immomax
Privacy
Version of August 24, 2026 · Version 2026-08-24
This policy describes what personal data we process when you use immomax.ch, why we do so, and what rights you have. It follows the Swiss Federal Act on Data Protection (FADP); for users in the EEA, the GDPR applies in addition.
1. Controller
The controller for personal data processed on immomax.ch is Swiss Max Group LLC. Company name, address and registration number are set out in the Imprint.
For anything to do with data protection, reach us through the contact form or at support@immomax.ch. Requests for access or deletion can be made directly with the form further down this page.
2. Our principles
We process personal data only as far as running the platform requires, and only for the purposes named here. We do not sell personal data. We run no advertising networks and embed no third-party analytics or tracking services.
We collect as little as we can: searching needs no account, a saved search needs only an e-mail address, and the tax figures are calculated from a household profile you pick rather than from your actual income.
3. What data we process
3.1 Data you give us
- account: name or display name, e-mail address, password (only as a cryptographic hash), language, notification settings;
- optional: mobile number (to verify you when publishing a listing), home address (only to work out your commute time), details about your agency;
- security features: two-factor secret, recovery codes, passkeys;
- content: your listings with their text and photos, favourites, saved searches and their criteria;
- correspondence: your messages to us through the contact and reporting forms, with whatever you put in them.
3.2 Data that arises from use
- server logs: IP address, timestamp, page requested, status code, referring page, browser and device identification;
- security data: sign-in attempts, active devices and sessions, and anomalies suggesting misuse;
- usage data: which listings were opened through the source link, in pseudonymous form (see the section on cookies);
- delivery data for our messages: whether an e-mail was opened and whether a link was clicked;
- RentScore: the details you enter yourself (locality, number of rooms, rent, optionally floor area and the year you moved in), the resulting score, and an optional display name. These are tied to your pseudonymous visitor identifier, not to your name. Anyone who has your result link sees the municipality or region, the number of rooms, the score, a rounded difference and the display name you chose — neither your address nor your exact rent.
3.3 Data from third-party listings
For aggregated listings we process data we do not collect from you, but obtain from our partners' data feeds and from publicly visible listings on other portals: property details, photographs and information about the advertising company. See "Information about advertisers and agencies" below.
4. Why we process data
Under Swiss law we may process personal data provided we do so in good faith, proportionately, and in a way whose purpose is recognisable. For users within the scope of the GDPR we rely, depending on the purpose, on performance of the contract (Art. 6(1)(b)), on our legitimate interest in a secure, working and economically viable service (Art. 6(1)(f)), on your consent (Art. 6(1)(a), for example for push notifications), or on a legal obligation (Art. 6(1)(c)).
- running the platform: search, map, listing pages, favourites, account and apps;
- saved searches and notifications: finding matching listings and delivering them by e-mail or push;
- your own listings: mobile-number verification, publication, review and moderation;
- security and abuse prevention: detecting fraud, spam and attacks, rate limiting, protecting accounts;
- improving the service: analysis in aggregate form to raise quality, speed and data coverage;
- correspondence: answering your enquiries and handling reports;
- paid services: ordering, payment, invoicing, accounting;
- meeting legal obligations and enforcing our rights.
5. Cookies and similar technologies
We use first-party cookies only — no advertising cookies, no cookies from third-party analytics services, no profiling across websites.
- session cookie: keeps you signed in and protects forms against cross-site submission (CSRF). Signing in does not work without it.
- visitor id ("vid"): a random identifier valid for one year. It lets us attribute listing clicks to one visit without identifying you, and lets us spot abuse such as automated click floods. It holds no name and no e-mail address, and is never shared with third parties.
- preferences: your language and most recent search criteria are stored locally in your browser so you can pick up where you left off.
5.1 How to stay in control
You can delete or block cookies in your browser at any time; the locally stored search settings are cleared through your browser's site data. Search still works afterwards; signing in and some convenience features do not.
Because we use no third-party advertising or analytics services, you will find no cookie banner here. We inform you on this page instead — as the Telecommunications Act requires for the use of such technologies.
6. Measurement in e-mails and push messages
To know whether our saved-search messages arrive at all and are of any use, we measure whether a message was opened and whether a link was clicked. Each e-mail therefore contains a small counting pixel, and links go through a redirect on our own domain.
Many mail apps now pre-load images through a privacy service (Apple Mail Privacy Protection, for example). We distinguish those automated fetches from probably-human opens and count them separately — the figures serve quality control, not profiling.
If you would rather not be counted: turn off automatic image loading in your mail app and no open is recorded. Or unsubscribe from the saved search concerned — the link is in every message.
7. Information about advertisers and agencies
A listing includes information about the company advertising it. We show contact details at company or agency level — company name, address, general phone number and website — because that is part of what lets you judge an offer.
We do not publish direct personal contact details of individual staff, such as private mobile numbers or personal e-mail addresses. Contact goes through the listing's original source.
This data originates from our partners' feeds and from publicly visible listings on the portals we cover; the source is stated on every listing. If you are affected and want your own details corrected or removed, write to support@immomax.ch — we handle such requests even where the data originally came from somewhere else, and pass them on to the source on request.
8. Disclosure to third parties
We disclose personal data only as far as operating the service requires or the law obliges us to. Our service providers process data solely on our instructions and are contractually bound to confidentiality and data security.
- hosting and infrastructure: Hetzner Online GmbH, Germany — servers, databases and image storage;
- e-mail delivery: Amazon Web Services (Amazon SES), data-centre region in the EU;
- SMS for number verification: BulkGate s.r.o., Czech Republic;
- push notifications: Google Firebase Cloud Messaging (Android and iOS apps) and your browser's push service (Web Push);
- signing in with Google or Apple, if you choose to: Google Ireland Ltd. and Apple Inc. respectively;
- map display: map tiles from the Federal Office of Topography swisstopo and fonts from OpenMapTiles — your IP address is transmitted to these services, as with any request for an external resource;
- payment for chargeable services: the payment provider named at checkout; card details are entered there and are not stored by us;
- authorities and courts, where we are legally obliged or where it is necessary to protect our rights.
9. Disclosure abroad
Our servers are located in Germany. From a Swiss perspective the European Economic Area provides adequate data protection, so no additional safeguards are needed for that processing.
The operator is domiciled in the United States and can access data from there. It is certified under the Swiss–U.S. Data Privacy Framework; since 15 September 2024 Switzerland has recognised the protection offered by certified US companies as adequate.
Where data is disclosed to a country without adequate protection, we rely on the standard contractual clauses recognised by the FDPIC or on another basis provided for by law.
10. How long we keep data
We keep personal data for as long as the purpose requires, and delete or anonymise it afterwards.
- account and its content: until you delete the account. On deletion we remove favourites, saved searches, passkeys, devices and sessions immediately, and your own listings are withdrawn.
- proof of a deletion: we keep a record of the request with the e-mail address and timestamp, so that we can show we acted on it.
- server logs: 60 days at most, then deleted automatically.
- click and delivery data for listings and messages: 12 months; after that we keep only daily statistics with no personal reference.
- RentScore usage events: 12 months. The result itself is kept until you delete it — otherwise every shared link would eventually lead nowhere. You can remove the result and the display name at any time from the device that created them.
- contact enquiries and reports: until they are dealt with, then for as long as comparable cases need to remain traceable, at most 24 months.
- acceptances of the terms and this policy: for the life of the account and afterwards for the statutory limitation periods.
- records with accounting relevance: ten years, in line with the statutory retention obligation.
11. Data security
We take appropriate technical and organisational measures: encrypted transmission throughout (TLS), passwords stored only as hashes, optional two-factor authentication and passkeys, restrictive access rights, logging of administrative access, regular updates and backups.
Nobody can guarantee absolute security. If we learn of a breach of data security that poses a high risk to the people affected, we notify the FDPIC and inform those affected as far as the law requires.
12. Abuse detection at registration and sign-in
At registration and at every sign-in we record a few technical characteristics in order to detect fake accounts, bulk-created accounts and takeover attempts. These are: the IP address, the country and network operator (autonomous system) derived from it using the local MaxMind GeoLite2 database, the timezone, language and device characteristics your browser reports (platform, screen resolution, graphics chip), and a checksum computed from those which makes the same device recognisable.
We deliberately do not determine your location at city level: the country and the network operator answer the questions abuse detection actually needs, and are considerably less intrusive.
This processing rests on our overriding interest in operating the platform securely. The data serves security only; it feeds neither advertising nor profiles for third parties, and we do not pass it on.
From these characteristics we compute an indicator value. That value alone never leads to a block or a refusal — it exists solely to put unusual patterns in front of a person for review (see also the section on automated individual decisions). Retention follows the section on how long we keep data.
13. Your rights
You have the right to information about the personal data we process, to have inaccurate data corrected, to have data deleted, and to object to processing. You may also ask us to hand over the data you provided to us, in a common electronic format.
You can cancel a saved search at any time without signing in, using the link in every message. You delete your account and its contents yourself in your account settings.
Handling your request is free of charge. We normally reply within 30 days. To stop anyone requesting access or deletion in your name, we first check that the request really comes from you.
Request a copy of your data, or its deletion
You can request a copy of your data or ask us to delete it — no account needed, free of charge.
14. No automated individual decisions
We take no decisions producing legal effects or similarly significant consequences based solely on automated processing. We do use automated methods to match listings, order search results and detect abuse; where an account is blocked on suspicion of misuse, a human reviews the case on request.
15. Children and young people
Our service is aimed at adults. We do not knowingly collect data from children. If we learn that an account was opened without the necessary consent of a legal representative, we delete it.
16. Right to complain
If you believe our handling of your data breaks the law, please come to us first — most matters are resolved fastest that way. Independently of that, you may approach the supervisory authority: the FDPIC in Bern and, for people in the EEA, the competent data protection authority in their country.
17. Changes to this policy
We update this policy when our service or the law changes. The version published on this page is the one that applies; its date and version number are shown at the top. For material changes we also inform registered users by e-mail.
Questions about your data?
Write to us — we answer every request.