NOKTÜRN.
Security & Trust

How Noktürn protects you

This page is maintained by the Noktürn operator (see Impressum) to explain the platform's current security practices and privacy controls. It describes the application-level safeguards we have built and the responsibilities shared with our hosting and payment providers. It is not a third-party certification or independent audit report.

Access & authentication

User accounts are secured with email-based authentication and session management provided by the Lovable Cloud backend. Passwords are never stored in plain text; the authentication provider handles hashing and credential protection.

Sensitive organizer data (banking details, tax IDs, full contact information) is kept behind Row-Level Security (RLS) policies and is only visible to the account owner and authorized backend processes. Public pages display only the organizer's display name and verification status.

Data protection basics

Transport between your browser and the platform is encrypted with TLS (HTTPS). The database is hosted in the EU by Lovable Cloud's backend infrastructure.

We limit the personal data we collect to what is necessary for the service: account email, event details, and anonymized usage signals. You can request deletion or export of your data at any time from your dashboard or via the contact page.

Payments & tickets

Ticket payments are processed by Stripe, a regulated payment service provider. Noktürn does not store full card numbers or payment credentials on its own servers. Stripe handles PCI-compliant card processing and tokenization.

Noktürn acts as a ticket broker (§ 164 BGB) between the event organizer and the buyer. The ticket price is passed to the organizer; Noktürn retains a clearly shown booking fee. Inventory is locked at checkout time to prevent the same ticket being sold twice.

Content moderation

Every event listing can be reported by visitors. Reported content enters a review queue where a moderator can approve the listing or remove it permanently. We also maintain an audit log of moderation decisions.

Organizers must verify their contact information (email and/or phone) before listing paid events, so ticket buyers can identify the contractual partner.

Retention & deletion

Event organizers choose how long their listing remains visible. After the chosen period ends, the listing moves to a personal "Dustbin" for a limited grace period and can then be permanently deleted.

Account data is retained while the account is active and for up to 90 days after closure, unless German law requires a longer retention period (for example tax records).

Hosting & subprocessors

The application is hosted on Lovable Cloud's edge infrastructure and uses Lovable Cloud's backend database (PostgreSQL) for data storage. Key subprocessors include Stripe (payments), Google (optional translation widget), and the hosting platform itself.

A current list of subprocessors is available in the Privacy Policy.

Cookies & analytics

We use only strictly necessary cookies by default. Optional analytics and translation widgets are only enabled when you consent or actively choose them. You can clear your browser cookies and local storage at any time.

The platform does not sell personal data or use it for third-party advertising.

Vulnerability reporting

If you discover a security issue on Noktürn, please report it responsibly using our security report form or by email to noktuern@gmx.net. We will investigate promptly and do our best to fix verified issues without unnecessary delay.

Please do not test vulnerabilities against live user data or disrupt the service.

Security & privacy contact

For privacy requests, data deletion, or security concerns, contact the operator:

  • Name: David Kungang Aminkeng
  • Email: noktuern@gmx.net
  • Phone: +49 221 42323396
  • Address: Schloß Straße 42, 51061 Köln, Germany

Last updated: 20 July 2026. This page is a living document and will be updated as the platform or its subprocessors change.