Controller and scope
The controller is Markus Morgenweck in Chiang Mai, Thailand. This notice covers the slow sip café app and its private administration area. Other websites opened through links have their own privacy notices.
Postal address
Markus Morgenweck434 M.1, T. Nong PhuengA. Saraphi
Chiang Mai 50140
Thailand
Purposes and legal grounds
We process data to provide the café collection, publish content, prevent technical problems and abuse, enable optional ratings and maps, and respond to enquiries. The following GDPR legal bases apply to the extent that the GDPR governs the processing concerned.
Operation, security, general enquiries and the publication of factual café information rely on legitimate interests (Article 6(1)(f) GDPR). These interests are a secure, functioning website, handling your requests and sharing information about cafés personally visited. Optional ratings and embedded maps rely on consent (Article 6(1)(a)). Consent records rely on Article 6(1)(c) where legally required and otherwise on Article 6(1)(f) to manage and demonstrate your choices.
Where German rules on access to terminal equipment apply, optional cookies and storage access rely on section 25(1) TDDDG, and strictly necessary access on section 25(2)(2). Since the project operates from Thailand, we also take account of the Thai Personal Data Protection Act (PDPA), where applicable. Relevant grounds include consent under Section 19, legitimate interests under Section 24(5), and legal obligations under Section 24(6). Mandatory rights under applicable law remain unaffected.
Hosting and access data
The app and its photos are hosted by ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. Requests involve processing an IP address, time, requested page or file, browser and operating system information, a referring page where available, status and data volume. These data support delivery, troubleshooting and protection against attacks.
Retention of technical logs and backups depends on how long they are needed for troubleshooting, recovery and operational security. A specific security incident or legal matter may require longer retention to investigate or establish, exercise or defend legal claims. Technical deletion follows the logging and backup rotation configured in the hosting account. A single fixed retention period for every log and backup therefore cannot be specified here.
The app contains no Google Analytics or advertising pixels of its own. Hosting access logs are separate from this. Maintenance and recovery may also involve processing café-data backups in the operator’s protected working environment; retention depends on their continuing necessity for recovery.
Session and private access
The necessary slow_sip cookie supports security checks and private sign-in. It contains a random identifier, not a password or translation key. It is a session cookie without a fixed browser expiry; browsers may preserve restored sessions. Private authorisation expires after twelve hours of inactivity. Server session files are cleaned up according to hosting settings.
Sign-in attempts are limited using an identifier derived from the IP address. Entries stop affecting the limit after 15 minutes and are removed during a later sign-in write operation. Only the signed-in operator can edit content, photos and translation settings.
Cookiebot and your choices
Cookiebot, provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, manages consent. The service receives technical connection data when loaded. Consent records include an IP address anonymised by removing its final part, time, browser information, page address, a random identifier and your choices. The provider specifies twelve months for consent records. The CookieConsent cookie normally stores your choice for up to twelve months; renewed consent may be requested earlier.
You can change or withdraw your choices through “Cookie settings”. Withdrawal applies to future processing and does not affect the lawfulness of earlier processing. Cafés and photos remain accessible without optional consent. The Cookiebot account is also used on the main domain. Additional services listed there are not necessarily part of this café app.
Optional likes and dislikes
Only after you allow “Preferences” does the app set slow_sip_visitor, a random, signed cookie identifier with a browser lifetime of at most one year. The server stores an identifier derived from it and your rating for each café. Only totals appear publicly. You can change a vote or tap again to remove it, without creating an account.
When you withdraw preference consent and the app receives that change, it removes the cookie and associated votes. Simply deleting cookies yourself or letting them expire does not automatically delete old server-side votes, which may then no longer be readily attributable to your browser. Votes remain until removed through the rating function, the withdrawal process described above or deletion by the operator; there is no automatic annual server deletion. Deleting a café removes its public listing but does not automatically erase its stored rating records.
To limit abuse, the app uses an identifier derived from the IP address, a time and a counter. The limit checks a 60-second window; expired entries are cleaned up during a later rating write. This protects the rating function and is not intended to build visitor profiles.
Google Maps and directions
An embedded map loads only after “Marketing” permission and a separate “Load map” click. Google receives information including your IP address, browser, connection details and map destination, and may use its own storage technologies. Depending on region, Google Ireland Limited or Google LLC is responsible. Processing may include the USA; see the provider for retention and transfer details.
Withdrawal removes loaded maps but cannot recall data already sent. “Directions” and “Google Maps” open Google's external website at your request. Our visitor page does not request your current location; you may separately grant Google location access for directions.
Café content, photos and translations
The operator records café names, descriptions, photos and locations and makes selected entries public. Sources are personal visits and photographs, and map information used by the operator for locations. Visitors cannot upload their own photos or texts. Where details or images identify people, their rights are taken into account; publication of factual information serves the information interest described above. Where consent or another permission is required, publication depends on that permission. Please report content affecting your rights.
Public and private café versions and translations are stored for the ongoing collection and updated or removed when edited or deleted. Existing backups may persist until removed or overwritten as part of recovery backups; they are not served as public café pages.
New or changed public café texts are translated through a server-side connection to OpenAI. The café name, address and notes are sent, not visitor ratings, visitor identifiers or photos. If these texts contain personal data, translation serves the same information purpose as publication. Under the provider’s terms, customers outside the EEA and Switzerland contract with OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, USA; customers in the EEA or Switzerland contract with OpenAI Ireland Ltd. The assignment for the particular account follows its contractual terms.
When saving, new or not yet checked German notes are also checked server-side with OpenAI for spelling and grammar, including private cafés. The café name and notes are sent for this purpose. The corrected German version forms the basis of public English and Thai translations, which are also proofread. The original input is retained for recovery in the protected private café record and is not provided to visitors. Previously checked, unchanged notes are not sent again for correction.
The translation request disables persistent storage as a retrievable API response object. This does not mean zero retention by the provider: its security logs may contain inputs and outputs for up to 30 days, and longer where required by law or necessary to prevent harm. API content is not used for model training by default. Completed translations are stored on our webspace.
Location and display in the private area
The private editor requests location permission only when the operator chooses that function. Coordinates may be sent through the server to OpenStreetMap's Nominatim service for address lookup and saved as the café pin. Shared Google Maps links are sent to Google to resolve destinations. These administration functions do not track visitor movements.
The public page and these notices serve fonts from this webspace. The private area currently uses external Google fonts; the explicitly opened demo also uses Unsplash example images and local browser storage (IndexedDB). Direct external requests disclose connection data to those providers. Public page language is carried in the URL.
When you contact me
If you email mm@designroad71.com, Markus Morgenweck and the service providers used for email delivery process your sender address, message, technical delivery data and any attachments you voluntarily supply to handle your request. Providing these data is voluntary. Without a way to contact you, a reply may not be possible.
Correspondence is deleted when no longer required for the completed enquiry, unless legal retention obligations or specific reasons for safeguarding legal claims require otherwise. Visitors do not need an account. There are no solely automated decisions with legal or similarly significant effects, or profiling for such purposes.
Recipients and international processing
Recipients are the operator and the hosting, email, consent, map and translation providers used for the functions described. The operator administers the app from Thailand. Storage on German webspace therefore does not mean all processing occurs within the EU. Google and OpenAI in particular may process data in the USA and other countries.
International transfers are subject to applicable data-protection requirements. Where the GDPR applies, relevant mechanisms include an applicable adequacy decision or appropriate Article 46 safeguards, such as standard contractual clauses; Sections 28 and 29 PDPA are relevant under Thai law. The linked Google and OpenAI information explains their intended transfer mechanisms. General cookie consent does not replace required transfer conditions. You can request details of recipients and safeguards for a specific processing activity, and a copy of relevant safeguards where applicable, at mm@designroad71.com.
Your rights and objections
Under applicable data-protection law, you may request access and a copy of your data, rectification, erasure, restriction and, where applicable, data portability. You can withdraw consent at any time for future processing. You may object to processing based on legitimate interests on grounds relating to your particular situation. Statutory conditions and exceptions apply.
Send requests to mm@designroad71.com or the postal address above and describe the data or content concerned. For browser-linked ratings, first use the rating or withdrawal function in the original browser where possible. An email does not automatically transmit that browser’s cookie identifier. Additional identity information is requested only where necessary to handle the request securely.
Where the GDPR applies, requests are generally answered within one month; any permitted extension is explained along with its duration. Otherwise, applicable statutory time limits govern. You may also complain to a competent data-protection authority. Under Article 77 GDPR this can in particular be the authority at your habitual residence, workplace or the place of the alleged infringement. In Thailand, the PDPC is the data-protection authority. The links below lead to the relevant authorities.
Changes to this notice
This privacy notice is updated when functions, providers or relevant legal requirements change. The date above identifies the current version. German, English and Thai describe the same processing activities. If anything is unclear, contact the controller using the details provided.