Back to homepage

Privacy Policy

We take the protection of your personal data very seriously. This Privacy Policy informs you about the processing of your personal data under the GDPR (EU), the revised Swiss Data Protection Act (revFADP) and other applicable data protection laws.

As of: 30. May 2026 | Version 2.0 | Controller: Winify AG

Table of contents

  1. Controller and contact
  2. Principles of data processing
  3. Data collected and purposes of processing
  4. Payment data and Stripe
  5. Cookies and tracking
  6. Third-party providers and data sources
  7. IP address recognition and geolocation
  8. AI assistant and chat data
  9. Data retention and deletion periods
  10. Data disclosure and recipients
  11. Data transfers to third countries
  12. Your rights as a data subject
  13. Data security
  14. Minors
  15. Changes to this policy

§1 Controller and contact

The controller within the meaning of the GDPR and the revised Swiss Data Protection Act for the processing of personal data on this platform is:

Winify AG
Churerstrasse 65b
8808 Pfaeffikon SZ
Switzerland
UID CHE-495.341.743
Website: www.goldkurs.ch
Email: privacy@goldkurs.ch
Privacy requests: privacy@goldkurs.ch

For all privacy-related enquiries, access requests or the exercise of your rights, please contact us directly at: privacy@goldkurs.ch

§2 Principles of data processing

We process personal data only within the framework of legal requirements. Processing is based on the following legal bases (Art. 6 GDPR):

We collect only the data necessary for the respective purpose (data minimisation, Art. 5(1)(c) GDPR).

§3 Data collected and purposes of processing

3.1 Registration and account data

Data categorydataPurposeLegal basis
IdentificationEmail address, automatically generated usernameAccount creation, login, communicationArt. 6 Abs. 1 lit. b DSGVO
SecurityPassword hash (bcrypt, not plain text)AuthenticationArt. 6 Abs. 1 lit. b DSGVO
Profile (optional)First name, last name, country, preferred languagePlatform personalisationArt. 6 Abs. 1 lit. b DSGVO
SettingsPreferred currency (EUR/CHF), languagePrice display, localisationArt. 6 Abs. 1 lit. f DSGVO

3.2 Usage data

Data categorydataPurpose
Access dataIP address, browser type, operating system, referrer URL, access timeSecurity, error analysis, geolocation for currency recognition
Session dataSession ID, login timestamp, last loginAuthentication, Security
Portfolio dataEntered precious-metal holdings, purchase prices, quantitiesPortfolio tracking function
AI chat dataInputs in the AI assistant, responses, timestampsCommission of the AI service, quota management

3.3 Subscription and transaction data

Data categorydataPurpose
SubscriptionPlan key, status, start/end date, trial informationSubscription management, access control
Stripe referenceStripe customer ID, subscription ID (no payment data)Payment processing via Stripe
InvoicesInvoice amount, date, statusAccounting (statutory retention obligation of 10 years)

3.4 Team and institutional data

Users of Pro Team and Institutional plans may invite team members and clients. Email addresses of invitees are processed and invitation tokens are generated. Invited persons are informed about data processing before accepting the invitation.

3.5 Newsletter and marketing

Marketing emails are sent only with the user’s explicit consent (double opt-in). Consent can be withdrawn at any time (unsubscribe link in every email or by email to privacy@goldkurs.ch).

§4 Payment data and Stripe

Payment processing is carried out exclusively via Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA). GoldKurs.ch stores no credit card numbers, bank details or other payment method information. These are processed directly by Stripe.

Stripe is a certified PCI-DSS Level 1 provider. During payment processing, your data is transmitted to Stripe, which is responsible for secure processing. Stripe’s privacy policy applies: stripe.com/de/privacy

From Stripe we receive only:

Legal basis for transmission to Stripe: Art. 6(1)(b) GDPR (performance of contract) in conjunction with Art. 49(1)(b) GDPR (US data transfer necessary for contract performance). Stripe contractually undertakes to process data in compliance with data-protection law through EU Standard Contractual Clauses (SCCs).

§5 Cookies and tracking

5.1 Technically necessary cookies

GoldKurs.ch uses technically necessary cookies and session cookies that are essential for operating the platform. These cookies cannot be disabled without impairing the platform’s functionality.

CookiePurposeBilling cycle
PHPSESSIDSession management, authenticationSession (until browser is closed)
currencyStorage of preferred currency (EUR/CHF)1 year

5.2 Analytics and tracking

GoldKurs.ch currently uses no third-party analytics tracking tools (such as Google Analytics, Facebook Pixel, etc.). Access data is stored exclusively in server-side log files and deleted after 30 days.

5.3 Cloudflare

The platform uses Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA) as CDN and DDoS protection. Cloudflare processes IP addresses as a processor for security and performance purposes. Cloudflare’s privacy policy applies: cloudflare.com/privacypolicy. Transmission is based on EU Standard Contractual Clauses.

§6 Third-party providers and data sources

GoldKurs.ch processes market, macro and price data server-side. Users generally do not establish a direct connection to market data providers; display takes place through our platform and may be delayed, cached or model-compressed.

Recipient/categoryPurposeNote
Market and macro data providersCommission of price, index and economic dataServer-side processing; no direct client connection
ip-api.comIP geolocation for currency recognitionSee §7; country/currency only, no permanent plain-text IP storage
Cloudflare CDNSecurity, performance and delivery of static resourcesPossible IP transmission to Cloudflare
StripePayment processingSee §4
AI service providersProcessing of AI requestsSee §8; do not enter sensitive data in chat

Market data is generally processed server-side by GoldKurs.ch and delivered to you. Your IP address is generally not passed directly to market data providers.

§7 IP address recognition and geolocation

GoldKurs.ch automatically determines your approximate location from your IP address for currency display (EUR or CHF). In this process:

Geolocation serves exclusively currency display (CHF for Swiss users, EUR for all others) and is not a tracking measure. You can change the currency manually at any time using the EUR/CHF switch on the website.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in correct price display).

§8 AI assistant and chat data

8.1 Data processed

When you use the AI assistant, the following data is processed:

8.2 Purpose of processing and storage

Chat messages are stored to provide the service and manage the monthly message quota. Chat history is visible in your account. Messages are automatically deleted after 12 months automatically.

8.3 AI model

The AI assistant is based on a language model. Your inputs may be transmitted to external AI providers for processing. Details will be added for the specific implementation. Please do not enter sensitive personal data (account data, passwords, etc.) in the AI chat.

§9 Data retention and deletion periods

Data categoryRetention periodReason
Account data (active)Until account deletionPerformance of contract
Account data (after cancellation)30 days after cancellationRestoration upon request, then deletion
Invoice and accounting data10 yearsStatutory retention obligation (CO/HGB)
Server logs (IP addresses)30 daysSecurity, error analysis
IP geo cache7 daysPerformance optimisation for currency recognition
AI chat history12 monthsService provision, quota tracking
Team invitations (expired)30 days after expiryThen automatically deleted
Newsletter consentsUntil withdrawal + 3 yearsProof of consent

§10 Data disclosure and recipients

We generally do not disclose your data to third parties unless:

Disclosure to third parties for advertising purposes does not.

§11 Data transfers to third countries

Some of our service providers are based in the USA (Stripe, Cloudflare, possibly AI providers). Transfers to the USA are based on:

For Swiss users, transfers to the USA are based on Switzerland’s adequacy decision or appropriate safeguards under the revised FADP.

§12 Your rights as a data subject

You have the following rights with respect to your personal data:

RightDescriptionLegal basis
AccessWhat data we have stored about youArt. 15 DSGVO / Art. 25 revDSG
RectificationCorrection of inaccurate dataArt. 16 DSGVO
DeletionDeletion of your data (where no retention obligation applies)Art. 17 DSGVO
RestrictionRestriction of processingArt. 18 DSGVO
Data portabilityExport of your data in machine-readable formatArt. 20 DSGVO
ObjectionObjection to processing based on legitimate interestArt. 21 DSGVO
WithdrawalWithdrawal of consent (e.g. newsletter)Art. 7 Abs. 3 DSGVO
ComplaintComplaint with a supervisory authorityArt. 77 DSGVO

To exercise your rights, please contact us by email at: privacy@goldkurs.ch. We respond to requests within 30 days.

Competent supervisory authorities

§13 Data security

GoldKurs.ch uses the following technical and organisational measures (TOMs) to protect your data:

In the event of a data breach that results in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and affected users without undue delay (Art. 33/34 GDPR).

§14 Minors

GoldKurs.ch is directed at persons aged 18 and over. We do not knowingly collect personal data from persons under 18. If you become aware that a minor has created an account with us, please inform us at privacy@goldkurs.ch.

§15 Changes to this policy

This Privacy Policy may be updated at any time to reflect changes to our services, legal requirements or new data protection practices. In the event of material changes, we will inform registered users by email. The date of the last update is stated at the beginning of this policy. The current version is always available on this page.

Questions about privacy? Write to us at any time at: privacy@goldkurs.ch – we respond within 48 hours.

DEEN