Privacy Policy
1. Controller
Traffic netWorks
Speditionstraße 8
40221 Düsseldorf, Germany
Email: support@letsg.ro
Website: https://letsg.ro
2. Collection and Processing of Personal Data
2.1 Website Visit
When you visit our website, the web server automatically records the following data and temporarily stores it in server log files:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the requested file
- Amount of data transferred
- Browser type and version
- Operating system
- Referrer URL
This data is used exclusively to ensure trouble-free operation and to improve our service (Art. 6(1)(f) GDPR).
2.2 Contact Form
When you use our contact form, we process the data you provide (name, email address, message) to handle your inquiry. The legal basis is Art. 6(1)(b) GDPR. This data will be deleted after your inquiry has been fully processed, unless statutory retention obligations apply.
2.3 Local Data Storage (localStorage)
The training app stores your selected training goal and progress locally in your browser (localStorage). This data does not leave your device and is not transmitted to our servers. You can delete this data at any time via your browser settings.
3. Hosting
This website is hosted by Vercel Inc. (340 Pine Street, Suite 701, San Francisco, CA 94104, USA). Vercel processes technical data (in particular IP addresses) as part of hosting. The processing is based on our legitimate interest in secure and efficient operation (Art. 6(1)(f) GDPR). Vercel is certified under the EU–US Data Privacy Framework.
4. Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies and similar technologies to collect and analyze information about your use of this website.
Data Processed
- IP address (anonymized/truncated)
- Pages visited and time spent
- Approximate location (city/country)
- Device, browser, and operating system
- Referrer (originating page)
We use Google Analytics 4 (GA4) with IP anonymization enabled. Your IP address is truncated before storage, making direct identification of individuals impossible.
Purpose and Legal Basis
We use Google Analytics to analyze user behavior and improve our service. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR in providing a user-friendly and optimized service.
Data Transfer to the USA
Google LLC is certified under the EU–US Data Privacy Framework. Data may be transferred to the USA. For more information, see Google's Privacy Policy and tools.google.com/dlpage/gaoptout.
Opt-Out
You can prevent Google Analytics from collecting data by installing the Google Analytics Opt-out Browser Add-on. Alternatively, you can disable or delete cookies in your browser settings.
5. Fonts (Google Fonts)
We use Google Fonts to display fonts consistently. When you load a page, your browser downloads the required fonts directly from Google servers, transmitting your IP address to Google. For more information, see Google's Privacy Policy.
6. Google Sign-In
We allow you to register or sign in to letsg.ro using your Google account ("Google Sign-In" / "Sign in with Google"). The provider is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), and for users outside the EEA, Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Data Processed
When you click "Sign in with Google," Google transmits an OpenID Connect ID token to our server. From this token, we process and store the following data in our database:
- Google account ID (unique identifier, "sub" claim) — to link login sessions to your letsg.ro account
- Email address (scope
https://www.googleapis.com/auth/userinfo.email) — as username and for account communication (verification, password reset, service emails) - First and last name (scope
https://www.googleapis.com/auth/userinfo.profile) — for personal salutation in the training app and emails - Profile picture URL (scope
userinfo.profile) — display in your profile (optional, can be removed at any time) - Language preference (locale) (scope
userinfo.profile) — for automatic UI language selection (German or English) - Email verification status ("email_verified" claim from the ID token) — to avoid duplicate email verification when Google has already confirmed your address
We do not access your Gmail content, contacts, calendar, Google Drive files, YouTube data, photos, or any other Google services. No OAuth access tokens or refresh tokens are stored on our servers. After the Google ID token has been verified, it is discarded and not retained further.
Purpose and Legal Basis
Processing is carried out to provide the login service and fulfill the contract (use of the training app with an account, storage of your training progress). The legal basis is Art. 6(1)(b) GDPR (contract performance) and your explicit consent under Art. 6(1)(a) GDPR when selecting "Sign in with Google" and confirming the Google consent screen.
Data Transfer to the USA
When using Google Sign-In, data is transmitted to Google and may also be transferred to the USA. Google LLC is certified under the EU–US Data Privacy Framework. EU Standard Contractual Clauses additionally apply. For more information, see Google's Privacy Policy and safety.google/security.
Storage Duration
Data obtained via Google Sign-In is stored for as long as your letsg.ro account exists. When you delete your account, all associated data (including Google account ID, training sessions, streak statistics) is fully deleted from our MariaDB database within 30 days.
Disconnect / Delete Account
You can disconnect from your Google account at any time:
- In your letsg.ro profile under "Settings" → "Disconnect Google account" (after disconnecting, you can continue to sign in with your email and a password you set)
- Remove third-party access in your Google account at myaccount.google.com/permissions
- Full deletion of your letsg.ro account by emailing support@letsg.ro
Limited Use Disclosure
letsg.ro's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the data exclusively for the purposes described in this Privacy Policy and do not share it with third parties except where necessary to provide the service.
7. Payment Processing (Stripe)
For paid subscriptions we use the payment provider Stripe. The EEA entity is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA is also involved in the technical processing.
Data Processed
When you take out a subscription you are forwarded to a checkout page hosted by Stripe, where you enter your payment details directly with Stripe.
- At Stripe: payment method data (e.g. card number, expiry, security code, or the data held by your wallet provider), billing data, amount, currency, time, IP address, browser and device data, plus the characteristics Stripe collects for fraud prevention.
- At our end: your Stripe customer ID, the subscription ID, the subscription status, the plan chosen, the end of the current term, and whether a cancellation is pending for the end of the term. We also store the time at which you consented to the service starting early.
Card details never reach our servers. We see neither the full card number nor the security code.
Purpose and Legal Basis
Processing serves the performance of the subscription contract, invoicing, and compliance with our commercial and tax obligations. The legal bases are Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (legitimate interest in secure, fraud-free payment processing).
Data Transfer to the USA
Stripe, Inc. is certified under the EU-US Data Privacy Framework. In addition, Stripe has entered into EU Standard Contractual Clauses. Details of Stripe's processing are set out in the Stripe Privacy Policy.
Storage Duration
We delete the subscription data held by us once it is no longer needed for the contract. Invoice-related data is retained for ten years under § 147 German Fiscal Code and § 257 German Commercial Code; during that time it is blocked from further use. How long Stripe stores the data it collects is governed by Stripe's privacy policy.
8. Abuse Detection for the Free Trial
The free week is available once per person and deliberately requires no payment details. So that it cannot be claimed repeatedly through ever-new accounts, we check when a trial is started whether the same person has already had one. This check happens at that single moment only — not while browsing, not while training, not when logging in.
Characteristics Processed
- Device characteristics: the result of a canvas and WebGL test rendering, the system fonts available on your device, screen resolution and colour depth, time zone, language settings, number of processor cores, approximate memory, touch capability, platform and browser identifier (user agent)
- IP address of the requesting connection
- First name, last name and year of birth from your profile
- E-mail address in normalised form (for Gmail addresses without dots and without a "+" suffix)
Only Hashes Are Stored
None of these characteristics is stored in the clear. Before storage, every value is turned into an HMAC-SHA-256 hash using a secret server-side key, and only that hash is kept. It answers the question "have I seen this value before?" — it does not allow your IP address, your name or your device to be reconstructed from it. No cross-device tracking profile is created and there is no link to your browsing behaviour.
How the Decision Is Made
A device or an e-mail address that is already known leads to refusal on its own. A name that is already known leads to refusal only if the same IP address or the same browser is also recognised — people who share a name should not be shut out. An IP address alone never leads to refusal; it merely limits the number of trials from one network to three within 60 days, so that households, offices and mobile networks remain usable.
Purpose, Legal Basis and Objection
The purpose is to prevent a one-time free benefit from being claimed repeatedly. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in being able to offer a paid product viably without demanding payment details from everyone who wants to look at it first. Since only hashes are stored, the check happens once when the trial starts, and a refusal blocks no account but merely withholds a voluntary free benefit, we consider that your interests do not override ours. You may object under Art. 21 GDPR; in that case we cannot grant the free trial, while paid access remains fully available.
The decision is automated but has no legal effect and does not similarly significantly affect you within the meaning of Art. 22 GDPR — it concerns a voluntary free benefit only. Independently of that, we review any refusal by hand on request: an informal message to support@letsg.ro is enough.
Storage Duration
We delete the hashes 24 months after the start of the respective trial, and at the latest when your account is deleted.
9. Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): Right to information about stored data
- Rectification (Art. 16 GDPR): Right to correction of inaccurate data
- Erasure (Art. 17 GDPR): Right to deletion of your data
- Restriction (Art. 18 GDPR): Right to restrict processing
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR): Right to object to processing
To exercise these rights, contact us at: support@letsg.ro
You also have the right to lodge a complaint with a data protection supervisory authority.
10. Data Security
We employ technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, or unauthorized access. Data transmission between your browser and our server is encrypted via HTTPS. Passwords are stored exclusively as bcrypt hashes; Google ID tokens are discarded after verification.
11. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy as needed. The current version is always available at letsg.ro/en/privacy.