Listings Alerts DE | EN Login
DE | EN

Privacy Policy

Last updated: 30 September 2026.

Personal data actually processed

Administration account and login

The database stores an administrator email address, a password hash, enabled status, and record timestamps. Plain-text passwords are not stored by the application.

Alerts and preferences

Telegram alerts store the linked Telegram user, the alert name, whether the alert is active, the selected event types (newly detected, updated, available again) and the chosen filters: providers, federal states or postal codes, rooms, rent, living area, financing contribution and an “available from” window. Older alerts may instead contain the earlier fields (postal codes, room, area, rent and contribution limits, keywords). This data is stored in PostgreSQL.

When you remove an alert or send /stop to the bot, the alert with its filters and its delivery log are deleted immediately, not just hidden.

The operator can view and manage saved alerts to run the service, fix delivery problems and help when you ask. Other users cannot see your alerts.

Telegram notifications

When a person interacts with the bot, the application can store the Telegram chat ID, username, first/display name, enabled status, alerts, delivery status and attempts, Telegram message ID, error message, and timestamps. Telegram receives the chat ID, notification text, and original listing URL when a message is sent. To connect Telegram, the website creates a one-time link that is valid for 10 minutes and deleted when used; only a SHA-256 hash of the link is stored, together with the filters and alert name you chose. After you confirm in Telegram, this browser can manage your alerts for 7 days.

Telegram delivery is configured in this deployment.

Housing listing data

The application stores factual data obtained from public provider pages, including source identity and URL, title, project, address, district/postal code, rooms, area, rent, financing contribution, availability, published/detection timestamps, status, change history, and selected raw parse fields. Map coordinates are derived locally from the Austrian address register, and each coordinate records which register snapshot placed it. It does not deliberately collect applicant profiles, but public source fields could incidentally contain information relating to an individual.

Technical and security logs

The current web server can log client/network address, request method and path, protocol, response status, and time. Application logs record crawler and notification operations, identifiers, status, and errors. The production host or reverse proxy may create additional logs; the operator must verify the final configuration.

First-party usage statistics

The application records page views and clicks on housing listing cards in its own PostgreSQL database. Each event contains a random anonymous browser identifier, event type, page path, timestamp, the device type (desktop, tablet or phone), and, for a listing click, the internal listing ID.

The random identifier is generated in the browser and remains in localStorage until browser storage is cleared. No third-party analytics service receives these events.

The analytics event does not contain a name, email address, Telegram identifier, device fingerprint, or deliberately collected IP address. Normal server and reverse-proxy access logs may still process network addresses as described above.

Legal review is advisable before public use. Browser storage can be subject to EU ePrivacy requirements even when it is not a cookie; the operator must determine whether prior consent and a consent interface are required.

Cookies and browser storage

An essential signed session cookie is set when an administrator signs in or when the alert pages are used. It contains a CSRF protection token and, depending on use, an administrator ID or the internal ID of the connected Telegram account with its 14-day access expiry and an unsaved alert name. It is not used for analytics, is HTTP-only, SameSite=Lax and Secure, and expires after 14 days at the latest. Browsing listings, the map and the information pages does not set it.

The essential gewosniper_locale cookie remembers DE or EN for one year. It is HTTP-only, SameSite=Lax, and Secure in production.

The frontend stores the selected light or dark appearance and a random anonymous statistics identifier locally in the browser. It contains no advertising, profiling, or third-party marketing tracker.

No consent banner is currently displayed. The operator must complete the legal review described above and add prior consent before public use if required.

Maps and geocoding

The map view (on the listings page and at /map) loads map images (tiles) from basemap.at, the public-sector base map of the Austrian federal states, delivered from City of Vienna servers (mapsneu.wien.gv.at). When you open the map, your browser requests these tiles directly, so that server receives your IP address, browser details and the visible map area. gewosniper.at sends no listing or personal data there. Listing addresses are matched against a local copy of the Austrian address register (BEV, open data); listings whose address cannot be matched exactly are placed in the middle of their street or at the centre of their postal code (GeoNames and Stadt Wien open data). No address is sent to any geocoding service. The map library (Leaflet) is served from this website and is only loaded when the map is opened; the list view loads no map content.

Google Maps and Google Geocoding are not used. Coordinates that an earlier development version had cached were deleted; listings and addresses were kept.

The current application does not request the user's device location or browser geolocation.

Provider disclaimer

gewosniper.at is not affiliated with the listed housing providers unless explicitly stated. It does not guarantee availability, eligibility, completeness, or accuracy. The original provider listing is authoritative, and applications must be completed with the provider.

Housing-provider websites receive server-side crawler requests with an identifiable gewosniper.at user agent. Alert or administrator account data is not intentionally sent to those providers.

Automated matching

Alerts automatically compare listing facts with user-selected filters and may queue a notification. The current system does not make decisions that allocate housing or determine legal eligibility.

gewosniper.at is an independent monitoring service and is not affiliated with the listed housing providers. Information may change. Applications must be completed on the official provider website.

Imprint Privacy About Providers at a glance