Legal

Privacy Policy

Version 1.1 · Last updated 30 August 2026

This Privacy Policy explains how Vake Up GmbH collects, uses, and protects personal data in connection with the Vake Up mobile app, web app (PWA), website at vakeupfridge.ch, and our smart fridges (together, the "Service").

We have written this policy under the Swiss Federal Act on Data Protection (revised FADP / nDSG) and its Ordinance (DPO/DSV). Where the EU General Data Protection Regulation (GDPR) applies to a particular user, the equivalent GDPR rights and legal bases described below apply in parallel.


1. Who we are

The controller responsible for your personal data is:

Vake Up GmbH Herbergsgasse 2 4051 Basel Switzerland UID: CHE-165.172.552

Data protection contact: dev@vakeupfridge.ch

Vake Up is offered to users in Switzerland. We do not target the Service at users in the EU/EEA and have therefore not appointed a representative under GDPR Article 27. If we begin offering the Service in the EU/EEA, we will update this policy and appoint a representative before doing so.


2. Scope

This policy covers personal data we process when you:

  • create and use a Vake Up account in the app or web app;
  • browse or place an order at a Vake Up smart fridge;
  • link a CSS Guthaben account or an employer/gym benefit;
  • connect a third-party health or fitness app;
  • visit vakeupfridge.ch;
  • contact our support team.

It does not cover the privacy practices of third parties whose services you separately choose to use (for example, Apple Health, CSS, or your employer's own systems). Those are governed by their own privacy notices.

Where this policy is published. This policy is permanently available at https://vakeupfridge.ch/privacy-policy.html (German: /datenschutz.html) — a public, non-geofenced, non-editable web page — and inside the app at any time under Settings → Legal → Privacy Policy. It is the same policy that is linked from the Vake Up listing on the Apple App Store and on Google Play, and from the Vake Up entry in Health Connect on Android.


3. What personal data we collect

3.1 Account and identity data

  • Name and email address
  • Authentication credentials, managed by our authentication provider Clerk (we never see or store your password in plain text)
  • Language preference and notification preferences
  • Account creation date and last login

3.2 Health and profile data (sensitive personal data)

To calculate your personalised daily macronutrient targets (energy, protein, carbohydrates, fat, fibre), we ask for:

  • Date of birth
  • Biological sex
  • Weight and height (optional)
  • Activity level, training type, and training frequency
  • Dietary preferences and allergen information
  • Your goal (for example: maintain, reduce body fat, lean gain)

Under Art. 5 lit. c nDSG this qualifies as sensitive personal data ("besonders schützenswerte Personendaten"), and we process it only with your express consent, which you give during onboarding and can withdraw at any time.

This data is encrypted at the database column level. If you choose not to provide weight, height, or date of birth, the macro engine runs in a reduced-accuracy mode using population averages — you can still use the Service.

3.3 Connected health and fitness apps

Connecting a health or fitness app is entirely optional. Every part of the Service works without it.

If you choose to connect Apple Health (HealthKit) on iOS, Health Connect on Android, Fitbit, or MyFitnessPal, we store:

  • The connection itself — OAuth access and refresh tokens, encrypted at rest
  • Only the specific data types needed to track your daily macro progress and energy balance (for example, active energy burned, logged meals and their macronutrients, steps and workout minutes). We request read access to nothing else.

You can disconnect any integration at any time in the app, and you can revoke our permission directly in Apple Health, in Health Connect, or in your device settings. Disconnecting stops all future syncing immediately. Data already synced remains in your account until you delete it or delete your account (see Section 9).

Health Connect is Google's replacement for the retired Google Fit APIs. If you previously connected Google Fit, that connection now runs through Health Connect.

3.3.1 How we handle platform health data — binding commitments

Data we read from Apple HealthKit, the Clinical Health Records API, Motion & Fitness, or Health Connect is subject to the following commitments, which apply in addition to everything else in this policy:

  • It is used only to show you your progress and to calculate and personalise your macronutrient targets and meal suggestions inside the Service.
  • It is never used for advertising, marketing, remarketing, or use-based data mining — by us or by anyone else.
  • It is never sold, rented, or otherwise disclosed to any third party, including data brokers, advertising networks, and insurers. In particular, it is never shared with CSS, with a sponsoring employer or gym, or with any other partner.
  • It is never used to determine eligibility, pricing, or the terms of any insurance, employment, credit, or benefit decision.
  • It is never stored in iCloud or in any other consumer cloud storage service. It is stored only in our own database in Switzerland, encrypted at column level.
  • It is read only after you grant the specific permission, only for the data types you approve, and only for as long as that permission is active.
  • We do not write false or inaccurate data into Apple Health or Health Connect.
  • If you delete your account, all data read from these sources is deleted with it (Section 7).

Apple Health and Health Connect are operated by Apple and Google respectively and are governed by their own privacy notices, not by this one.

3.4 Orders, payments, and loyalty

  • Order history, including a snapshot of the macronutrient values of each item at the time of purchase (so your history stays accurate even if we later reformulate a recipe)
  • Payment status, amount, currency, and payment method type (for example "Visa ··1234" or "TWINT") — we never receive or store your full card number; card data is handled entirely by Stripe
  • Your VakeUp Coins balance and transaction history
  • Fridge location and timestamp of each purchase

3.5 CSS Guthaben linking

If you link a CSS Guthaben (health-insurance wellness credit) account:

  • We store your CSS membership identifier, encrypted at rest
  • We store the credit balance and sync status returned to us by CSS
  • We never receive your CSS login credentials. Linking uses OAuth, so you authenticate directly with CSS

We transmit to CSS only the information required to validate and draw down your credit — the transaction amount and your membership identifier. We do not share your health profile, macro targets, or the contents of your order with CSS.

3.6 Employer and gym benefits (B2B)

If your employer or gym sponsors your Vake Up use, we store your membership status with that organisation and your monthly subsidy usage.

We report to the sponsoring organisation only aggregate or individual subsidy usage amounts — that is, how much of the benefit has been used. We never disclose your health data, macro targets, dietary preferences, or what you bought.

3.7 Location data

The app requests access to your device's precise location in order to show you nearby fridges on a map and sort locations by distance.

  • This is optional. You can decline, and the app will show all fridge locations without distance sorting. No feature, price, or benefit is withheld if you decline — you can browse every fridge, place every order, and use every other part of the Service.
  • We process this location only on request, to render the map. We do not store a history of your device location, and we do not track your movements in the background.
  • Separately, the fridge location associated with each purchase is stored as part of your order record (Section 3.4). This is transaction data, not device tracking.

You can revoke location permission at any time in your device settings.

3.8 Usage and analytics data

We use PostHog, self-hosted on our own infrastructure in Switzerland, to understand how the Service is used and to improve it — for example, which screens are viewed, which features are used, and where users encounter errors.

  • Analytics data is pseudonymised where technically possible
  • It is not shared with any third party and never leaves our Swiss infrastructure
  • It is not used for advertising or sold to anyone

3.9 Cookies and similar technologies

We keep this deliberately minimal.

Type Purpose Consent required
Strictly necessary Session management, authentication (Clerk), security, load balancing, storing your language choice No — required to deliver the Service you requested
First-party analytics PostHog, self-hosted in Switzerland, used only for product improvement No — but you can opt out at any time (see below)
Advertising / third-party tracking We do not use any. No ad networks, no social media pixels, no cross-site tracking n/a

Because we run no third-party tracking and our analytics are first-party and self-hosted, we do not display a consent banner. You can opt out of analytics at any time under Settings → Privacy → Analytics in the app, or by enabling "Do Not Track" in your browser, which we honour.

No cross-app or cross-site tracking. We do not track you across apps or websites owned by other companies. We do not read or use advertising identifiers (Apple's IDFA or Android's Advertising ID), we do not link your data with data from data brokers, and we do not run advertising, attribution, or social-media SDKs. For that reason the app does not present Apple's App Tracking Transparency prompt: there is nothing to ask for. In App Store terms, we carry out no "tracking" at all.

3.10 Community features

If you take part in community votes ("Abstimmungen") on new recipes or products, we record your vote linked to your account so that we can enforce one vote per user per round. Vote results are only ever published in aggregate.

3.11 Device and technical data

  • Push notification tokens (via Expo Push Notification Service), if you enable notifications
  • Device type, operating system version, and app version
  • Server logs: IP address, timestamps, requested URLs, and error traces, retained for security, fraud prevention, and debugging

3.12 Camera

The app requests access to your device camera for one purpose only: to scan the QR code on a Vake Up fridge or on a price tag, so the app knows which fridge and which item you are looking at.

  • Camera frames are decoded on your device. Images and video are never recorded, uploaded, transmitted, or retained by us.
  • If you decline camera access, you can still use the Service — enter the fridge's short code manually instead.

What we do Why Legal basis (nDSG) GDPR parallel
Create and manage your account To give you access to the Service Contract performance Art. 6(1)(b)
Calculate personalised macro targets Core personalisation feature Express consent (sensitive data) Art. 9(2)(a)
Sync connected health apps To track your progress against your targets Express consent Art. 9(2)(a)
Process payments and issue receipts To complete your purchase Contract performance / legal obligation Art. 6(1)(b), 6(1)(c)
Operate VakeUp Coins To run the loyalty programme you joined Contract performance Art. 6(1)(b)
Apply CSS Guthaben credit To process the benefit at your request Contract performance / consent Art. 6(1)(b)
Report subsidy usage to your employer or gym To administer the sponsored benefit Contract performance / legitimate interest Art. 6(1)(b), 6(1)(f)
Show nearby fridges Convenience feature Consent (device permission) Art. 6(1)(a)
Product analytics To understand and improve the Service Legitimate interest Art. 6(1)(f)
Send transactional notifications (order confirmations, fridge issues) To keep you informed about your purchases Contract performance Art. 6(1)(b)
Send marketing notifications To tell you about new products and offers Consent (opt-in, revocable) Art. 6(1)(a)
Security, fraud prevention, debugging To keep the Service and your account safe Legitimate interest / legal obligation Art. 6(1)(f), 6(1)(c)
Retain accounting records Swiss commercial law Legal obligation (Art. 958f CO) Art. 6(1)(c)

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawing consent for health data processing will disable macro personalisation, but you can continue to use the rest of the Service.


5. Who we share your data with

We do not sell personal data, and we do not share it for advertising purposes.

We use the following processors, each bound by a data processing agreement:

Processor What they do Data involved Where processed
Clerk User authentication and session management Name, email, credentials EU data residency
Stripe Payment processing Payment method, amount, billing details EU / US (SCCs)
PostHog (self-hosted by us) Product analytics Pseudonymised usage events Switzerland
Infomaniak Application hosting and database All application data Switzerland
Expo Push notification delivery Push token, notification content US (SCCs)

We also share limited data with the following parties, who act as independent controllers, not processors:

Party What they receive What they never receive
CSS Your membership identifier and the transaction amount, when you use Guthaben credit Health profile, macro data, order contents
Your employer or gym (if sponsored) Membership status and subsidy amount used Health data, macro data, order contents, purchase times

Beyond this, we disclose personal data only where we are legally required to — for example in response to a valid order from a Swiss court or authority — or where necessary to establish, exercise, or defend legal claims.

Equal protection commitment. Every third party listed above is contractually required to provide the same or an equal level of protection for your personal data as this policy describes; to process it only on our documented instructions and only for the purposes stated; to keep it confidential; to apply appropriate technical and organisational security measures; to impose the same obligations on any sub-processor; and to delete or return the data when our agreement ends. None of them is permitted to use your data for its own purposes, to sell it, or to use it for advertising. None of them receives your health, macro, or connected-health-app data, other than Infomaniak in its capacity as the host of our encrypted Swiss database.

The independent controllers listed above receive only the narrow data described, under the partnership or benefit arrangement you chose to activate, and are responsible for their own compliance under their own privacy notices.

We maintain a current sub-processor list. If we add or replace a processor, we will update this policy and notify registered users of material changes in advance (Section 12).


6. International data transfers

Our database, application infrastructure, and analytics are hosted in Switzerland (Infomaniak, self-hosted PostHog).

Where a processor operates outside Switzerland:

  • Clerk processes data within the EU. Switzerland recognises the EU/EEA as providing adequate protection.
  • Stripe and Expo may process data in the United States. These transfers are covered by the European Commission's Standard Contractual Clauses with the Swiss addendum recognised by the FDPIC, together with supplementary technical measures (encryption in transit and at rest, data minimisation).

You can request a copy of the relevant transfer safeguards by writing to dev@vakeupfridge.ch.


7. How long we keep your data

Data category Retention period
Account and profile data Until you delete your account
Health and macro profile data Until you delete your account or withdraw consent, then deleted within 30 days
Connected health app tokens and synced data Until you disconnect the integration or delete your account
Order and payment records 10 years from the end of the financial year, as required by Art. 958f of the Swiss Code of Obligations
VakeUp Coins transaction history Until account deletion, subject to the accounting retention above
CSS Guthaben transaction records 10 years (accounting obligation)
Product analytics events 12 months, then deleted
Server and security logs 12 months
Support correspondence 3 years after the matter is closed
Marketing consent records For as long as consent is active, plus 3 years as proof of consent

After you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except for records we are legally required to retain — principally order and payment records under Art. 958f CO. Those retained records are locked down: they are used only for accounting, tax, and legal-defence purposes and are not used to profile you or contact you.


8. Security

We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including:

  • TLS 1.2 or higher for all data in transit
  • Column-level encryption at rest for health data, weight, height, date of birth, CSS membership identifiers, and OAuth refresh tokens
  • Password hashing with bcrypt/argon2, handled by our authentication provider
  • Two-factor authentication available to all users and mandatory for all administrative access
  • Role-based access control — staff can access personal data only where their role requires it
  • Audit logging of every administrative action taken on user data
  • Encrypted, access-controlled backups held in Switzerland
  • Regular dependency and vulnerability scanning

No system is perfectly secure. If a data security breach occurs that is likely to result in a high risk to your rights, we will notify the FDPIC and affected users as required by Art. 24 nDSG.


9. Your rights

Under the nDSG — and, where it applies to you, the GDPR — you have the right to:

  • Access — obtain confirmation of whether we process your data, and receive a copy of it
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — request deletion of your data, subject to our legal retention obligations (Section 7)
  • Data portability — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another provider where technically feasible
  • Withdraw consent — at any time, for health data processing, location access, or marketing communications
  • Object — to processing based on our legitimate interests, on grounds relating to your particular situation
  • Restriction of processing — request that we limit how we use your data while a dispute about its accuracy or lawfulness is resolved
  • Not be subject to a decision based solely on automated processing that has a significant effect on you. Note: our macro engine generates nutrition recommendations, not binding decisions, and it has no legal or similarly significant effect on you.

How to exercise your rights

The fastest route for most requests is directly in the app:

  • Settings → Account → Download my data — generates a machine-readable export
  • Settings → Account → Delete account — starts the deletion process

If you no longer have the app installed, you do not need to reinstall it. You can request deletion of your account and its associated data at any time at:

https://vakeupfridge.ch/delete-account.html

or by writing to dev@vakeupfridge.ch with the subject line "Delete my account". That page explains exactly what is deleted, what we are legally required to retain, and how long it takes.

For all other requests, write to dev@vakeupfridge.ch with the subject line "Data request". We will:

  1. Acknowledge your request within 5 working days
  2. Verify your identity — we may ask you to confirm from your registered email address, or to provide additional information if we cannot otherwise establish who you are
  3. Respond substantively within 30 days. If your request is complex, we may extend this by a further 30 days and will tell you why within the initial 30-day period

Exercising your rights is free of charge. We may charge a reasonable fee, or decline to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if we do.

Complaints

If you are not satisfied with how we have handled your data, you can contact:

Federal Data Protection and Information Commissioner (FDPIC) Feldeggweg 1, 3003 Bern, Switzerland www.edoeb.admin.ch

If the GDPR applies to you, you may also lodge a complaint with the supervisory authority in your country of residence.

We would appreciate the chance to resolve the issue first — please write to us at dev@vakeupfridge.ch.


10. Age requirement

Vake Up is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.

We apply an age declaration at registration, and the date of birth you provide for macro calculation is checked against this requirement. If we become aware that we have collected data from a person under 18, we will delete it without undue delay. If you believe a minor has created an account, please contact dev@vakeupfridge.ch.


11. Automated processing and profiling

We use your profile data to automatically calculate macronutrient targets and to recommend fridge items that fit those targets. This is profiling in the sense of data protection law, and we want to be clear about it:

  • It affects what the app suggests to you — it does not restrict what you can buy, what you pay, or your access to the Service
  • It produces no legal effect and no similarly significant effect on you
  • You can see the inputs behind your targets under Settings → Nutrition profile, and adjust or override them
  • You can turn personalisation off entirely by withdrawing your health data consent

We do not use your data to set individual prices, and we do not carry out any automated decision-making about creditworthiness or eligibility.


12. Changes to this policy

We review this policy whenever we introduce a feature that processes personal data, change or add a processor, change a processing purpose, or following a legal change or a security incident.

For material changes — for example a new category of data, a new purpose, or a new recipient — we will notify registered users in the app and by email at least 14 days before the change takes effect. For minor or clarifying changes, we will update the version number and date at the top of this policy.

Previous versions are available on request from dev@vakeupfridge.ch.


13. Contact

Questions about this policy, or about how we handle your data:

Vake Up GmbH Herbergsgasse 2 4051 Basel Switzerland

Email: dev@vakeupfridge.ch


14. App store disclosures

This section exists so that the App Store privacy labels and the Google Play Data safety section for Vake Up can be read against this policy line by line. If you ever find a discrepancy, this policy is the binding statement and we will correct the store form.

14.1 What we collect and what we do with it

Category Specific data Why Linked to you Used for tracking Shared for a third party's own purposes
Contact info Name, email address Account, receipts, support Yes No No
Health & fitness Body metrics, goal, activity and training data, macro logs, data read from Apple Health / Health Connect / Fitbit / MyFitnessPal Macro targets, progress tracking, meal suggestions Yes No No
Financial info Payment method type, amount, order totals (never your full card number) Processing purchases, refunds, accounting Yes No No — Stripe processes it on our instructions
Location Precise location, on request only, not stored as a history Showing nearby fridges No No No
Purchases Items bought, macro snapshot, fridge, timestamp Order history and macro tracking Yes No No
Identifiers Account ID, push notification token, device identifier Running the Service, notifications Yes No No
Usage data Screens viewed, features used, in-app errors Product improvement Pseudonymised No No
Diagnostics Crash and error logs, IP address, server logs Security, fraud prevention, debugging Yes No No

Not collected at all: contacts, photos or videos, audio, browsing history, search history from outside the app, messages, files, calendar, sensitive data beyond the health data described above, and any data about other apps installed on your device.

14.2 Tracking, advertising, and sale of data

  • We do not track. No cross-app or cross-site tracking, no advertising identifiers, no data brokers (Section 3.9).
  • We show no advertising and run no ad networks.
  • We do not sell or rent personal data, and we do not "share" it in the sense of US state privacy statutes.
  • Health data is never used for advertising, marketing, or use-based data mining (Section 3.3.1).

14.3 Data security

All data in transit is protected with TLS 1.2 or higher (HTTPS). Sensitive fields are encrypted at rest at column level. Full detail in Section 8.

14.4 Account and data deletion

  • In the app: Settings → Account → Delete account.
  • On the web, without the app: https://vakeupfridge.ch/delete-account.html
  • By email: dev@vakeupfridge.ch, subject "Delete my account".

Deletion removes your account and its associated personal data within 30 days. We retain order and payment records for 10 years because Swiss accounting law (Art. 958f CO) requires it; those retained records are locked to accounting, tax, and legal-defence use and are never used to profile or contact you. Full detail in Section 7.

14.5 Permissions the app requests

Permission Purpose Optional?
Camera Scanning fridge and price-tag QR codes, decoded on device (Section 3.12) Yes — manual code entry available
Precise location Showing nearby fridges and sorting by distance (Section 3.7) Yes — full functionality without it
Notifications Order confirmations, pickup reminders, and — only if you opt in — product news (Section 4) Yes
Apple Health / Health Connect Reading activity and nutrition data to personalise macro targets (Section 3.3) Yes

No paid or core functionality depends on granting any of these.


This policy is published in English and German. In the event of any discrepancy, the German version prevails.

← Back to vakeupfridge.ch