Privacy Policy
The protection of your personal data has highest priority at PianoHub. This privacy policy informs you about which data we collect, how we use it, and what rights you have.
Data Controller
Responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR):
Futura Eleven, Owner: Felix Ebner
Steinstraße 37
85051 Ingolstadt
Deutschland
Email: support@pianohub.de
Overview
PianoHub was developed with a clear goal: maximum data protection for all users. We only collect data that is absolutely necessary for operating the platform. There are no user accounts, no tracking, no analytics tools, and no sharing of your data with third parties for advertising purposes.
Legal Basis for Data Processing
The processing of your personal data is based on the following legal grounds of the GDPR:
- Art. 6 (1) lit. a GDPR (Consent): If you have given explicit consent, e.g., when using technically non-essential cookies.
- Art. 6 (1) lit. b GDPR (Performance of a Contract): If processing is necessary for the performance of a contract, e.g., when creating a listing.
- Art. 6 (1) lit. f GDPR (Legitimate Interest): If we have a legitimate interest in processing, e.g., to ensure IT security.
Data Processing in Detail
Email Addresses
Your email address is the only personal data we collect from you. It is required when you create a listing or contact a seller. We use your email address exclusively for anonymized message forwarding through our PianoHub Messenger and store it only as long as necessary for this purpose.
If you send a support request via the contact form, we store your email address to reply to you. This communication is not anonymized.
Retention period: For listings: Until deletion or expiration of the listing. For contact requests: As long as the associated listing is online. For support requests: Until final processing or earlier upon request.
Legal basis: Art. 6 (1) lit. b GDPR (Performance of a Contract) or Art. 6 (1) lit. f GDPR (legitimate interest in providing support services)
PianoHub Messenger
Our self-developed PianoHub Messenger enables anonymized communication between buyers and sellers. When you send a message through PianoHub, it is sent via an automatically generated forwarding address. Your real email address is never disclosed to the other party.
The content of your messages is only temporarily cached for forwarding and then immediately deleted. We do not permanently store message contents on our servers.
Retention period: Email addresses of communication partners: As long as the associated listing is online. Message contents: Only for technical delivery (a few seconds).
Legal basis: Art. 6 (1) lit. b GDPR (Performance of a Contract)
Listing Data
When you create a listing, we store the information you provide about the instrument (brand, model, price, location, description, images, etc.) as well as your email address. This data is used to display the listing on the platform and enable contact requests. Most of this data is publicly visible, with the exception of your email address and optionally your name.
Retention period: Until deletion of the listing by you or automatically after expiration of the listing period.
Legal basis: Art. 6 (1) lit. b GDPR (Performance of a Contract)
Cookies and Local Storage
PianoHub uses only technically necessary cookies and local browser storage (localStorage). There are no tracking cookies or analytics cookies.
Technically Necessary Cookies
We use the following cookies to ensure the functionality of the website and improve your user experience:
- NEXT_LOCALE: Stores the language you selected in the website settings. Retention period: Until browser is closed (session cookie).
- pianohub_currency: Stores your preferred currency for price display. Retention period: 1 year.
- pianohub_sortBy: Stores your preferred sorting order for listings. Retention period: 1 year.
- pianohub_pageSize: Stores your preferred number of listings per page. Retention period: 1 year.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in providing a user-friendly website). These cookies are technically necessary and do not require consent.
Local Storage (localStorage)
In addition to cookies, we use your browser's local storage to save the following settings locally on your device:
- settings: Stores the website settings you configured.
- search-filters: Stores your search filters and display settings.
- watchlist: Stores the IDs of listings on your watchlist.
- info-banner: Stores whether you have dismissed the information banner.
Retention period: Unlimited, until you clear your browser cache or manually remove the data
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in providing convenient user features). The data is stored exclusively locally in your browser and not transmitted to our servers.
External Services
Frontend Hosting (Website Delivery)
The PianoHub website is hosted and delivered via specialized hosting providers (Vercel Inc., San Francisco, USA and/or Netlify Inc., San Francisco, USA). When you visit PianoHub or submit forms, your requests are routed through the respective hosting infrastructure.
Technical data such as your IP address, browser information, and timestamps may be temporarily processed. The providers use global Content Delivery Networks (CDN) that distribute data across various regions for optimal loading speed. Both providers operate in compliance with GDPR based on Standard Contractual Clauses.
The hosting providers do not permanently store personal user data and have no access to the contents of your listings or messages, which are stored exclusively in our backend database.
Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA and Netlify Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in performant and reliable website delivery)
Backend and Database
All permanently stored data on PianoHub (listing data, email addresses for message delivery, relay conversations, etc.) is stored in our backend database, which is hosted by an external database service provider.
We carefully select our service providers and ensure that they operate in compliance with GDPR and run servers within the EU or in countries with adequate data protection standards. The service provider has access to the data solely for the purpose of providing the technical infrastructure.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in a functional platform)
Email Delivery
For sending emails (confirmation emails for listings, forwarding via PianoHub Messenger, etc.), we use external email delivery service providers (SMTP providers). These service providers have access to email contents solely for the purpose of technical delivery.
Email service providers store messages only temporarily for delivery and delete them afterwards. We use exclusively GDPR-compliant providers.
Legal basis: Art. 6 (1) lit. b GDPR (Performance of a Contract) or Art. 6 (1) lit. f GDPR (legitimate interest in reliable email delivery)
Cloudflare Turnstile (Bot Protection)
To protect against spam and automated requests, we use Cloudflare Turnstile. This service checks whether form requests come from real users. Unlike traditional CAPTCHAs, Turnstile is privacy-friendly and GDPR-compliant.
When using forms (create listing, contact form, send message), IP addresses and technical information (browser fingerprint) may be briefly transmitted to Cloudflare to validate the request. No personal data is permanently stored.
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in preventing abuse and spam)
Google Fonts (Typography)
PianoHub uses Google Fonts for displaying typefaces. However, these are not loaded from Google servers but are automatically downloaded during website build time and hosted as part of our website infrastructure (self-hosting via Next.js).
This means: When you visit PianoHub, no requests are sent to Google servers and no data (such as your IP address) is transmitted to Google. The fonts are provided exclusively through our website infrastructure.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in appealing typographic design of the website without data transmission to third parties)
No Other Google Services
Apart from the self-hosted Google Fonts (see above), PianoHub deliberately avoids using other Google services such as Google Analytics, Google Maps, or Google reCAPTCHA. This ensures that no usage data is transmitted to Google.
Website Analytics
To better understand the usage and performance of PianoHub, we use Vercel Web Analytics. This service collects basic website metrics such as page views, visitor sources (referrers), device information, and geographic regions (at country level).
Vercel Web Analytics is fully cookieless and GDPR-compliant. No personal data such as IP addresses is stored or associated with you. Analysis is performed exclusively on an aggregated basis to improve website performance and user experience.
There is no cross-site tracking, profiling, or sharing of data for advertising purposes.
Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analyzing and improving our website)
Data Security
We employ technical and organizational security measures to protect your data from loss, manipulation, or unauthorized access. Data transmission between your browser and our servers is encrypted via HTTPS (SSL/TLS).
Our servers are located in Germany and are subject to strict German and European data protection regulations.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): You can obtain information about the personal data we store about you at any time.
- Right to Rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
- Right to Erasure (Art. 17 GDPR): You can request the deletion of your data, provided there are no legal retention obligations.
- Right to Restriction of Processing (Art. 18 GDPR): You can request a restriction on the processing of your data.
- Right to Data Portability (Art. 20 GDPR): You can request the delivery of your data in a structured, commonly used format.
- Right to Object (Art. 21 GDPR): You can object to the processing of your data on grounds relating to your particular situation.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection supervisory authority about the processing of your data.
To exercise your rights, please contact us at: support@pianohub.de
Changes to Privacy Policy
We reserve the right to update this privacy policy to reflect changes in legislation or changes to our services. The current version can always be found on this page.
Last updated: 06.12.2025