Privacy Policy
Last updated: 13 August 2026
This describes what actually happens when you visit merkuron.de and use the demo. It was checked against the running system, not produced by a generator.
Who is responsible
The controller is Florian Schneider, c/o Online-Impressum.de #37276, Europaring 90, 53757 Sankt Augustin, Germany, hallo@merkuron.de. No data protection officer has been appointed; neither Art. 37 GDPR nor § 38 BDSG requires one here.
Hosting and server logs
The site runs on our own server in Germany. There is no content delivery network and no third party relaying your requests. The web server records each request with your IP address, the time, the address requested, the status code, the referrer and your browser identification. We rely on our legitimate interest in running and defending the server (Art. 6(1)(f) GDPR).
Fonts and embedded content
Every font is served from our own server. This site loads nothing from Google Fonts, no analytics, no advertising networks, no embedded maps or video. Visiting it, your browser contacts no host other than ours. An automated test checks this on every change.
Cookies
This site sets no cookies. That is also why there is no cookie banner — there would be nothing to consent to.
The live demo
Starting a demo creates a test tenant with no registration and no email address. You receive an access token valid for 24 hours. That token and a device identifier are kept in your browser's local storage so the till recognises you across the page change; they leave your device only as proof to our server. You can clear them at any time through your browser's storage settings. Demo tenants are reset every hour, and everything you enter into one is deleted then.
Do not put real customer, staff or business data into the demo. It is publicly reachable, it is emptied every hour, and it is not a protected environment.
Abuse protection
To stop the demo being created in bulk automatically, we count requests per IP address. The key holding that count lives in memory for 70 seconds and is then discarded (Art. 6(1)(f) GDPR).
If you write to us
We process what you send in order to answer you and to handle follow-up questions (Art. 6(1)(b) and (f) GDPR). Our outgoing mail is delivered technically by Brevo (Sendinblue GmbH, Cologne) acting on our instructions.
Your rights
You may ask what we hold about you (Art. 15), have it corrected (Art. 16) or deleted (Art. 17), have its use restricted (Art. 18), receive it in a portable form (Art. 20), and object to processing based on legitimate interests (Art. 21 GDPR). You may also complain to a supervisory authority (Art. 77) — either where you live or where we are established.
What a deletion does not delete
Better said in advance than afterwards: when a customer profile is deleted in the till, the name, email address and phone number on that profile are made unreadable, but the receipts and till records behind it stay. German tax law requires that — §147 AO and the GoBD demand that till records be kept unalterable for ten years, and Art. 17(3)(b) GDPR exempts exactly such legal obligations from the right to erasure. A receipt cannot be removed without trace afterwards; that is the entire point of a tamper-proof till.
Changes
When what the site does changes, this changes with it. The date above says which version you are reading.