Privacy Policy
Last updated: 16 September 2026
1. Controller
The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
StagWorks Maximilian Rosnauer und Benjamin Seeger GbR Beinsteinerstraße 40 71394 Kernen im Remstal Germany
- Email: info@stagworks.de
- Phone: +49 174 7696867
Use this address for any privacy matter and to exercise your rights. We are not legally required to appoint a data protection officer.
This privacy policy applies to the RenoStack app (iOS, Android) and to the RenoStack web application at renostack.stagworks.de. Both use the same account and the same project data.
2. What data we process
Account data. When you register we process your name, your email address and an encrypted credential. If you sign in with "Sign in with Apple" or "Google Sign-In", we receive a user identifier, the email address you released and, where available, your display name.
Guest mode. You can try the app without an account. In that case we only create an anonymous technical identifier; your project data stays on your device only and is not transferred to the cloud.
Project data. Projects, budgets, contractors, quotes, phases, tasks, appointments, diary entries, planned costs and expenses you record in the app — including amounts and the cost split between project members.
Receipts and attachments. Photos and documents you attach to expenses, quotes or as project documents are stored on your device. With RenoStack Pro, these are additionally uploaded to Firebase Cloud Storage (Google) so they are available across all your devices and in the web application, and can be shared with project partners. We store the file itself plus its name, size, type, category, upload time and project assignment. Attachments are stored per project and are only accessible to members of that project. As a free user, your own attachments remain local on your device; you can still view documents uploaded by Pro members of a shared project. If your Pro access lapses, attachments already uploaded are retained and remain accessible.
Invitations. When you share a project we generate an invite link containing a random token. For this we store the project name, your user identifier and — once accepted — the user identifier of the invited person. Invitations expire automatically after 14 days.
Purchase data (RenoStack Pro). When you buy RenoStack Pro in the App Store, on Google Play or in the web application, we process through RevenueCat your user identifier, email address, display name, the product purchased (monthly, annual or lifetime), the start, expiry, renewal and cancellation status of the subscription, and a pseudonymous transaction identifier assigned by the store or by Stripe. We never receive payment details (card or bank data); they remain with Apple, Google or our payment provider Stripe. For a purchase in the web application, Stripe additionally processes your billing details (name, email address, country and, where applicable, billing address and VAT ID) for payment processing, fraud prevention and invoicing. The resulting Pro status (yes/no, expiry date) is stored in your user profile.
Technical data. Crash reports and usage statistics — but only if you have explicitly consented (see section 5).
3. Storage on the device and in the cloud
Your project data is stored on your device and also synced to our cloud database (Google Cloud Firestore). This is required so your data is available across devices and in the web application, and so you can share a project with a partner.
Sharing a project makes that project's data visible to everyone you invite — they see the budgets, costs, expenses, documents and the names of the other members of the shared project.
Your Pro status is written to your user profile server-side by a Cloud Function (Google Cloud Functions) whenever RevenueCat notifies us of a purchase, renewal or expiry.
We do not sell your data and do not share it for advertising.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
4. Device access
Camera and photo library. Only when you photograph a receipt or pick an image. The capture stays on your device; with RenoStack Pro it is additionally uploaded to the cloud (see section 2).
Files. Only when you attach a document (e.g. a PDF) via your device's file picker.
Calendar. Only when you add an appointment to your calendar. The app opens your device's calendar app for this; we do not read your calendar ourselves.
Notifications. The app reminds you of appointments and deadlines through local notifications scheduled directly on your device. No push token is transmitted to us or to any third party. You can withdraw the permission at any time in your system settings.
Rating prompt. After a few successful actions the app may ask you for a rating via Apple's or Google's system dialog. Whether and when it appears is controlled by the operating system; we receive no personal data from it.
Legal basis: consent and performance of a contract (Art. 6(1)(a) and (b) GDPR).
5. Crash reports and analytics (consent only)
Firebase Crashlytics and Firebase Analytics help us find crashes and understand which features are used. Both run only with your explicit consent, which we ask for on first launch. You can withdraw it at any time in your profile under Privacy; the withdrawal takes effect from the moment you change the setting.
In the web application, Firebase Analytics likewise runs only with your consent, which we ask for via a notice on your first visit. Without consent the analytics script is not loaded at all. Your decision is stored locally in your browser and can be changed at any time in your profile under Privacy. Crashlytics is not used in the web application.
Legal basis: consent (Art. 6(1)(a) GDPR).
6. Processors and third parties
- Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Firebase Crashlytics, Firebase Analytics — Google LLC / Google Ireland Ltd.
- RevenueCat, Inc. — managing purchase entitlements for RenoStack Pro (app and web).
- Apple Inc. / Google LLC — sign-in via "Sign in with Apple" and "Google Sign-In", and processing of purchases through the App Store or Google Play.
- Stripe Payments Europe Ltd. (Ireland) / Stripe, Inc. (USA) — payment processing when you buy RenoStack Pro in the web application. Stripe is an independent controller for the payment itself; see Stripe's privacy policy.
- Oracle Cloud Infrastructure (Oracle Corporation) — hosting of the web application. Server logs (IP address, timestamp, page requested, browser type) are generated on access and deleted after no more than 7 days.
- Google reCAPTCHA Enterprise — abuse protection (Firebase App Check) in the web application. Your IP address and browser characteristics are transmitted to Google for this.
We have data processing agreements pursuant to Art. 28 GDPR with these providers. Data may be transferred to the US; the providers are covered by Standard Contractual Clauses or an equivalent level of protection (EU-US Data Privacy Framework).
Legal basis for hosting and abuse protection: legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
7. Retention and deletion
We store your account and project data for as long as your account exists. Delete account in your profile permanently removes your account, your user profile, your projects, invitations and attachments stored in the cloud. Individual cloud attachments are deleted as soon as you delete them, the associated entry or the project. For projects you own and share with others, you can hand them over to another member or delete them for everyone. Data and attachments stored locally are removed by signing out or uninstalling the app. Purchase records held by RevenueCat and the stores are subject to their retention periods. Statutory retention obligations remain unaffected.
Export data in your profile lets you download your project data as a JSON file at any time.
8. Your rights
You have the following rights towards us:
- Access to the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on a legitimate interest (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
Simply contact info@stagworks.de.
9. Full version
The current version of this privacy policy is also available at stagworks.de/privacy.