Privacy Policy
1) About us
Zwinoo is a mobile app connecting buyers and travellers. We operate in Europe and Africa. Core hosting and processing occur in the European Union (Google Cloud Firebase — region europe‑west1).
2) Data we process
- Account: e‑mail (login), password (hashed), username, phone number, city of residence, avatar, internal user ID.
- Payments & payouts: IBAN and BIC (payouts), payment events (webhooks); Zwinoo does not store card details.
- User content: images and PDFs you upload, photos taken with the app.
- Technical: device type (mobile/tablet), OS (Android/iOS), notification token. We do not collect location, contacts, microphone audio, or Bluetooth data.
- Support: assistance messages you send from the app and our replies.
- Camera & scanning: used to scan QR codes or take photos; no video stream is kept.
3) Purposes & legal bases
- Provide the service & manage the account (contract): e‑mail/password authentication, user‑specific settings, in‑app assistance.
- Payments & payouts (contract & legal obligations): collections with Stripe, payouts via WISE; webhook‑based updates.
- Security (legitimate interests & legal obligations): access control, App Check between UI and backend, anti‑abuse protections (reCAPTCHA/SMS phone verification).
- Notifications (legitimate interests / device‑level consent): important app events; occasionally a promo code; never advertising.
- Support (contract): handle your requests and incidents.
4) Sharing & service providers
- Firebase (Google Cloud): Auth, Firestore, Cloud Messaging, hosting. Data hosted in the EU.
- Stripe: card payment processing; we do not store your card data.
- WISE: bank transfers to remunerate users.
- Google (reCAPTCHA / APIs) & fixer.io: verification and auxiliary services.
- No commercial sharing, no data sales, and no third‑party ads.
5) International transfers
Our systems are configured for EU hosting. We do not perform processing‑purpose transfers outside the EU/EEA.
6) Security
- Encryption in transit (TLS) and at rest with our cloud providers.
- App Check between the mobile UI and backend; secrets are stored only server‑side.
- Strict access control, admin access logging, and least‑privilege principles.
- Breach notification process: if a data breach occurs, we will notify you within a target of 72 hours and take corrective actions.
7) Retention
- Account & usage data: 3 years after the last activity.
- Technical logs strictly needed: 6 months.
- Accounting records (e.g., invoices): 5 years (legal obligations).
- User content (images/PDF): for the life of the account and deleted on request.
- Account deletion: available in‑app; we erase related data unless we must keep some items to comply with the law.
8) Your rights (GDPR)
You have the rights to access, rectification, erasure, restriction, objection, portability, and to set instructions for data after death where applicable. To exercise a right, use the in‑app assistance module or e‑mail us at admin@zwinoo.com. You can also complain to your supervisory authority (e.g., the Data Protection Commission in Ireland or your local authority).
9) Minors
The service is intended for users aged 12+. Minors must use the app under the responsibility and guidance of an adult.
10) Notifications & marketing
In‑app and push notifications are only for important app events and, rarely, a promo code. No advertising. You can disable notifications in your device settings.
11) Changes
We may update this policy to reflect service or legal changes. We will inform you within the app if a material change occurs.
12) Contact
Questions or requests: admin@zwinoo.com.