Privacy Policy

Data protection is of high priority for ToCraft’s Site. Standard use of our website is possible without providing personal data. For specific functionalities (such as persistent login), essential data is stored locally on your device.

1. Controller

Tobias Cuiper
Email: development@tocraft.dev
Website: tocraft.dev

2. No Tracking Cookies & Local Storage

We do not use tracking, analytical, or marketing cookies.

To maintain user preferences and keep you logged in across sessions, we store essential operational data in your browser’s Local Storage.

Stored Categories & Purpose:

  • Session & Authentication Data: Secure authentication tokens used strictly to keep you logged in across visits without requiring repeated logins.
  • User Interface Preferences: Layout settings, theme choices, tab states, and display configurations to preserve your custom viewing options.
  • Storage Duration: Data in Local Storage has no expiration date and remains stored on your end device indefinitely until you manually delete it or clear your website data via your browser.

  • Legal Basis: Art. 6(1)(f) GDPR / Sec. 25(2) No. 2 TDDDG (legitimate interest in providing a user-friendly, secure, and personalized interface).
  • Control: All Local Storage entries remain stored locally on your device until manually cleared. You can inspect, modify, or delete this data at any time via your browser settings or developer tools.

3. Service Worker & Offline Caching

Our website utilizes a Service Worker—a background script running in your browser that caches static assets (such as HTML files, scripts, and images) to enable offline functionality.

  • Web browsers may categorize Service Workers under “Cookies and Site Data” in developer tools, but they are technically cache scripts rather than cookies.
  • No personal data is tracked, analyzed, or transmitted to third parties via the Service Worker.
  • Legal Basis: Art. 6(1)(f) GDPR / Sec. 25(2) No. 2 TDDDG.

4. Server Log Files

When accessing the website, the server automatically collects standard technical connection data sent by your browser:

  1. Browser type and version
  2. Operating system used
  3. Referrer URL
  4. Date and time of server access
  5. IP address

This data is processed anonymously solely to deliver website content, ensure technical stability, and prevent cyber-attacks (Art. 6(1)(f) GDPR).

  • Retention Period: Server log files are stored for security and operational monitoring purposes and are automatically deleted after 7 days. Data whose further storage is required for evidentiary purposes (e.g., in the event of a cyber-attack) is exempt from erasure until the respective incident is fully resolved.
  • Legal Basis: Art. 6(1)(f) GDPR.

5. Data Subject Rights

Under the GDPR, you retain full rights regarding any processing of your personal data, including access, rectification, erasure, restriction of processing, objection, and data portability.

To exercise these rights, contact the controller via the email address above. You also have the right to lodge a complaint with a supervisory authority.

6. No Automated Decision-Making

We do not engage in automated decision-making or profiling.