Privacy Policy for Next Level Order Engineering

Effective Date: June 08, 2026

Provider (Controller): Next Level Order Engineering UG (haftungsbeschränkt)

Applies to: Websites, web apps, mobile apps, and related online services operated by Next Level Order Engineering UG (haftungsbeschränkt) that link to this Privacy Policy

This Privacy Policy explains how personal data is collected, used, and shared when you use our websites, web apps, mobile apps, and related online services. If you do not agree with this policy, please do not use those services.

1. Introduction

Next Level Order Engineering UG (haftungsbeschränkt) ("we", "our", "us") respects your privacy and is committed to protecting it. This Privacy Policy describes how we process personal data when you use websites, web apps, mobile apps, and other digital services that we own or operate and that link to this Privacy Policy (collectively, the "Services").

We may operate the Services across multiple domains, subdomains, country-specific domains, branded domains, and application endpoints. This Privacy Policy applies to those Services when they reference or link to this policy, even if the specific domain changes over time.

Some of our websites are hosted or delivered through Squarespace. For those websites, Squarespace may process visitor data on our behalf and for certain purposes described in Squarespace's own privacy documentation.

Product-specific features. Some Services store data locally on your device by default, while others rely on hosted infrastructure. Data is only transmitted to online services when required to provide the Service, when you enable a feature, or when you consent where consent is required.

2. Information We Collect

Depending on how you use the Services and your privacy choices, we may collect the following types of information:

3. How We Use Your Information

We use personal data for the following purposes:

4. Legal Bases for Processing (EEA/UK/Switzerland)

If you are located in the European Economic Area (EEA), the UK, or Switzerland, we rely on these legal bases where applicable:

5. How We Share Information

We do not sell your personal data. We may share data in the following cases:

6. Your Choices and Controls

You can control how your data is handled in several ways:

7. Data Retention

We retain personal data only as long as necessary to provide the Services, fulfill the purposes described in this policy, and comply with legal obligations.

Website cookies, local storage entries, and consent records may remain on your browser or our systems for different periods depending on their purpose, your consent choices, and the default expiration periods set by our providers such as Squarespace.

If you enable cloud sync or cloud sharing, we retain synced content, sharing records, metadata, quota records, and related technical data only as long as necessary to provide the feature, maintain account integrity, comply with legal obligations, resolve disputes, prevent abuse, or as otherwise described in the app. If you disable cloud sync or sharing, delete shared content, or delete your account, we will stop the relevant processing and delete or de-identify associated service data within a reasonable period, subject to technical backups and legal or security retention requirements.

Local reminders. Reminder records and related scheduling data remain on your device until you delete them, remove the app data, or replace them through backup/restore or similar device-level actions.

Remote push tokens. If remote push is enabled, we may retain the current push token, platform, associated account identifier (if any), and related registration timestamps while the token remains active and reasonably needed for delivery, fraud prevention, troubleshooting, or compliance. If you opt out in the app, we attempt to deactivate the token. If you delete your account, we also deactivate or remove push-token records linked to that account as part of account cleanup. Invalid or stale tokens may also be deactivated operationally when delivery receipts indicate they no longer work.

AI and barcode data. Images, text, or other content you submit for AI or barcode processing is deleted from our servers upon completion of the request, or if the request cannot be fulfilled, within at most 48 hours.

If you disable tracking, we limit processing to the minimal technical data required for the Services to function and remain secure, except where certain strictly necessary cookies or storage technologies are required.

If a website is hosted on Squarespace, certain visitor data and strictly necessary cookies may still be processed by Squarespace in order to securely deliver the website, operate core functions, and protect the platform, even when non-essential analytics or advertising cookies are not enabled.

7A. Squarespace Commerce Status

We do not currently sell products or services through Squarespace checkout. As a result, Squarespace-specific commerce processing such as store checkout data, customer account data, shipping data, invoicing data, or Squarespace Payments processing does not currently apply to our Squarespace-hosted websites unless and until we enable those features in the future.

If we later enable Squarespace commerce or related transaction features, we may update this Privacy Policy to describe the additional categories of data collected and the third parties involved.

8. Security

We use reasonable technical and organizational measures to protect your data from unauthorized access, loss, misuse, or alteration. However, no system can be guaranteed 100% secure.

Please note that network communications may be logged by infrastructure providers as part of standard operations. We take steps to reduce and protect such data where feasible.

9. International Data Transfers

Because we use service providers such as Squarespace, Firebase, Google services, and potentially other providers for AI, barcode lookups, cloud sync, or cloud sharing, your data may be processed on servers located outside of your country, including the United States.

Where required by law, we rely on appropriate safeguards for cross-border transfers (such as contractual protections).

10. Children’s Privacy

Our Services are not directed to children under the age of 16. We do not knowingly collect personal data from children. If we learn we have collected such data, we will delete it.

11. Your Rights

Depending on your location, you may have rights such as access, correction, deletion, restriction, objection, and data portability. You may also withdraw consent at any time where processing is based on consent (e.g., optional analytics/ads), without affecting processing that occurred before withdrawal.

To exercise rights, contact us using the details below. We may need to verify your identity before fulfilling requests.

12. Account Deletion

If a Service offers user accounts and account deletion, you can request deletion using the instructions provided in that Service or on the relevant support page. For services that use the Containd deletion flow, the current instructions are available here: Information about account deletion .

For Containd services that support remote push notifications, account deletion also triggers deactivation of the current push token before the account is deleted, and we also clean up any remaining account-linked push-token records on the backend within a reasonable period.

Because we operate across multiple domains and products, account deletion workflows may differ by Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be communicated within the relevant Service, on our website, and/or by updating this page. The “Effective Date” at the top will reflect the latest version.

14. Contact Us

If you have questions or concerns about this Privacy Policy, please contact:

Next Level Order Engineering UG (haftungsbeschränkt)
Email: policies@nextlevelorderengineering.com


Last updated: June 08, 2026