This Privacy Policy explains how Vake Up GmbH collects, uses, and protects personal data in connection with the Vake Up mobile app, web app (PWA), website at vakeupfridge.ch, and our smart fridges (together, the "Service").
We have written this policy under the Swiss Federal Act on Data Protection (revised FADP / nDSG) and its Ordinance (DPO/DSV). Where the EU General Data Protection Regulation (GDPR) applies to a particular user, the equivalent GDPR rights and legal bases described below apply in parallel.
1. Who we are
The controller responsible for your personal data is:
Vake Up GmbH Herbergsgasse 2 4051 Basel Switzerland UID: CHE-165.172.552
Data protection contact: dev@vakeupfridge.ch
Vake Up is offered to users in Switzerland. We do not target the Service at users in the EU/EEA and have therefore not appointed a representative under GDPR Article 27. If we begin offering the Service in the EU/EEA, we will update this policy and appoint a representative before doing so.
2. Scope
This policy covers personal data we process when you:
- create and use a Vake Up account in the app or web app;
- browse or place an order at a Vake Up smart fridge;
- link a CSS Guthaben account or an employer/gym benefit;
- connect a third-party health or fitness app;
- visit vakeupfridge.ch;
- contact our support team.
It does not cover the privacy practices of third parties whose services you separately choose to use (for example, Apple Health, CSS, or your employer's own systems). Those are governed by their own privacy notices.
Where this policy is published. This policy is permanently available at https://vakeupfridge.ch/privacy-policy.html (German: /datenschutz.html) — a public, non-geofenced, non-editable web page — and inside the app at any time under Settings → Legal → Privacy Policy. It is the same policy that is linked from the Vake Up listing on the Apple App Store and on Google Play, and from the Vake Up entry in Health Connect on Android.
3. What personal data we collect
3.1 Account and identity data
- Name and email address
- Authentication credentials, managed by our authentication provider Clerk (we never see or store your password in plain text)
- Language preference and notification preferences
- Account creation date and last login
3.2 Health and profile data (sensitive personal data)
To calculate your personalised daily macronutrient targets (energy, protein, carbohydrates, fat, fibre), we ask for:
- Date of birth
- Biological sex
- Weight and height (optional)
- Activity level, training type, and training frequency
- Dietary preferences and allergen information
- Your goal (for example: maintain, reduce body fat, lean gain)
Under Art. 5 lit. c nDSG this qualifies as sensitive personal data ("besonders schützenswerte Personendaten"), and we process it only with your express consent, which you give during onboarding and can withdraw at any time.
This data is encrypted at the database column level. If you choose not to provide weight, height, or date of birth, the macro engine runs in a reduced-accuracy mode using population averages — you can still use the Service.
3.3 Connected health and fitness apps
Connecting a health or fitness app is entirely optional. Every part of the Service works without it.
If you choose to connect Apple Health (HealthKit) on iOS, Health Connect on Android, Fitbit, or MyFitnessPal, we store:
- The connection itself — OAuth access and refresh tokens, encrypted at rest
- Only the specific data types needed to track your daily macro progress and energy balance (for example, active energy burned, logged meals and their macronutrients, steps and workout minutes). We request read access to nothing else.
You can disconnect any integration at any time in the app, and you can revoke our permission directly in Apple Health, in Health Connect, or in your device settings. Disconnecting stops all future syncing immediately. Data already synced remains in your account until you delete it or delete your account (see Section 9).
Health Connect is Google's replacement for the retired Google Fit APIs. If you previously connected Google Fit, that connection now runs through Health Connect.
3.3.1 How we handle platform health data — binding commitments
Data we read from Apple HealthKit, the Clinical Health Records API, Motion & Fitness, or Health Connect is subject to the following commitments, which apply in addition to everything else in this policy:
- It is used only to show you your progress and to calculate and personalise your macronutrient targets and meal suggestions inside the Service.
- It is never used for advertising, marketing, remarketing, or use-based data mining — by us or by anyone else.
- It is never sold, rented, or otherwise disclosed to any third party, including data brokers, advertising networks, and insurers. In particular, it is never shared with CSS, with a sponsoring employer or gym, or with any other partner.
- It is never used to determine eligibility, pricing, or the terms of any insurance, employment, credit, or benefit decision.
- It is never stored in iCloud or in any other consumer cloud storage service. It is stored only in our own database in Switzerland, encrypted at column level.
- It is read only after you grant the specific permission, only for the data types you approve, and only for as long as that permission is active.
- We do not write false or inaccurate data into Apple Health or Health Connect.
- If you delete your account, all data read from these sources is deleted with it (Section 7).
Apple Health and Health Connect are operated by Apple and Google respectively and are governed by their own privacy notices, not by this one.
3.4 Orders, payments, and loyalty
- Order history, including a snapshot of the macronutrient values of each item at the time of purchase (so your history stays accurate even if we later reformulate a recipe)
- Payment status, amount, currency, and payment method type (for example "Visa ··1234" or "TWINT") — we never receive or store your full card number; card data is handled entirely by Stripe
- Your VakeUp Coins balance and transaction history
- Fridge location and timestamp of each purchase
3.5 CSS Guthaben linking
If you link a CSS Guthaben (health-insurance wellness credit) account:
- We store your CSS membership identifier, encrypted at rest
- We store the credit balance and sync status returned to us by CSS
- We never receive your CSS login credentials. Linking uses OAuth, so you authenticate directly with CSS
We transmit to CSS only the information required to validate and draw down your credit — the transaction amount and your membership identifier. We do not share your health profile, macro targets, or the contents of your order with CSS.
3.6 Employer and gym benefits (B2B)
If your employer or gym sponsors your Vake Up use, we store your membership status with that organisation and your monthly subsidy usage.
We report to the sponsoring organisation only aggregate or individual subsidy usage amounts — that is, how much of the benefit has been used. We never disclose your health data, macro targets, dietary preferences, or what you bought.
3.7 Location data
The app requests access to your device's precise location in order to show you nearby fridges on a map and sort locations by distance.
- This is optional. You can decline, and the app will show all fridge locations without distance sorting. No feature, price, or benefit is withheld if you decline — you can browse every fridge, place every order, and use every other part of the Service.
- We process this location only on request, to render the map. We do not store a history of your device location, and we do not track your movements in the background.
- Separately, the fridge location associated with each purchase is stored as part of your order record (Section 3.4). This is transaction data, not device tracking.
You can revoke location permission at any time in your device settings.
3.8 Usage and analytics data
We use PostHog, self-hosted on our own infrastructure in Switzerland, to understand how the Service is used and to improve it — for example, which screens are viewed, which features are used, and where users encounter errors.
- Analytics data is pseudonymised where technically possible
- It is not shared with any third party and never leaves our Swiss infrastructure
- It is not used for advertising or sold to anyone
3.9 Cookies and similar technologies
We keep this deliberately minimal.
| Type | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Session management, authentication (Clerk), security, load balancing, storing your language choice | No — required to deliver the Service you requested |
| First-party analytics | PostHog, self-hosted in Switzerland, used only for product improvement | No — but you can opt out at any time (see below) |
| Advertising / third-party tracking | We do not use any. No ad networks, no social media pixels, no cross-site tracking | n/a |
Because we run no third-party tracking and our analytics are first-party and self-hosted, we do not display a consent banner. You can opt out of analytics at any time under Settings → Privacy → Analytics in the app, or by enabling "Do Not Track" in your browser, which we honour.
No cross-app or cross-site tracking. We do not track you across apps or websites owned by other companies. We do not read or use advertising identifiers (Apple's IDFA or Android's Advertising ID), we do not link your data with data from data brokers, and we do not run advertising, attribution, or social-media SDKs. For that reason the app does not present Apple's App Tracking Transparency prompt: there is nothing to ask for. In App Store terms, we carry out no "tracking" at all.
3.10 Community features
If you take part in community votes ("Abstimmungen") on new recipes or products, we record your vote linked to your account so that we can enforce one vote per user per round. Vote results are only ever published in aggregate.
3.11 Device and technical data
- Push notification tokens (via Expo Push Notification Service), if you enable notifications
- Device type, operating system version, and app version
- Server logs: IP address, timestamps, requested URLs, and error traces, retained for security, fraud prevention, and debugging
3.12 Camera
The app requests access to your device camera for one purpose only: to scan the QR code on a Vake Up fridge or on a price tag, so the app knows which fridge and which item you are looking at.
- Camera frames are decoded on your device. Images and video are never recorded, uploaded, transmitted, or retained by us.
- If you decline camera access, you can still use the Service — enter the fridge's short code manually instead.
4. Why we process your data, and on what legal basis
| What we do | Why | Legal basis (nDSG) | GDPR parallel |
|---|---|---|---|
| Create and manage your account | To give you access to the Service | Contract performance | Art. 6(1)(b) |
| Calculate personalised macro targets | Core personalisation feature | Express consent (sensitive data) | Art. 9(2)(a) |
| Sync connected health apps | To track your progress against your targets | Express consent | Art. 9(2)(a) |
| Process payments and issue receipts | To complete your purchase | Contract performance / legal obligation | Art. 6(1)(b), 6(1)(c) |
| Operate VakeUp Coins | To run the loyalty programme you joined | Contract performance | Art. 6(1)(b) |
| Apply CSS Guthaben credit | To process the benefit at your request | Contract performance / consent | Art. 6(1)(b) |
| Report subsidy usage to your employer or gym | To administer the sponsored benefit | Contract performance / legitimate interest | Art. 6(1)(b), 6(1)(f) |
| Show nearby fridges | Convenience feature | Consent (device permission) | Art. 6(1)(a) |
| Product analytics | To understand and improve the Service | Legitimate interest | Art. 6(1)(f) |
| Send transactional notifications (order confirmations, fridge issues) | To keep you informed about your purchases | Contract performance | Art. 6(1)(b) |
| Send marketing notifications | To tell you about new products and offers | Consent (opt-in, revocable) | Art. 6(1)(a) |
| Security, fraud prevention, debugging | To keep the Service and your account safe | Legitimate interest / legal obligation | Art. 6(1)(f), 6(1)(c) |
| Retain accounting records | Swiss commercial law | Legal obligation (Art. 958f CO) | Art. 6(1)(c) |
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawing consent for health data processing will disable macro personalisation, but you can continue to use the rest of the Service.
5. Who we share your data with
We do not sell personal data, and we do not share it for advertising purposes.
We use the following processors, each bound by a data processing agreement:
| Processor | What they do | Data involved | Where processed |
|---|---|---|---|
| Clerk | User authentication and session management | Name, email, credentials | EU data residency |
| Stripe | Payment processing | Payment method, amount, billing details | EU / US (SCCs) |
| PostHog (self-hosted by us) | Product analytics | Pseudonymised usage events | Switzerland |
| Infomaniak | Application hosting and database | All application data | Switzerland |
| Expo | Push notification delivery | Push token, notification content | US (SCCs) |
We also share limited data with the following parties, who act as independent controllers, not processors:
| Party | What they receive | What they never receive |
|---|---|---|
| CSS | Your membership identifier and the transaction amount, when you use Guthaben credit | Health profile, macro data, order contents |
| Your employer or gym (if sponsored) | Membership status and subsidy amount used | Health data, macro data, order contents, purchase times |
Beyond this, we disclose personal data only where we are legally required to — for example in response to a valid order from a Swiss court or authority — or where necessary to establish, exercise, or defend legal claims.
Equal protection commitment. Every third party listed above is contractually required to provide the same or an equal level of protection for your personal data as this policy describes; to process it only on our documented instructions and only for the purposes stated; to keep it confidential; to apply appropriate technical and organisational security measures; to impose the same obligations on any sub-processor; and to delete or return the data when our agreement ends. None of them is permitted to use your data for its own purposes, to sell it, or to use it for advertising. None of them receives your health, macro, or connected-health-app data, other than Infomaniak in its capacity as the host of our encrypted Swiss database.
The independent controllers listed above receive only the narrow data described, under the partnership or benefit arrangement you chose to activate, and are responsible for their own compliance under their own privacy notices.
We maintain a current sub-processor list. If we add or replace a processor, we will update this policy and notify registered users of material changes in advance (Section 12).
6. International data transfers
Our database, application infrastructure, and analytics are hosted in Switzerland (Infomaniak, self-hosted PostHog).
Where a processor operates outside Switzerland:
- Clerk processes data within the EU. Switzerland recognises the EU/EEA as providing adequate protection.
- Stripe and Expo may process data in the United States. These transfers are covered by the European Commission's Standard Contractual Clauses with the Swiss addendum recognised by the FDPIC, together with supplementary technical measures (encryption in transit and at rest, data minimisation).
You can request a copy of the relevant transfer safeguards by writing to dev@vakeupfridge.ch.
7. How long we keep your data
| Data category | Retention period |
|---|---|
| Account and profile data | Until you delete your account |
| Health and macro profile data | Until you delete your account or withdraw consent, then deleted within 30 days |
| Connected health app tokens and synced data | Until you disconnect the integration or delete your account |
| Order and payment records | 10 years from the end of the financial year, as required by Art. 958f of the Swiss Code of Obligations |
| VakeUp Coins transaction history | Until account deletion, subject to the accounting retention above |
| CSS Guthaben transaction records | 10 years (accounting obligation) |
| Product analytics events | 12 months, then deleted |
| Server and security logs | 12 months |
| Support correspondence | 3 years after the matter is closed |
| Marketing consent records | For as long as consent is active, plus 3 years as proof of consent |
After you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except for records we are legally required to retain — principally order and payment records under Art. 958f CO. Those retained records are locked down: they are used only for accounting, tax, and legal-defence purposes and are not used to profile you or contact you.
8. Security
We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including:
- TLS 1.2 or higher for all data in transit
- Column-level encryption at rest for health data, weight, height, date of birth, CSS membership identifiers, and OAuth refresh tokens
- Password hashing with bcrypt/argon2, handled by our authentication provider
- Two-factor authentication available to all users and mandatory for all administrative access
- Role-based access control — staff can access personal data only where their role requires it
- Audit logging of every administrative action taken on user data
- Encrypted, access-controlled backups held in Switzerland
- Regular dependency and vulnerability scanning
No system is perfectly secure. If a data security breach occurs that is likely to result in a high risk to your rights, we will notify the FDPIC and affected users as required by Art. 24 nDSG.
9. Your rights
Under the nDSG — and, where it applies to you, the GDPR — you have the right to:
- Access — obtain confirmation of whether we process your data, and receive a copy of it
- Rectification — have inaccurate or incomplete data corrected
- Erasure — request deletion of your data, subject to our legal retention obligations (Section 7)
- Data portability — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another provider where technically feasible
- Withdraw consent — at any time, for health data processing, location access, or marketing communications
- Object — to processing based on our legitimate interests, on grounds relating to your particular situation
- Restriction of processing — request that we limit how we use your data while a dispute about its accuracy or lawfulness is resolved
- Not be subject to a decision based solely on automated processing that has a significant effect on you. Note: our macro engine generates nutrition recommendations, not binding decisions, and it has no legal or similarly significant effect on you.
How to exercise your rights
The fastest route for most requests is directly in the app:
- Settings → Account → Download my data — generates a machine-readable export
- Settings → Account → Delete account — starts the deletion process
If you no longer have the app installed, you do not need to reinstall it. You can request deletion of your account and its associated data at any time at:
https://vakeupfridge.ch/delete-account.html
or by writing to dev@vakeupfridge.ch with the subject line "Delete my account". That page explains exactly what is deleted, what we are legally required to retain, and how long it takes.
For all other requests, write to dev@vakeupfridge.ch with the subject line "Data request". We will:
- Acknowledge your request within 5 working days
- Verify your identity — we may ask you to confirm from your registered email address, or to provide additional information if we cannot otherwise establish who you are
- Respond substantively within 30 days. If your request is complex, we may extend this by a further 30 days and will tell you why within the initial 30-day period
Exercising your rights is free of charge. We may charge a reasonable fee, or decline to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if we do.
Complaints
If you are not satisfied with how we have handled your data, you can contact:
Federal Data Protection and Information Commissioner (FDPIC) Feldeggweg 1, 3003 Bern, Switzerland www.edoeb.admin.ch
If the GDPR applies to you, you may also lodge a complaint with the supervisory authority in your country of residence.
We would appreciate the chance to resolve the issue first — please write to us at dev@vakeupfridge.ch.
10. Age requirement
Vake Up is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.
We apply an age declaration at registration, and the date of birth you provide for macro calculation is checked against this requirement. If we become aware that we have collected data from a person under 18, we will delete it without undue delay. If you believe a minor has created an account, please contact dev@vakeupfridge.ch.
11. Automated processing and profiling
We use your profile data to automatically calculate macronutrient targets and to recommend fridge items that fit those targets. This is profiling in the sense of data protection law, and we want to be clear about it:
- It affects what the app suggests to you — it does not restrict what you can buy, what you pay, or your access to the Service
- It produces no legal effect and no similarly significant effect on you
- You can see the inputs behind your targets under Settings → Nutrition profile, and adjust or override them
- You can turn personalisation off entirely by withdrawing your health data consent
We do not use your data to set individual prices, and we do not carry out any automated decision-making about creditworthiness or eligibility.
12. Changes to this policy
We review this policy whenever we introduce a feature that processes personal data, change or add a processor, change a processing purpose, or following a legal change or a security incident.
For material changes — for example a new category of data, a new purpose, or a new recipient — we will notify registered users in the app and by email at least 14 days before the change takes effect. For minor or clarifying changes, we will update the version number and date at the top of this policy.
Previous versions are available on request from dev@vakeupfridge.ch.
13. Contact
Questions about this policy, or about how we handle your data:
Vake Up GmbH Herbergsgasse 2 4051 Basel Switzerland
Email: dev@vakeupfridge.ch
14. App store disclosures
This section exists so that the App Store privacy labels and the Google Play Data safety section for Vake Up can be read against this policy line by line. If you ever find a discrepancy, this policy is the binding statement and we will correct the store form.
14.1 What we collect and what we do with it
| Category | Specific data | Why | Linked to you | Used for tracking | Shared for a third party's own purposes |
|---|---|---|---|---|---|
| Contact info | Name, email address | Account, receipts, support | Yes | No | No |
| Health & fitness | Body metrics, goal, activity and training data, macro logs, data read from Apple Health / Health Connect / Fitbit / MyFitnessPal | Macro targets, progress tracking, meal suggestions | Yes | No | No |
| Financial info | Payment method type, amount, order totals (never your full card number) | Processing purchases, refunds, accounting | Yes | No | No — Stripe processes it on our instructions |
| Location | Precise location, on request only, not stored as a history | Showing nearby fridges | No | No | No |
| Purchases | Items bought, macro snapshot, fridge, timestamp | Order history and macro tracking | Yes | No | No |
| Identifiers | Account ID, push notification token, device identifier | Running the Service, notifications | Yes | No | No |
| Usage data | Screens viewed, features used, in-app errors | Product improvement | Pseudonymised | No | No |
| Diagnostics | Crash and error logs, IP address, server logs | Security, fraud prevention, debugging | Yes | No | No |
Not collected at all: contacts, photos or videos, audio, browsing history, search history from outside the app, messages, files, calendar, sensitive data beyond the health data described above, and any data about other apps installed on your device.
14.2 Tracking, advertising, and sale of data
- We do not track. No cross-app or cross-site tracking, no advertising identifiers, no data brokers (Section 3.9).
- We show no advertising and run no ad networks.
- We do not sell or rent personal data, and we do not "share" it in the sense of US state privacy statutes.
- Health data is never used for advertising, marketing, or use-based data mining (Section 3.3.1).
14.3 Data security
All data in transit is protected with TLS 1.2 or higher (HTTPS). Sensitive fields are encrypted at rest at column level. Full detail in Section 8.
14.4 Account and data deletion
- In the app: Settings → Account → Delete account.
- On the web, without the app: https://vakeupfridge.ch/delete-account.html
- By email: dev@vakeupfridge.ch, subject "Delete my account".
Deletion removes your account and its associated personal data within 30 days. We retain order and payment records for 10 years because Swiss accounting law (Art. 958f CO) requires it; those retained records are locked to accounting, tax, and legal-defence use and are never used to profile or contact you. Full detail in Section 7.
14.5 Permissions the app requests
| Permission | Purpose | Optional? |
|---|---|---|
| Camera | Scanning fridge and price-tag QR codes, decoded on device (Section 3.12) | Yes — manual code entry available |
| Precise location | Showing nearby fridges and sorting by distance (Section 3.7) | Yes — full functionality without it |
| Notifications | Order confirmations, pickup reminders, and — only if you opt in — product news (Section 4) | Yes |
| Apple Health / Health Connect | Reading activity and nutrition data to personalise macro targets (Section 3.3) | Yes |
No paid or core functionality depends on granting any of these.
This policy is published in English and German. In the event of any discrepancy, the German version prevails.