1. Controller
The controller responsible for data processing is Fabian David Koder. Contact: office@kdr.ai.
2. This website
This website is provided as a static website through Cloudflare. When you access it, the hosting provider processes technically necessary connection data, in particular your IP address, access time, requested resource, and browser and device information, to deliver content and defend against attacks.
The website does not set its own cookies, includes no user accounts, and uses no web analytics. It provides forms through which you can deliberately submit a support or data-quality report.
The coverage page first displays a map footprint provided directly by PT Widgets. Only if you choose to load the interactive map does your browser connect to Apple and download Apple MapKit JS and map data. Apple then receives technically necessary connection data, including your IP address, and may process the visible map area and your interactions. PT Widgets does not request your precise location for this embedded map. The interactive map remains optional; the coverage footprint and directory work without it. Apple describes its processing in Apple Maps & Privacy.
A report contains your message and, only when you provide them, an email address, selected station, operator and departure context, and technical app or device information. PT Widgets uses this data to respond to support requests, investigate app problems, and review or correct displayed transport data. The report content, without your email address, is recorded as an issue in Linear and retained there for as long as needed to handle the support or data-quality work. The temporary intake record and its delivery metadata are deleted automatically from D1 after 30 days. If you provide an email address, Resend sends a receipt containing only the report reference to that address and a blind copy to the PT Widgets support inbox so the team can respond; the message and technical or transit context are not included in that email. Linear processes the issue and Resend processes the optional receipt as service providers. The connecting IP address is used only transiently by Cloudflare as a rate-limit key; it is not stored with the report or included in the queue, logs, email, or Linear issue.
Submitting a report is deliberate and separate from automatic diagnostics. Report content, contact details, station or departure context, and technical details entered in the report are used only to handle the report. You can also contact support by email instead of using a form.
3. The PT Widgets app
Stop search and departures
When you search for stops or retrieve departures, the app sends the necessary search and stop parameters to the PT Widgets service. The server also processes connection data generated for technical reasons. This processing is necessary to provide the function you requested.
Location
With your iOS permission, the app uses your location to find nearby stops and transport services and to select the closest favourite in the widget. You can change this permission at any time in iOS Settings. Your location is not used for advertising.
Favourites and settings
Favourites, filters, walking times, and display options are stored on your device or in the app container shared by the app and its widgets. This data is used for the configuration you choose.
Widget updates, notifications, and Live Activities
If you enable these functions, the service processes technical push tokens and the lines or stops to be monitored so that Apple Push Notification service (APNs) can deliver update signals. Apple processes the information required for delivery under its own privacy policy.
Product analytics
The current App Store version does not include or initialise PostHog and does not collect product analytics. Usage events, purchase analytics, and cross-session product-analytics identifiers are not sent. If product analytics are introduced in a future version, this policy and the App Store privacy information will be updated before collection begins.
Automatic error diagnostics
To detect and resolve crashes, hangs, and uncaught errors, and to assess the stability of released app versions, the published app may use Sentry. Only when diagnostics are enabled in a particular app build does the app automatically send pseudonymous session data to Sentry: a randomly generated installation identifier, the session start, end or duration and status, the number of errors encountered, and the app version and deployment environment. This is used in particular to determine version distribution and crash-free session or installation rates. When an error occurs, technical diagnostic information such as stack traces, operating-system and device information, and technically necessary connection data is also sent. Product analytics events are disabled in Sentry. Stops, favourites, location data, search text, request URLs, network logs, screenshots, user-interface views, and memory contents are not sent to Sentry. These diagnostics are used only for app functionality and are not used for advertising or tracking.
In-app purchases
Purchases and subscriptions are handled by Apple through the App Store. PT Widgets receives the product and entitlement information needed to unlock and restore a purchase, but no complete payment details. PT Widgets does not send purchase or subscription events to a product analytics service.
4. Data sources
Departure and transport data comes from public or licensed services including Wiener Linien/City of Vienna, LINZ AG, Mobilitätsverbünde Österreich, DELFI/GTFS.de, opentransportdata.swiss, and Entur. When data is requested, the technical information required for that request may be sent to directly integrated interfaces.
5. Retention
Data is stored only for as long as necessary for the relevant function, security, error analysis, or legal obligations. Temporary support intake records and their delivery metadata are retained in D1 for 30 days and then deleted automatically; the corresponding Linear issue is retained only as long as needed to handle the support or data-quality work. You can delete local app data by removing the relevant content or the app. Push registrations are removed when you sign out or when they become invalid.
6. Legal bases
Depending on the processing activity, we rely on performance of a contract or pre-contractual steps, legitimate interests in secure and reliable operation, your consent, or legal obligations. You may withdraw consent at any time with effect for the future.
7. Your rights
Where the legal requirements are met, you have rights to access, rectification, erasure, restriction, data portability, and objection. You may also lodge a complaint with the competent data protection authority. In Austria, this is the Austrian Data Protection Authority.
8. Changes
This policy will be updated when functions, service providers, or legal requirements change. The version published here at the relevant time applies.