Data Protection Notice for the My Lidl World App

Many thanks for using the My Lidl World App (hereinafter referred to as "the App").


To use the App, a minimum age of 16 is required.


This data protection notice is intended to inform you about how we process your data when you use our App.


1. Responsible person and data protection officer

The person responsible for processing personal data within the app, the so called Controller, is Lidl Stiftung & Co. KG, Stiftsbergstraße 1, 74167 Neckarsulm (which we call „Lidl", „we" or „us" in the following), who processes the data for the operation of the app and transfers it to other companies of the Lidl group of companies.


The Lidl group of companies includes several national and regional companies, which are listed here[OC1] in detail, as well as the Lidl Digital International GmbH & Co. KG (which we call „Lidl-Companies" in the following). The list contains only the current composition of the Lidl-Companies. The composition of the Lidl-Companies can change in the future (e.g. a new Lidl-Company can be added).


If a Lidl-Company receives the data from the app to inform you about offers and promotions, it acts as an independent Controller.


You can contact the data protection officer of Lidl via: datenschutz@lidl.com


2. Processing of usage data during the use of the App

The processing of some data is necessary to provide the various functions of the app. The legal basis for this data processing is Art. 6 sec. 1 lit. b of the General Data Protection Regulation (GDPR). The following processing operations are involved:


a) Viewing content on your device


We process the so-called log data listed here so that we can display the app on your device:


  • the type of mobile device from which you start our app;
  • the IP address;
  • Access date and access time;
  • the request of the client;
  • the http response code;
  • the amount of data transferred;
  • the app version used.


These data are automatically deleted after 14 days.


b) Preventing Bar Code Detective Fraud


We use the location registered by your device while you use the barcode detective to ensure that the scanned products are actually scanned in a Lidl store.


Here we automatically compare if the location data of the device during the scan matches the location of one of our stores. This way we can prevent individual players from cheating and, for example, scanning products outside a Lidl market, thus protecting our honest players.


The location data will be made anonymous as soon as you stop using the barcode detective.


c) Store rankings


On the basis of location data, we can see how often the barcode detective was used in which market and conclude how popular the individual Lidl markets are in Germany. For this purpose we use the location data transmitted when using the barcode detective as well as your other location data, provided that you have allowed us to process them accordingly.


From this we create a ranking of the three most popular stores in the country and display it in the App.


d) Player ranking


We will use the points, money and other resources earned by each player to create and display the player ranking in the App.


e) Login


You have the opportunity to create a My Lidl World Player Account (hereinafter the "Account") and to log in with the Account later in on in order to save your game online. To make this possible, we will process your email address, your password and your saved games to enable you to continue playing on several and additional devices when logging in with your account.


Lidl's online services will grow and develop over time. In the future you will also be able to use your Account to log in to other Lidl services and use them, if you wish (so called "Single-Sign-On" or abbreviated "SSO").


You may delete your Account at any time in the settings of the App. Should you delete your Account, it may take up to 72 hours for all data to be deleted from all our systems in entirety.


3. Access to functions, sensors and location data of your device

We access the following device functions or device sensors via the interfaces of your device:


Camera


Only with your explicit consent according to Art. 6 sec. 1 lit. a GDPR via the dialogue "Allow authorization" will we gain access to the camera of your device. The camera of your device is used for scanning product barcodes within the app.By scanning real products in the store, additional advantages can be activated in the app.


The consent is voluntary and you can withdraw it at any time.


Internet


The app retrieves content such as text and images for certain functions of the game from the Internet. For example, the "Barcode Detective" retrieves images for the products to be scanned from the Internet so that they can be displayed.


The data is processed only as long as you are playing the game. After that, the data is not stored any further.


Location data


Only with your express consent pursuant to Art. 6 sec. 1 lit. a GDPR do we also process your location data to determine how many of our players are also store visitors and can determine more precisely how often a store is visited by different players. This improves the accuracy of the store rankings as we have described above.


Furthermore, we use your location data to display region based advertisement and other information regarding our products and services inside and outside of the App, for instance to display the adequate Lidl leaflet for your current region inside the App. Again, we will only do so, if you have provided us with your explicit consent pursuant to Art. 6 sec. 1 lit. a GDPR. You can find further information on the personalisation of advertisements below (Section 5).


Giving consent is voluntary and you can withdraw it at any time via the settings of the App.


4. Usage analysis to improve the app

In order to improve the features of our app and thus the overall gaming experience, we analyse how the app is used by you and other players.


We process this data on the basis of Art. 6 sec. 1 lit. f GDPR. This provision allows us to process data for the purposes of our legitimate interests, which are not overriden by your interests and the interests of other users. Our legitimate interest here lies in a need-based design of the App, based on the actual usage of the App.


a) General usage analysis


Some data we can collect directly when the app is used. This includes, for example, how often a certain intro screen was displayed, how often a certain tutorial was viewed, how often certain info tabs were called, how often certain quests were completed, how long it takes to reach certain market levels, how often certain achievements are achieved, how often a job was switched to, or which decoration was built how often and at which market level.


We use this information for statistical analysis to understand how the App is used. So we can check if the game works as intended and if not, adjust the game. For example, we can determine if a quest or market level is too difficult and adjust the difficulty level accordingly. As a further example, we can also determine which features of the app are most frequently used, and thus highlight the most popular features, or improve other features


b) Google Analytics / Google Firebase


In addition, we use Google Analytics and/or Google Firebase, an analysis service of Google LLC ("Google") to analyse the use of the App. Google will therefore use this information on our behalf to evaluate the use of the App, to compile reports on the activities and to inform us about how the App is used overall. Google will not associate your IP address with any other data held by Google or use it for its own purposes.


Google Analytics and/or Google Firebase usually transfers the generated information about the use of the App to a Google server in the USA, where it is stored. Before the transmission, the user's IP address will be shortened within member states of the European Union or in other states that are parties to the Agreement on the European Economic Area, so that it cannot be linked to an individual user as easy. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there.

5. Usage analysis for the display of advertising

To improve our advertising, we would like to analyse how you use our app. Doing so enables us to display advertisement for our products and services, which is especially relevant for you personally – inside and outside of the App (outside the App being for instance within your Browser while surfing the internet).


However, we will only do this if you have given us your express consent in accordance with Art. 6 Sec. 1 lit. a GDPR. We will ask for this consent when you create an account for the App or open the game for the first time. You can also give your consent at a later date via the settings in the App.


The consent is voluntary and you can use the App in a basic function even if you do not give us your consent. However, you may not be able to use some functions of the App if you do not give us your consent. We also offer you some in-game benefits as a thank you if you give us your consent.


Once you have given your consent, you can withdraw it at any time via the settings in the App. We will then no longer process the data as described in this section.


a) Personalisation of advertising with the help of adjust


In this context we also use the analysis program "adjust" by adjust GmbH. If you install the App and give us your consent, adjust collects data about how you use the App and which settings you have made.


By doing so, we can understand how you use the app. This allows us to analyse and improve our advertising with this information. Based on your use of the app, we can also select and display advertisements that we think are of particular interest to you personally. For this analysis, adjust uses various identifiers of your device, which it encrypts together to create a unique identifier, called a "fingerprint", for your device. This way we know on which device we should display which ads. To generate this fingerprint, adjust uses the so-called ad identifiers of iOS and Android devices, certain information that is necessary to retrieve information from the Internet anyway (so-called IP address and MAC address and the HTTP header), the time of access to the information, and the settings in the device (country, language, operating system and its version and the version of the app).


b) Other data processed for the personalisation of advertising


Insofar as you have given us your consent, we will evaluate the following data in order to provide you with personalized advertising:


  • The Lidl stores you have visited and how often you have visited them, which we can deduce from the location data you have transmitted, provided you have given us your consent;
  • Your location data to the extent you allow in the settings of your device (for instance, only when using the App or also in the background);
  • The answers you gave in the knowledge tests, as well as the Achievements you achieved;
  • Your clicks on the Lidl leaflet within the App; and
  • The videos and promotional videos you watched in the App and whether you watched them to the end.


6. Networking with your friends

We offer the possibility to find and make friends inside the App. In order to do so, you may either send a friend request to strange players or search for player's names you already know and send them a friend request.


Furthermore, in certain situations within the App, you may share milestones such as Achievements or reaching a new Store Level with your contacts via external Apps such as WhatsApp, Facebook Messenger or other similar services. The players addressed by you will then receive a link via which they may also download the App, if they wish.


Please notice that the other services you may use to send such messages are services offered by external service providers and different data protection information and terms of use do apply. Lidl does not have any influence on the data processing carried out in connection to the these services and does not act as controller in the meaning of data protection law (Art. 4 no. 7 GDPR).


Lidl does not gain access to your device's address book and will never learn to whom and via which channel (for instance WhatsApp or Facebook) you have contacted a friend or other player.


We enable the contact with other players in accordance with Art. 6 Sec. 1 lit. f GDPR, because of our legitimate interest in enabling players to contact their friends in the game, regardless of whether they are already players of My Lidl World or not, and because this legitimate interest is not being overridden by the interests of the affected persons.


7. Transfer of your data

We may transfer your data on usage of the App, your location, and our respective insights to other companies within the Lidl group of companies (as described above under no. 1), so that these may display advertisements, which are particularly interesting and personalised for you. These companies will be controllers regarding this processing of your personal data.


We will however only transfer your data to other companies of the Lidl-Group, if you have given us your express consent within the meaning of Art. 6 sec. 1 lit. a GDPR. Your consent is voluntary and you can withdraw it at any time.


Furthermore we may transfer your data to service providers, so called data processors, which are strictly bound by our orders and may not use the data for their own purposes. The legal basis for this transfers are Art. 28 and Art. 6 sec. 1 lit. f GDPR, since we have a legitimate interest to use the services of such service providers.


Also, individual information that you send to another person via an external messenger service (for instance WhatsApp or Facebook), may also be processed by the providers of these services in order to operate the service (cf. above, Section 6).


In some cases, these transfers may lead to your personal data being transferred to third countries, meaning a country which is not part of the European Economic Area. Should the European Commission not have determined that this country provides an adequate level of protection, we will take appropriate safeguards to guarantee the security of your data. This can, for instance, be done by concluding contracts encompassing the so called EU data protection clauses, which offer appropriate safeguards according to a decision of the EU Commission (these clauses can inter alia be found here: https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32010D0087).


8. Your rights

a) Right to information, Art. 15 GDPR


You have the right that to be informed about which data we have stored about you.


b) Right of rectification, Art. 16 GDPR


If we have stored incorrect data about you, you have the right to have your data corrected.


c) Right of erasure, Art. 17 GDPR


Under certain circumstances, you have the right to have your data deleted. This applies in particular where we no longer need your data in order to provide the App to you.


d) Right to restriction of processing, Art. 18 GDPR


You have the right, under certain conditions, that we no longer process your data for all purposes explained in this text. This applies, for example, if you tell us that your data is incorrect or you want us to delete your data and we have to check it first.


e) Right to object


Under certain circumstances you have the right to tell us that we may not process your data any more. This is called "objection". We then check whether the law allows or even obliges us to use your data anyway or whether we have to stop processing your data.


f) Exercise of these rights


If you wish to exercise any of your rights, please write an e-mail to our data protection officer via Datenschutz@lidl.com.


g) Right of appeal


You also have the right to complain to a state authority for data protection supervision.


Version: May 2020