Privacy Policy
1. Introduction & Identity of the Controller
This Privacy Policy explains how Radu Popa ("Company," "we," "us," or "our") collects, uses, stores, and shares your personal data when you use the Stocked mobile application ("App," "Service").
Radu Popa is the data controller responsible for your personal data processed in connection with this Service. For questions or requests regarding your personal data, contact our designated privacy contact at contact.stocked@gmail.com.
We are committed to processing your data in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and all other applicable data protection legislation.
2. Data We Collect
We collect the minimum personal data necessary to provide the Service. Below is a summary of the categories of data we process.
2.1 Account & Authentication Data
- Email Address: Collected when you register via email/password or sign in with Google. Used for account creation, authentication, password reset communications, and to link your identity to shared household workspaces.
- Display Name: The name you choose to display within the App. Shared with other members of household workspaces you participate in for collaborative identification.
2.2 Household & Product Content Data
- Household names and product names you create within the App ("User Content"). This data is stored to provide the core inventory management functionality.
- Household membership records, including the email addresses of users you invite to shared household workspaces and the membership status of those invitations.
2.3 Technical & Usage Data
- Anonymous device identifiers (such as the IDFA on iOS or the Advertising ID on Android) may be used by our advertising partners to deliver and attribute App Open Ads served to free-tier users. See Section 6 for full details.
- Firebase Analytics and Crashlytics may collect anonymized crash reports and aggregate usage telemetry to help us diagnose technical issues and improve the App. This data is not linked to your personal identity.
2.4 Data We Do NOT Collect
- Payment card details — all billing is handled exclusively by Apple App Store Billing or Google Play Billing. We never receive, store, or process your payment instrument data.
- Precise geolocation data.
- Photos, camera, or microphone data.
- Contacts from your device address book.
3. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA) and the United Kingdom, we process your personal data on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Account creation & authentication | Performance of a contract (Art. 6(1)(b) GDPR) |
| Collaborative household mapping (sharing your Display Name & Email with co-members) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending password reset emails | Performance of a contract (Art. 6(1)(b) GDPR) |
| Displaying App Open Ads to free-tier users | Consent (Art. 6(1)(a) GDPR) — obtained via the device tracking prompt (App Tracking Transparency on iOS / consent dialog on Android) before any advertising identifier is accessed. |
| Crash reporting & app stability | Legitimate interests (Art. 6(1)(f) GDPR) — improving service reliability |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
4. How We Use Firebase (Google LLC)
The App uses Firebase, a platform developed by Google LLC, as its core backend infrastructure. Specifically:
- Firebase Authentication: Processes your email address and password hash (for email/password accounts) or Google ID token (for Google Sign-In) to create and manage your account. Firebase Authentication is operated by Google LLC and is subject to Google's Privacy Policy.
- Firebase Firestore: Stores your Display Name, Email Address (as an account identifier), household names, product names, and household membership records in Google's cloud infrastructure. Data stored in Firestore is encrypted at rest and in transit.
- Firebase data is stored in data centers in the United States (us-central1). If you are in the EEA, please be aware that your data may be transferred to and processed in the United States. Such transfers are subject to appropriate safeguards, including Google's Standard Contractual Clauses.
Google LLC's Privacy Policy is available at: https://policies.google.com/privacy
5. How We Share Your Data
We do not sell, rent, or trade your personal data. We share your data only in the following limited circumstances:
5.1 With Other Household Members
When you join or create a shared household workspace, your Display Name and the first two characters of your name (for avatar display) are visible to all other accepted members of that household. If you invite another user by email, their email address is temporarily stored in the household record until they accept or decline the invitation.
5.2 Service Providers
We engage the following third-party service providers who may process your data on our behalf as data processors:
- Google LLC (Firebase) — authentication, database, and crash reporting.
- Apple Inc. / Google LLC — billing and subscription management via their respective platform billing systems.
- Advertising network partners — delivery of App Open Ads to free-tier users (see Section 6).
5.3 Legal Requirements
We may disclose your personal data if required to do so by law, regulation, court order, or governmental authority, or if we believe disclosure is necessary to protect our legal rights or the safety of others.
5.4 Business Transfer
In the event of a merger, acquisition, reorganization, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.
6. Advertising & Device Identifiers
6.1 App Open Ads (Free Tier Only)
Users on the free tier of the App may be shown a standard, non-invasive App Open Advertisement upon the initial launch of the application. This advertisement is displayed as a full-screen interstitial before the main dashboard loads and auto-dismisses within a short time period.
Paid subscribers are not shown App Open Ads.
6.2 Advertising Identifiers
For the purpose of serving and attributing these advertisements, our advertising partners may access your device's anonymous advertising identifier — the Identifier for Advertisers (IDFA) on iOS, or the Google Advertising ID (GAID) on Android. These identifiers are anonymized hardware-level identifiers managed entirely by your operating system. They are not linked to your name, email address, or any other personally identifiable information held by the Company.
You can reset or limit the use of your advertising identifier at any time in your device settings:
- iOS: Settings → Privacy & Security → Tracking → Allow Apps to Request to Track (off) or Settings → Privacy & Security → Apple Advertising.
- Android: Settings → Google → Ads → Reset Advertising ID or Opt out of Ads Personalization.
6.3 No Sensitive Targeting
We do not use your personal data (email, household content, or product data) for advertising targeting purposes.
7. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide the Service. Specifically:
- Account data (email, display name): Retained for the lifetime of your account. Account data and personal content are permanently deleted from our live production databases immediately upon executing the 'Close Account' command in-app, with cached backups purged within 30 days.
- Household and product content: Deleted immediately upon household deletion by the owner, or within 30 days of account deletion for all owned households.
- Pending email invitations: Retained until accepted, declined, or the associated household is deleted.
- Anonymized crash and analytics data: Retained in accordance with Google Firebase's data retention policies (typically up to 14 months).
You may request deletion of your account and all associated personal data at any time via the Account screen within the App or by contacting us at contact.stocked@gmail.com.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access: To request a copy of the personal data we hold about you.
- Right to Rectification: To request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): To request deletion of your personal data. Exercisable via the "Close Account" function in the App or by contacting us.
- Right to Restriction of Processing: To request that we limit how we use your data in certain circumstances.
- Right to Data Portability: To receive your data in a structured, machine-readable format.
- Right to Object: To object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority in the EU/EEA, or the ICO in the UK).
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at contact.stocked@gmail.com.
To exercise any of the above rights, please contact us at contact.stocked@gmail.com. We will respond to verifiable requests within the timeframes required by applicable law (generally 30 days under GDPR, 45 days under CCPA).
9. Children's Privacy
The App is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete such data promptly. If you believe we may have collected data from a child under 16, please contact us at contact.stocked@gmail.com.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Transport Layer Security (TLS/HTTPS) encryption for all data in transit between the App and Firebase.
- Encryption at rest for data stored in Firebase Firestore.
- Firebase Authentication for secure credential management (passwords are never stored in plaintext).
- Optional biometric authentication (Face ID / Touch ID / Fingerprint) for App access, with credentials stored in the device's secure enclave via iOS Keychain / Android Keystore.
- Role-based Firestore Security Rules ensuring users can only access household data they are authorized to view.
While we strive to protect your data, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
11. International Transfers
As the App uses Firebase infrastructure operated by Google LLC, your personal data may be transferred to and stored in countries outside your country of residence, including the United States. Where such transfers involve data from the EEA or UK, we rely on Google's Standard Contractual Clauses and supplementary technical measures to provide an adequate level of data protection.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this Policy and, where required by law, by providing you with prominent in-app notice or seeking your fresh consent.
We encourage you to review this Policy periodically to stay informed about how we protect your data.
13. Contact & Complaints
For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact:
Radu Popa
contact.stocked@gmail.com
If you are in the EU/EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your national Data Protection Authority. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en