Information under Art. 13 GDPR

Privacy policy

As of September 7, 2026

Translation for convenience. The German version is the legally binding one.

1. Controller

The controller for data processing on this website is:

Gérôme Dexheimer
Wiener Straße 74
48145 Münster
Germany
Email: [email protected]

No data protection officer has been appointed because there is no legal obligation to appoint one. Please direct privacy requests to the address above.

2. What this website is

smabar.com presents the desktop application smabar, explains how to use it, lists the Community Store and offers a newsletter and a contact form. The application itself runs entirely on your computer, needs no account and sends no usage data to us. This policy covers the visit to the website only.

The connections the desktop application itself makes, for the update check and the Community Store among others, are described in the privacy notice for the desktop app.

3. General

We process personal data only where necessary to provide this website, handle requests, send the newsletter, pursue legitimate interests or where you have given consent. Personal data is any information relating to an identified or identifiable natural person, such as an IP address, an email address or usage data.

4. Hosting and server logs

This website runs on a server we manage at [hosting provider, server location]. Each request processes technically necessary data: IP address, date and time, requested URL, referrer URL, browser type and version, operating system, HTTP status code and transferred bytes.

The purpose is delivering the website, keeping it stable and secure and preventing abuse. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is safe operation. Server logs are deleted after 14 days at the latest unless a security incident requires longer retention.

5. Cloudflare

[Delete this section if smabar.com is not served through Cloudflare.]

We use services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, as DNS provider, content delivery network, protection against attacks and for delivering the installation packages at updates.smabar.com. Requests to our domains pass through Cloudflare servers, where Cloudflare processes IP addresses, request headers, requested URLs, timestamps and security events.

The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is secure, fast and reliable delivery. A data processing agreement with Cloudflare is in place. Cloudflare may process data in the USA and is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses apply in addition.

Cloudflare may set technically necessary security cookies (for example __cf_bm for bot detection, lifetime about 30 minutes). They serve no marketing purpose and need no consent under § 25 (2) TDDDG.

6. Contact

When you contact us by email, we process your details to handle the request. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR where a contract is involved. Requests are deleted once they are settled and no retention duty applies.

Through the contact form at smabar.com/contact you send a name, an email address and a message. Our own software on our server (api.smabar.com) forwards the message as an email to [email protected] and does not store it; delivery uses Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) as a processor. The message is received in our mailbox at an external provider and kept there as long as handling it requires. Replies go to the address you gave.

The newsletter sign-up and the contact form are protected against automated use: by a hidden form field, by a limit on attempts per IP address (the address is held briefly in memory for that and not stored), and by ALTCHA, a computational puzzle your browser solves itself. No data is sent to third parties and no cookies are set; the puzzle comes from our server and is checked there.

7. Cookies and similar technologies

Without your consent this website sets exactly one cookie: smabar_cc stores your decision in the consent banner (categories, version of the prompt) for 182 days. It is sent to smabar.com only and needs no consent under § 25 (2) TDDDG, because it implements and documents your choice. The legal basis for processing it is Art. 6 (1) (c) and (f) GDPR.

Non-essential technologies, specifically Google Analytics, are used only after your consent. The legal basis is § 25 (1) TDDDG for accessing your device and Art. 6 (1) (a) GDPR for the subsequent processing. You can withdraw consent at any time with effect for the future via “Cookie settings” in the footer. Withdrawal stops the measurement and deletes the related cookies.

Without consent nothing is loaded from Google; the website works fully without it.

8. Google Analytics 4

After your consent we use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It shows us which pages are read and where visitors come from. It processes cookies (_ga, _ga_*, lifetime up to two years), device identifiers, event and usage data, technical device information and coarse location. Google states that it discards IP addresses from the EU before storage.

We use Google Consent Mode: all storage types are off by default; after your consent only analytics_storage is granted. Advertising signals stay off permanently. Data retention in Google Analytics is set to two months.

The legal basis is § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. Data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework, and standard contractual clauses apply in addition.

9. Newsletter

You can subscribe to a newsletter with smabar news. For this we process your email address, the chosen language, and the timestamps of subscription and confirmation. Subscription uses double opt-in: you receive an email with a confirmation link valid for 48 hours, and only confirming on the linked page completes the subscription. An unconfirmed subscription never takes effect.

The newsletter is managed with our own software on our server (api.smabar.com). For delivery we use Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) as a processor; Brevo processes the data in the European Union under a data processing agreement pursuant to Art. 28 GDPR.

The legal basis is your consent, Art. 6(1)(a) GDPR. The consent is documented on the basis of Art. 6(1)(c) and (f) GDPR. Every email contains an unsubscribe link and supports your mail program’s one-click unsubscribe; after unsubscribing we delete your data at once. Unconfirmed subscriptions are deleted after 30 days.

The protection against automated sign-ups is described in section 6.

10. Community Store and content from GitHub

The Community Store shows plugins and themes that their authors published in public GitHub repositories. Our server fetches the catalog; your browser talks to smabar.com only.

When you submit a repository to the store, we record the submitting IP address, time, request identifier, GitHub target, observed plugin/theme counts and result, including rejected attempts, to detect and limit spam. We compare which addresses submit which GitHub repositories and owners using a rolling 24-hour window. This does not identify the submitter as the GitHub account owner. These associations are available only to the operator and are not published in the catalog. Older submission records are deleted during the regular hourly cleanup, on server startup and on the next submission; when automatic crawling is disabled, cleanup takes place on startup or the next submission. Public listing history and manually recorded source blocks are retained separately without these IP associations.

A plugin’s detail page shows its README. If it contains images, your browser loads them directly from GitHub (github.com, raw.githubusercontent.com and other githubusercontent.com subdomains), which gives GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA, your IP address. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is showing the description a third party published in full. GitHub is certified under the EU-U.S. Data Privacy Framework. Links to GitHub repositories lead to a third-party website with its own privacy policy.

11. Fonts and external services

All fonts are served from our server. No fonts from Google and no content from other providers are loaded, except in the cases named in sections 8 and 10. There are no social media plugins.

12. Transfers to third countries

Where providers outside the EU or EEA process personal data (Cloudflare, Google, GitHub), we rely on the adequacy decision for the EU-U.S. Data Privacy Framework and on standard contractual clauses.

13. Retention

We keep personal data only as long as the purpose requires, consent exists or legal retention duties apply. Specific periods are given in the sections above.

14. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. You may withdraw consent at any time with effect for the future; processing before the withdrawal remains lawful.

You also have the right to lodge a complaint with a data protection supervisory authority, for example the authority responsible for your residence or for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (the data protection authority of North Rhine-Westphalia), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

15. TLS encryption

This website uses TLS encryption for all transfers.

16. Changes

We update this policy when the website, the services used or legal requirements change. The date at the top names the current version.