Your data at flatdibs

Privacy policy

Last updated: 17 August 2026

This policy explains which personal data flatdibs uses, why it is needed, where it may be processed, and the choices you have.

1. Controller and contact

flatdibs is an independent project run from Zürich, Switzerland, and is responsible for the processing described here.

Everything about your data goes to flatdibs: questions, access requests, corrections and deletion requests. Use the contact address at the bottom of this page.

2. Data we collect

  • Account data: email address, authentication identifiers, account status and security records.
  • Profile data: display name, private mobile number and, if you add them, a bio, date of birth, household size, desired move date and gross salary range.
  • Marketplace data: listing addresses and details, photos, waitlist activity, favourites, saved searches, confirmations, viewing bookings, reports and messages.
  • Rent-check and early-access data: addresses and dwelling facts, rent information, search or moving intent, email address and rough timing when you submit them.
  • Technical data: request metadata infrastructure providers may process, security and error logs, browser information, language, IP address and coarse product events.

3. Google sign-in

When you choose Continue with Google, Google provides an ID token containing basic account information such as a stable Google account identifier, email address, email-verification status, name and, if supplied, a profile image. Supabase validates the token and creates or signs in your flatdibs account.

flatdibs uses this Google data only for account access and an initial display-name suggestion. It does not request access to Gmail, Google Drive, contacts or calendar, and it does not use Google user data for advertising.

4. Why we process data

Where the GDPR applies, these purposes rely on performance of our agreement with you, legitimate interests in operating and securing the service, consent where specifically requested, and compliance with legal obligations.

  • Create and secure accounts, authenticate users and prevent abuse.
  • Operate listings, fixed-capacity unordered waitlists, chats, viewing invitations and bookings.
  • Send transactional and safety-related notifications.
  • Provide rent checks, saved searches and requested launch updates.
  • Maintain reliability, resolve reports, investigate misuse and understand aggregate product use.
  • Comply with legal duties and establish or defend legal claims.

5. Visibility to other users

Display names and content you publish are visible where the product needs them, for example in a listing, waitlist roster, viewing roster or chat. Detailed listing locations are restricted to authenticated product flows.

Your private phone number, account email, date of birth and salary range are not shown to other users unless a future screen clearly asks you to share them. A waitlist is never ranked by profile or salary data.

6. Providers and disclosures

We do not sell personal data. We may disclose data when required by law, to protect users or the service, or in a future transfer of the project under equivalent confidentiality obligations.

  • Supabase provides authentication and the application database.
  • Fly.io hosts the application; Cloudflare R2 stores and delivers listing photos.
  • Resend sends transactional email; Google provides optional sign-in.
  • PostHog EU receives coarse, cookieless product events. Autocapture, session recording and person profiles are disabled. Addresses, emails and exact rents are excluded from analytics events.
  • Sentry receives scrubbed reliability and error information. Default personal-information sending is disabled.
  • geo.admin.ch / swisstopo supports address and building lookup. CARTO and OpenStreetMap data support map display. Requests may expose an IP address and requested map or location information.

7. Processing outside Switzerland

The main application, database and EU analytics infrastructure are configured in Germany. Some providers may process data in the United States or other countries where they operate. Where required, transfers rely on an adequacy decision, recognised contractual safeguards or another lawful transfer mechanism.

8. Browser storage and analytics

flatdibs stores authentication tokens locally in your browser so you stay signed in. It may also store a random session identifier, a previously entered email for form convenience and short-lived password-recovery state. You can clear these items through your browser or by signing out.

PostHog is configured in cookieless mode and does not record sessions or build person profiles. Google may use its own browser storage when you open Google sign-in. flatdibs does not use advertising cookies.

9. Retention

We keep account and marketplace data while your account is active and the information is still needed to run the service.

When you close your account, your profile is anonymised immediately: email address, phone number, date of birth, household size, desired move date and salary range are cleared, your authentication record is deleted, your waitlist places are released and your listings are withdrawn, so nobody is left waiting on you.

Chats attached to a finished listing stay readable for 30 days and are then archived. Minimised records of a transaction can remain so other people keep a coherent history of what happened. Rent-check and early-access submissions, operational logs and analytics identifiers are kept only as long as they serve the purpose they were collected for, and are deleted or anonymised when that purpose ends. Backups are overwritten on their normal rotation.

Information is kept longer only where a legal obligation, an active dispute, a fraud investigation or a security incident requires it.

10. Your rights

Send requests to flatdibs using the contact address at the bottom of this page. We may verify that a request concerns your account before acting on it.

  • Request information about your personal data and a copy.
  • Correct inaccurate information.
  • Request deletion, restriction or object where applicable.
  • Withdraw consent for future processing where processing depends on consent.
  • Request an account export or close your account.
  • Complain to the Swiss Federal Data Protection and Information Commissioner or another competent authority.

11. Security and changes

We use access controls, private service credentials, encrypted transport, restricted photo links and privacy-focused logging. No online service can guarantee absolute security.

We will update this policy when the product, providers or legal requirements materially change. The date at the top shows the current version.