Privacy notice
This notice explains which personal data astrometrik.com processes, why, and for how long. We use no analytics, no advertising and no tracking, and we never handle payments.
1. Who is responsible
The website astrometrik.com ("Astrometrik", "we") is run by a private individual:
Alper ÇEVİK
Schnirchgasse 11/ 810 1030 Wien
Austria
Email: info@astrometrik.com
We have no data protection officer, because the law does not require one for a website of this kind. For all questions about your data, write to the email address above.
2. Two roles: us and the event organisers
Astrometrik is a free website with sky data and a calendar of astronomy events. Clubs, observatories, planetariums, universities and associations ("organisers") can use free tools on the site to publish events, take registrations and run the event on the day.
Who is responsible for your data depends on the data:
- We are the controller for the website itself: the public calendar, the sky features, the game, organiser accounts, the notification system and security.
- The organiser of an event is the controller for attendee data of that event: registration, check-in, photos and comments on that event, SOS messages, the event's hunt ranking and notification subscriptions for that event. We process this data only on the organiser's behalf, under a data processing agreement.
You can send requests about event data to the organiser or to us. If you write to us, we forward your request to the organiser and help to answer it.
3. What we do not do
- No analytics, no advertising, no tracking pixels.
- No social media plugins. Share buttons are plain links; nothing is sent until you click one.
- No external font services: our fonts come from our own server.
- No payments: we never take, hold or process money.
- No newsletters and no marketing emails.
- No automated decisions and no profiling.
4. Overview
The table shows what we process, why, on which legal basis under the GDPR, and for how long. Details follow in the next sections.
| Data | Purpose | Legal basis | How long |
|---|---|---|---|
| Server logs: IP address, time, requested URL, browser type | Running the website, security | Art. 6(1)(f): our interest in a safe, working website | the period set by the hosting provider |
| Salted hash of the IP address plus the action | Stopping abuse (rate limiting) | Art. 6(1)(f) | 2 days |
| Device ID (on the server only as a salted hash) | Recognising the same device; letting you delete your own data | Art. 6(1)(f) | Cookie 2 years; removed from event data 30 days after the event |
| Registration: name, email, number of people, language, time, status, arrival time and how, "paid" note | Taking part in the event, ticket, waiting list, event emails | Art. 6(1)(b): taking part in the event you asked for | Name and email erased 30 days after the event |
| Photo and/or comment, optional nickname | Event wall and summary page | Art. 6(1)(a): consent | Until deleted; posts never approved: 30 days after the event |
| SOS message, optional location | Getting help from the organiser | Art. 6(1)(d) and (f) | 30 days after the event |
| Hunt at an event: optional nickname, score, found objects | Game and public ranking | Art. 6(1)(f) | Ranking stays; link to your device removed 30 days after the event |
| Daily game: score per device; name, city and catches only if you opt in | Game and ranking | Art. 6(1)(f); opt-in data: Art. 6(1)(a) | 90 days, or until you choose "forget me" |
| Push notifications: push address, link to event or ticket, language | Sending the notifications you switched on | Art. 6(1)(a): consent | Until you switch them off; event links 30 days after the event |
| Emails and internal notification log | Event emails, "My data" access link | Art. 6(1)(b) | Log 30 days; queued push messages 3 days |
| Organiser account data | Checking the applicant, running the account | Art. 6(1)(b) | While the account exists; rejected applications 90 days |
| Public information about organisations and their events | Public calendar and organiser pages | Art. 6(1)(f) | While shown; corrected or removed if you object |
5. Your location
The sky map, ISS passes and similar features use your device's location only inside your browser. It is not sent to us.
Your location reaches our server only if you choose one of these options:
- "I've arrived" with ticket and location: we check whether you are within 2 km of the venue. We store only the result (yes or no), not your coordinates.
- SOS message with location ticked: your coordinates, rounded to about 1 metre, are shown to the organisers of that event.
- Game ranking or map with "show my city and photos" ticked: we store your city, rounded to about 10 km.
6. Device ID
Your browser creates a random device ID. It is kept in the cookie astro_dev and in the browser storage (localStorage astro-game-dev) for 2 years. Our server stores only a salted hash of it.
We use it only to recognise the same device for check-in, posts, hunt scores and notifications, and so that you can see and delete your own data on My tickets & my data. We do not use it for tracking or profiling.
7. Event registration and tickets
If the organiser has switched registration on, we process your name, email address, number of people, language, time of registration, status (registered, waiting list, cancelled), arrival time and how you checked in, and a "paid" note that the organiser may set.
We use this data to:
- let you take part and give you a ticket;
- run the waiting list;
- send reminder emails 24 hours and 3 hours before the event;
- deliver the organiser's messages to registered guests (at most 3 per day per event);
- tell you if the event is changed or cancelled.
The organiser sees your name, email address, number of people, arrival and the "paid" note, and can download them as a CSV file. The organiser is responsible for files it downloads.
Your ticket link is saved on your device in the cookie astro_tk_<event> (httpOnly, 400 days), so you can open your ticket again.
Payment: for paid events, the organiser tells you how to pay: at the venue, on the organiser's own ticket or payment page, or by bank transfer to details the organiser enters. Such bank details are shown only on your ticket and in the email. The "paid" mark is only a note by the organiser. Prices, receipts, invoices and refunds are a matter for the organiser.
8. Photos and comments
At some events you can post a photo and/or a comment, with an optional nickname. Only people who have checked in or have a ticket can post.
- The organiser must approve a post before it becomes public.
- If a post is reported three times, it is hidden again.
- We re-encode every uploaded image. This removes embedded metadata such as GPS location and camera data (EXIF).
The legal basis is your consent: you tick a box confirming that you may share the picture and that the people shown in it agree. You can withdraw by deleting your post from the same device on My tickets & my data, or by asking us or the organiser. Approved posts stay on the event's summary page until they are deleted by you, by the organiser or on request.
9. SOS button
At an event you can send an SOS message to the organisers. You can add a text and, if you tick the box, your location. The organisers of that event see the message in their panel and receive it as a push notification.
The SOS button is not an emergency service. In an emergency, call the emergency number shown on the page (112 in the EU and in Turkey).
Legal basis: Art. 6(1)(d) GDPR (protecting vital interests) and Art. 6(1)(f) (safety at the event). SOS messages are deleted 30 days after the event.
10. Sky hunt game
Hunt at an event
You play with an optional nickname. We store your score and the objects you found. The ranking with nicknames is public on the event page. 30 days after the event, the link between the results and your device is removed.
Daily game on the website
We store a score per device. Your name, your city (rounded to about 10 km) and your catches are stored and shown only if you opt in. Data of the daily game is kept for 90 days. You can delete it at any time in the game with "forget me".
11. Push notifications
Notifications are optional. You switch them on yourself and can switch them off at any time in your browser or on the page.
We store your browser's push address (endpoint), the link to the event or ticket, and your language.
To deliver a notification, we send only an empty "wake-up" signal through the push service of your browser's vendor. Your browser then fetches the text from our server, so the push service does not see the content. Your browser decides which service is used:
- Chrome and Android: Google Firebase Cloud Messaging
- Safari and iOS: Apple Push Notification service
- Firefox: Mozilla autopush
- Edge: Microsoft
These services may process technical data (the push address and the IP address of the push request) in the USA, under their own terms. No notification content passes through them. Legal basis: your consent, Art. 6(1)(a) GDPR.
12. Calendar files and emails
"Add to calendar" creates a .ics file on our server. It contains only public event data. The optional "Google Calendar" link sends event data to Google only when you click it.
Emails are sent through the email service (SMTP) of our hosting provider Hostinger International Ltd.. As an attendee, you only receive emails about events you registered for, and the "My data" access link when you ask for it.
13. Organiser accounts
If you apply for or manage an organiser page, we process your name, role, email address, optional phone number, optional proof link and note, your password (stored only as a strong hash), language, and the date and version of the terms you accepted.
Purpose: checking that you may act for the organisation, and running your account. Legal basis: Art. 6(1)(b) GDPR. We keep the data while the account exists. Rejected applications are deleted after 90 days. When an account is closed, its personal data is deleted; the organisation's public event pages can stay.
14. Information from public sources
Some organiser pages and calendar entries come from public sources, such as organisation websites and public announcements. We show the source link next to them. This is information about organisations and their public events. The legal basis is Art. 6(1)(f) GDPR: our interest in a useful public calendar of astronomy events.
If you find your personal data there, you can object (Art. 21 GDPR). We will then correct or remove it.
15. Cookies and browser storage
We only use cookies and browser storage that are strictly necessary for functions you use. Under Austrian law (§ 165(3) TKG 2021), no consent is needed for this, so we show no cookie banner.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| astro_dev | Cookie | Device ID | 2 years |
| astro_tk_<id> | Cookie (httpOnly) | Your ticket link | 400 days |
| astro_ev | Session cookie | Only when logging in to the organiser panel or admin area | Until the browser is closed |
| astro-game-dev | localStorage | Device ID | 2 years |
| astro-ev-nick | localStorage | The nickname you typed | Until you clear it |
| astro-ch | localStorage | A hunt in progress | Until you clear it |
| astro-push | localStorage | Notification state | Until you clear it |
| Game settings, today's score | localStorage | The game | Until you clear it |
16. Automatic deletion
An automatic job runs hourly and daily and deletes data on this schedule.
30 days after an event ends:
- names and email addresses of registrations are erased; only anonymous counts stay for the organiser's statistics;
- names at check-in are removed;
- device pseudonyms in check-ins and hunt results are replaced;
- SOS messages are deleted;
- posts that were never approved are deleted;
- push links to the event are deleted.
Other periods: internal notification log 30 days; queued push messages 3 days; rate-limit data 2 days; daily game data 90 days. The hosting provider deletes server logs after the period set by the hosting provider.
Approved photos and comments stay on the event's summary page until they are deleted by the author, the organiser or on request.
17. Recipients and transfers
- Hosting: Hostinger International Ltd. stores the website and database and sends our emails. Data is stored in the EU/EEA, in Germany, Dusseldorf.
- Organisers: the organiser of an event receives that event's data as described above.
- Push services: see section 11.
- Google: only if you click the "Google Calendar" link.
If the organiser of an event is outside the EU/EEA (for example in Turkey), the registration data of that event is made available to that organiser. This is necessary for you to take part in their event (Art. 49(1)(b) GDPR).
18. Security
- HTTPS only.
- Passwords are stored only as strong hashes.
- Ticket and access links are signed and cannot be guessed.
- The database and data folder cannot be reached from the web.
- Every uploaded image is re-encoded; this removes metadata and hidden code.
- Protection against forged form submissions, limits on login attempts and on repeated actions.
- Each organiser sees only the data of its own events.
- In our own tables, IP addresses are stored only as salted hashes.
- Backups are made by the hosting provider.
- Only the operator can access the admin area, with an individual password.
19. Age and automated decisions
You must be at least 14 years old to post photos or comments or to use a public nickname (§ 4(4) DSG, Austria). Younger people need the consent of a parent.
We make no automated decisions and do no profiling.
20. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw your consent at any time; this does not affect processing that happened before.
The quickest way is My tickets & my data. There you can:
- see the tickets saved on this device;
- switch notifications off;
- delete the data of this device;
- enter your email address and receive a link (valid 24 hours) that lists all registrations with that email address, lets you download them (JSON) and delete them.
You can also write to info@astrometrik.com. For event data you can also contact the organiser.
21. Complaints
You can complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, www.dsb.gv.at) or to the authority where you live or work.
People in Turkey can also contact the organiser of the event as data controller under the Turkish data protection law (KVKK) and the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).
22. Changes to this notice
We update this notice when our processing changes. The current version and its date are shown below.
Version 2026-10 · 2026-09-29