Privacy Policy
This privacy policy explains what personal data we process when you visit www.yeapea.com and the rights you have.
This is a single-page personal and marketing website. Browsing it is fully anonymous: there is no account, no login, and no web forms of any kind. We process personal data only as far as necessary to deliver and secure this website and to measure usage in a privacy-preserving way.
Controller
Andreas Wieser
℅ ElementarySupplies UG (haftungsbeschränkt)
Ringbahnstr. 42, 12099 Berlin, Germany
Email: hello@yeapea.com
We have not appointed a data protection officer, as we are not legally required to do so. For any privacy matter, please contact us at hello@yeapea.com.
Overview of Data Processing
This is a single-page marketing website. Browsing it is anonymous — you do not need an account, there is no login, and there are no forms to fill in. We do not actively collect personal data from you. The only data processing that occurs is what is technically necessary to deliver and secure the website (handled by our host and by Cloudflare), to measure usage in an aggregated, privacy-preserving way (Matomo), and to detect and fix technical faults (Flare and Nightwatch).
Hosting and Server Location
This website is hosted by ElementarySupplies UG (haftungsbeschränkt), Berlin, Germany, on servers located within the European Union. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in providing a reliable, secure website).
Content Delivery and Security (Cloudflare)
We use Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) as a DNS, TLS, caching and security layer in front of our website. When you access the site, Cloudflare processes connection data such as your IP address, connection metadata and the requested URL in order to deliver content and to protect against attacks. During security events Cloudflare may set strictly necessary cookies (see our Cookie notice). Cloudflare may process data in the USA; it is certified under the EU-US Data Privacy Framework, and we additionally rely on EU Standard Contractual Clauses and a data processing agreement (Art. 28 GDPR). Legal basis: Art. 6(1)(f) GDPR.
Server Logs
Web-server access logging is disabled on this site. Only error-level diagnostic entries may be recorded briefly to detect and fix faults; these can contain an IP address. Such entries are kept only for a short period and then deleted. Legal basis: Art. 6(1)(f) GDPR.
Web Analytics (Matomo)
We measure website usage with Matomo, a self-hosted analytics tool operated by ElementarySupplies UG on servers in Germany (EU). No third-party analytics provider is involved. Our Matomo setup is privacy-preserving: it runs entirely server-side (there is no Matomo JavaScript or tracking pixel in your browser), sets no cookies, anonymizes your IP address (the last octet is removed before storage), uses no cross-site tracking, fingerprinting or device identifiers, and honors the Do-Not-Track and Global Privacy Control signals. Legal basis: Art. 6(1)(f) GDPR; no consent is required (§ 25(1) TDDDG).
To understand which parts of the interface are useful, we additionally record a small set of anonymous interaction events — for example which terminal command you run, which colour theme you choose, or that an outbound link was opened. These events are sent by a first-party request to our own server (not to any third party) and recorded by Matomo with the same safeguards: no Matomo JavaScript, no Matomo cookies, no personal data and no device identifiers, and we honor the Do-Not-Track and Global Privacy Control signals here too.
Error Monitoring (Flare)
To detect and fix technical errors, we use Flare, a server-side error-monitoring service provided by Flare App BV (Belgium, flareapp.io). When an application error occurs, Flare receives a diagnostic report that can include the requested URL, a stack trace and — incidentally — an IP address. Flare runs no code in your browser and sets no cookies. Reports are retained for a limited period (typically 30–90 days). Legal basis: Art. 6(1)(f) GDPR; a data processing agreement is in place (Art. 28 GDPR).
Application Monitoring (Nightwatch)
To keep the application healthy and to diagnose performance and reliability issues, we use Nightwatch, Laravel’s server-side application monitoring. It runs entirely server-side, runs no code in your browser and sets no cookies. The diagnostic data it processes may include the requested URL and — incidentally — an IP address, and is used only to detect and fix faults. Legal basis: Art. 6(1)(f) GDPR; a data processing agreement is in place (Art. 28 GDPR).
Cookies
We do not use cookies for tracking, advertising or analytics. Only strictly necessary cookies are set.
Our application framework sets one first-party session cookie ("yeapea-session") and one CSRF-protection token ("XSRF-TOKEN"), each with a lifetime of about 2 hours. These cookies keep the site secure and functioning; they are not used for tracking and, as there is no newsletter or form, are not tied to any sign-up.
During security events Cloudflare may additionally set strictly necessary security cookies ("__cf_bm", lasting about 30 minutes, and "cf_clearance", about 30 minutes) when verifying that a request is legitimate.
Our analytics, error-monitoring and application-monitoring tools (Matomo, Flare, Nightwatch) set no cookies at all. Strictly necessary cookies do not require consent (§ 25(2) TDDDG).
No Third-Party Content
All resources this website loads — stylesheets, scripts, fonts and images — are served from our own domain. We do not embed Google Fonts, Google Analytics, social-media widgets, advertising or retargeting pixels, third-party login, device fingerprinting or any other third-party content.
Recipients of Data
We do not sell personal data and do not share it for advertising purposes. Data is processed only by the following service providers acting on our behalf as processors, each bound by a data processing agreement (Art. 28 GDPR): our host, ElementarySupplies UG (haftungsbeschränkt), on EU servers; Cloudflare, Inc. as our DNS, TLS, caching and security layer; Flare App BV for server-side error monitoring; and Nightwatch (Laravel) for server-side application monitoring. Matomo is self-hosted by us on servers in Germany, so no third party is involved in our analytics.
Storage Duration
We keep personal data only as long as necessary for the purpose for which it was processed. Error-monitoring reports (Flare) are retained for a limited period, typically 30–90 days. Matomo statistics are stored only in aggregated, IP-anonymized form. Server-side diagnostic entries and application-monitoring data are short-lived and deleted once no longer needed to detect and fix faults. Cloudflare connection data is retained according to Cloudflare’s own short retention periods for security purposes.
Data Security
We protect this website with state-of-the-art measures, including encrypted transport via HTTPS/HSTS, serving all resources from our own domain with no third-party scripts, and regular security updates. These measures help protect your data against unauthorized access, alteration or loss.
Your Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21) to processing based on legitimate interests. To exercise your rights, contact us at hello@yeapea.com.
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection authority. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin (www.datenschutz-berlin.de).
Changes to This Privacy Policy
We may update this privacy policy to reflect changes to our website or legal requirements. The current version is always available here.