This privacy policy explains which personal data we process when you visit onehourleft.de, make a booking or contact us. Personal data means any information that can identify you directly or indirectly.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
One Hour Left GmbH
Jägerweg 10
85521 Ottobrunn
Germany
Telephone: +49 (89) 66 594 204
Email: team@onehourleft.de
2. Technical provision and hosting by STRATO
Our website, content management system, server-side booking integration and other software used for our online services operate on server infrastructure provided by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin. STRATO processes the data necessary for hosting, storage, databases, backups, network operation and technical protection. According to STRATO, the servers used are located in Germany or elsewhere within the European Union.
When the website or software provided through it is accessed, technically necessary connection data is processed. This may include, in particular, IP address, access date and time, requested address, referrer, HTTP status, volume of data transferred, and browser and operating system information. Further information is available in STRATO’s privacy information.
Processing is necessary to deliver the website, ensure its stability and security, and detect faults or attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and economical operation of our online services. Hosting and technical service providers receive data only insofar as necessary to provide their services. Where they act on our behalf, this takes place in accordance with Article 28 GDPR.
Technical log data is deleted once it is no longer required for operation and security. Longer retention occurs only where a specific security incident is investigated, a claim is pursued or a statutory obligation must be met.
3. Cookies and consent management
We distinguish between technically necessary functions, cookieless Google signals and optional services for statistics and marketing. Non-essential information is stored on or read from your device only after you make your choice. The legal basis is section 25(1) TDDDG; subsequent processing of personal data is based on Article 6(1)(a) GDPR. Strictly necessary storage takes place under section 25(2), number 2 TDDDG; depending on its purpose, the associated data processing is based on Article 6(1)(b) or (f) GDPR. Cookieless Google processing that takes place independently of consent is described separately under “Google Consent Mode v2”.
Your choice is voluntary. The website and booking function can also be used with “Necessary only”. You can change or withdraw your decision at any time using the “Cookie settings” button at the edge of the page. Withdrawal applies prospectively and does not affect the lawfulness of processing before withdrawal. When you withdraw consent, we also attempt to delete analytics and marketing cookies that we can access.
Storage used
- ohl_consent: stores your choices for statistics and marketing and the time of your decision. Provider: One Hour Left GmbH. Purpose: demonstrating and respecting your consent. Retention period: 180 days. Technically necessary.
- _ga and _ga_<identifier>: may be set by Google Analytics after consent to statistics to distinguish visitors and sessions. Provider: Google. Standard maximum period according to the provider: up to 2 years; browsers may limit this period.
- _gcl_au and comparable Google advertising cookies: may be set after consent to marketing for conversion measurement and advertising functions. Provider: Google. The specific period depends on the cookie and browser and is typically up to 90 days.
- _fbp and, where applicable, _fbc: may be set by the Meta Pixel after consent to marketing to measure visits and campaigns. Provider: Meta. The specific period depends on the cookie and browser and is typically up to 90 days.
- booking-result (sessionStorage): stores the current booking result, including booking reference, selected experience, date, time, group size, price and status, so the confirmation or status page can be displayed. Provider: One Hour Left GmbH. Technically necessary for the requested booking flow. Storage is limited to the browser tab’s session; browser session restoration may retain it.
- ohl_booking_purchase_v1_… (localStorage): after consent to analytics or marketing, stores a local hashed key derived from a booking reference, a randomly generated measurement identifier, creation time and separate delivery flags for analytics and marketing. This prevents a confirmed booking from being counted repeatedly. Provider: One Hour Left GmbH. At most 20 records are retained; records older than 180 days are removed when this measurement function next runs. Withdrawal of analytics or marketing consent clears these records. The booking reference itself is not sent to Google or Meta by this measurement function.
The cookies actually present depend on your choice, your browser and how you reached our website.
4. Online booking and TimeSlot
Our website provides the booking interface and communicates with our booking service. The service uses TimeSlot to retrieve availability and process bookings. The TimeSlot provider is iMi digital GmbH, Matheus-Müller-Straße 3, 65343 Eltville am Rhein. Our gift voucher links open the external TimeSlot voucher shop.
When you select or book a time, we process in particular the selected experience, date and time, participant number, price and tariff information, and the contact, invoice, voucher and message information you enter. Technically necessary connection and log data may also arise. Required information is needed to prepare and perform the requested booking; without it, we cannot enter into the contract.
The legal basis is Article 6(1)(b) GDPR. Where commercial or tax retention obligations apply, storage is also based on Article 6(1)(c) GDPR. The recipient of data required for technical operation is iMi digital GmbH. Further information is available in TimeSlot’s privacy information.
We retain booking and accounting documents for the statutory retention periods. Depending on the document, periods of six, eight or ten years regularly apply. We delete data not subject to a statutory retention obligation once the booking has been fully completed and no warranty, limitation or other legitimate grounds for retention remain.
5. Payments in the external voucher shop
No online payment is taken in our website’s escape-room and VR booking flow. Payment for these bookings is made on site by card. Purchasing a gift voucher opens the external TimeSlot voucher shop; the payment methods displayed there apply.
When you select a payment method in that shop, the shop and the selected payment provider process the information needed to carry out the payment. This may include order and transaction identifiers, amount, currency, payment status and payer information. Processing necessary to perform your chosen payment is based on Article 6(1)(b) GDPR; statutory retention obligations are based on Article 6(1)(c) GDPR. The external shop’s privacy information and the selected payment provider’s notices also apply.
If PayPal is offered in the voucher shop and you select it, its provider for customers in the European Economic Area is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg (R.C.S. Luxembourg B 118 349). PayPal acts as an independent controller, including for regulatory obligations, identity and credit checks and fraud prevention. PayPal operates internationally and may process data outside the European Economic Area, particularly in the USA. Further information about recipients, retention periods, international transfers and your rights is available in PayPal’s privacy statement.
We retain our payment and booking records for the commercial and tax retention periods applicable to each document.
6. Audience measurement and advertising
Google Consent Mode v2 and cookieless pings
We use the “Advanced” version of Google Consent Mode v2. The Google tag is technically loaded when the page is accessed. Before you make a choice, the signals analytics_storage, ad_storage, ad_user_data and ad_personalization default to “denied”. In this state, Google tags may not read or write analytics or advertising cookies or corresponding device identifiers. This does not load Meta or other third-party providers that are not consent-aware.
While these signals are denied, Google tags may send cookieless consent and measurement pings. According to Google, these may include, in particular, consent status, timestamp, referrer, page address, browser or device information, whether an advertising click parameter was present, and a random number generated anew for each page view. The IP address is technically processed during transmission; for Google Ads, Google describes truncation during collection. We have additionally activated ads_data_redaction. When advertising storage is denied, this removes advertising click identifiers such as GCLID or DCLID and corresponding information in page addresses from advertising pings.
Cookieless pings transmit and respect consent status, provide basic audience, event and conversion measurement, technically check our measurement configuration, and support statistical estimation of visits or conversions that cannot be observed. Google may model data for these purposes if the respective technical and volume requirements are met. We cannot guarantee that these requirements will be met or that modelled values will be available. We do not use cookieless pings to recognise individual visitors or create our own user profiles.
We rely on Article 6(1)(f) GDPR for cookieless processing. Our legitimate interest is aggregated measurement of reach, booking success and technical errors using limited data, and checking that consent decisions are implemented correctly. In particular, we take account of the fact that, according to our configuration, no analytics or advertising cookies or device identifiers are read or written, and advertising click identifiers are redacted. You may object to this processing on grounds relating to your particular situation under Article 21 GDPR using the contact details under “Controller”.
The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other group companies in the USA is possible. Transfers may rely on the adequacy decision for the EU-US Data Privacy Framework for certified recipients and, additionally, the EU standard contractual clauses. Further information and links appear in the following Google sections.
Google Tag Manager
We use Google Tag Manager (container ID GTM-5H7K3TD) to technically control the analytics and marketing services described below. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The container is loaded after the default denied signals have been set. Google tags with built-in consent checks adapt their processing to those signals. Other tags may be triggered only after the consent they require has been given. The Meta Pixel remains independently blocked until you consent to marketing.
Google Analytics 4
With your consent to statistics, we use Google Analytics 4 (measurement ID G-YFS5S1YKJF) with analytics storage. The service helps us understand which pages and booking steps are used, where visits end, and where loading or functional problems occur. Without consent to statistics, Google Analytics receives only the cookieless consent and measurement pings described above; we send our own detailed funnel, booking and performance events only after you consent to statistics.
Processing may include, in particular, page views, clicked booking actions, calendar and time selection, starting and submitting a booking, successful bookings, abandonment, the chosen offer, date and time, participant number, price, and technical load-time and Web Vitals measurements. Google also processes device and browser information, approximate location information and a client ID stored in cookies. Our tracking implementation does not transmit names, email addresses, telephone numbers, booking references or free-text fields to Google Analytics.
The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. The provider is Google Ireland Limited; processing by Google LLC and other group companies in the USA is possible. Google states that it does not log or store EU users’ IP addresses before storing Analytics data. Transfers to the USA may rely on the adequacy decision for the EU-US Data Privacy Framework for certified recipients and, additionally, the EU standard contractual clauses.
Depending on the setting, user and event data in a standard GA4 property may be retained for two months or a maximum of 14 months; aggregated standard reports may remain available longer. According to the provider, Google’s analytics cookies normally last for up to two years unless your browser limits them earlier or you withdraw consent.
Further information: Google’s privacy policy and information about EU data processing in Google Analytics.
Google Ads and conversion measurement
After you consent to marketing, we use Google Ads functions (account 158-623-0693) to measure whether advertisements lead to website visits or bookings, evaluate campaigns and, where activated, create audiences for interest-based advertising. Google click identifiers, cookie and device identifiers, page and event data, and booking events including value and selected offer may be processed and linked to our Google Ads account. Without marketing consent, advertising storage, advertising user data and personalisation remain denied; only the cookieless, redacted pings described above are possible. Our tracking implementation does not transmit names, email addresses or telephone numbers to Google Ads.
The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. The provider, possible recipients and transfers to third countries are as described in the Google Analytics section. You may withdraw your choice at any time using the “Cookie settings” button. You can also manage personalised advertising in Google’s advertising settings.
Meta Pixel
After you consent to marketing, we use the Meta Pixel (pixel ID 469805955715663). The provider for users in the European Economic Area is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The pixel helps us measure whether advertisements on Facebook or Instagram lead to visits and bookings, evaluate campaigns and create audiences for interest-based advertising.
Meta may process page views, interactions and booking events, browser and device information, IP address, referrer, cookie and device identifiers and, where applicable, a Meta click identifier. If a person is logged into Facebook or Instagram, Meta may be able to link the information to their account. Our pixel implementation does not transmit names, email addresses, telephone numbers, booking references or free-text fields to Meta.
The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Insofar as Meta and we jointly determine the collection and transmission of event data, we are joint controllers under Article 26 GDPR; Meta handles data subject rights relating to its subsequent processing. Processing by Meta Platforms, Inc. and other recipients in the USA is possible. For this, the adequacy decision for the EU-US Data Privacy Framework for certified recipients and, additionally, the EU standard contractual clauses may be used.
Further information: Meta’s privacy policy and Controller Addendum. You can manage interest-based advertising settings in your Facebook or Instagram account.
For confirmed bookings, our measurement function generates a random transaction identifier for the consented analytics or marketing event. A hash derived locally from the booking reference is used only to prevent duplicate counting. Neither the booking reference nor that local hash is transmitted to Google or Meta by this function.
7. Contacting us
If you contact us through a contact form, by email, telephone or post, we process your contact details and the content of your enquiry to handle your request. If the enquiry concerns a contract or steps towards a contract, the legal basis is Article 6(1)(b) GDPR. In other cases, processing is based on our legitimate interest in appropriate and efficient communication under Article 6(1)(f) GDPR, or on your consent under Article 6(1)(a) GDPR where we expressly request it.
We delete enquiries once the matter is concluded and no statutory retention duties or legitimate grounds for further storage remain. Communication relevant to contracts or business may be retained for the statutory periods.
Email hosting by Host Europe
We use the mail servers of Host Europe GmbH, c/o Spaces, Gertrudenstraße 30–36, 50667 Köln to receive, send and store business emails. This concerns in particular messages to and from addresses under onehourleft.de and emails sent in connection with contact enquiries, bookings and booking confirmations.
Processing may include sender and recipient addresses, name, subject, message content, attachments, date and time, technical headers, IP and server information, and delivery, error, spam and security data. Host Europe processes this data insofar as necessary for transport, storage, delivery, spam and malware filtering, and secure operation of the mail servers.
Depending on the content, processing takes place to prepare or perform a contract under Article 6(1)(b) GDPR, or on the basis of our legitimate interest in reliable, secure and efficient business communication under Article 6(1)(f) GDPR. Where statutory retention obligations exist, Article 6(1)(c) GDPR is an additional legal basis.
We retain emails for as long as necessary for communication, contract handling and statutory evidence. Technical transport and security logs are deleted once they are no longer required for delivery, error analysis and system protection, unless a security incident or statutory obligation requires longer retention. Further information is available in Host Europe’s privacy policy.
If you click a WhatsApp link or contact us through WhatsApp, you open a service provided by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Data is transmitted to WhatsApp or Meta; this may include processing in the USA. We receive the telephone number you use, visible profile information and the content of your message. Please do not use this channel for particularly confidential information. Depending on the content, our processing is based on Article 6(1)(b) or (f) GDPR. Use is voluntary; you can alternatively contact us by email or telephone. WhatsApp’s privacy information also applies.
8. Newsletter
If you subscribe to our newsletter, we process your email address and, where applicable, your name and technical records of registration to send the newsletter and demonstrate your consent. The legal basis is Article 6(1)(a) GDPR; storing evidence of consent is additionally based on Article 6(1)(f) GDPR. Our legitimate interest is demonstrating a proper registration.
To send and manage our newsletter, we use Brevo, a service of Brevo GmbH, Köpenicker Straße 126, 10179 Berlin (formerly Sendinblue GmbH). Your email address, your name where applicable, and registration, confirmation, unsubscribe and sending data are transmitted to Brevo. Brevo processes this data on our behalf for double opt-in, mailing list management, sending and technical delivery of the newsletter.
We have concluded a data processing agreement with Brevo under Article 28 GDPR. According to Brevo, the hosting servers on which it processes and stores databases are located within the European Union. Further information is available in Brevo’s privacy policy.
You can unsubscribe from the newsletter at any time using the unsubscribe link in each message or by contacting us. After withdrawal, we delete your data from the active mailing list. A limited suppression or evidentiary record may remain stored insofar as necessary to prevent further messages or defend against claims.
9. External links
The directions map on our pages is our own map extract stored on our server. No connection to a map service is established when you open the page, and no personal data is transmitted to Google or other third parties for it. The map extract is based on OpenStreetMap data (© OpenStreetMap contributors).
Our website also contains links to third-party services, including Google Maps and our social media profiles. Until you click such a link, the mere presence of the link does not generally establish a connection to the third-party provider. After clicking, the destination provider’s privacy terms apply. Use of external links is voluntary and is not required to use the rest of our website.
10. Locally provided web fonts
The fonts used on this website are delivered locally from our own web server. Loading the fonts therefore does not establish a connection to Google Fonts servers.
11. Recipients and transfers to third countries
Within our company, only persons who need personal data for their tasks have access to it. External recipients include, in particular, STRATO GmbH for website, server and software hosting, Host Europe GmbH for email services, booking service provider iMi digital GmbH, Brevo GmbH for newsletter sending and mailing list management, Google for the cookieless consent and measurement pings described and for further statistics and marketing processing, and Meta for marketing processing. Authorities, courts, tax advisers or other bodies receive data only where required by law or necessary to establish, exercise or defend legal claims.
Services from Google, Meta and WhatsApp may involve processing outside the European Union or European Economic Area. Transfers take place only if the requirements of Articles 44 et seq. GDPR are met, particularly on the basis of an adequacy decision such as the EU-US Data Privacy Framework for certified recipients, or appropriate safeguards such as the European Commission’s standard contractual clauses. Despite such safeguards, different access and legal protection arrangements may exist in third countries.
12. Your rights
Subject to the statutory requirements, you have the rights of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR and data portability under Article 20 GDPR. You may withdraw consent at any time with prospective effect under Article 7(3) GDPR.
Right to object: Where processing is based on Article 6(1)(e) or (f) GDPR, you may object at any time on grounds relating to your particular situation under Article 21 GDPR. You may object to direct marketing and associated profiling at any time without giving reasons.
To exercise your rights, send a message to team@onehourleft.de. We may request suitable evidence if we cannot otherwise reliably establish your identity.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is in particular the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, www.lda.bayern.de. You may also contact another competent supervisory authority.
13. Security, required information and automated decisions
We protect transmission of this website using TLS encryption and take appropriate technical and organisational measures to protect your data. Providing personal data is generally voluntary. However, we need information marked as required in the booking process to make the booking and perform the contract.
We do not make solely automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR on the basis of data collected through this website.
14. Keeping this privacy policy up to date
We update this privacy policy when our data processing activities or legal requirements change.
Last updated: 12 September 2026
