via the unsubscribe link in each letter.
Legal bases: Art. 6 para. 1 lit. b GDPR (contract fulfillment — coordinating the group you booked the Quest for); Art. 6 para. 1 lit. f GDPR (legitimate interest — presence events that allow real-time multiplayer to function); Art. 6 para. 1 lit. a GDPR (consent — the optional Chronicler letters checkbox).
3.6 Photos and Group Selfies
At the end of a quest, your group can choose to take or upload a group photo to mark the moment. Sharing a photo is entirely optional and never required to play or to finish a quest.
What we store. If you choose to share, we store the photo with Google Cloud (see section 5.3). We store it together with a record of: an internal photo identifier; the expedition and quest the photo belongs to; the city and language; the identifier of the adventurer who uploaded it; where the photo file is stored; when it was uploaded; and the details of your consent (that consent was given, when it was given, on which screen, and which version of the consent text you agreed to). We do not attach your email address to the photo record.
Who can reach the photo. The photo file has its own web address. That address contains a randomly generated identifier, and we do not publish the address. We do not offer any way to browse or list the stored photos. The address is not protected by a sign-in, however: anyone who has the address can open the photo, and the address does not expire.
What we use the photo for. With your consent, we may show your photo publicly in a photo gallery on our website and in our newsletter. We do not show it anywhere else, and we ask for the full purpose in advance so that no further consent is needed later. We never sell your photo and never use it for third-party advertising.
The photo in your completion email. After your quest ends, we send each adventurer who joined your expedition an email recapping the adventure. If your group shared a photo, that email shows the photo and links to it. The completion email belongs to our newsletter, one of the channels named above, and goes to everyone who joined the expedition as part of the quest they took part in. The completion email is not the subscription newsletter described in section 6, which you receive only if you sign up for it.
Group photos. A shared photo usually shows several identifiable people. When you share it, you confirm that you told each person shown what the photo is for and where it will appear, and that each of them agreed. One consent covers the whole picture and everyone in it. If you do not have everyone's agreement, do not share the photo.
How you consent. We show you the consent statement in full. Consent is then given by an unmistakable, deliberate action: you tick a checkbox that is never pre-ticked, and you then tap the button that uploads the photo. Until that box is ticked, the photo is not uploaded. The version of the consent text you agreed to is stored with each photo record, and that version changes whenever the wording changes.
Photos of children. Children take part in quests alongside adults, so a group photo may show children. If a child appears in the photo, you confirm when you share it that you are that child's parent or legal guardian, or that you have that guardian's agreement (Art. 8 GDPR). If you cannot give that confirmation for every child shown, do not share the photo.
Withdrawing consent. Anyone shown in the photo can withdraw at any time, whether or not they uploaded it and whether or not they have ever bought a Quest. Write to privacy@urban-quest-adventures.eu and tell us which quest and city the photo is from, so that we can find it. On withdrawal we delete the photo and take it down from our website and our newsletter. We cannot undo copies that have already been sent out or that other people have shared onward; where that has happened, we take reasonable steps to have them removed (Art. 17 para. 2 GDPR).
Retention. We do not keep shared photos for a fixed period. A photo stays stored only for as long as your consent stands, and we delete it as soon as that consent is withdrawn. Anyone else shown in the photo can do the same: if they ask us to delete the photo (by emailing privacy@urban-quest-adventures.eu), we delete it. A photo is never kept longer than the consent that justifies storing it.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent); for photos showing children, additionally Art. 8 GDPR (consent of the holder of parental responsibility). Where we publish a photo, the German right to one's own image (§ 22 KUG) applies alongside this consent: everyone shown must have agreed to publication, and we rely on the confirmation described above as evidence that they have.
4. Cookies and Tracking
4.1 Cookies and Local Storage
Across our website and quest app we use cookies and comparable browser storage (local and session storage). Storing information on, or reading it from, your device is governed by § 25 TDDDG. The strictly necessary entries below keep our surfaces working and do not require consent:
- Website: cookie-consent (local storage) remembers your consent choices, and NEXT_LOCALE (cookie) remembers your chosen language.
- Quest app: adv_token (cookie) keeps you signed in to your expedition; urban-quest-adventurer-id / urban-quest-expedition-id, compass-tutorial-seen, urban-quest-statistics, and chapter or catch-up markers (e.g. chapter-intro-seen, mp_initial_caught_up) let you resume your quest where you left off.
For website analytics we additionally use Google Analytics (_ga, _gid), which is set only after you agree via the cookie banner (see section 4.2). A full list of every entry, its purpose, and its storage duration is set out in our separate Cookie and Storage Policy. You can also configure your browser to inform you about, or block, cookies and to clear stored data.
4.2 Google Analytics
We use Google Analytics to analyze website usage. The collected data includes:
- Anonymized IP addresses
- Pages visited and duration
- Device and browser information
- Visitor origin
You can prevent Google Analytics tracking by setting an opt-out cookie or installing the browser add-on to disable Google Analytics.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent) in conjunction with § 25 TDDDG
4.3 Attribution and Reach Measurement
To understand which channels bring visitors to us, our website notes the marketing parameters and landing page of your visit. This information stays in your browser's memory while you browse and is written to storage only once you agree to analytics via the cookie banner; if you decline, nothing is stored. When you have agreed, we keep two first-party entries:
- uqa_attribution_session (session storage) — holds the marketing parameters and landing page of your current visit; it is cleared when you close the browser tab.
- uqa_attribution_first_touch (local storage) — records the same details for your first visit, so that a later sign-up can be attributed to the channel that first brought you to us.
These entries are first-party only, are never shared with third parties, and contain no directly identifying information such as your name or email address. They are written only after you agree to analytics via the cookie banner; until then the information stays in your browser's memory and is discarded if you decline. You can remove any stored entries at any time by clearing your browser's site data.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent) in conjunction with § 25 TDDDG
5. Third-Party Services
5.1 Vercel (Hosting)
Our website is hosted on Vercel. The following data may be processed:
- IP address
- Access data (date, time, page accessed)
Privacy policy: https://vercel.com/legal/privacy-policy
5.2 Resend (Email Service)
We use Resend for email delivery. Processed data includes:
- Email addresses
- Names (if provided)
- Email interactions (opens, clicks for marketing emails)
- The web address of a shared photo, where your group's completion email includes one
Privacy policy: https://resend.com/legal/privacy-policy
5.3 Google Cloud (Database)
We use Google Cloud to store Quest data, progress, and shared photos. Processed data may include:
- Email address (as purchase identifier)
- Quest progress and completion status
- Pseudonymized usage data
- Shared photos and their metadata (with consent)
Privacy policy: https://cloud.google.com/terms/cloud-privacy-notice
5.4 Stripe (Payment Processing)
Payment processing is handled by Stripe. Stripe may process:
- Payment card data (handled directly by Stripe; we do not store card numbers)
- Transaction amounts and dates
- Billing details as provided at checkout
Privacy policy: https://stripe.com/privacy
6. Marketing and Newsletter
We send marketing emails, our newsletter, and occasional updates only with your express, opt-in consent. Wherever we offer a sign-up, consent is collected through a clearly labelled checkbox that is never pre-ticked — we never treat silence or inactivity as agreement. Our newsletter additionally uses a double opt-in: you confirm your email address before we send anything. You can withdraw your consent at any time through the unsubscribe link in every email or by emailing privacy@urban-quest-adventures.eu.
We also use retargeting through the Meta (Facebook / Instagram) Pixel, which lets us show relevant reminders about our adventures to people who have visited our website. It runs only after you agree via the cookie banner and stays off if you decline. Full details are set out in our separate Cookie and Storage Policy.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
7. Protection of Minors
To purchase a Quest and enter into the contract, the buyer must be at least 18 years of age or, if younger, act with the consent of their legal guardian. There is no minimum age to take part in a purchased Quest: children take part alongside — and under the supervision of — an accompanying adult.
Where children take part, any personal data relating to a child — in particular a shared photo (see section 3.6) — is processed only with the consent of the child's parent or legal guardian (Art. 8 GDPR). For a shared photo, that consent is the guardian's, and we rely on the confirmation given by the person who shares it: that they are the child's parent or legal guardian, or that they have that guardian's agreement.
8. Data Transfers to Third Countries
Some of our service providers (Google, Stripe, Vercel, Resend) are based in the USA. Data transfer occurs based on standard contractual clauses or other appropriate safeguards according to Art. 46 GDPR.
9. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy to comply with changed legal situations or changes to the service. The new privacy policy will then apply to all data collected from the time of publication.
10. Contact for Privacy Questions
For questions about data protection, please contact us at:
Email: privacy@urban-quest-adventures.eu
