Privacy Policy
Last updated: 8 February 2026
1. Controller (who is responsible)
Weckli is operated by:
Oliver Widler
Hohlstrasse 186, 8004 Zurich
Email: [email protected]
2. Scope
This Privacy Policy explains how we process personal data when you use:
- the Weckli website (weck.li and weckli.ch), and
- the Weckli Telegram bot (@wecklibot, deep link: t.me/wecklibot).
3. Personal data we process
We process only what is needed to provide the service.
A) Messaging bot data (Telegram)
When you use the bot via Telegram, we store:
- platform_chat_id (numeric Telegram chat ID)
- your language (en/de)
- your settings: location name, latitude/longitude, morning alert time, default notification lead time, pause/active state, onboarding status
- your train routes and alert preferences: from/to stations (and station IDs), departure time, notify minutes, morning/active flags
- referral data: referral code, referred-by, referral status
- feedback you submit: message text and resolution status (kept until resolved)
We do not store Telegram usernames, Telegram user IDs, or a general history of incoming/outgoing bot messages.
Important: Telegram itself processes your communications and related metadata on its platform under its own policies. (Telegram Privacy Policy)
B) Subscription and payment data
We store:
- subscription status (trial/active/cancelled), trial end / subscription end timestamps, payment timestamps
- last_charge_id (Stripe charge identifier)
Payments are processed via Stripe (and the payment flow may be initiated through Telegram's payments flow). We do not store full card details. (Stripe DPA)
C) Technical data (website + backend)
For security, operation, and debugging we (and our hosting provider) may process:
- server logs (e.g., IP address, timestamps, request info, error logs)
We do not run analytics or advertising trackers on the public website.
4. Purposes (why we process data)
We process personal data to:
- provide Weckli's functionality (alerts, routes, preferences, onboarding)
- operate subscriptions and payments
- handle support and feedback
- run referral functionality
- ensure security, prevent abuse, and maintain reliability
5. Recipients / service providers
To operate Weckli, we use providers that may process data:
- Telegram — delivering bot messages and handling interactions on the Telegram platform. (Telegram Privacy Policy)
- Stripe — payment processing and subscription management. (Stripe DPA)
- Railway — hosting for the website and database. (Railway DPA)
- Data providers used to generate alerts:
- Transport API at transport.opendata.ch (connections/delays). (Transport API Docs)
- Open-Meteo (weather forecasts). (Open-Meteo Docs)
When calling these data APIs from our backend, we send request parameters such as station identifiers/times (Transport API) and latitude/longitude (Open-Meteo) to retrieve results.
6. Transfers abroad
Some providers above may process data outside Switzerland. Where personal data is disclosed abroad, we ensure appropriate safeguards in line with Swiss data protection requirements (e.g., contractual protections such as DPAs / recognized clauses, depending on the provider and transfer). (FADP)
7. Retention (how long we keep data)
- Account data: deleted 90 days after cancellation/inactivity or after a valid deletion request (unless we must keep specific elements longer for legal reasons).
- Feedback: kept until resolved, then deleted or anonymized where possible.
- Server logs: retained for 30 days (typical provider retention), unless needed longer for security investigations.
- Billing-related records: retained as required for statutory accounting/tax obligations.
8. Your rights and how to exercise them
You can request access, correction, or deletion of your personal data and object to certain processing where applicable under Swiss law. Contact: [email protected].
We may ask for reasonable proof of identity before fulfilling a request.
9. Data security
We use appropriate technical and organizational measures to protect personal data (e.g., access controls, least-privilege, and encryption in transit where available). Guidance on controller responsibilities with processors/cloud services is reflected in FDPIC materials.
10. Changes to this policy
We may update this policy from time to time. The latest version will always be published on the website.