Privacy Policy

Last updated: June 2026 (web analytics moved to consent-based + Klaro!)

1. Controller

The controller responsible for data processing on this website is:

Mydroponics UG (haftungsbeschränkt)

Am Amtsgraben 28

12559 Berlin, Germany

Email: info@orgo.me

Managing Director: Rob Gerrebrands

2. Overview of data processing

We take the protection of your personal data seriously. We process personal data only in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Personal data is collected on this website only to the extent technically necessary. Under no circumstances will collected data be sold to third parties.

3. Hosting

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you visit our website, Vercel automatically collects and stores technical data in server log files that your browser transmits. This includes:

  • IP address
  • Browser type and version
  • Operating system
  • Referrer URL
  • Time of the request

This data is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient provision of this website). Data transfer to the USA is covered by the EU-US Data Privacy Framework. For more information, see Vercel's Privacy Policy.

4. Waitlist signup

What data we collect

When you sign up for the orgo.me waitlist, we collect your email address, first name, and last name. Only your email address is required; providing your name is optional.

Purpose and legal basis

Your data is processed solely for the purpose of informing you about the orgo.me launch and related product updates. Your name, if provided, is used to personalize our communications. The legal basis for this processing is your consent (Art. 6(1)(a) GDPR), which you give by submitting the signup form.

Email service provider

We use Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany) to manage waitlist contacts and send emails. Brevo is an EU-based provider. Your data is stored on Brevo's servers in the EU. For more information, see Brevo's Privacy Policy.

Retention

Your data is stored for as long as you remain subscribed to our waitlist. You can unsubscribe at any time via the link in any email you receive, or by emailing unsubscribe@orgo.me. Upon unsubscribing, your data will be deleted promptly.

5. Web analytics (Matomo)

This website uses Matomo, an open-source web analytics platform. Matomo is self-hosted on our own server infrastructure in Germany (All-Inkl, Friedersdorf) at analytics.orgo.me. No data is transferred to third parties.

Consent required

Matomo only starts collecting data after you accept the consent banner shown on your first visit. Before you accept, no analytics cookies are set and no tracking requests are sent. You can withdraw your consent at any time via the "Privacy preferences" link below or in the footer.

Data collected when you consent

Matomo collects pages visited, referring website, approximate geolocation (country/region level, based on anonymized IP), browser type and version, operating system, screen resolution, and time of visit. Your IP address is anonymized by masking the last two bytes before any processing occurs. A first-party cookie (_pk_id and _pk_ses) is set on your device to recognize you as a returning visitor and to group your actions into a single visit. No personally identifiable information is stored.

Consent management (Klaro!)

The consent banner itself is rendered by Klaro!, an open-source consent management tool. Klaro! is self-hosted as part of this website's code and does not make any third-party network requests. Your decision (accepted or declined, with a timestamp and the consent version) is stored in a first-party cookie named orgo_consent on your device for 365 days. If we materially change what is tracked, we bump the consent version and the banner re-appears so you can review and decide again.

Do Not Track

Matomo respects the "Do Not Track" (DNT) setting in your browser. If you have enabled DNT, your visit will not be tracked even if you accept the consent banner.

Legal basis

The processing is based on your consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG). You can withdraw your consent at any time with effect for the future: .

Retention

Matomo visit and event data is retained for 14 months and then automatically deleted. Aggregated, non-identifying statistics may be retained longer.

6. Mobile app analytics (Matomo)

The orgo.me mobile app uses the same self-hosted Matomo instance described above (analytics.orgo.me, hosted in Friedersdorf, Germany) to understand how the app is used and to improve it. App analytics are processed as a separate measurable from the website.

Consent required

Unlike the website, the mobile app stores a pseudonymous device identifier in app storage on your phone in order to group your actions into sessions. This counts as storage on terminal equipment under § 25 TTDSG. We therefore request your prior consent before any tracking occurs. On first launch, the app shows a consent prompt with equally prominent "Accept" and "Decline" options. No tracking takes place until you accept, and no device identifier is created on your phone until you accept.

What we collect when you consent

  • Screen views (the names of screens you visit, e.g. "Feed", "Search", "Profile")
  • Event categories and actions (e.g. category "Save" with action "share_intent_received", category "Auth" with action "login_complete")
  • A randomly generated 16-character pseudonymous device identifier, stored locally on your phone (never shared with any third party)
  • Approximate locale and operating system version
  • Anonymized IP address (last two bytes masked) for visit enrichment

What we never collect

  • Saved URLs, page titles, or the content of any saved items
  • Search queries
  • Your email address or any account-identifying information from your Supabase account
  • Real names or contact details
  • Any data that could directly identify you as a person

User ID (logged-in users)

If you are logged in, we send a one-way SHA-256 hash of your Supabase user ID to Matomo so that we can recognize the same user across reinstalls and devices. The raw Supabase ID and your email address are never sent. The hash cannot be reversed to recover your identity.

Legal basis

Processing is based on your consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG). You can withdraw consent at any time with effect for the future via the in-app toggle under Profile → Anonymous usage data. When you withdraw consent, the locally stored device identifier is immediately deleted and no further tracking requests are sent.

Consent record

Your consent decision (granted or declined, timestamp, consent version, and source) is stored locally on your device and, if you are logged in, also synced to our Supabase database (EU region). We maintain an append-only history of consent changes in order to demonstrate compliance to supervisory authorities upon request. Storing the consent record itself is permitted without prior consent under § 25(2) TTDSG, as it is strictly necessary to remember your expressed preference.

Retention

Matomo visit and event data from the mobile app is retained for 14 months and then automatically deleted. Consent records are retained for the duration of your account plus 36 months after account deletion, in line with the statutory limitation period for GDPR-related claims. Aggregated, non-identifying statistics may be retained for longer.

Re-prompt on policy changes

If we materially change what is tracked, who receives the data, or the retention period, we bump the consent version. The app will then show you the consent prompt again on next launch, regardless of any previous decision, so you can review and decide again.

7. Cookies and local storage

Website — consent record — A first-party cookie named orgo_consent stores your consent decision (accepted or declined, timestamp, consent version) for 365 days. Storing this is permitted without consent under § 25(2) TTDSG, as it is strictly necessary to remember the preference you expressed.

Website — analytics (only after you accept) — If you accept analytics in the consent banner, Matomo sets first-party cookies on .orgo.me to recognize you as a returning visitor and to group your actions into a single visit:

  • _pk_id.* — visitor identifier, 13 months
  • _pk_ses.* — current session, 30 minutes

These cookies are removed automatically if you later decline in privacy preferences. If you do not accept, neither cookie is set.

Website — technically necessary — Only technically necessary cookies may be set by the hosting provider to ensure the website functions correctly. These are processed on the basis of Art. 6(1)(f) GDPR.

Mobile app — The mobile app uses local app storage on your phone for two purposes related to analytics: (1) the consent record described in section 6 (permitted without consent under § 25(2) TTDSG), and (2) after you grant consent, the pseudonymous device identifier described in section 6. The app additionally uses local storage for technically necessary purposes such as your authenticated session and the offline save queue; these are necessary to provide the service you requested and do not require separate consent.

8. Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — You can request information about the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR) — You can request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) — You can request deletion of your personal data.
  • Right to restriction (Art. 18 GDPR) — You can request restriction of processing.
  • Right to data portability (Art. 20 GDPR) — You can request to receive your data in a machine-readable format.
  • Right to withdraw consent (Art. 7(3) GDPR) — You can withdraw your consent at any time with effect for the future.
  • Right to lodge a complaint (Art. 77 GDPR) — You have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, please contact us at info@orgo.me.

9. Supervisory authority

The competent supervisory authority for data protection is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Friedrichstr. 219

10969 Berlin

Website: datenschutz-berlin.de

10. Changes to this policy

We reserve the right to update this privacy policy to reflect changes in our data practices or legal requirements. The current version is always available at orgo.me/privacy.