Logo Lola Market
DE

Privacy Policy

Last updated: 12.08.2026

This version has applied since 25.08.2026. The previous policy remains available in the archive. This is a translation of the German original; in case of discrepancies, the German version prevails.

1. General
At LOLA market FlexCo, Lindengasse 56/18-19, 1070 Vienna ("LOLA", "we", "us"), the protection of your personal data is an important concern. Compliance with data protection provisions, in particular the General Data Protection Regulation ("GDPR"), the Austrian Data Protection Act ("DSG") and the Telecommunications Act 2021 ("TKG 2021"), is therefore a matter of course for us.

This privacy policy informs you about the nature, scope and purposes of the collection and processing of your personal data in connection with visiting and using our website (lola.market) and our app (LOLA market).

2. Details of the controller
Name: LOLA market FlexCo
Address: Lindengasse 56/18-19, 1070 Vienna, Austria
Companies Register number: FN 655577i, Commercial Court of Vienna
Email address: [email protected]

3. What is personal data?
Personal data is information about data subjects (natural persons) whose identity is determined or at least identifiable (e.g. name, email address or IP address).

4. What data do we collect from people who visit or use our website?

4.1 Contacting us
Data categories and purpose: If you contact us using the contact details given above or via the contact form, we process your personal data (name, email address or telephone number as well as the content of your enquiry and any further correspondence relating to it) for the purpose of handling and answering your enquiry.
Legal basis: The legal basis is the performance of our (pre-)contractual obligations pursuant to art 6(1)(b) GDPR and our legitimate interests pursuant to art 6(1)(f) GDPR in dealing promptly with and responding to any queries.
Retention period: We store your data in connection with enquiries for a period of six months so that we can respond appropriately to follow-up questions. Longer storage takes place only where a business relationship subsequently arises, or on the basis of statutory retention obligations, or for the defence of potential legal disputes.

4.2 Newsletter
Data categories and purpose: If you have subscribed to our newsletter about our services and offers, we process your email address and the open and click rates of the newsletters. We use a service provider established in the EU for sending them.
Legal basis: Processing takes place on the basis of your voluntary and express consent pursuant to art 6(1)(a) GDPR in conjunction with sec 174 TKG 2021. You may withdraw your consent at any time with effect for the future (e.g. by email to [email protected] or via the unsubscribe link included in every newsletter).
Retention period: We process your personal data for the purpose of the newsletter until you withdraw your voluntary consent, but no longer than three years from your last contact with us.

4.3 Social media
Data categories and purpose: You can interact with us on our social media pages by commenting on our posts, reacting to them (e.g. via the "like" button), sharing them or sending them to other users. In doing so, we process your interactions, your username and, where applicable, personal data of invited third parties. This data may also be processed by the platforms in this context. In such cases, the respective platform and we are joint controllers pursuant to art 26 GDPR. We have therefore concluded joint controllership agreements.
Legal basis: The processing serves to answer your questions, to give you the opportunity to express yourself, to respond to your opinions and feedback and to promote our offering. Processing therefore takes place both on the basis of our and your legitimate interests pursuant to art 6(1)(f) GDPR and for the performance of our (pre-)contractual obligations pursuant to art 6(1)(b) GDPR.
Further information on the data processing carried out by the platforms, including retention periods, can be found at:
(1) Facebook: https://de-de.facebook.com/privacy/policy/
(2) Instagram: https://de-de.facebook.com/help/instagram/155833707900388
(3) LinkedIn: https://de.linkedin.com/legal/privacy-policy

4.4 Provision of the website and creation of log files
Data categories and purpose: The following technically necessary data within the meaning of sec 165(3) TKG 2021 is collected automatically when you visit our website, in order to display the website to you and to ensure its stability and security:
(1) information about the browser type and version used,
(2) the user's operating system,
(3) the user's internet service provider,
(4) the user's IP address,
(5) date and time of access,
(6) content of the request (specific page).
Legal basis: All of this data is transmitted by your web browser when you access our website. We process this data solely for the provision of the website and for operational security purposes, and it is therefore strictly technically necessary within the meaning of sec 165(3) TKG 2021. This processing is therefore based on our legitimate interests pursuant to art 6(1)(f) GDPR and also includes the logging of system use, user authorisation processes and the evaluation of server logs for problem analysis.
Retention period: We generally store your usage data from visits to the website for a period of one year. This data is not stored together with other personal data of the user.

4.5 Cookies
Which cookies we use, for what purpose and on what legal basis can be found on our cookie page. In addition, a banner appears the first time you access our website, via which you can accept or reject analytics and statistics cookies. You can return there at any time via the "Cookies" menu item in the footer of the website and change your decision with effect for the future.

4.6 Protection against misuse
Data categories and purpose: To protect our forms and registration in the app against automated and abusive access, we use a verification procedure. In doing so, your IP address as well as technical information about your browser and device are transmitted and evaluated in order to determine whether the request originates from a person or from an automated system.
Legal basis: Processing is based on our legitimate interests in the security of our systems and in preventing misuse pursuant to art 6(1)(f) GDPR.
Provider: We use a service provider established in the USA for this detection. Regarding transfers to the USA, see the section "International data transfers".
Retention period: The data is processed only for the duration of the check and deleted thereafter.

5. What data do we collect from people who visit or use our app?

5.1 Usage data
Data categories and purpose: The following technically necessary data within the meaning of sec 165(3) TKG 2021 is collected automatically when you use our app, in order to display the app to you and to ensure its stability and security:
(1) the IP address of your device,
(2) language,
(3) operating system and version,
(4) screen resolution, and
(5) data on usage behaviour.
Legal basis: We process this data solely for the provision of the app and for operational security purposes, and it is therefore strictly technically necessary within the meaning of sec 165(3) TKG 2021. This processing is therefore based on our legitimate interests pursuant to art 6(1)(f) GDPR and includes the logging of system use, user authorisation processes and the evaluation of server logs for problem analysis.
Retention period: We generally store your usage data from use of the app for a period of one year.

5.2 Registration of a user account
Data categories and purpose: When you register to use the app or sign in via a single sign-on service (SSO) such as Google, Apple or Facebook, we process your first and last name, your date of birth and your email address in order to provide you with a user account. If you register as a business or as an association, we additionally process the details of your organisation. For the processing of rentals for a fee and in order to fulfil statutory reporting and accounting obligations, we also process your address and, where available, your VAT identification number.
Legal basis: We collect and process this data in order to make our app and our services available to you and to prevent fraud. The legal basis is therefore the performance of a contract and our legitimate interests pursuant to art 6(1)(b) and (f) GDPR.
Retention period: We generally process registration data for as long as you hold an active account with us or until you terminate your contract.

5.3 Analysis of your user behaviour
Data categories and purpose: We process data relating to your use of our services, in particular regarding listings posted and viewed, search histories, functions used and — where activated — location data. This data is collected in part automatically and serves to improve our services, to prevent fraud and to personalise the presentation of content and listings (e.g. displaying recently searched content or sorting listings by distance as part of the proximity search). You can enable or disable the transmission of location data at any time in the settings of your mobile device. We analyse usage data in order to produce statistics and market trends and to develop our services further. On the basis of your user behaviour and preferences, we provide you with personalised content and recommendations.
Legal basis: Processing takes place on the basis of your voluntary consent pursuant to sec 165 TKG 2021 in conjunction with art 6(1)(a) GDPR. You may withdraw your consent at any time, without giving reasons and with effect for the future, via our contact form or by email to [email protected].
Provider: We use self-hosted analytics software whose provider is established in New Zealand.
Retention period: Data in this context is processed only for as long as consent exists and the data is necessary for the purpose. Upon withdrawal of consent, and where processing is no longer necessary for the purpose, the data is deleted without delay.

5.4 Statutory reporting and retention obligations
Data categories and purpose: Where the statutory thresholds under the Austrian Digital Platform Reporting Act (DPMG) are reached (30 transactions or EUR 2,000 total turnover per calendar year), we are obliged to report your identification and transaction data to the Austrian tax authority within the prescribed period. This includes in particular name, address, date of birth, tax identification number or VAT identification number, and the amounts earned through the app.
Legal basis: Processing takes place in order to fulfil a legal obligation pursuant to art 6(1)(c) GDPR.
Retention period: We retain the information reported to the tax authority for ten years after the end of the relevant reporting period (sec 15(3) DPMG). Receipts and payment data are subject to retention periods under tax and accounting law of generally seven years.

5.5 Use of services
Data categories and purpose: Depending on your use of our app, we also process the following data:
(1) If you post listings as an "offer" or "search listing", we process the details you provide (details of the product, description, photos, transaction type, price, category and validity date for a "search listing") in the app and may also place this content on our social media pages. Optional details such as the serial number are stored exclusively for you as the creator and are not visible to other users.
(2) We process data on your past product searches and the transactions you have carried out in the areas of "sale", "giving away", "rental" and "free rental".
(3) If you participate in groups, we process your membership of them and your activities.
(4) If you voluntarily share your location, we also process this and will show you listings near you. This is not mandatory in order to use the app. When handing over and returning a rental item, you can additionally share your location specifically with the other person involved so that you can find each other at the meeting point. This sharing takes place only when you expressly trigger it and applies only to the transaction concerned.
(5) If you use the chat function, we process the content of your messages as well as the details of the participants and the time, in order to enable communication between you and other users. In chats relating to rentals we add automatically generated system messages about the status of the transaction.
(6) Following the completion of a rental, the parties involved may review one another. The review consists of ratings in several categories and a text; it is assigned to your user account and is visible to other users once both sides have submitted a review or the review period has expired. A submitted review cannot be withdrawn. If you delete your user account, the reviews you have submitted and received are retained; the link to your account is removed in the process.
Legal basis: We collect and process this data in order to make our app and our services available to you. The legal basis is therefore the performance of a contract pursuant to art 6(1)(b) GDPR and our legitimate interests pursuant to art 6(1)(f) GDPR.
Retention period: We generally process registration and account data for as long as you hold an active account with us or until you terminate your contract. You can also delete your listings yourself in the app at any time. You can likewise remove your membership of groups in the app at any time.

5.6 Payment processing for rentals for a fee
Data categories and purpose: If you book a rental for a fee or offer one, we process the data required for processing it: the service booked, the period, the amounts including the service fee and VAT, the payment status and the associated receipts. Your payment details are entered on a page provided by our payment service provider; we neither collect nor store complete card details. We receive only the payment method, the last digits of the card and its expiry date. If you rent out items for a fee, verification with the payment service provider is required in order for payouts to be made. In doing so, the provider processes the data required for identity verification as well as your bank details. We receive the status of this verification and the information as to whether a payout is possible. Where a payment is subsequently charged back, we additionally process the details of that event. In order to contest the chargeback, we transmit the information documented in the app for the rental — in particular the confirmations of both parties, photos, shared locations and the chat history — to the payment service provider and the payment institutions involved. Where this gives rise to a claim against you, we store its amount, the reason and the related transaction until it has been settled or offset against a payout.
Legal basis: Processing serves the performance of the user agreement and the processing of your booking pursuant to art 6(1)(b) GDPR. Insofar as we are obliged to retain or report data, processing takes place in order to fulfil legal obligations pursuant to art 6(1)(c) GDPR. We have a legitimate interest in preventing fraud and payment defaults, in contesting chargebacks and in asserting the claims arising from them pursuant to art 6(1)(f) GDPR; the transmission also serves the establishment and defence of legal claims.
Provider: Stripe Payments Europe, Ltd., Ireland. Stripe processes payment data in part as an independent controller; for further details see https://stripe.com/privacy. If you choose Klarna as your payment method, the data required for processing is additionally transmitted to Klarna Bank AB (publ), Sweden.
Retention period: For the duration of the performance of the contract and thereafter until the statutory retention periods expire.

5.7 AI-supported functions
Data categories and purpose: When you create a listing, the photos you upload and the details you provide are evaluated automatically in order to generate suggestions for the listing. A photo may show more than the item offered – other people, the surroundings in which it was taken, or legible details on labels and documents. Where such content contains personal data, it is processed along with the rest. Suggestions are made in particular for category and transaction type, condition, title and description as well as product characteristics such as brand, model or main colour; in addition, a price recommendation is generated. The suggestions are non-binding and can be changed or discarded by you at any time. No automated decision in an individual case within the meaning of art 22 GDPR takes place. When you carry out a search, we additionally check which of the listings found match your search query. For this purpose we transmit your search term as well as the title, description and category of the listings found to an AI service; the result determines which matches are highlighted for you. Your user ID is not transmitted in the process.
Legal basis: Processing takes place for the performance of the user agreement pursuant to art 6(1)(b) GDPR and on the basis of our legitimate interests in the quality and completeness of listings pursuant to art 6(1)(f) GDPR.
Provider: For the evaluation of photos and the price recommendation we use Google Ireland Limited, Ireland, and for the generation of text OpenAI Ireland Limited, Ireland. Both providers may also transfer data to their parent companies in the USA; see the section "International data transfers". The AI services used do not use the content transmitted to train their models. They store it only for a short period in order to detect misuse.
Retention period: The details derived from the photos are stored together with your listing and deleted with it.

5.8 Crash and error reports
Data categories and purpose: In order to identify and fix errors and crashes in the app, we process technical error reports. These contain details of the device and operating system, the app version, the time and type of the error and the technical sequence of events leading to it. If you are signed in, your user ID and email address are additionally assigned to the report so that we can attribute recurring errors to an account and help you specifically. A proportion of sessions is additionally evaluated on a sample basis for speed and stability.
Legal basis: Processing is based on our legitimate interests in the stability, security and correct functioning of the app pursuant to art 6(1)(f) GDPR.
Provider: We use a service provider established in the USA; the data is stored in that provider's EU region. Access from the USA cannot be ruled out; see the section "International data transfers".
Retention period: Error reports are deleted after 90 days.

5.9 Notifications
Data categories and purpose: If you activate notifications, we process a device identifier (push token) as well as your notification settings and selected language in order to deliver messages about activity in the app to your device. We also send notifications by email. You can determine in the settings what you are notified about; notifications relating to the processing of an ongoing transaction and to account security are excluded. You can additionally disable push notifications at any time in the settings of your device.
Legal basis: Processing takes place for the performance of the user agreement pursuant to art 6(1)(b) GDPR and on the basis of our legitimate interests in informing you about activity in the app pursuant to art 6(1)(f) GDPR.
Provider: Push notifications are delivered via a service provider established in the USA and via the push services of the operating system manufacturers. For sending emails we use a service provider established in the USA. Regarding transfers to the USA, see the section "International data transfers".
Retention period: We store the push token for as long as you have notifications activated and hold a user account.

5.10 Moderation, restriction and blocking of user accounts
Data categories and purpose: Where we receive a report of a possible breach of our T&C or of the law, or where such a suspicion arises otherwise, we review the content concerned and the associated details of your user account. The review is carried out exclusively manually; no automated decision in an individual case within the meaning of art 22 GDPR takes place. As a result, we may remove content, restrict your user account for future use or block it; we store this status with your user account. If you lodge a complaint against such a measure, we process your complaint and our decision on it. Where rentals are open at the time of a block, we inform the respective other person involved that the transaction can no longer be continued through the app.
Legal basis: The review and the resulting measures are based on the performance of the user agreement pursuant to art 6(1)(b) GDPR and on our legitimate interests in a safe and legally compliant platform pursuant to art 6(1)(f) GDPR.
Retention period: For the duration of the measure and thereafter for as long as this is necessary for the defence of legal claims.

6. Recipients of personal data
We treat your personal data confidentially as a matter of course. We therefore deliberately keep the group of recipients of your data small. To operate our website and app we use service providers who also have access to personal data in order to be able to provide the services commissioned. These include in particular service providers in the following areas:
(1) Payment processing: Stripe, and additionally Klarna where Klarna is used (sec 5.6);
(2) AI-supported functions: Google and OpenAI (sec 5.7);
(3) Crash and error reports (sec 5.8);
(4) Delivery of notifications and sending of emails (sec 5.9);
(5) Protection against misuse (sec 4.6);
(6) Audience measurement (sec 5.3);
(7) Sending of newsletters (sec 4.2);
(8) Hosting, operation and maintenance of our systems.
These service providers process your data on our behalf, on the basis of our instructions and exclusively for the purposes described; we have concluded agreements with them pursuant to art 28 GDPR. Where we engage a different or additional service provider for one of these areas, the same requirements apply. Insofar as a service provider is an independent controller for part of the processing – in particular the payment service provider in respect of fraud prevention and the fulfilment of its own regulatory obligations – that provider's own privacy policy applies.

In addition, we transmit your personal data on a case-by-case basis and to the extent necessary to the following recipients:
(1) to external third parties to the extent necessary on the basis of our legitimate interests (e.g. auditors, debt collection agencies, insurers in the event of a claim, legal representatives where applicable, etc.);
(2) to authorities and other public bodies to the extent required by law (e.g. tax authorities, data protection authority, etc.).
(3) to the payment service provider and the payment institutions involved where a payment is charged back and we contest the chargeback (sec 5.6).
(4) to third parties entitled to information under the E-Commerce Act, in particular in the case of a request for information pursuant to sec 13(3) ECG, where someone asserts that a listing or other content infringes their rights.
Your personal data is not passed on to any other third parties for their own purposes without your consent.

7. International data transfers
Your personal data may be transferred to countries outside the European Union (EU) or the European Economic Area (EEA) which offer an adequate level of data protection as determined by adequacy decisions of the European Commission (https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).

The transfer of your personal data to countries which do not belong to the EU or the EEA and which do not ensure an adequate level of protection takes place only where the controller and the recipients of the data have concluded the Standard Contractual Clauses of the European Commission (SCC) as appropriate safeguards for the protection of your personal data, have carried out a transfer impact assessment and have implemented supplementary security measures, or where you have given your express and voluntary consent.

In concrete terms this concerns audience measurement, whose provider is established in New Zealand, for which an adequacy decision of the European Commission exists. In addition, data may be transferred to providers established in, or with a parent company in, the USA: payment processing, the AI-supported functions, crash and error reports, the delivery of notifications and protection against misuse. For these transfers we rely on the Standard Contractual Clauses of the European Commission.

Where we contest a chargeback, the information required for this may also be transmitted to payment institutions outside the EU if the card was issued there. This transfer serves the establishment and defence of legal claims.

8. Retention period
We generally store your personal data only for as long as we need it to fulfil the purposes described. Where we no longer need your personal data, we delete it from our systems or anonymise it so that you can irreversibly no longer be identified.
Details of the specific retention periods can be found above under the respective purpose.

Where data processing takes place in our legitimate interest or that of a third party, your personal data is deleted as soon as that interest no longer exists, unless statutory retention obligations require us to store it for longer. This also applies to data processing on the basis of consent given. As soon as such consent is withdrawn by you with effect for the future, the personal data is deleted immediately, unless a statutory retention obligation requires longer retention.
In determining the retention period we also take into account the statutory limitation periods, for example under the Austrian Civil Code (ABGB), which are generally three years and in certain cases up to 30 years (sec 1489 ABGB).
Receipts and payment data are subject to retention periods under tax and accounting law of generally seven years. We store your data in connection with the exercise of data subject rights for 18 months as evidence that your request has been dealt with, on the basis of our legitimate interests (art 6(1)(f) GDPR).
This applies without prejudice to cases in which longer retention is necessary for legal disputes, requests from the competent authorities or under applicable law.

9. Data security
We have taken appropriate technical and organisational security measures within the meaning of art 32 GDPR in order to ensure the confidentiality and security of your personal data.

10. Data subject rights
You have a right of access to the personal data processed by us as controller (art 15 GDPR). You additionally have the right to rectification of inaccurate data and to erasure of your data ("right to be forgotten") (art 16 and 17 GDPR). You may further have a right to restriction of the processing of your data (art 18 GDPR) as well as a right to receive the data you have provided in a structured, commonly used and machine-readable format ("data portability", art 20 GDPR). You may also withdraw at any time, with effect for the future, any consent you have voluntarily given to the processing of personal data, e.g. by email to [email protected] (art 7(3) GDPR).

In addition, you have the right to object at any time to direct marketing measures and, on grounds relating to your particular situation, to the processing of your data (art 21 GDPR). In such a case we will refrain from further processing your personal data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or where the processing serves the establishment, exercise or defence of legal claims.

If you believe that we are processing your personal data unlawfully, you also have the right to lodge a complaint with the competent supervisory authority or to seek a judicial remedy (art 77 GDPR). In Austria this is:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Email: [email protected]
You may also lodge the complaint with the supervisory authority of the EU country in which you have your habitual residence or place of work, or with the supervisory authority of the place where the alleged infringement took place.
To exercise these rights you can contact us at any time, for example by email to hello@lola.market.

You can delete your user account yourself at any time: in the app under "Profile" → "Delete profile". If you no longer have the app installed, or if you would like individual data deleted without giving up your account, an informal message to hello@lola.market is sufficient.

When your account is deleted, we remove your profile and the associated data, and your listings are deleted as well. Reviews remain in place without any reference to your account (point 5.5); receipts and payment data are retained for the statutory periods (point 5.6). If there is still an outstanding balance, if you are the sole administrator of a group, or if a rental is still in progress, we will delete your account as soon as these have been concluded.

11. Changes
The further development of our offering may lead to changes. We will of course keep this privacy policy up to date and adapt it where necessary. We make the currently valid version of the privacy policy available on our website at https://lola.market/privacy-policy_en and will notify you separately of material changes. We also recommend that you inform yourself regularly about the current version.