Skip to content
SShineLoad
  • Home / Startseite
  • Privacy / Datenschutz
  • Impressum
Public privacy notice

Privacy Policy / Datenschutzerklärung

Effective date: 2 August 2026 · Version 1.0-prelaunch

Pre-launch scope. This is a static legal-information website. It has no account system, backend, payment flow, scanning function, form, analytics, advertising, or client-side storage. The full ShineLoad application is not available through this site.
Contents
  • Controller
  • Website access
  • Application data
  • HalalScan
  • Recipients
  • Retention and transfers
  • Security
  • Your rights

1. Controller

The controller responsible for ShineLoad is Shine Eagle UG (haftungsbeschränkt) i.G..

In der Weide 1, 21339 Lüneburg, Germany

Privacy contact: [email protected]

Represented by the managing director: Abdul Hakeem Barakzai.

The company is in formation and is not yet registered in the Handelsregister.

No Data Protection Officer is currently appointed. Data-protection enquiries may be sent to [email protected].

Die Gesellschaft befindet sich in Gründung. Datenschutzanfragen können an [email protected] gesendet werden. Derzeit ist kein Datenschutzbeauftragter bestellt.

2. Accessing this static website

When a website is requested, the delivery infrastructure necessarily receives technical request data such as the IP address, date and time, requested path, response status, referrer where supplied, and browser or user-agent information. This is used to deliver the pages, maintain security, diagnose faults, and prevent abuse.

This site is designed for delivery through Cloudflare Pages. It contains only static files and does not send data to a ShineLoad backend. It sets no cookies, uses no local storage, runs no analytics or advertising, and contains no forms or JavaScript trackers. We do not make a claim here about a storage region, transfer mechanism, or log-retention period that has not yet been confirmed.

3. Full-application processing

The following describes the implemented application design and the processing expected if the full ShineLoad service is activated. It is not a statement that these operations are active through this pre-launch website. The full application remains blocked until its production providers, locations, contractual safeguards, retention controls, and release declarations are verified.

Accounts and authentication

If activated, account and authentication processing may include an internal user ID, email address or phone number where supplied, identity-provider identifiers, session records, sign-in timestamps, security events, and limited device or network signals used to protect accounts. Only the information needed for the enabled sign-in method is intended to be processed.

Top-up orders and payment processing

If a customer requests a mobile top-up, the service is designed to process the recipient phone number, country, operator or product, top-up amount, currency, order identifier, status events, and timestamps. Payment processing is designed to use transaction amount, currency, status, and provider references needed for payment confirmation, reconciliation, refunds, disputes, fraud prevention, and legal record-keeping. ShineLoad is not designed to store full card numbers or card security codes.

The recipient phone number can belong to another person. Customers should provide it only where they are entitled to request the top-up. The public notice will be updated with the active payment, authentication, top-up, database, and infrastructure recipients before those production flows are enabled.

Purposes and legal bases

Where the application is activated, data necessary to provide a requested account, payment, or top-up service is intended to be processed for contract performance under Article 6(1)(b) GDPR. Limited records may be processed to meet legal duties under Article 6(1)(c). Proportionate fraud prevention, service security, and legal defence may rely on legitimate interests under Article 6(1)(f), following the required assessment. Optional processing requiring consent will not be enabled without an appropriate consent flow.

4. HalalScan barcode lookup and image scanning

Barcode lookup

The implemented barcode-lookup design sends a product barcode and a limited product-field request to Open Food Facts. It does not include a ShineLoad account identifier, email address, phone number, or authentication token. Open Food Facts operates its own service and information; its public information may be incomplete or inaccurate.

Account-free image-scanning design

The technical design for optional ingredient-image scanning is account-free. A selected image would be protected by a short-lived, single-use OCR credential that is not linked to a ShineLoad profile. The implemented design validates file type, signature, size, and dimensions, removes metadata through safe image re-encoding, processes image data in volatile memory, and releases source and derivative buffers after completion, failure, or timeout.

HalalScan image scanning is not enabled in the production service while the production hosting provider and processing region are being finalised.

The provider and region are therefore not identified as active production recipients. Intended safeguards are described above as technical design, not as a claim that production OCR processing currently occurs.

No scan history or religious profiling

The production design does not save uploaded images, extracted text, or scan results to an account, cloud scan history, database, object storage, or advertising profile. ShineLoad does not ask a user to state a religion, infer or assign religious belief, or use HalalScan activity for marketing, segmentation, recommendations, or religious profiling.

HalalScan results are informational ingredient assessments. They are not religious rulings, product certification, or medical advice.

5. Recipients and processors

For this static pre-launch site, technical website-access data is handled only as necessary to deliver and secure the pages through the selected static hosting service. Open Food Facts is relevant only when a user actively performs a barcode lookup in an enabled app version.

No not-yet-confirmed full-application processor list is published here. Authentication, payment, mobile top-up, database, email, monitoring, or OCR providers will be disclosed before the corresponding production processing is enabled. ShineLoad does not sell personal data.

6. Retention and international transfers

This static site stores no account, payment, top-up, barcode, image, or scan-history data and sets no browser storage. Technical access logs, if generated by the hosting service, must be limited according to the verified operational configuration and applicable legal requirements.

Application retention periods and any international-transfer safeguards will be published only after the relevant production configuration and legal or contractual basis are verified. No specific hosting region, transfer safeguard, or application retention period is claimed on this pre-launch site.

7. Security and abuse prevention

This static site uses restrictive browser-security headers, disallows scripts and outbound browser connections, and contains no authentication or payment endpoints. The full application code includes measures such as encrypted transport, input validation, rate limits, short-lived credentials, session protection, webhook verification, data minimisation, and abuse controls. Those are implemented technical measures; their production operation remains subject to deployment and live verification.

8. Your rights and account deletion

Subject to the GDPR and applicable law, you may have rights of access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, consent may be withdrawn for future processing. You may also object to processing based on legitimate interests.

This static site has no account to delete. If you later use an activated ShineLoad account, account deletion is intended to be available from the account settings. You may also send a privacy or deletion request to [email protected]. We may need proportionate information to verify that a request relates to you.

You have the right to lodge a complaint with a competent data-protection supervisory authority. The authority identified for the controller is Der Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen), Prinzenstraße 5, 30159 Hannover, Deutschland, [email protected].

9. Changes to this notice

This notice will be updated before additional production processing is enabled and whenever material facts change. The effective date and version appear at the top of this page.

© 2026 ShineLoad
  • Privacy / Datenschutz
  • Impressum