Your data, your control
Privacy Policy
Version 2026-09-13 · Effective for the private beta when account access opens
Pre-launch notice: This policy describes the private-beta product currently being built. A privacy and legal review, including the final operator address and launch jurisdictions, is required before public registration. The marketing website itself uses no analytics, cookies, forms, or third-party embeds.
1. Who is responsible
The OnMyRadar project is responsible for the personal data described here. Until final operator details are published, privacy requests can be sent to info@onmyradar.pro. We will add the operator’s legal name and postal address before the public beta.
2. Scope
This policy covers the OnMyRadar iOS and Android apps, this website, customer support, and the backend services used to provide Radars, event matches, maps, notifications, submissions, export, and deletion. An event organizer or linked source controls data you provide directly on its own site.
3. Data we process
- Account and consent: Firebase user ID, provider, provider-verified email when supplied, preferred language and timezone, account status, and the Terms and Privacy versions you accepted.
- Your use of the product: Radar criteria, interests, saved events, match feedback, event annotations, notification preferences, contribution submissions, reports, and support requests.
- Location: an optional, foreground-only approximate location or selected area used for “Near me” and map results. We do not request background location or retain movement history.
- Device and delivery: push token, app/platform version, locale, timezone, delivery status, bounce or suppression status, and privacy-safe idempotency identifiers.
- Security and operations: App Check signals, coarse request metadata, bounded job state, audit events, and error/performance records needed to prevent abuse and keep the service reliable. Routine logs must not contain email, Radar text, precise location, device tokens, or raw source bodies.
- Public-source event data: event facts and provenance collected from approved sources. This is kept separate from your private Radars and profile.
4. Why we use it
We use personal data to authenticate you, create and interpret Radars, return and explain matches, save your choices, deliver notifications you selected, moderate contributions, answer requests, secure and operate the service, and meet legal obligations. We do not sell personal data or use sensitive Radar text for advertising.
Where European data-protection law applies, processing is based on performance of the service you request, your consent for optional permissions or communications, legitimate interests in security and reliable operation, and legal obligations where applicable. You may withdraw optional consent without affecting earlier lawful processing.
5. Service providers and transfers
- Google Firebase and Google Cloud: Authentication, App Check, Functions, Firestore, private Storage, push delivery through Firebase Cloud Messaging, and operational infrastructure.
- Google Maps: map display in the app. Opening a map may send device/network and viewport information to Google under Google’s own privacy terms. The app does not use background location.
- Resend: transactional email and delivery/suppression handling when email delivery is enabled.
- Apple and Google: authentication when you choose the corresponding sign-in provider.
Providers may process data in countries outside your own. Before external launch we will document the applicable processor terms and transfer safeguards. Crash reporting, performance monitoring, and product analytics are not enabled merely by visiting this website; if enabled in an app build, this policy and the in-app disclosure will identify the data and controls first.
6. When data is shared
We disclose data to the providers above only as needed to operate the service, when you direct us to, to protect users and the service, or when law requires it. Approved event contributions can become public only after automated screening and authorized moderation. We do not publish your Radars, attendance intent, email, or precise location.
7. Retention
- Profiles, Radars, saved events, and feedback: for the account lifetime, then the deletion workflow.
- Push tokens: until invalid, logout, account switch, or deletion.
- Notification and email delivery records: 30 days; payload is removed before minimal metadata where possible.
- Export files: 24 hours after completion.
- Deletion evidence: minimal non-content fields for 90 days; a one-way identifier hash blocks accidental account recreation for 30 days.
- Routine application logs: 30 days; restricted security audit records: up to 365 days.
- Moderation cases: up to 365 days after closure, then deletion or anonymization.
- If privacy-safe product analytics are later enabled: no more than 14 months.
Legal duties, fraud or security investigations, disputes, and source-specific permissions may require a shorter or longer period. Any extension is limited to the purpose and access is restricted.
8. Security
We use encrypted transport, private-by-default storage, short-lived deployment credentials, least-privilege service identities, server-side authorization, App Check, bounded audit records, and tested export/deletion workflows. No service can promise perfect security; report a concern through Support.
9. Your choices and rights
You can change notification and location permissions in the app or operating-system settings, pause or delete Radars, export your data, and request account deletion. Depending on where you live, you may also ask to access, correct, restrict, object to, or receive a portable copy of your data, or complain to a data-protection authority. We verify requests to protect the account and do not discriminate for exercising applicable rights.
See Delete your account for the in-app and support paths.
10. Children
OnMyRadar is not directed to children under 16 or a lower local digital-consent age where applicable. We do not knowingly create accounts for children below the required age. Contact us if you believe a child provided personal data improperly.
11. Changes
Material changes receive a new version and effective date. When required, we will notify account holders and request renewed acknowledgement before continued use.
12. Contact
Email info@onmyradar.pro with “Privacy request” in the subject. Please do not email passwords, identity documents, precise location, or authentication tokens unless we provide a secure request channel.