NewReynt AI: a link becomes a finished listing

Privacy Policy

Last updated: August 25, 2026

Scope: This privacy policy relates to the operator’s marketing site (https://www.reynt.co). It does not apply to tenant storefronts or the operator console — end customers and tenant staff are informed about those through separate privacy notices.

This is a courtesy translation. The German version is authoritative.

Version: 1.7 — Stand: 2026-08-25


1. Controller

The controller within the meaning of Art. 4 (7) GDPR is:

DK2 Ventures UG (haftungsbeschränkt)
Uhlbacher Str. 34
70329 Stuttgart
Germany

Email: contact@reynt.co
Data protection enquiries: datenschutz@reynt.co

2. Data protection officer

Under § 38 BDSG, a data protection officer must be appointed only from 20 persons permanently engaged in the automated processing of personal data onwards. As we do not currently reach that threshold, no data protection officer has been appointed.

Please direct data protection enquiries to datenschutz@reynt.co or by post to the address given in the imprint.

3. General information on data processing

3.1 Extent

We process our users’ personal data only to the extent necessary to provide a functioning website together with our content and services. Any processing beyond that takes place only with consent or where permitted by law.

  • Art. 6 (1) (a) GDPR — consent
  • Art. 6 (1) (b) GDPR — contract or pre-contractual measures
  • Art. 6 (1) (c) GDPR — legal obligation
  • Art. 6 (1) (f) GDPR — legitimate interests

3.3 Erasure and storage period

Personal data is erased or blocked as soon as the purpose of storage ceases to apply. Storage beyond that occurs where European or German legislation requires retention (§§ 147 AO, 257 HGB) or where it is necessary to defend legal claims.

4. Hosting and server logs

Our marketing site is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. A data processing agreement is in place with the hosting provider.

Each time the site is accessed, the following data is automatically stored in server logs:

  • IP address
  • Date and time of the request
  • HTTP method and requested path
  • HTTP status code
  • Volume of data transferred
  • Referrer (where transmitted)
  • User agent

Purpose: ensuring stable operation, preventing misuse, error analysis.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the security and functionality of the website).

Storage period: thirty (30) days; log entries are then deleted automatically and in full.

5. Cookies and similar technologies

5.1 General

On our marketing site we set no cookies and use no comparable technologies (e.g. localStorage) for analytics, marketing or recognition purposes. No information is stored on your device or read from it beyond what is strictly necessary to deliver the page you requested.

Because no consent-requiring cookies or device access take place on this site, you are not shown a cookie banner and no consent is obtained. The conditions of § 25 (1) TDDDG are not met, as no information on your device is accessed.

Should we integrate consent-requiring services in future, they will be loaded only after your express consent; we would then provide a corresponding selection tool and update this privacy policy in advance.

5.3 Reach measurement (self-hosted Umami)

To evaluate the use of our marketing site statistically we use Umami, an open-source analytics application that we operate at analytics.reynt.co on our own infrastructure — on the same Hetzner Online GmbH servers that host this site (see section 4). No external analytics provider is involved; the data collected never leaves our infrastructure.

Umami operates without cookies: no cookies are set and no information is stored on or read from your device. Consent under § 25 (1) TDDDG is therefore not required.

Only aggregated metrics are recorded (page visited, page title, referral source, screen size, browser, operating system, language setting and country of origin). Your IP address and user agent are processed only briefly in order to derive an anonymous session identifier and the characteristics listed above; they are themselves not stored. No profiles are created, no cross-site tracking takes place, no user identifiers are assigned, and no data is passed on to third parties.

Processing takes place exclusively on our servers in Germany; no transfer to third countries occurs. Because we operate the software ourselves, no further processor is involved in reach measurement; for the hosting, the data processing agreement with Hetzner referred to in section 4 applies.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in the data-minimising statistical evaluation of website use in order to improve our offering. You may object to this processing at any time under Art. 21 GDPR (contact details in section 1).

Beyond this, no consent-requiring marketing or tracking services are used — in particular no conversion tracking and no advertising pixels.

6. Contact by email or form

If you send us enquiries by email or contact form, the details you provide (name, email address, content of the message) are stored for the purpose of handling the enquiry and for any follow-up questions.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures / performance of a contract) or Art. 6 (1) (f) GDPR (legitimate interest in responding).

Storage period: data is erased once the enquiry has been dealt with conclusively and no statutory retention periods apply — typically after three years.

7. Product registration (sign-up)

Through the marketing site’s registration form you can create or request an account for the Reynt platform. The data you provide is transmitted to and processed by our platform.

Categories of data: email address, company or business name, contact person, country, selected plan and operating mode (direct or marketplace mode).

Purpose: creation and administration of the customer account, initiation and performance of the usage agreement.

Legal basis: Art. 6 (1) (b) GDPR (contract or pre-contractual measures).

Storage period: for the duration of the business relationship; erased after it ends unless statutory retention periods (§§ 147 AO, 257 HGB) apply.

8. Transactional email delivery (Brevo)

For sending transactional emails — such as the confirmation of receipt for your contact enquiry (section 6) or registration-related notifications (section 7) — we use Brevo, a service of Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany. The data required for delivery (email address, name, message content) is transmitted to Brevo for this purpose and processed exclusively on our behalf for sending the emails; it is not used for advertising purposes (e.g. newsletter marketing). A data processing agreement pursuant to Art. 28 GDPR is in place with Brevo.

Legal basis: Art. 6 (1) (b) GDPR (communication in the course of handling your enquiry or the contract) and Art. 6 (1) (f) GDPR (legitimate interest in reliable and efficient delivery of our emails).

Retention: The retention periods of the underlying processing apply (sections 6 and 7).

9. Payment processing for paid plans (Mollie)

If you subscribe to a paid Reynt plan, we process the recurring payment through Mollie, a service of Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. When you set up your payment method you are redirected to a payment page operated by Mollie; the payment details entered there (in particular card or account data) are collected and processed solely by Mollie — we neither receive nor store them at any point. What comes back to us is limited to payment references (customer, mandate and payment IDs), the payment status and the amount. Conversely, we transmit to Mollie the data required for billing (name, billing address, email address, VAT ID where applicable, amount and billing period). Mollie also processes this data as a controller in its own right, among other things to meet its own legal obligations (anti-money-laundering, financial supervision). Mollie is established in the European Union; no transfer to a third country takes place in this context.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the paid plan) and, insofar as Mollie meets its own legal obligations, Art. 6(1)(c) GDPR.

Storage period: We retain payment references and billing data for the periods required by commercial and tax law (§ 147 AO, § 257 HGB — up to ten years). The periods and details for data stored by Mollie are set out in Mollie’s privacy policy.

Note on end-customer/guest payments: Payments from your own guests do not run through us. They are made by bank transfer to your own account or that of the respective owner, in cash on arrival — or, if you set this up, through your own merchant organization at a payment service provider, which you connect within the platform. In that case the payment services contract is concluded directly between you and that provider, the money reaches only your account or the owner’s, and we transmit no more than the amount, the currency and a pseudonymous booking reference — no names, addresses, email addresses or payment credentials of your guests. For that processing you are the controller and we act as processor (§ 6(5) of the data processing agreement; see also section 13).

10. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption.

11. Social media and external content

The marketing site currently embeds no third-party content (e.g. YouTube videos, maps or social media plugins). Should such content be embedded in future, it will be loaded only after your express consent (two-click solution).

12. Rights of data subjects

You have the following rights in relation to personal data concerning you:

  • Art. 15 GDPR — access: you may request information about the personal data we process.
  • Art. 16 GDPR — rectification: you may request the correction of inaccurate data.
  • Art. 17 GDPR — erasure: you may request erasure of your data where no ground for storage remains.
  • Art. 18 GDPR — restriction of processing: you may request that processing be restricted.
  • Art. 20 GDPR — data portability: you may request that we provide your data in a structured, commonly used and machine-readable format.
  • Art. 21 GDPR — objection: you may object to processing of your data based on Art. 6 (1) (f) GDPR.
  • Art. 7 (3) GDPR — withdrawal of consent: you may withdraw consent at any time with effect for the future.
  • Art. 77 GDPR — complaint: you have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The competent authority is:

Der Landesbeauftragte für den Datenschutz und die
Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20, 70173 Stuttgart
https://www.baden-wuerttemberg.datenschutz.de

Please direct requests under these rights to datenschutz@reynt.co.

13. Note on tenant storefronts and customer portals

This privacy policy applies exclusively to the operator’s marketing site. If, as a traveller or end customer, you use the storefront of a provider that uses our platform, that provider’s privacy notice applies; that provider is the controller within the meaning of Art. 4 (7) GDPR. In that relationship we act exclusively as a processor (see the Data Processing Agreement).

14. Changes to this privacy policy

We reserve the right to adapt this privacy policy where legal or functional changes require it. The current version is always available on this page. The version date given above is authoritative.


Related documents: Imprint · DPA (for tenants) · Notice-and-Action