Privacy Policy
Last updated: May 2026
Scope
This Privacy Policy applies to all Oxploria services: the website www.oxploria.com and the Oxploria mobile app (available on the App Store and Google Play). By using either service, you agree to the practices described below.
Data we collect
Creating an account is mandatory to access the Oxploria app. We only collect data that is strictly necessary for the services to work:
• Account data (required) — first name, date of birth, email address and password (hashed and managed by Firebase Authentication — we never have access to your raw password).
• Unique identifier (UID) — automatically generated by Firebase Authentication when you create an account, to link your data (favourites, rewards, history).
• Newsletter email — only if you subscribe, with your explicit consent. Each email includes an unsubscribe link.
• GPS location — in the mobile app only, if you grant permission. Used solely in real time to display your position on the map and suggest nearby places. Never transmitted to or stored on our servers.
• App usage data — via Firebase Analytics: in-app events (places viewed, rewards unlocked), device type, OS version, language. Data is pseudonymised and used in aggregated form to improve the app.
• Website usage data — via Vercel Analytics: pages visited, device type, country. Aggregated statistical data, no advertising or marketing tracking.
• Crash reports — via Firebase Crashlytics: if the app crashes, technical data (error trace, app version, device type) is collected to improve app stability.
What we don't collect
We do not collect your GPS location in the background or outside active use of the app.
We do not collect your contacts, photo library, advertising identifier (IDFA/GAID), or any biometric data.
We never sell, rent, or share your data with third parties for commercial or advertising purposes.
App permissions
• Location ("While using the app") — to show your position on the map and calculate distances to nearby places. This permission is optional; the app remains usable without it.
• Push notifications (optional) — to notify you of new cities, features or important announcements. You can disable notifications at any time in your device settings.
Purpose
• User account: access to your favourites, rewards and visit history.
• Location: displaying your position on the map and suggesting nearby places.
• Newsletter: sending Oxploria updates (new cities, features, announcements).
• Analytics: improving the user experience on the website and in the app.
• Crashlytics: app stability and quality.
Legal basis for processing
In accordance with the GDPR, Oxploria processes data on the following legal bases:
• Performance of service — creating and managing your user account, access to favourites, rewards and history.
• Consent — newsletter, push notifications and location permission.
• Legitimate interest — audience measurement, performance improvement, app stability and security.
Data retention
• User account: retained until you delete your account from within the app.
• Newsletter email: retained until you unsubscribe.
• Analytics & Crashlytics data: retained for a maximum of 13 months.
• GPS location: never transmitted or stored — processed in real time on your device only.
Security & liability
Your data is never sold, rented, exchanged or shared with any third party for commercial or advertising purposes. This is an absolute rule.
Your data is stored exclusively within the services mentioned in this policy (Firebase and Vercel).
We implement all reasonable measures to protect your data and select recognised providers with high security standards. However, no computer system can guarantee absolute security against all risks of hacking, intrusion or technical incidents.
Third-party services
The app and website use the following services, which may process certain data:
• Firebase Authentication (Google LLC) — account management. Data hosted in Europe (eur3). Policy: firebase.google.com/support/privacy
• Firebase Firestore (Google LLC) — storage of favourites, rewards and history. Data hosted in Europe (eur3).
• Firebase Analytics (Google LLC) — app usage analysis.
• Firebase Crashlytics (Google LLC) — crash reports and stability.
• Google Maps (Google LLC) — interactive mapping in the app. Policy: policies.google.com/privacy
• Vercel Inc. — website hosting and analytics. Policy: vercel.com/legal/privacy-policy
• App Store (Apple Inc.) — iOS distribution. Policy: apple.com/legal/privacy
• Google Play (Google LLC) — Android distribution. Policy: policies.google.com/privacy
International data transfers
Some services used by Oxploria are provided by international companies, including Google LLC and Vercel Inc., which may involve transfers of data outside the European Union, including to the United States.
These transfers are governed by the legal mechanisms provided for under the GDPR, including the European Commission's standard contractual clauses and/or the Data Privacy Framework where applicable.
Cookies and similar technologies
The Oxploria website does not use advertising cookies or marketing tracking.
Certain technical technologies required for the website to function or for user login may however be used by the third-party services mentioned above.
Minimum age
Oxploria services are not intended for children under the age of 15.
Your rights (GDPR)
Under the GDPR, you have the right to access, rectify, erase, object to, and port your data.
To delete your account and all associated data, go to app Settings → "Delete my account".
For all other requests: contact@oxploria.com. We will respond within a maximum of 30 days.
Contact
contact@oxploria.com