Caisse4All

Privacy policy

Last updated : 14 août 2026 · Germany and SEPA area

This policy explains what personal data Caisse4All collects, why, how it is protected, and how you can exercise your rights, including requesting deletion of your account and your data.

Data controller

For your region, the data controller is Mega-Ique Digital UG (haftungsbeschränkt) (www.megaique.de), the company that publishes the Caisse4All app. Its full details appear in the legal notice, and any question about your data can be sent to it by email. Caisse4All is published jointly by two partner companies, each acting as data controller for its own area.

Data we collect

  • Account and identity: phone number, which serves as your login, name, optional email address, language and country.
  • Use of the service: funds, members, contributions, expenses, receipts, fundraisers, balances and the history of operations recorded by you or by the members of your funds.
  • Notifications: a Firebase Cloud Messaging device token and your notification preferences.
  • Technical data: IP address, device type, connection logs and the audit log required for security and for the traceability of money flows.

We do not collect sensitive data that the service does not need, and we never sell your data.

Purposes and legal bases

  • To provide and run the shared funds and fundraisers service, which is the performance of the contract between us.
  • To authenticate you and secure your account, based on our legitimate interest in protecting accounts and on our security obligations.
  • To send you notifications about your funds, which you can turn off at any time.
  • To prevent fraud, ensure the traceability of money flows and meet our legal and accounting obligations.

Under the General Data Protection Regulation, this processing relies on Article 6(1)(b) for performance of the contract, Article 6(1)(f) for our legitimate interest in securing the service, and Article 6(1)(c) for our legal obligations.

Sharing your data

  • Hosting and secure infrastructure.
  • Google Firebase, to deliver notifications.
  • The payment providers concerned when you declare a payment by SEPA transfer or PayPal, for the sole purpose of matching the reference you entered.
  • The competent authorities, only where the law requires it.

Members of the same fund can see that fund's operations by default. The group can restrict what is shown: when an administrator or a treasurer turns on transaction privacy, each member only sees their own, while the people in charge and the auditor keep the full view they need to check the accounts. The anonymity of a contribution is respected according to the level chosen by the contributor, and the real identity behind an anonymous contribution is never exposed to ordinary members, including in the technical data exchanged with the app.

Some of our technical providers, including Google Firebase, may process data outside the European Economic Area. These transfers are governed by the European Commission's standard contractual clauses.

How long we keep your data

Your personal data is kept for as long as your account is active. When the account is deleted, your identity and contact details are erased or anonymised. Some financial records are kept in anonymised form, with no link to your identity, for the period required by law and to preserve the integrity of the funds you shared with other members.

Security

Traffic is encrypted with HTTPS, access is controlled by role within each fund, uploaded files are checked, and an audit log records important operations. No financial operation is ever physically deleted: it is cancelled or archived, and the record remains.

Your rights

Under the General Data Protection Regulation, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21), as well as the right to withdraw your consent at any time. To exercise these rights, write to us.

If our answer does not satisfy you, you may lodge a complaint with the competent supervisory authority in your country of residence. In Germany, this is the data protection authority of the relevant federal state.

Deleting your account and your data

You can ask at any time for your Caisse4All account and the associated personal data to be deleted, without needing the app. Your identity, contact details, device tokens and preferences are deleted; anonymised financial records may be kept where the law requires it or to preserve the integrity of shared funds. Your request is processed within thirty days.

Minors

Caisse4All is not intended for people below the legal age required to enter into a contract, and we do not knowingly collect their data.

Changes

This policy may change. Any significant change is published on this page, together with a new update date.

Account and data deletion

Use this form to request deletion of your Caisse4All account and the personal data attached to it. No sign-in is required.

Send my request