This English version is provided for convenience. The legally binding version is the German original.

Legal

Privacy Policy

Information pursuant to Art. 13 and 14 GDPR (General Data Protection Regulation) on the processing of personal data in Floatly.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Floatly UG (haftungsbeschränkt)
represented by its managing director Philipp Poppe
Ulmenweg 44, 46397 Bocholt, Germany
Phone: 02871 48 98 421
Data protection email: datenschutz@6p-marketing.de

A data protection officer is not legally required. If you have any questions about the processing, contact us directly at the email address provided above.

2. What Floatly is and the role we take on

Floatly is a booking and ticketing platform for water parks. We broker bookings between guests and the respective park operators („Operator“) and provide the technical infrastructure required for this.

Floatly is the controller under data protection law for providing and securely operating the platform. The respective park operator is jointly responsible with us, pursuant to Art. 26 GDPR, for the operational processing of booking and guest data (e.g. check-in, communication on the event day).

3. Which data is processed

We process only data that is necessary for booking and carrying out your session as well as for operating the platform.

3.1 Booking data

  • Name, email, optionally phone number
  • Park, date, time, number and type of tickets, booking reference (QR token)
  • Check-in time (as soon as you are scanned at the entrance)
  • Booking status (booked, paid, cancelled, checked in)

3.2 Payment data

Payment is processed exclusively via Stripe (see Section 4). Floatly does not store any card data or bank account details. From Stripe we receive only a transaction reference and the status of the payment.

3.3 Operator data

Park operators who use Floatly enter their name, email and (via Stripe) their business and identity data. This data is processed to operate the operator account and for payouts.

3.4 Server log data

When our pages are accessed, technically necessary data (anonymised IP address, timestamp, page accessed, user agent) is processed by our hosting provider. This data serves exclusively the security and stability of the platform.

4. Legal bases and purposes

  • Art. 6 (1) (b) GDPR (performance of a contract) for booking, payment, e-ticket delivery, check-in, rebooking and cancellation.
  • Art. 6 (1) (c) GDPR (legal obligation) for statutory retention periods (HGB, AO – German Commercial Code and Fiscal Code).
  • Art. 6 (1) (f) GDPR (legitimate interest) for platform security, abuse prevention, server logs.

5. Recipients and processors

We use carefully selected service providers. Data processing or brokerage agreements (AVV) pursuant to Art. 28 GDPR are in place with all processors. Transfers to third countries take place on the basis of Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework (DPF). An always up-to-date list of subprocessors with purpose, storage region and transfer basis is available at floatly.app/subprocessors.

  • Stripe (payment processing) – Stripe Payments Europe Ltd., Ireland. Processes card and SEPA payments and pays amounts out directly to the respective park operator. stripe.com/de/privacy
  • Supabase (database, authentication, data storage) – Supabase Inc., USA. Data is stored in the EU region (Ireland, eu-west-1). supabase.com/privacy
  • Resend (transactional emails such as booking and cancellation confirmations) – Resend, Inc., USA. resend.com/legal/privacy-policy
  • Vercel (hosting, CDN, edge delivery) – Vercel, Inc., USA. Server-side processing takes place in the EU (Dublin, eu-west-1); delivery via EU edge locations. vercel.com/legal/privacy-policy
  • Park operator of your booked session receives your name, booking details and check-in status in order to be able to carry out your session.

6. Storage period

  • Booking data: until the end of the statutory retention periods (generally 10 years after completion of the booking pursuant to § 147 AO, § 257 HGB – German Fiscal Code and Commercial Code).
  • Server logs: 30 days, then deleted or fully anonymised.
  • Operator accounts: for as long as the operator relationship exists, thereafter in accordance with statutory retention.

7. Your rights

You have the right at any time to:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data, insofar as no statutory retention obligations stand in the way (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR)
  • Complaint to a supervisory authority, e.g. the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Art. 77 GDPR)

To exercise your rights, an informal message to datenschutz@6p-marketing.de is sufficient.

8. Children and minors

Floatly does not knowingly collect personal data directly from children. Where a booking includes minors, the data about the minor (name and, if the park enabled it, a health declaration) is entered and consented to by the booking adult or legal guardian, not by the child. We do not knowingly collect data directly from children under 13 (United States) or under 14 (Quebec). If you believe a child provided us data directly, contact datenschutz@6p-marketing.de and we will delete it.

9. United States and Canada residents

We do not sell or share your personal information and have not done so in the preceding 12 months. We do not use it for cross-context behavioural advertising. Health declarations, where collected, are treated as sensitive personal information.

Your rights. Depending on your state or province, you may request access to, correction of, or deletion of your personal information, and confirmation of how it is processed. To exercise any of these, email datenschutz@6p-marketing.de. We honour browser opt-out signals (Global Privacy Control). We will not discriminate against you for exercising a right.

Cross-border processing. Floatly is operated from Germany; your data is stored in the EU (Ireland) and processed by providers in the EU and the United States (see Section 5). For US and Canadian users this means your personal data is processed outside your home country, under the safeguards described above.

Complaints.US residents may contact their state Attorney General. Canadian residents may contact the Office of the Privacy Commissioner of Canada, or their provincial authority (e.g. the Commission d’accès à l’information du Québec, or the BC / Alberta Information and Privacy Commissioners).

Privacy contact: Philipp Poppe, Floatly UG (haftungsbeschränkt), datenschutz@6p-marketing.de.

10. Cookies and local storage

Floatly uses only technically necessary cookies and comparable storage mechanisms (e.g. localStorage) that are required for the operation of the login, the booking flow and the check-in scanner. No tracking, analytics or advertising cookies are used beyond this.

11. Data security

Transmission is encrypted throughout (TLS / HTTPS). Database access is secured by Row-Level Security and server-side write operations take place exclusively via authenticated and signature-verified calls.

12. Changes to this privacy policy

We adapt this privacy policy when processing activities or the legal situation change. The respective current version is always available on this page.

Last updated: July 31, 2026