Privacy Policy
Last Updated: April 27, 2026
Effective Date: January 01, 2025
1. Introduction
1.1 About This Policy
This Privacy Policy describes how Gems Around S.R.L. ("GemsAround," "we," "us," or "our") collects, uses, shares, stores, and otherwise processes your personal information in connection with the GemsAround mobile applications, website at gemsaround.com, APIs, and related services (collectively, the "Services").
This Privacy Policy applies to all Users of the Services and forms part of our Terms and Conditions. Capitalized terms not defined here have the meanings given in our Terms and Conditions.
We are committed to data minimization: we collect only the personal information that is necessary to provide and improve the Services.
1.2 Data Controller
The data controller responsible for your personal information is:
Gems Around S.R.L.
bd. Moscova 17/4, Chișinău, Republic of Moldova
Registration number (IDNO): 1025603000335
Contact: support@gemsaround.com
1.3 EU Digital Services Act — Point of Contact
Pursuant to Article 11 of Regulation (EU) 2022/2065 (Digital Services Act), our point of contact for users, regulators, and authorities under the DSA is: copyright@gemsaround.com. Communications may be made in English and, where practicable, Romanian.
For the procedure to report illegal content under Article 16 DSA, please refer to our Terms and Conditions and Copyright Policy.
1.4 Your Agreement
By using the Services, you acknowledge that you have read and understood this Privacy Policy. For certain processing activities, including the use of analytics and advertising cookies, we will ask for your explicit consent.
2. Personal Information We Collect
We collect personal information in three ways: (a) information you provide directly; (b) information we collect automatically; and (c) information we receive from third parties.
2.1 Information You Provide to Us
Required information (collected when you create an account):
| Category | Description |
|---|---|
| Email address | For account creation, password recovery, and important communications |
| Password (hashed) | For authentication; we never store passwords in plain text |
| Age confirmation | A confirmation that you meet the applicable minimum age requirement (see Section 11) |
| Username | Auto-generated by the system at registration; you can change it at any time |
Optional information (you can choose to add):
| Category | Description |
|---|---|
| First and last name | Optional; may be imported from Google or Apple Sign-In if you use those |
| Profile image | Optional; may be imported from Google or Apple Sign-In if you use those |
| Short bio | Optional self-description |
| Social media handles | Optional Instagram and TikTok usernames |
Other information (collected only when relevant):
| Category | Description |
|---|---|
| User Content | Videos, photos, captions, ratings, comments, location tags, itineraries, and travel notes you upload |
| Messages | Content of messages sent through in-app communication features (if enabled) |
| Support communications | Information you provide when contacting customer service |
| Survey or research responses | If you choose to participate in optional surveys, questionnaires, or research |
| Transaction information | Confirmations of purchases (note: payment card details are handled by third-party payment processors and are not stored by us) |
2.2 Information Collected Automatically
When you use the Services, we automatically collect:
| Category | Description |
|---|---|
| Device information | Device model, operating system and version, mobile carrier, time zone, language settings, screen resolution |
| Log and usage data | IP address (anonymized where applicable), browser type, pages viewed, features used, actions taken, session duration, timestamps |
| Crash reports | Anonymized technical data necessary to debug application crashes |
| Location information | (a) Approximate location derived from IP address; (b) Precise location from GPS or device sensors, only if you have granted location permission through device prompts; (c) Location embedded in User Content you upload |
| Content metadata | Date, time, geolocation, device, file size, format of uploaded content |
| Cookies and similar technologies | See Section 7 for detailed information |
We do not currently use mobile advertising identifiers (IDFA, AAID) and we do not build user profiles for personalization beyond your stated preferences.
2.3 Information From Third Parties
We may receive personal information about you from:
- Third-party sign-in providers (Google, Apple) — name, email, and profile image, limited to information you authorize them to share when you choose to sign in;
- Payment processors (Apple, Google, and other payment partners) — transaction confirmations and billing details necessary to process payments;
- Analytics and advertising partners — aggregated information about your interactions with our advertising;
- Other Users — when they tag you, mention you, or report you;
- Public sources — where permitted by law and relevant to operating the Services;
- Law enforcement, government authorities, and professional advisors — where required by law or necessary to protect rights.
2.4 Special Note on Geolocation
Because GemsAround is a location-based service, geolocation is central to its functionality. We distinguish between:
- Coarse location (IP-based or SIM-based): collected to provide basic, non-precise location features and for security purposes;
- Precise location (GPS, Wi-Fi triangulation, or device sensors): collected only with your explicit consent through device permission prompts, and used only to power location-based features (e.g., "places near you," content tagging);
- Location embedded in User Content: you are responsible for ensuring that geotagged content does not reveal sensitive information about yourself or others. We may process, display, and (where appropriate) obfuscate such data.
You can revoke location permissions at any time in your device settings.
2.5 Sensitive Personal Information
We do not intentionally collect sensitive personal information (e.g., data revealing racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, biometric data). If you voluntarily include such information in User Content, it will be processed under this Privacy Policy, and you acknowledge that it may be visible to others depending on your privacy settings.
3. Legal Bases for Processing (EU/UK/EEA Users)
If you are located in the European Union, United Kingdom, or European Economic Area, we only process your personal information when we have a valid legal basis under GDPR Article 6 (or UK GDPR). The legal basis depends on the processing activity:
| Processing Purpose | Legal Basis |
|---|---|
| Creating and maintaining your account | Contract — necessary to perform the agreement with you (Article 6(1)(b)) |
| Providing core Services (map, content upload, itineraries) | Contract — Article 6(1)(b) |
| Processing payments and transactions | Contract + Legal obligation (tax, accounting) — Article 6(1)(b), (c) |
| Ensuring security, detecting fraud, preventing abuse | Legitimate interest — Article 6(1)(f) (protecting the Services, Users, and third parties) |
| Service-related communications (security alerts, transactional emails) | Contract + Legitimate interest — Article 6(1)(b), (f) |
| Marketing emails or push notifications | Consent — Article 6(1)(a), which you may withdraw at any time |
| Web analytics (Google Analytics) | Consent — Article 6(1)(a) and ePrivacy Directive |
| Advertising and conversion tracking (Meta Pixel, Google Ads) | Consent — Article 6(1)(a) and ePrivacy Directive |
| Collecting precise location data | Consent — Article 6(1)(a) |
| Complying with legal obligations | Legal obligation — Article 6(1)(c) |
| Exercising or defending legal claims | Legitimate interest — Article 6(1)(f) |
| Corporate transactions (merger, acquisition) | Legitimate interest — Article 6(1)(f) |
For processing based on legitimate interest, we have conducted balancing tests to ensure that your fundamental rights and freedoms do not override our interests. You may request details of these assessments at support@gemsaround.com.
You have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
4. How We Use Your Information
We use personal information for the following purposes:
4.1 Providing and Operating the Services
- Creating and managing your account;
- Enabling you to create, upload, share, and discover content and locations;
- Powering the interactive map, itinerary planning, and related features;
- Providing premium features (route optimization, Google Maps export, subscriptions);
- Facilitating communication between Users.
4.2 Personalization and Recommendations
- Recommending destinations, content, and itineraries based on your activity and explicit preferences;
- Customizing your map and feed.
4.3 Improving the Services
- Analyzing usage patterns to identify issues and improvement areas;
- Conducting research, surveys, and A/B testing (where you choose to participate);
- Developing new features and services.
4.4 Safety, Security, and Integrity
- Detecting and preventing fraud, abuse, spam, and unauthorized access;
- Enforcing our Terms and Conditions, Community Guidelines, and other policies;
- Moderating content and investigating reports;
- Protecting Users, third parties, and GemsAround.
4.5 Communications
- Sending service notifications, security alerts, and administrative messages;
- Responding to inquiries and providing customer support;
- Sending marketing communications where permitted by law (with your consent where required).
4.6 Advertising
We use third-party advertising platforms (Meta Pixel, Google Ads) to:
- Measure the effectiveness of our advertising campaigns;
- Reach Users with relevant content about GemsAround on Facebook, Instagram, and Google;
- Conduct retargeting (showing our ads to people who previously visited the Services).
These activities require your consent, which you can grant or refuse via our Cookie preference center. See Section 7 for details.
4.7 Legal and Compliance
- Complying with applicable legal obligations (tax, accounting, copyright, DSA reporting);
- Responding to lawful requests from authorities;
- Exercising or defending legal claims.
4.8 Automated Decision-Making (GDPR Article 22)
We use algorithms for the following automated processing:
- Recommendation systems (suggesting locations and routes based on your activity);
- Route optimization;
- Spam and abuse detection;
- Content moderation triage.
None of these automated decisions produce legal or similarly significant effects on you (e.g., we do not use automated decisions to deny service, refuse payments, or impose penalties without human review). If you believe an automated decision has materially affected you, you may request human review by contacting support@gemsaround.com.
4.9 AI and Machine Learning
We may use aggregated, anonymized, or pseudonymized data to develop and improve our own algorithms and features. We do not use your User Content to train third-party large language models or generative AI without your explicit consent.
5. How We Share Your Information
We share personal information only as described below. We do not sell your personal information in the sense of CCPA/CPRA or similar laws.
5.1 With Service Providers (Data Processors)
We share information with vendors who process data on our behalf. These providers are contractually bound to use your data only as instructed and to implement appropriate safeguards. Categories of service providers include:
| Category | Examples of Providers | Purpose |
|---|---|---|
| Cloud hosting and infrastructure | OVHcloud | Hosting the Services |
| Content delivery network (CDN) | Cloudflare | Video and image delivery |
| Web analytics | Google Analytics (Google LLC) | Understanding usage and performance |
| Advertising and conversion tracking | Meta Pixel (Meta Platforms Ireland), Google Ads (Google LLC) | Measuring advertising effectiveness, retargeting |
| Crash reporting | Firebase Crashlytics (Google LLC) | Debugging |
| Authentication | Google Sign-In, Apple Sign-In | User login |
| Payment processing | Apple IAP, Google Play Billing, Stripe | Transactions |
| Customer support | Email (Gmail Workspace) | Support tickets |
| Push notifications | OneSignal | Communications |
| Maps and geocoding | Google Maps API, Mapbox | Map display and geocoding |
A current and complete list of our service providers is available by request at support@gemsaround.com.
5.2 With Other Users
Depending on your privacy settings, certain information is visible to other Users or the public, including:
- Your username, profile image, and bio (if provided);
- Your User Content (videos, photos, comments, ratings);
- Public itineraries and shared collections;
- Contribution points and travel statistics;
- Comments and interactions you post publicly.
Use caution when posting location-tagged content, as it may reveal your location or the location of others. You can adjust privacy settings in your account.
5.3 With Business Partners
Where you explicitly opt in or where otherwise permitted by law, we may share limited information with:
- Tourism boards and destination partners — for B2B partnerships, limited to aggregated or anonymized data;
- Advertising partners — for advertising and measurement, subject to your consent.
5.4 Within Our Corporate Group
We may share information with affiliates or subsidiaries under common control with GemsAround for internal administration, consolidated reporting, security, and legal compliance.
5.5 In Corporate Transactions
If GemsAround is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred to the involved parties, subject to appropriate safeguards and notice.
5.6 For Legal Reasons
We may disclose information when we believe in good faith that disclosure is reasonably necessary to:
- Comply with a subpoena, court order, or other valid legal process;
- Comply with regulatory or governmental requests;
- Enforce our Terms and Conditions or Copyright Policy;
- Respond to copyright infringement notices (including DMCA and DSA notices);
- Detect, prevent, or address fraud, security, or technical issues;
- Protect the rights, property, or safety of GemsAround, our Users, or the public;
- Report suspected child sexual abuse material to authorities such as NCMEC, as required by law.
5.7 With Your Consent
We may share information for other purposes with your explicit consent or at your direction.
5.8 Aggregated or De-Identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for any lawful purpose.
6. International Data Transfers
6.1 Transfers Outside the EU/EEA/UK
GemsAround is headquartered in the Republic of Moldova, and we use service providers located in various countries, including the European Union, United Kingdom, United States, and others. Your personal information may be transferred to, stored in, and processed in jurisdictions outside your country of residence, where data protection laws may differ.
6.2 Safeguards
Where we transfer personal information of EU/UK/EEA individuals to a country not deemed to provide adequate protection, we rely on appropriate safeguards, including:
- European Commission adequacy decisions, where applicable;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- UK International Data Transfer Agreement or UK Addendum to SCCs;
- Other lawful transfer mechanisms under GDPR Chapter V.
6.3 Transfers to the United States — EU-US Data Privacy Framework
Some of our service providers (Google LLC, Meta Platforms) are located in the United States. We rely on the EU-US Data Privacy Framework for these transfers, in which Google and Meta are certified participants.
You can verify their certification at https://www.dataprivacyframework.gov/list:
- Search for "Google LLC" for Google Analytics, Google Ads, Firebase Crashlytics, and Google Maps API
- Search for "Meta Platforms" for Meta Pixel
6.4 Your Right to Information
You may request details of the safeguards applied to specific transfers by contacting support@gemsaround.com.
7. Cookies and Similar Technologies
7.1 What We Use
We and our service providers use cookies, SDKs, pixels, web beacons, local storage, and similar technologies ("Cookies") to:
- Operate the Services (essential Cookies);
- Analyze usage and performance (analytics Cookies);
- Remember your preferences (functional Cookies);
- Deliver and measure advertising (advertising Cookies, with consent).
7.2 Categories of Cookies
| Category | Purpose | Legal Basis | Examples |
|---|---|---|---|
| Strictly necessary | Authentication, security, load balancing | Legitimate interest / Contract | Session tokens |
| Functional | Remembering preferences, language | Consent (where required) | Language settings |
| Analytics | Measuring usage and performance | Consent | Google Analytics |
| Advertising | Targeted advertising, retargeting | Consent | Meta Pixel, Google Ads |
7.3 Specific Third-Party Services
We use the following third-party services that place cookies and similar identifiers on your device. Each requires your explicit consent before loading (where consent is required by law):
Google Analytics
- Provider: Google LLC (United States)
- Purpose: Understanding how Users interact with the Services
- Data collected: Anonymized IP address, pages viewed, session duration, device type, approximate location
- Retention: Up to 14 months
- Legal basis: Consent
- International transfer: EU-US Data Privacy Framework
- Privacy: https://policies.google.com/privacy
Meta Pixel
- Provider: Meta Platforms Ireland Limited (with onward transfers to Meta Platforms, Inc., United States)
- Purpose: Measuring effectiveness of our advertising on Facebook and Instagram, retargeting
- Data collected: Events (page views, clicks, conversions), hashed user identifiers, browser data
- Legal basis: Consent
- International transfer: EU-US Data Privacy Framework
- Privacy: https://www.facebook.com/privacy/policy
Google Ads
- Provider: Google LLC (United States)
- Purpose: Measuring conversions, retargeting users across Google's network
- Data collected: Click IDs, conversion events
- Legal basis: Consent
- International transfer: EU-US Data Privacy Framework
- Privacy: https://policies.google.com/privacy
7.4 Managing Cookies
You can manage Cookie preferences through:
- Our Cookie preference center (presented on first visit and accessible via the link in the website footer at any time);
- Your browser or device settings;
- Opt-out tools provided by Google (https://adssettings.google.com) and Meta (https://www.facebook.com/ads/preferences).
If you withdraw consent, we will stop loading the relevant cookies. Cookies already placed will be deleted by the browser on schedule, or you can clear them manually.
Disabling certain Cookies may affect the functionality of the Services.
7.5 Do Not Track
We currently do not respond to "Do Not Track" browser signals, as there is no industry consensus on how to interpret them. We honor explicit consent choices made through our Cookie preference center.
8. Data Retention
8.1 Retention Periods
We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods include:
| Data Category | Retention Period |
|---|---|
| Account information (active account) | For the duration of your account + up to 90 days after deletion for technical removal and backup cycles |
| User Content | Until you delete it or your account is terminated, plus up to 90 days for removal from backups |
| Transaction records (payments, subscriptions) | 7-10 years or as required by applicable tax and accounting law |
| Customer support communications | Up to 3 years after resolution |
| Content moderation and Trust & Safety records | Up to 5 years to enforce Terms and prevent repeat abuse |
| Copyright notices and counter-notices (DMCA log) | At least 3 years, as required to document Safe Harbor compliance |
| Marketing preferences and consents | Until consent is withdrawn + 2 years to demonstrate compliance |
| Cookies and similar technologies | Varies per Cookie (see Section 7) |
| Server logs and security logs | 12-24 months |
| Anonymized or aggregated data | May be retained indefinitely |
8.2 Deletion After Termination
Upon account deletion, we will delete or anonymize your personal information within the retention periods above, unless we are required to retain it for:
- Legal obligations (tax, accounting, law enforcement);
- Dispute resolution;
- Enforcement of our Terms and Conditions;
- Fraud prevention and repeat infringer tracking.
Some User Content may remain visible if it has been shared, reposted, or included in collaborative itineraries by other Users, in accordance with the license granted under our Terms and Conditions.
9. Your Rights
9.1 Rights for EU/UK/EEA Users (GDPR / UK GDPR)
If you are located in the EU, UK, or EEA, you have the following rights in relation to your personal information:
- Right of access (Article 15): Obtain confirmation of whether we process your data and a copy of it.
- Right to rectification (Article 16): Correct inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Article 17): Request deletion under certain conditions.
- Right to restriction of processing (Article 18): Limit how we process your data in certain circumstances.
- Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to object (Article 21): Object to processing based on legitimate interest, including profiling.
- Right to withdraw consent (Article 7(3)): Withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making (Article 22): Where automated decisions produce legal or similarly significant effects.
- Right to lodge a complaint with your national Data Protection Authority. A list of EU Data Protection Authorities is provided in Appendix A.
9.2 Rights for California Users (CCPA/CPRA)
If you are a California resident, you have the following rights:
- Right to know what personal information we collect, use, disclose, and sell/share;
- Right to delete personal information we collected from you;
- Right to correct inaccurate personal information;
- Right to opt-out of the "sale" or "sharing" of personal information and targeted advertising. We do not sell personal information for monetary consideration; however, the use of Meta Pixel and Google Ads may constitute "sharing" under CCPA/CPRA, which you can opt out of via our Cookie preference center;
- Right to limit use and disclosure of sensitive personal information;
- Right to non-discrimination for exercising your rights.
We do not knowingly sell or share the personal information of Californians under 16 without opt-in consent.
To exercise these rights, email support@gemsaround.com. We will verify your request using reasonable methods appropriate to the sensitivity of the data.
9.3 Rights for Other Jurisdictions
Users in other jurisdictions may have additional rights under local law (including Brazil's LGPD, Canada's PIPEDA, Quebec's Law 25, China's PIPL, and others). We honor these rights in accordance with applicable law. Contact us at support@gemsaround.com.
9.4 How to Exercise Your Rights
To exercise any of the rights above:
- Email: support@gemsaround.com
- In-app: Account settings → Privacy → Data Requests
We will respond within one (1) month (or as otherwise required by applicable law). In complex cases, we may extend this by up to two additional months with notice to you.
9.5 Verification
To protect your privacy, we may need to verify your identity before fulfilling a request. We may ask you to provide information sufficient to reasonably verify you are the person about whom the information pertains.
9.6 No Fee
Requests are processed free of charge, unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse the request.
10. Data Security
10.1 Security Measures
We implement appropriate technical and organizational measures to protect personal information against unauthorized access, loss, misuse, alteration, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest where appropriate;
- Access controls, authentication, and authorization systems;
- Regular security assessments;
- Secure software development practices;
- Employee training on data protection;
- Incident response procedures.
10.2 No Absolute Security
While we work hard to protect your information, no system is completely secure. You are responsible for maintaining the confidentiality of your password and notifying us immediately of any suspected unauthorized access.
10.3 Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and/or the relevant supervisory authority as required by applicable law (within 72 hours under GDPR where feasible).
11. Children's Privacy
11.1 Minimum Age
The Services are not intended for children below the applicable minimum age (see our Terms and Conditions, Section 4):
- 16 years in the EU/EEA, unless a lower age applies under national law (in Slovenia: 15; in some Member States: 13);
- 13 years in the United States and certain other jurisdictions;
- Higher ages as specified in Supplemental Terms.
11.2 Parental Consent (GDPR Article 8, COPPA)
Where required by law, Users below the age of digital consent may only use the Services with verifiable parental or legal guardian consent. We may refuse to provide the Services pending verification.
11.3 If We Discover Underage Use
If we become aware that we have collected personal information from a child without required consent, we will delete that information and terminate the account. Parents or guardians may contact us at support@gemsaround.com to review or delete information about their child.
11.4 California Minors ("Eraser Law")
California residents under 18 who are registered Users may request removal of content they have publicly posted by emailing support@gemsaround.com. Note that removal does not guarantee complete removal from all sources (e.g., backups, archives by other parties).
12. Marketing Communications
12.1 Types of Communications
We may send you marketing communications (email, push notifications, in-app messages) about new features, travel tips, promotional offers, and events.
12.2 Your Choices
- Email: Opt out via the unsubscribe link in any marketing email.
- Push notifications: Manage in your device settings or account preferences.
- In-app notifications: Manage in account settings.
Opting out of marketing does not affect transactional or service-related communications (e.g., security alerts, subscription confirmations).
12.3 Consent for Marketing
In jurisdictions where consent is required for marketing (including most EU countries for email marketing to individuals), we will ask for your consent at sign-up or before sending the first marketing communication.
13. Public Content and Location Data — Special Considerations
Because GemsAround is a location-based, video-first platform, we draw your attention to specific privacy considerations:
13.1 Public Visibility
Content you upload may be visible to other Users and, depending on your settings, to the general public. This includes:
- Videos and photos, including any identifiable individuals or license plates visible in them;
- Location tags, which may reveal the place where you filmed;
- Your username, profile, and activity.
13.2 Location-Related Risks
Location data can reveal sensitive information about you or others. Be mindful when:
- Uploading content from your home, workplace, or someone else's private residence;
- Tagging content with precise coordinates in real time (we recommend uploading after you have left the location);
- Featuring identifiable individuals without their consent.
13.3 Obfuscation
We may, at our discretion, obfuscate or generalize coordinates for certain sensitive content (e.g., residences) to protect privacy.
13.4 EXIF Data
Photos and videos may contain embedded metadata (EXIF), including GPS coordinates, date, and camera info. We process this metadata to power location features, and we may strip or modify it before public display.
13.5 Removal Requests
If you believe content on the Services reveals your location or private information without your consent, contact us at support@gemsaround.com.
14. Third-Party Links and Integrations
The Services may contain links to or integrations with third-party websites, apps, and services (e.g., Google Maps, Instagram, TikTok, app stores). This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of third parties before interacting with them.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy;
- Provide notice within the Services or by email;
- For significant changes affecting how we use your data based on consent, obtain new consent where required.
We encourage you to review this Policy periodically.
16. Contact Us
If you have questions, comments, or requests about this Privacy Policy or our privacy practices, please contact:
GemsAround Privacy Team
Gems Around S.R.L.
bd. Moscova 17/4, Chișinău, Republic of Moldova
General inquiries and privacy requests: support@gemsaround.com
Copyright, intellectual property, and DSA matters: copyright@gemsaround.com
If we cannot resolve your concern, you have the right to lodge a complaint with your national Data Protection Authority. A list of EU/EEA/UK Data Protection Authorities is provided in Appendix A.
Appendix A — Supervisory Authorities (EU/EEA/UK)
Examples of national Data Protection Authorities where EU/EEA/UK Users may lodge complaints:
- Slovenia: Informacijski pooblaščenec (https://www.ip-rs.si)
- Germany: BfDI and state authorities (https://www.bfdi.bund.de)
- France: CNIL (https://www.cnil.fr)
- Italy: Garante (https://www.garanteprivacy.it)
- Spain: AEPD (https://www.aepd.es)
- Austria: DSB (https://www.dsb.gv.at)
- United Kingdom: ICO (https://ico.org.uk)
- Full list of EU DPAs: https://edpb.europa.eu/about-edpb/board/members_en
Users in Moldova may lodge complaints with:
- Centrul Național pentru Protecția Datelor cu Caracter Personal (CNPDCP) — https://datepersonale.md
Appendix B — Categories of Personal Information Under CCPA/CPRA (California Users)
The following table summarizes personal information categories we have collected in the past 12 months:
| Category | Collected | Sources | Business Purpose | Shared With |
|---|---|---|---|---|
| Identifiers (name, email, IP, device ID) | Yes | You, automatic, third-party sign-in | Providing Services, security, analytics | Service providers, analytics partners (with consent), advertising partners (with consent) |
| Commercial information (transaction history) | Yes | You, payment processors | Providing paid features | Payment processors, service providers |
| Internet activity (usage data, clickstream) | Yes | Automatic | Analytics, security | Analytics partners (with consent), advertising partners (with consent) |
| Geolocation data | Yes | Automatic, with consent | Location-based features | Service providers |
| Audio/visual information (User Content) | Yes | You | Providing Services | Other Users (per your settings), service providers |
We do not sell personal information for monetary consideration. The use of Meta Pixel and Google Ads may constitute "sharing" for cross-context behavioral advertising under CCPA/CPRA, which you may opt out of via our Cookie preference center.
[END OF DOCUMENT]