Sign In Sign Up

Privacy Policy

What we process, why, and what you can do about it.

Last updated: 29 July 2026

Controller

newnow.cool GmbH & Co. KG, Frankfurter Tor 2, 10243 Berlin, Germany, operates P2P Dash and is the controller for the processing described here. You can reach us at tim@newnow.de. Full provider details are in our imprint.

We have not appointed a data protection officer and are not required to.

In short

P2P Dash runs without analytics, tracking pixels, advertising networks or social media plug-ins. We do not build profiles of you and we do not sell data to anyone. That is also why you see no cookie banner: the few cookies we set are technically necessary.

The transaction files you import are read in your browser. The files themselves never reach our servers.

Hosting and server logs

The application runs on servers of DigitalOcean, LLC in Frankfurt am Main, Germany. The database is a managed PostgreSQL instance from the same provider, also in Frankfurt. Our marketing website is hosted on Cloudflare Pages (Cloudflare, Inc.).

When you open one of our pages, the server processes connection data: IP address, time of the request, the page requested, the referring page and your browser identifier. This is needed to deliver the page and to defend against attacks. Legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in operating the service securely. We keep these logs only as long as we need them for operation and security.

Cookies

We set three cookies. All of them are first-party and technically necessary, so they need no consent under section 25 (2) TDDDG:

  • A session cookie that keeps you logged in. It is removed when you log out or the session expires.
  • NEXT_LOCALE, which remembers your language.
  • sidebar_state, which remembers whether the sidebar is open. It lasts seven days.

Your account

To create an account we process your email address, a name of your choosing and your password. The password is only ever stored as a hash, never in plain text. Legal basis is Art. 6 (1) (b) GDPR, performance of a contract.

While you are logged in we store session data including your IP address and browser identifier, so we can keep the session secure. You can delete your account at any time in the account settings. Deleting it removes your account and the data attached to it.

The data you import

P2P Dash works with the account statements you export from P2P lending platforms. Those files are read in your browser. We neither receive nor store the files.

What is stored on our servers is the result: per platform and per day, the amounts for interest, repayments, fees, taxes, deposits, withdrawals, investments, losses and bonuses, plus the platform name you chose. This is financial information about you and we treat it as such. Legal basis is Art. 6 (1) (b) GDPR.

Unknown transaction types

If single rows in an import cannot be matched to a transaction type we know, we store one example row per unknown type. Not the whole file, and not every affected row.

We store these rows without any link to your account. They carry no user identifier, and we cannot tell which account they came from.

The purpose is to add the unknown transaction type to the importer, so that the import works for you and for other users of that platform. Legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in a working importer.

Such a row usually contains a date, an amount, a currency and the description of the transaction, for example a project name. Depending on the platform it can contain further fields from the export.

We keep the row until the transaction type has been added, and delete it afterwards. There is no fixed period, because how long it takes depends on how many new types come in. Only the developer of P2P Dash has access.

Because we cannot link these rows to any account, we can neither give you information about them nor delete them on request (Art. 11 GDPR). This is deliberate: linking them to your account would create more data about you, not less.

Export files you send us

In our guide on adding a platform we ask you to email us an export file. This is voluntary. Without such a file we usually cannot support a new platform, because some export formats only make sense in the context of the complete file. You do not have to send it.

Such a file contains your full transaction history at that platform and, depending on the provider, may contain your name, account numbers or other personal details. If you would rather avoid that, remove those columns before sending.

The recipient is Tim Rottmann at tim@newnow.de. We use the file solely to build import support for that platform and delete the file and the message afterwards. Legal basis is Art. 6 (1) (f) GDPR.

Unlike the unknown transaction types above, this can be linked to you. You can ask us for information or for deletion at any time, informally by email.

Anonymised statistics

We compute anonymised statistics across all portfolios: platform rankings, average returns, capital flows and investment intent. These are aggregated over many users and cannot be traced back to you. Figures below a minimum group size are not published at all.

Legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in offering these statistics as part of the product.

Shared portfolios

You can publish a portfolio under a public link. This is switched off by default.

Once you switch it on, anyone holding the link can open the page without an account. It shows the portfolio data and the name on your account, and search engines may index it. You can switch sharing off again at any time, which makes the page inaccessible.

Legal basis is Art. 6 (1) (a) GDPR, your consent, which you give by enabling sharing and can withdraw at any time.

API keys

If you create a personal access token, we store the token, the name you gave it and the time it was last used, so we can enforce rate limits and let you revoke it. Legal basis is Art. 6 (1) (b) GDPR.

Email

Password reset emails are sent through Resend (Plus Five Five, Inc., USA). Your email address is passed on for that purpose. The transfer to the USA is covered by the EU standard contractual clauses. Legal basis is Art. 6 (1) (b) GDPR.

Our contact address tim@newnow.de is a Google Workspace mailbox (Google Ireland Limited, Dublin). Anything you email us is processed there. Legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in answering enquiries.

Affiliate links

Links to P2P platforms are affiliate links. When you click one, you are taken to the Target Circle affiliate network or straight to the platform. From that point the privacy policy of that provider applies, and it will usually set a cookie to attribute the referral.

We receive no personal data about you from this, only aggregated commission reports. How this works and what it does not influence is set out on our transparency page.

Storage and deletion

We keep your account data for as long as your account exists. Deleting the account deletes that data. Retention for unknown transaction types and for export files sent by email is described in the sections above.

Backups of the database are created by DigitalOcean as part of the managed database service and are overwritten on a rolling basis. Deleted data can therefore still be present in a backup for a transitional period.

Your rights

You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), deleted (Art. 17) or restricted (Art. 18), the right to data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you can withdraw it at any time with effect for the future. An informal email to tim@newnow.de is enough.

For unknown transaction types we cannot identify you, so these rights cannot be exercised there (Art. 11 GDPR), as explained above.

You also have the right to complain to a supervisory authority. The one responsible for us is Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.

Changes to this policy

We update this policy when the product changes. The version published here is the one that applies, and the date at the top tells you when it last changed.