Legal
Privacy
Ubivo keeps your data in Switzerland, collects only what is absolutely necessary and hands nothing to advertising networks. This page explains in detail what we store, when and why.
This statement was written by Marco personally, without legal review. Its contents are factually correct and aligned to the best of our knowledge with Swiss data protection law (revDSG). In case of discrepancies, the German version prevails.
Controller
Ubivo (sole proprietorship Marco Scherer) · Switzerland · Contact for data protection requests: hallo@ubivo.ch
Full provider details in the imprint.
What data Ubivo stores
- When you visit anonymously: nothing personal. Address searches are not linked to you, there are no tracking cookies and no analytics scripts. We keep your IP only transiently in memory for the rate limit against bot sweeps (max. 30 reports/h) — not in a database, not linked to your account. The entry is removed automatically once the time window (up to 1 hour) elapses.
- When you log in: your email address — solely for sending the magic link and recognising your account. No further login identifiers (we do not store passwords).
- When you save profiles: a name you choose yourself + the factor weightings you selected for your life situation. Optionally profile fields such as income, household, age, health-insurance deductible — only if you enter them yourself.
- When you bookmark an address (☆ Save): the address + coordinates are linked to your account — the point of the saved list. Removable again at any time.
- When you buy (Quick Check or Dossier): your user ID, starting address, product tier (Quick Check or Dossier), purchase status, Stripe session ID as well as the project name you choose. We do not see any credit card data — the payment provider Stripe handles the payment.
- Within a search project: the addresses you add as comparison alternatives to your starting address (max. 1 or 5 depending on tier). Addresses can be removed at any time. We store how many swap actions you have already performed, in order to enforce the contractually agreed swap allowance (max. 2 or 12).
- NOT stored: no browsing history beyond the anonymous funnel statistics described below, no user-agent profiles tied to an account, no server logs linked to your account.
Anonymous usage statistics (funnel telemetry)
To understand which parts of Ubivo lead visitors to a personalised purchase — and which do not — we measure five steps of your visit anonymously: report viewed → pricing viewed → compare viewed → Stripe checkout started → purchase completed.
- Identification: a pseudonymous identifier, computed as a SHA256 hash of your IP address, a coarse browser category and the calendar day. We set no cookie and store none of these details in plain text. Because the calendar day is part of it, the identifier changes daily — we do not recognise you again across days. No cross-site tracking, no linkage with advertising networks.
- A/B tests: we occasionally test two text variants against each other (e.g. a choice of wording on the factor cards) and measure, using the funnel steps above, which is more helpful. The assignment uses the same pseudonymous IP + browser hash — here without the calendar day, so that you see the same variant within an experiment. This too is cookie-free and involves no personal storage.
- Logged-in users: if you are signed in, the event is linked to your account ID so that we can show you your purchase and usage history in your account. Through account deletion (Art. 32 DSG) you can have your account data removed at any time.
- What is stored: the five steps above + for purchases the product (tenant/buyer). Addresses are hashed before storage (SHA256, only the first 16 hex characters) — we can evaluate funnel trends but cannot reconstruct which addresses you actually viewed. In addition the coarse source of the visit (only the host name of the referring page, e.g. a search engine — not the full URL), to understand how visitors find their way to Ubivo.
- What is NOT stored: no mouse behaviour, no scroll depth, no dwell time, no precise device data. UA classification only as a coarse category (desktop/mobile/bot/unknown) for bot filtering.
- Retention: 90 days. After that the raw events are deleted; aggregated daily totals may be kept longer, but contain nothing identifying.
- Legal basis: legitimate interest in product improvement under DSG Art. 31 para. 2 lit. c — without a way to measure, we could not decide which parts of Ubivo bring value to buyers.
- Objection: the identifier is computed pseudonymously from IP + browser (no cookie) and therefore cannot be switched off by clearing cookies. The raw events are deleted after 90 days and contain nothing that points directly to your person. To object under Art. 30 DSG or for questions about processing, reach us at hallo@ubivo.ch.
Where the data resides
All user data resides in a PostgreSQL instance at the provider HostBott (Blumenweg 8, 7204 Untervaz GR); the servers stand in Swiss data centres. No US cloud, no third country for storage. Data transit to the recipients named below is encrypted (TLS).
To whom data is passed on
Ubivo shares data with third-party providers only where it is technically necessary — and each time limited to the minimum:
- Stripe (payment provider): for purchases of Quick Check and Dossier. Data: your user ID, the purchase address, product choice, your amount. We see no credit card data; Stripe is an independently responsible payment processor with its own privacy policy (stripe.com/ch/privacy).
- Resend (email delivery): for magic-link login and transactional emails (purchase confirmation). Data: your email address + mail content. Details at resend.com/legal.
- swisstopo, BAFU, BFS, ARE, MeteoSchweiz, ESTV and other official CH bodies: geo and statistical data are retrieved publicly by us — these bodies receive NO data about you (requests come from Ubivo servers). For municipal queries, the server IP may go to the respective WMS server, without any link to the user.
- Open-Meteo + Copernicus CAMS: weather and air data are retrieved server-side — no link to the user.
- swisstopo WMTS tile service: when you open the marker picker for new-build addresses, your browser loads swisstopo map tiles directly (standard WMTS protocol). swisstopo thereby sees your IP address and the requested tile coordinates — equivalent to when you visit map.geo.admin.ch. We pass nothing on and store nothing about it.
- Otherwise NOBODY. We do not sell data, we do not give it to advertising networks or data brokers, we do not share it with authorities without a court order.
How long data is stored
- Account data remains until you delete the account. Deletion flow in the account area — one click, immediate deletion of all account-related data.
- Saved addresses / profiles remain until you remove them yourself or delete the account.
- Purchase receipts we keep for tax and accounting reasons for 10 years (statutory retention obligation). These receipts contain user ID, address, amount, date — no factor values.
- IP for the rate limit is kept only transiently in memory (no persistent storage) and removed once the time window (up to 1 hour) elapses, never linked to an account.
- Anonymous funnel statisticsare stored for 90 days (see section "Anonymous usage statistics" above). Aggregated daily totals longer.
Your rights
Under revDSG (Swiss Data Protection Act, Art. 25 ff.) you have the following rights:
- Access (Art. 25): everything we have stored about you, you can download at any time as a JSON file · /api/me/export.
- Rectification: correcting wrong data — most fields you can change yourself in the account area, otherwise email hallo@ubivo.ch.
- Erasure: delete account + all linked data via /account/delete (immediate, no waiting period).
- Data portability: the JSON export linked above is machine-readable — you can take it anywhere.
- Withdrawal of consent: possible at any time, without giving reasons. The withdrawal takes effect for the future.
- Right to complain to the EDÖB (Swiss FDPIC): in case of grievances you can turn to the Federal Data Protection and Information Commissioner.
Cookies
Ubivo sets exactly one technically necessary cookie:
- Session cookie after login (HttpOnly, SameSite=Lax, Secure) — links your session to your account. Required for logged-in features. It is the only cookie we actively set.
- Funnel telemetry:the chaining of your five session steps (see section "Anonymous usage statistics") runs cookie-free via a computed pseudonymous identifier (IP + coarse browser category + calendar day). A cookie
ubivo_telemetry_sid(HttpOnly, SameSite=Lax) is technically only read, if one already exists — it is currently not actively set. Cross-site tracking does not take place.
No advertising cookie, no third-party tracking, no analytics from Google/Meta/Adobe. For this reason there is no cookie banner — the only actively set cookie is the login session cookie (technically necessary); the funnel telemetry works entirely without a set cookie and is covered by our legitimate product-improvement interests under DSG Art. 31.
Security
HTTPS enforced (HSTS), restrictive CSP headers, no third-party JS scripts. The particularly sensitive details of your personalisation profile — income, health-insurance deductible and place-of-work address — are additionally field-encrypted at rest (pgcrypto/pgp_sym, key kept separate from the database). Report security bugs to security@ubivo.ch — responsible disclosure welcome.
Changes
We update this page when substantial processing purposes change. For material changes we inform logged-in users by email. Version of this document: 2026-06-14.
Questions about privacy: hallo@ubivo.ch