Updated 8 October 2026. This notice covers the NuroStride website, kit purchases and technical setup enquiries.
Controller and contact
Arne Kellmann
Odenwaldstraße 134L
64372 Ober-Ramstadt, Germany
contact@arnekellmann.de
Your training profile stays in your browser
Onboarding processes your goal, experience, availability and training inputs locally. We send this profile neither to our server nor to Stripe or Resend. The tab retains your inputs in sessionStorage until you use “Clear profile” or the tab session ends. Browser restoration can resume a session. Downloading does not automatically erase the tab inputs. You save the personal ZIP and any exported JSON on your own device.
If you later provide files to your AI provider or connect an MCP service, that provider’s data terms and your chosen settings apply. NuroStride does not perform this transfer for you. Please avoid sending complete training histories, diagnoses or access keys when a technical support question does not require them.
Purchase, access and email
For billing, download access and kit updates, we store a payment-session hash, Stripe payment identifier, email address, amount and currency, order status, billing country, purchase date and update end date. This also includes identifiers of processed payment events and delivery status of order emails. Card details are processed in Stripe Checkout; NuroStride does not store them. A purchase cannot be processed without the necessary payment and contact information.
Arne Kellmann provides the digital kit. Stripe Managed Payments handles the purchase through Link, processes billing information in its checkout and provides payment and tax receipts. Resend sends our product/access confirmation and private access link. These messages contain order and access information, not your training profile. Keep the access link private: possession can enable download access. We process contact and setup enquiries to respond and, where agreed, provide the requested service.
For online withdrawal, we process your name, email, contract description, request identifier, statement and receipt time to handle the withdrawal. Resend receives the information for the statutory acknowledgement. We coordinate the necessary order and withdrawal information with Stripe/Link to identify and refund a digital purchase. Order identification and reimbursement are checked afterwards. Withdrawal data is not stored in your browser profile; you can download a local text acknowledgement.
The market selection before checkout stays in your browser. Our backend checks only the Stripe-confirmed billing country against supported countries. It supports available fulfillment and tax handling and contains no training profile.
Hosting and security
Cloudflare serves the website and operates the backend and database. Order data is stored in a Cloudflare D1 database with EU jurisdiction. Website delivery involves necessary connection data such as IP address, time, requested URL and browser information. Abuse protection processes hashed IP identifiers and login attempts; administrative changes are logged. Global hosting can involve processing outside the EU.
Cookies and local storage
- ns_buyer and ns_admin: necessary signed HttpOnly session cookies for buyer access and administration, lasting up to twelve hours.
- Profile in sessionStorage: the in-progress onboarding you requested, retained for this tab.
- nurostride-receipt in sessionStorage: a private Stripe access identifier or signed purchase key used to resume downloads. This proof is sent to our backend to verify access; your training profile is not transferred with it. It remains until the tab session ends or website data is cleared. “Clear profile” removes only the training profile; close the tab to remove the retained purchase proof as well.
- ns-theme in localStorage: your explicitly selected light or dark theme, until you clear website data or replace the setting.
We use no visitor analytics or advertising tracking. Fonts are served with the website. The storage listed above supports functions you select; we do not use it for advertising on this website. § 25 TDDDG
Legal bases and retention
Order processing, access and requested services rely on GDPR Article 6(1)(b). Security and reliable website operation rely on Article 6(1)(f); our interest is preventing abuse and providing the service. Statutory withdrawal handling and record retention rely on Article 6(1)(c).
Access and order records remain necessary while we administer your purchased licence, update rights and possible refunds. Invoices and accounting vouchers generally have an eight-year retention period; other tax records may require six or ten years depending on type, generally starting at year end. Security data and correspondence are deleted when their purpose ends unless legal duties or unresolved claims require retention. The twelve-month update period is not a blanket deletion deadline for purchase records. § 147 AO
Providers and international processing
Recipients are Cloudflare for hosting, security and the database, Stripe/Link for payment processing, tax receipts and refunds, and Resend for our transactional email. These providers can process data outside the European Economic Area, particularly in the US. Where applicable, provider agreements include EU Standard Contractual Clauses as transfer safeguards. You can request information and copies of applicable safeguards using the contact address.
Cloudflare Privacy · Stripe Privacy · Resend Privacy · Resend DPA
Your rights
Subject to legal conditions, you may request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. Any consent can be withdrawn for the future. We make no solely automated decisions about you producing legal or similarly significant effects. DSGVO / GDPR
For requests, write to contact@arnekellmann.de. You may complain to a data protection authority, including the Hessian Commissioner for Data Protection and Freedom of Information. Complain to the HBDI