Privacy Policy - Shopping app
This policy describes the personal data processed by the Shopping mobile app
(package name com.bridgescom.shopping) for Android and iOS.
1. Who is responsible
The data controller is:
Artem Romanchenko, an individual, Ukraine.
"Bridges Community" is the name of the project under which the apps are published. There is no separate legal entity behind it: all rights and obligations under these documents rest with the individual named above.
Contact for any data-related matter: bridges@bridges.net.ua.
2. The essentials in three sentences
The app collects exactly what a shared list cannot work without: who you are, so that other members can see who added an item, and what is in your lists. There is no advertising, no advertising identifier and no behavioural analytics in the app, and data is never sold. The main data store is located in the European Union.
3. What data is processed
3.1. Account data
Sign-in is handled by Google or Apple. The app never sees or receives the password for those accounts: authentication is performed by the operating system and Firebase Authentication.
After sign-in the app receives and stores:
| Data | Purpose | Legal basis |
|---|---|---|
| Internal account identifier (UID) | the only way to tell one member from another | performance of a contract |
| The name from your Google or Apple account | the "added by Oleh", "bought by Olha" labels in shared lists | performance of a contract |
| Email address | account recovery, contacting you about your account | performance of a contract |
| Profile photo (avatar), if you set one in the app | the circle next to your name for your friends and in shared lists | performance of a contract |
| Selected interface language | notification text is sent in your language | performance of a contract |
| Account code - six letters and digits the app generates when you first open the Friends screen | lets another person find you and send a friend request; along with the code they see your name | performance of a contract |
| Your list of friends in the app and friend requests (sent and received) | so that lists and subscriptions are opened only to people you added yourself | performance of a contract |
If you sign in with Sign in with Apple and choose "Hide My Email", the app only ever receives Apple's relay address and works with that. Your real address is not disclosed.
3.2. Content you create
- list names;
- the items in them: name, quantity, note;
- item categories (groups) and their order;
- "bought" marks, including who set them and when;
- your personal bank of item and category names used for suggestions;
- your profile photo, if you set one: the app shrinks the chosen picture to a small circle (128 by 128 pixels, a few kilobytes) and stores only that, never the original;
- the nicknames and photos you assign to your friends for your own convenience: only you can see them;
- your subscriptions (from version 1.2): name, price and currency, period, next payment date, how many days ahead to remind you, icon, note, the "paid" mark including who set it and when, and - only if you typed them in yourself - the payment method (a bank name or a few card digits) and the address of the payment site. The app does not verify these fields, does not send them anywhere and does not make payments: they are a reminder for you alone. There is no need to enter a full card number.
This content is yours. It is stored so that the app can show the list on all your devices and to everyone in the lists you share.
3.3. Technical data
| Data | Purpose |
|---|---|
| Device push notification token | delivering "item added" / "item bought" notifications |
| Creation and modification timestamps | ordering and synchronisation |
| Interface settings on the device itself (collapsed groups and similar) | convenience; this data never leaves the device |
| Crash report: error type, location in the code, device model and OS version (Firebase Crashlytics) | finding and fixing the crash |
3.4. What the app does NOT collect
- No location data.
- No access to contacts, calls, SMS or microphone.
- No reading of your photo library and no camera use on its own. They are opened only when you yourself pick a photo for your avatar, and the app receives just the one picture you chose; on iOS this works without access to the whole library. Photo metadata, including location, is neither read nor stored.
- No advertising identifier (AAID / IDFA) and no ad networks.
- No behavioural analytics and no advertising trackers: Google Analytics and Firebase Analytics are not integrated into the app. The single exception is crash reporting (Firebase Crashlytics), described in section 3.3; it carries no content from your lists and is not used for profiling.
- No tracking of you across other sites and apps.
- No selling of data and no sharing with data brokers.
4. What other members of a list can see
This is the most important thing to understand before you invite anyone.
If you create a shared list or join someone else's, every member of that list can see:
- your name and profile photo, if you set one; your friends in the app can see the photo too;
- every item you added or marked as bought, attributed to you;
- when you did it.
The same applies to family subscriptions (from version 1.2): every member of a subscription you shared can see its name, price, period, payment date, who pays, the "paid" marks and whatever you entered as the payment method and site. Members receive notifications about due payments, payments made and being added to a subscription; these can be turned off in the app separately from list notifications.
Members cannot see your email address or your personal bank of item names, which stays private.
A list or subscription can only be opened to a friend in the app, and becoming friends takes two steps: you give the other person your account code (or they give you theirs), they send a request, you accept it. An account code is six letters and digits generated by the app itself; it is not, and is not derived from, a phone number, and you hand it only to whoever you choose. Whoever knows the code sees your name before you accept the request, so both of you can make sure it is the right person. Nobody can find you in the app by name, email address or phone number. A friendship can be ended at any time; shared lists and subscriptions stay, but that person can no longer be added to new ones.
5. Where data is stored
The app runs on the Google Firebase platform:
| Service | What it does | Where |
|---|---|---|
| Firebase Authentication | sign-in with Google or Apple | Google infrastructure |
| Cloud Firestore | storage of lists and profiles | region europe-central2 (Warsaw, European Union) |
| Cloud Functions | composing notification text | region europe-central2 (Warsaw, European Union) |
| Firebase Cloud Messaging | delivery of push notifications | Google infrastructure |
| Firebase Crashlytics | crash reports | Google infrastructure |
The primary database is located in the European Union. Certain supporting operations (authentication, notification delivery) technically run on Google's global infrastructure and may be processed outside the EU. Google LLC and Google Ireland Limited act as data processors under the EU Standard Contractual Clauses.
All traffic between the app and the server is encrypted in transit (TLS).
6. How long data is kept
- Account data and your content: for as long as your account exists.
- After account deletion: see section 7; the provider's backups may retain data for up to 90 days before being overwritten.
- Push notification tokens are removed when you sign out or when they expire.
7. Deleting your account and data
You can delete your account at any time, either in the app or by email. The procedure, the timelines and the exact list of what gets deleted are on a separate page: Account and data deletion.
8. Your rights
Under the Ukrainian Personal Data Protection Act, and for users in the EU under the GDPR, you have the right to:
- access - find out exactly what data about you is processed and get a copy;
- rectification of inaccurate data;
- erasure ("right to be forgotten");
- restriction of processing;
- data portability - receive your data in a machine-readable format;
- object to processing;
- lodge a complaint with a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, your local data protection authority.
To exercise any right, write to bridges@bridges.net.ua from the address you use to sign in. I will respond within 30 days.
9. Children
The app is not intended for anyone under 13. In countries where the law sets a higher age of consent for processing personal data (in the European Union this ranges from 13 to 16 depending on the country), the app is not intended for anyone below that age.
Personal data of such users is not knowingly collected. If you are a parent and believe your child created an account without your consent, write to me and the account will be deleted.
10. Security
- Connections are encrypted (TLS).
- Only members of a list can access it: this is enforced by database-level security rules, not merely by checks inside the app.
- The app never knows or stores your Google or Apple password.
No system is perfectly secure. If you find a vulnerability, please write to bridges@bridges.net.ua - such messages are genuinely appreciated.
11. Changes to this policy
An updated version is published on this page and the date at the top changes. Material changes (new categories of data, new recipients) will also be announced inside the app.
12. Governing law
The laws of Ukraine; for users in the European Union, the GDPR applies in addition.