Legal
Privacy policy
This policy covers heylabapp.com (including heylabapp.web.app) and heylabapp products that use this domain. German version: Datenschutzerklärung. Legal notice: Impressum.
1. Controller
Tanvir Rahmanheylabapp
Berlin, Germany
Email: hello@heylabapp.com
No data protection officer is appointed.
2. Your rights
You may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. You may withdraw consent for the future. You may complain to a supervisory authority; for us that is the Berlin Commissioner for Data Protection and Freedom of Information (datenschutz-berlin.de).
3. This website
The site is hosted on Google Firebase Hosting. Each visit creates connection data needed to serve the page: IP address, time, URL, referrer, browser and device. Legal basis: GDPR Art. 6(1)(f) — operating and securing the site. Data may be processed in the United States. Google participates in the EU-US Data Privacy Framework. Logs are kept only as long as needed for hosting.
We do not set our own tracking or advertising cookies.
4. Fonts
Type is loaded from Google Fonts. Google may receive your IP address and request metadata. See policies.google.com/privacy.
5. Email
Mail to hello@heylabapp.com is processed to answer you. Legal basis: Art. 6(1)(b) or (f). Cloudflare Email Routing forwards it to our inbox. We keep messages until the request is done, longer only where law requires.
The subscribe field on the home page does not send data yet. No addresses are stored until mailing is connected.
6. Overlap sign-in callback
/overlap/auth/callback is a static page that reopens the Overlap app after sign-in. The website does not keep an account there. App data is processed in Overlap (section 7).
7. Overlap app
Overlap is a shared leave calendar. If you create an account we process:
- Email and sign-in (magic link, Sign in with Apple, or Google)
- Calendars, members, time off, trips, and content you enter
- Booking mail you forward to a calendar address at
in.heylabapp.com, including attachments - A push token if you allow notifications
Purpose: providing the app. Legal basis: Art. 6(1)(b). Processors include Supabase (database and auth), Postmark (inbound mail), and Apple or Google if you use their sign-in. Data is kept while the account exists. Email us to delete it.
metiscale is a separate product with its own policy at metiscale.com/datenschutz.
8. No automated decisions
We do not make GDPR Art. 22 automated decisions.
9. Changes
We will update this page if the services or the law change. The version published here is the current one.
Last updated: 18 August 2026