Privacy notice
This describes what this site actually does, rather than what a site of this kind usually does.
The short version
This site sets no cookies, embeds no analytics or tracking service, runs no JavaScript, loads no external fonts and has no user accounts. There is nothing to consent to, which is why there is no cookie banner.
Three things do happen: the web server writes access logs, deleted automatically after 14 days; your browser loads product photos straight from the shops; and clicks on a shop's offer are counted, without an IP address or a cookie. All three are set out below.
Controller
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:
Razvan Ginfalean
Melchiorstraße 39
81479 München
Germany
Hosting
The site runs on a server rented from Hetzner Online GmbH, which operates it on our behalf as a processor under Article 28 GDPR.
The datacentre is in Germany, so your data does not leave the European Union.
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
Content delivery network
Cloudflare, Inc. sits in front of this site as a content delivery network and as protection against overload (Free plan, "Full (strict)" mode). Every request to bikefind.de reaches one of its servers first, which terminates the TLS connection and passes the request on to our server over a second encrypted connection. In doing so it processes your IP address and the technical details of your request.
The legal basis is Article 6(1)(f) GDPR; the legitimate interest is running a site served by a single small machine without it falling over or being trivially attacked. The provider is based in the United States, so a transfer to a third country may take place; it is covered by the European Commission’s standard contractual clauses.
Cloudflare, Inc.
101 Townsend St.
CA 94107 San Francisco
USA
Server logs
The web server writes one line per request: the time, the address requested, the HTTP status code, the number of bytes sent, the browser identification (user agent), the referring page and the IP address of the requester. These files are deleted automatically after 14 days.
The IP address in the log is not yours: Cloudflare, Inc. sits in front of the site and we deliberately do not restore the original address, so what our log holds is the address of one of that provider's servers. We cannot tie a request to a connection ourselves.
The legal basis is Article 6(1)(f) GDPR; the legitimate interest is keeping the site running, finding faults and fending off attacks.
Once a day we count from the logs how often each kind of page was requested (a category page, a size page, a bike page) and whether the request came from a browser or a crawler, judging by its user agent. No figure about any one person comes out of that: the count knows no IP address, does not distinguish visitors, and is not combined with anything else.
The application itself writes no request log of its own. What it stores when you click a shop's offer is under "Links to the shops".
No cookies, no analytics service, no accounts
Nothing is stored in your browser. There is no third-party analytics tool or audience measurement, no ad network, no social media plugin, no embedded video or map, and no sign-up. Counting happens only on our own server and only in totals: page views by kind of page from the log files, and clicks on shop offers, both described above and below.
That is enforced rather than promised: the server’s Content-Security-Policy allows no scripts at all, so these pages cannot run JavaScript even if one were added by mistake. Every choice you make here, your frame size and the components you want, lives in the address bar and nowhere else.
Type is set in whatever fonts your device already has. No font is fetched from anyone else’s server.
Product photos from the shops
There is exactly one kind of request your browser makes to a third party when you open a page here: the product photo. We do not store the shops’ photos; we point at the address the shop serves them from itself.
What that means for you: the shop, or its image service, sees your IP address and your browser’s technical details when the photo loads. Your browser sends only "https://bikefind.de/" as the referrer and not the address of the page you are reading, because of the "strict-origin-when-cross-origin" referrer policy we set.
Photos may be loaded from these shops:
- BIKE24
- Bike-Discount
- Bikeinn
- Statera
- Canyon
- ROSE Bikes
- CUBE Göttingen
- fahrrad.de
- RABE Bike
- BIKER-BOARDER
- Zweirad Stadler
- Fahrrad XXL
- Lucky Bike
- Bike-Components
- Liquid-Life
- B.O.C.
- Multicycle
- bikes.de
- BikeHouse24
- Mount7
- Bike-Mailorder
- BikeExchange
Which of them it is on any given page depends on which bicycle is shown there; on an overview page it can be several. The legal basis is Article 6(1)(f) GDPR: a comparison without pictures of the products would not do the job the page exists for. What each shop does with that request is governed by its own privacy notice.
Links to the shops
Every link to a shop’s offer goes through an address on our own server (it starts with /go/), which sends you straight on to the shop’s product page with no page in between. As it does, we store one line: the time, which offer, from which kind of page, in which language, category and price band, whether the referring page was one of ours, a search engine or something else, and whether the request came from a browser or a crawler, judging by its user agent. No IP address, no cookie, no device details: the line cannot be tied to a person, and because it describes nobody it is not deleted.
Nothing is appended for the shop. The product address is exactly the one the shop publishes itself, there is no tracking parameter and, at present, no affiliate or partner link. The shop sees only "https://bikefind.de/" as the referrer, as it does for the product photo.
The legal basis is Article 6(1)(f) GDPR; the legitimate interest is knowing which offers get opened at all, so that the site can be developed further.
Once the shop’s page is open you have left this site, and the shop’s own privacy notice applies from there.
Alerts by email
On the Alerts page you can tell us which bike to watch for. It is the only place on this site where we store anything about you, and it is voluntary.
Exactly three things are stored: your email address, the search itself (kind of bike, size, budget, components) and when we last wrote to you. No IP address, no browser, no cookie, no clicks.
Your address is held encrypted in a file of its own, separate from the bicycle data, and the key is not kept where the data is. For lookups we also keep a hash of it made with that same key, so that we never have to read your address in the clear to know whether we already have it.
Nothing happens without your confirmation. After you submit, we send one email with a link, and only your click on it activates the alert. If you do not click, we delete the address by ourselves within seven days. The legal basis is your consent under Article 6(1)(a) GDPR, and you may withdraw it at any time.
Every email we send carries the link that lets you see your alerts, delete one, or delete everything including your address. There is no account and no password; that link is the only way in. We keep an alert for as long as it is running, and no longer.
To deliver the messages we use a provider, which receives your address and the text of the message:
Resend, Inc.
2261 Market Street #5039
CA 94114 San Francisco
USA
https://resend.com/legal/privacy-policy
The company is based in the United States, but the sending itself runs through its European region in Ireland, so your address and the text of the message do not leave the European Union.
There are no tracking pixels, no open tracking and no per-recipient link rewriting. We do not know whether or when you opened an email from us.
Your rights
Under the GDPR you have the right to know what personal data we process about you (Article 15), to have it corrected (Article 16) or erased (Article 17), to have processing restricted (Article 18), to receive your data in a portable form (Article 20), and to object to processing based on a legitimate interest (Article 21).
An email to the address above is enough to exercise any of them.
One practical limit, so that our answer does not come as a surprise: because there are no accounts and no identifiers stored, there is nothing in our logs we could attribute to you. An access request will therefore usually be answered with the fact that we hold no data about you.
Separately, you may lodge a complaint with a data protection supervisory authority under Article 77 GDPR. The competent one is the authority of the federal state we are based in:
Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach
https://www.lda.bayern.de/
Changes
This notice describes the site as it is today. It changes when the site changes, not on a schedule and not pre-emptively.
Last changed: 7 September 2026