Privacy Policy

Last updated: August 31, 2026

Privacy Policy (B2C) – OpenBowling

Online Reservation of Bowling Lanes

1. Controller

Pro Bowl Bowlingservice

Tiefkarstraße 12, 82481 Mittenwald, Germany

Email: info@openbowling.de

Phone: +49 8823 926567

VAT ID: DE245876877

Privacy contact: info@openbowling.de

2. Scope

This privacy policy applies to the website openbowling.de and to the online reservation of bowling lanes via OpenBowling (end customer area).

3. Definitions

The definitions of the General Data Protection Regulation (GDPR) apply, in particular "personal data", "processing", and "controller".

4. Data Processing When Visiting the Website (Server Log Files)

4.1 Scope of Processing

When you access the website, data is technically processed by the hosting provider (server log files), e.g.:

  • IP address
  • Date and time of access
  • Accessed page/file
  • Referrer URL
  • Browser type/version, operating system
  • Transmitted data volume, status codes

4.2 Purpose and Legal Basis

Purposes: technical provision of the website, stability/security, error analysis, defense against attacks. Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in secure, stable operation).

4.3 Storage Duration

Server log files are deleted after 14 days, unless longer retention is required to investigate security incidents.

5. Online Reservation of Bowling Lanes (Booking)

5.1 Scope of Processing

The following data is processed for reservations:

  • Name
  • Email address
  • Phone number
  • Booking data (center, date/time, number of lanes/time slot, notes if applicable)

5.2 Purpose and Legal Basis

Purposes: processing of reservations, sending booking confirmations and email verifications, inquiries, cancellations/changes, fraud prevention. Legal basis: Art. 6 (1) lit. b GDPR (contract/pre-contractual measures) and Art. 6 (1) lit. f GDPR (security/fraud prevention).

5.3 Recipients

The recipient of the booking data is the selected bowling center, where the reservation is carried out. Pro Bowl Bowlingservice provides the technical platform.

6. Cancellation and Changes

Online cancellation is possible up to 24 hours before the start of the booking. Within 24 hours, cancellation/changes must be made by phone directly with the bowling center. The data required for processing will be processed. Legal basis: Art. 6 (1) lit. b GDPR.

7. Contact

When contacting us (e.g., by email), the provided data is processed to handle the inquiry. Legal basis: Art. 6 (1) lit. b GDPR (contractual/pre-contractual) or Art. 6 (1) lit. f GDPR (processing general inquiries).

8. Cookies and Local Storage

8.1 Technically Required Cookies

OpenBowling may use technically required cookies or comparable storage technologies (e.g., session cookies) that are necessary for operation and explicitly desired functions. Legal basis: Art. 6 (1) lit. f GDPR; national regulations (TDDDG) apply for storage/access to terminal equipment information – no consent is required if technically necessary.

8.2 Non-Essential Cookies/Tracking

If non-essential cookies/tracking technologies are used (e.g., analytics/marketing), this is done only after consent. Legal basis: Art. 6 (1) lit. a GDPR, possibly additionally under TDDDG.

9. Payment Processing (PayPal) – Only When Activated

If online payments via PayPal are offered, data required for payment is transmitted to PayPal. PayPal processes data under its own responsibility according to PayPal's privacy policy. Legal basis: Art. 6 (1) lit. b GDPR (payment processing).

10. Data Processors (Service Providers)

Service providers may be used as data processors for hosting, email delivery, operations/support. These are contractually obligated under Art. 28 GDPR.

11. Third Country Transfer

If service providers process data outside the EEA, this is done only if legal requirements are met (e.g., adequacy decision or standard contractual clauses).

12. Storage Duration (General)

Personal data is stored only as long as necessary for the stated purposes or as required by legal retention obligations. Booking data is anonymized or deleted 12 months after the booking date, unless legal retention obligations (e.g., tax law: 10 years pursuant to § 147 AO) prevent this.

12a. Necessity of Providing Personal Data

Providing your name, email address, and phone number is required for the conclusion of the booking contract. Without this information, no reservation can be made. The provision of IP address and server log files is technically required for the operation of the website.

12b. Automated Decision-Making

Automated decision-making including profiling pursuant to Art. 22 GDPR does not take place.

13. Rights of the Data Subject

Data subject rights (depending on requirements): access, rectification, deletion, restriction, data portability, objection to processing based on Art. 6 (1) lit. f GDPR, revocation of given consents with effect for the future.

14. Right to Lodge a Complaint with a Supervisory Authority

There is a right to lodge a complaint with a data protection supervisory authority, particularly at the place of habitual residence or the place of the alleged infringement.

Responsible for the non-public sector in Bavaria:

Bavarian State Office for Data Protection Supervision (BayLDA)

Promenade 18, 91522 Ansbach, Germany

15. Security

Pro Bowl Bowlingservice implements appropriate technical and organizational measures to protect data from loss, misuse, and unauthorized access.

16. Changes to This Privacy Policy

This privacy policy may be updated to reflect legal or technical changes.

Privacy Policy (B2B) – Center Portal
B2B

Processing of our business customers' data during registration, use and billing of the Center Portal

1. Controller and Scope

The controller for the processing described in this section is the entity named in Section 1 of the B2C policy (Pro Bowl Bowlingservice, Tiefkarstraße 12, 82481 Mittenwald, Germany). This section applies to operators of leisure venues who register, trial or use the Center Portal, as well as to their contact persons and user accounts.

2. Distinction from Processing on Behalf

For the end-customer data booked or managed through the Center Portal, the respective center is the controller; in that respect we act solely as a processor under the data processing agreement (DPA). For the contract, billing and usage data of the center itself described in this section, we are the controller in our own right.

3. Categories of Data Processed

We process the following data of our business customers:

  • Registration and master data: company name, address, contact person, email address, telephone number, website, number of lanes, time of acceptance of the terms and conditions
  • Access and user account data: name, email address, role, password hash and login times — the latter also to identify prolonged inactivity under Section 6(2) of the terms and conditions
  • Billing and payment data: billing address, invoice recipient, VAT ID, payment method and, for SEPA direct debit, IBAN, BIC, account holder, mandate reference and the time the mandate was granted
  • Contract and plan data: selected plan, payment interval and the time of that selection, start and end of the trial period, end of the decision period, pre-selected plan, renewal dates
  • Billing and usage data: the number of bookings received via the online booking flow per billing period, the fees derived from it, invoices issued and their payment status
  • Communication data: system and reminder messages sent to the contact persons (for example notices on the end of the trial period and the plan decision) and support correspondence
  • Change records for the contract: time, previous and new state, and the user account that triggered changes to plan, payment interval and account status

4. Purposes and Legal Bases

Processing takes place for the following purposes:

  • Establishment, performance and termination of the usage contract, including provision of the Center Portal, administration of the trial period and plan decision and the related notifications — Article 6(1)(b) GDPR
  • Billing, invoicing and collection of payments, including the SEPA direct debit scheme — Article 6(1)(b) GDPR
  • Compliance with legal obligations, in particular invoicing and retention obligations under Section 14 of the German VAT Act, Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code — Article 6(1)(c) GDPR
  • Ensuring secure operation, preventing misuse and payment default, and keeping contract changes traceable through the change log — Article 6(1)(f) GDPR
  • Responding to support requests — Article 6(1)(b) or (f) GDPR

5. Recipients

Recipients are the hosting provider, the email delivery provider, the bank instructed in the case of SEPA direct debit, and tax advisers and tax authorities within the scope of statutory obligations. Service providers act on the basis of data processing agreements under Article 28 GDPR. No transfer to third countries takes place.

6. Retention Period

Contract and usage data are stored for the duration of the contractual relationship. After it ends, the data are not deleted immediately but initially retained so that an account can be reactivated and a data export provided; processing is then limited to those purposes and to compliance with statutory obligations. Invoices, booking records and the underlying billing data are retained for ten years under Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code. Bank and mandate data are removed from the Center Portal once the mandate is revoked or the payment method is changed, unless a retention obligation applies.

7. Rights of Data Subjects

You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and the right to object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) (Article 21). Requests should be addressed to the address given in Section 1.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the one named in Section 14 of the B2C policy.

9. Necessity of Provision

Providing the registration and billing data is required for the conclusion and performance of the usage contract. Without complete billing data, a paid subscription cannot begin; in that case access reverts to the free Basic Plan (Section 6a of the terms and conditions).

10. No Automated Decision-Making

No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place. The automatic switch to the free Basic Plan after the decision period expires is the contractually agreed consequence of a missing declaration and does not create any payment obligation.

Cookie Details

This website uses cookies. Cookies are small text files that are stored on your device and enable or improve the use of the website.

Necessary Cookies

These cookies are essential for the operation of the website and cannot be disabled.

next-auth.session-token

User authentication and session management

Duration: 30 days

next-auth.csrf-token

Protection against Cross-Site Request Forgery attacks

Duration: Session

NEXT_LOCALE

User language preference (de/en)

Duration: 1 year

cookie_consent

Storage of the user's cookie consent decision

Duration: 1 year

Functional Cookies

These cookies enhance your user experience but are not strictly necessary.

theme

Dark/Light mode preference

Duration: 1 year

Analytics Cookies

Currently not activated. Future use for anonymized usage statistics.