peil.nu / en / privacy

Privacy at PEIL

PEIL is designed privacy-first. We collect only what is needed for a feature you use yourself and explain that limit per feature. Below, per surface: which data, on which legal basis, for how long, and who processes it on our behalf.

last revised: 19-08-2026

Who is responsible

The controller is iBridge, the company of Max Hermans, trading as PEIL, registered with the Chamber of Commerce (KvK) under number 75968851. Contact for privacy questions: info@peil.nu. The full particulars are in the colophon. PEIL has no data protection officer: PEIL is not a public authority and its core activities are not large-scale systematic monitoring or large-scale processing of special-category personal data.

What applies today

  • Your GPS location is used locally and stays on your device, unless you enable Friends yourself: we then temporarily share your name and latest position with your invite group.
  • Recorded trips and saved places are stored locally on your device.
  • There are no advertising trackers and no personal advertising profile is built.
  • PEIL Amsterdam is a closed beta. The optional account feature and payments are not active yet.
  • We do not sell your data and do not use it for profiling or automated decisions.

Cookies

Short and complete: we set no cookies on peil.nu and peilje.nl, and there is no other counter or measurement script on these sites either. That is why you see no consent banner here: there is nothing to ask consent for.

The checks on peilje.nl also keep nothing else in your browser: no cookie, no localStorage, no session storage. What you type is there while the page is open and gone the moment you close it. The PEIL Amsterdam app keeps local app data; the champagne shop keeps only product id and quantity for your basket in localStorage. Both are described below.

If the account feature on account.peil.nu opens later, it will set one necessary session cookie to keep you signed in; it is not there today, because that feature is not active.

Per surface: which data, why, for how long

the app PEIL Amsterdam

trips, saved places and settings stay on your device; your location does too, except when you switch on Friends yourself, when name and latest position temporarily go to the same invitation group

local path: no server processing; erase in the app or by removing it · access: necessary peil_beta cookie for up to 90 days; local recovery copy of the invitation token until overwritten or browser data is erased; the token contains no location · Friends path: legal basis consent, purpose temporarily finding one another on the map, recipients the same invite group; name and latest position expire after 15 minutes; when the server is reachable, switching Friends off deletes the position immediately, otherwise it expires within 15 minutes

Ask about this point in PEIL Amsterdam

after you send, your question, at most five earlier conversation turns and the source pack for the selected place travel through PEIL to Anthropic; location and boating history are not included

legal basis: carrying out what you ask yourself · purpose: produce an answer · retention: PEIL does not retain the conversation; Anthropic up to 30 days by default, with longer exceptions for abuse investigations or law

entering an address on peilje.nl

what you type goes straight to the PDOK address search (Kadaster); the page then fetches one file for the neighbourhood that address is in

legal basis: carrying out what you ask yourself · retention: none, we store your address nowhere · limit: peilje.nl thereby learns which neighbourhood was requested, not which address

the energy figures on peilje.nl

the page requests current price and generation figures from our own service; no address travels with it

legal basis: legitimate interest (the page has to work) · retention: technical logs at Cloudflare, short

the basket in the champagne shop

only product id and quantity are stored locally in your browser; the basket is not sent to a server before you continue to Stripe checkout

legal basis: local storage needed for the basket you fill yourself · retention: until you empty the basket or erase your browser data

ordering a bottle

Stripe processes your name, e-mail, phone, delivery address and payment details; the PEIL database keeps order number, bottle and quantity, and Max receives an order e-mail with name, e-mail, phone and delivery address through Resend

legal basis: performance of the purchase contract · retention: at PEIL and Resend for as long as statutory record-keeping and warranty duties run; at Stripe according to Stripe's legal and regulatory retention criteria

withdrawing from an order

your e-mail address, the order number and your explanation

legal basis: legal obligation (we must confirm your withdrawal and refund you) · retention: until the refund is done and the record-keeping duty has expired

buying a paid document

not active yet

once this opens, this row states what is kept; the design is that the report table keeps only a payment session, without a name, e-mail address or address, while Stripe processes checkout and payment details under its own retention policy

e-mail contact and interest in a beta or check

your e-mail address, subject and message; used to answer or to send the one message you request when a beta or check opens

legal basis: your request and consent through the e-mail button · retention: the mailbox has no automatic expiry; we manually delete the message after answering or sending the requested launch notice, unless a legal duty or dispute requires longer retention

a PEIL account

not active yet

legal basis then: performance of the agreement you enter into yourself, plus separate consent per kind of data you let it synchronise · retention: until you delete the account

security

technical hosting logs briefly hold your IP address and browser type

legal basis: legitimate interest (preventing abuse) · retention: short, and we link them to nobody

What PEIL does not process on a server: trips, routes, usage statistics tied to a person, and data about health, religion, politics or anything else in the special categories. Only when you enable Friends yourself do we temporarily share your name and latest GPS position with your invite group.

Optional PEIL account and Google sign-in

An optional PEIL account is being prepared. If you later choose "Continue with Google" yourself, PEIL receives only your Google account ID, name, e-mail address and the profile information needed to sign you in. PEIL asks no access to Gmail, your messages, contacts, Drive or calendar.

Google sign-in uses only the standard openid, email and profile scopes. Anonymous use remains possible. Google itself is responsible for what it does with your Google account in that sign-in step; we are responsible for what we keep afterwards.

Champagne orders and withdrawal

If you order a bottle on peil.nu/champagne, payment goes through Stripe. Stripe processes your name, e-mail address, phone, delivery address and payment details. PEIL does not process your full card or bank credentials itself; PEIL does receive payment status and the data needed for the order and its records. The PEIL database keeps only the order number, bottle and quantity for stock and to prevent duplicate processing. For delivery, Max receives an order e-mail with your name, e-mail address, phone and delivery address through mail processor Resend; Max keeps that mail while delivery, warranty and record-keeping duties require it.

If you use the withdrawal button, PEIL keeps your e-mail address, the order number you give and your optional explanation. That is not a choice: the law obliges us to confirm your withdrawal on a durable medium and to refund the money, and for that we need an address. We keep this as long as the refund and our record-keeping duty require, and use it for nothing else.

At handover we check your age against an identity document. We make no copy of it and record nothing; we only establish on the spot that you are 18 or older.

Recipients and service providers: role and location

Cloudflare

hosting of the sites and of our own service; the database for a future account

where: the network is worldwide; a future account database is demonstrably in the EU only after deployment creates it with EU jurisdiction and verifies that setting · paperwork: Cloudflare's data processing agreement and transfer mechanisms

Stripe

payments; Stripe is a processor when it facilitates a payment on our instructions and a controller for its own fraud, legal and service purposes

where: Stripe processes worldwide, with a parent company in the United States · transfer basis: under the Stripe Data Transfer Addendum, first the EU-US Data Privacy Framework and standard contractual clauses where needed

Resend

sends the e-mails belonging to an order; account e-mails are not active yet

where: sending runs from Ireland (eu-west-1), but Resend stores account data, e-mail metadata, logs and API records in the United States · transfer basis: standard contractual clauses in the Resend DPA

Anthropic

only after your question, produces the answer for Ask about this point; does not use this commercial API input for model training

where: storage in the United States and possible processing in the United States, Europe, Asia and Australia · retention: up to 30 days by default, with exceptions for abuse investigations or law · transfer basis: DPA with EU standard contractual clauses

Vimexx

hosting of the app beta; no account data lives here

where: the Netherlands · paperwork: hosting terms; the access logs hold IP addresses

Google

signing in with a Google account, if you choose to yourself

role: Google is not our processor here but a controller itself · limit: we see only the four items above

For transfers outside the EU, these parties use the transfer basis in their current terms: Stripe the EU-US Data Privacy Framework and standard contractual clauses where needed; Resend and Anthropic standard contractual clauses. If this list or basis changes, this page changes with it.

Your rights

You may see what we hold about you, have it corrected, have it erased, have processing restricted, receive your data in a usable file, and object to processing based on legitimate interest. Today that is almost always a short answer, because for most visitors we hold nothing.

Send your request to info@peil.nu. We respond within one month. For a complex request or many requests this may be extended by up to two months; you will be told within the first month. Once the account feature opens, you can view, export and erase yourself in your account.

If you disagree with what we do, you may complain to the supervisory authority: the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) in The Hague, autoriteitpersoonsgegevens.nl. We would rather hear it first ourselves, but that route is always open and you do not need our permission.

If something goes wrong

If a data breach is reportable, we report it to the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours after becoming aware of it. If it is likely to result in a high risk to you, we also inform you without undue delay. The future account service will open only after its backup and erasure procedure is executable and tested; this site does not promise a procedure that is not running today.

PEIL is an independent beta and not an official body or an official navigation aid.