Pilotphase: Die Plattform Zusammen Wohnen befindet sich aktuell in der Pilotphase. Wir sind froh um jedes Feedback an info@zusammen-wohnen.ch.
Feedback geben
Zusammen-Wohnen Logo
Zusammen WohnenDie nichtkommerzielle Berner WG-Plattform
Dokumentation
Zurück
  • Introduction
    • Installing Dependencies
    • Quick Start
    • Project Structure
    • Configuration
  • Authentication Overview
    • Configuration
    • Email & Password
    • OAuth
    • Magic Links
  • Database
    • Database Overview
    • Migrations
    • Row Level Security
    • Querying Data
    • Functions & Triggers
  • Features
    • Features Overview
    • Team Collaboration
    • Platform Guide & Privacy Control
  • Billing & Payments
    • Billing Overview
    • Pricing Plans
    • Webhook Integration

Platform Guide & Privacy Control

A comprehensive page-by-page guide to Zusammen Wohnen covering personas, features, and strict data visibility shielding rules.

Welcome to the Zusammen Wohnen Platform Guide. This documentation provides a comprehensive breakdown of the platform's features, page-by-page directories, core user personas, and strict security and privacy controls designed for Swiss flatsharing and co-living.


User Personas

The platform is designed around three main user personas, each with distinct workflows, goals, and data access levels:

1. Room Seeker (Applicant)

  • Goal: Find a suitable flatshare room in Bern and its surrounding areas, apply easily, and communicate safely.
  • Core Actions:
    • Browse verified room ads.
    • Build a private Roommate Resume (WG-Dossier).
    • Apply to room ads with a single click.
    • Communicate with flatshares via the secure inbox.
  • Privacy Shielding: Personal details (name, bio, hobbies, work, contact details) remain fully hidden from the public and search engines. Street addresses of WGs are only unlocked once the seeker is shortlisted.

2. Flatmate (WG Member)

  • Goal: Participate collectively in listing rooms, reviewing candidates, and onboarding new roommates.
  • Core Actions:
    • View workspace dashboards and current flatmate lists.
    • Review candidates on the applications Kanban board.
    • Move applicants through workflow stages (shortlisted, accepted, etc.).
    • View and reply to incoming flatshare outreach messages collectively.
  • Privacy Shielding: Flatshare member details and history are kept secure within the flatshare workspace. Exact street addresses of listed rooms are only disclosed to shortlisted candidates.

3. Flatshare Admin (WG Owner)

  • Goal: Manage the administrative settings, members, and billing for the flatshare workspace.
  • Core Actions:
    • Invite new flatmates to the workspace.
    • Modify member roles and permissions.
    • Transfer workspace ownership to another flatmate.
    • Manage subscription plans and billing settings.

Page-by-Page Directory & Functionality

Public Directory Pages

These pages are accessible to any visitor without authentication and are optimized for public search.

Home / Landing Page (/)

  • Function: Marketing portal explaining the core value propositions: the verified WG-Dossier and the Privacy Shield.
  • Aesthetics & Call-to-Actions: Dynamic layouts prompting Room Seekers to build a profile and WG Members to list their rooms.

Public Flatshares (/flatshares)

  • Function: A directory listing all co-living groups that have chosen to make their flatshare profile public.
  • Outreach Flow: Authenticated visitors can click "Message" to start a direct inquiry. To protect privacy, this button is hidden from users who are already members of that flatshare.

Room Search (/rooms)

  • Function: A map-integrated feed listing all active, native room ads.
  • Confidentiality: Only general geographical areas (e.g. city, ZIP code) are visible. Exact street names and house numbers are hidden.

Info & Legal Guides (/info)

  • Function: Educational articles, including legal guides on Swiss subletting law (CO Art. 262/264), genossenschaftskapital (co-op equity), and co-living tips.

Legal Information Pages

  • Cookie Policy (/cookie-policy): Details the platform's strict cookie minimization policy (essential functional session cookies only; zero third-party tracking pixels or Google Analytics).
  • Privacy Policy (/privacy-policy): Formal document detailing data visibility controls and role-based data shielding.
  • Terms of Service (/terms-of-service): Governs platform usage, highlighting its non-commercial private nature, exclusion of warranties, and Bern jurisdiction.
  • Imprint (/imprint): Provider disclosures for Swiss compliance (Markus Roder, Bern).

Protected App Pages

These pages require authentication and enforce strict Row Level Security (RLS) policies.

User Home Dashboard (/home)

  • Function: Personal entry point showing shortcuts, system notifications, and status overviews.

My Profile / Resume Builder (/home/profile)

  • Function: Where Room Seekers fill out their WG-Dossier (full name, bio, hobbies, work, living habits, and contact info).
  • Privacy Controls: Features no public ID banner to prevent UUID exposure. Saves data as drafts until actively submitted in an application.

Flatshare Workspace Dashboard (/home/[account])

  • Function: The home page of a flatshare workspace. Shows current flatmates and a consolidated list of room ads.
  • Scoping: Displays the switcher dropdown accompanied by the inline "Flatshare" label at the top. Selecting a flatshare filters all displayed room ads and pages to that specific workspace.

Flatshare Profile & Defaults (/home/[account]/settings/profile)

  • Function: Allows workspace members to edit public descriptions, upload flatshare images, specify geographical areas, and establish defaults for future room ads.

Room Ad Applications Kanban (/home/[account]/room-ads/[adId]/applications)

  • Function: Displays applicants for a room ad in a column-based pipeline (Applied, Shortlisted, Accepted).
  • Interaction: WG members drag-and-drop candidates to update their status. Moving a candidate to "Shortlisted" automatically triggers the address privacy shield unlock.

Inbox & Messaging (/home/inbox)

  • Function: Unified chat interface handling multiple context-specific categories:
    • author_inquiry: Direct private chats between two user personas.
    • public_wg_outreach: Inquiry messages sent from a room seeker to a flatshare account. Visible and replyable by all members of the recipient flatshare.
    • application: Thread linked to an active room application.
    • shortlisted: Dedicated thread for candidates moving into onboarding.

Privacy Shield & Data Visibility Matrix

The platform enforces strict visibility boundaries to secure personal information. Below is the precise access permission matrix:

Data ElementPublic Viewers / Search EnginesRegular Authenticated UsersShortlisted / Accepted CandidatesFlatshare Workspace Members
Room Ad (General Info)VisibleVisibleVisibleVisible (Creator & Editors)
Room Ad (Exact Address)HiddenHiddenVisibleVisible
Applicant Resume (WG-Dossier)HiddenHiddenHiddenVisible (only if candidate applied to their WG)
Direct Outreach ThreadsHiddenHidden (Sender only)N/AVisible (All current workspace members)
Workspace Settings & InvitesHiddenHiddenHiddenVisible
Application Notes (Private)HiddenHiddenHiddenVisible (All current workspace members)

Technical Security Design

  1. Database Row Level Security (RLS):
    • Authenticated clients access Supabase with limited database permissions. RLS rules inspect user IDs (auth.uid()) and flatshare memberships (accounts_memberships) before allowing SELECT, INSERT, UPDATE, or DELETE operations.
  2. Security Definer RPCs:
    • Confidential fields like the exact street address (exact_address) are fetched through security-definer database functions (e.g. public.get_unlocked_address(p_ad_id)). This function validates the user's role and checks if they are a flatshare member or a shortlisted/accepted applicant before releasing the raw text.
  3. Automatic Data Scrubbing:
    • Obsolete applications and old message threads are automatically scrubbed by background database maintenance tasks to avoid data hoarding.