Version 1.0 · Effective {{EFFECTIVE_DATE}} · Permanent address: https://{{DOMAIN}}/privacy-en · This is a courtesy translation of the Russian version, which is legally controlling in case of any discrepancy.
1.1. This Policy is adopted under Art. 18.1(2) of Russian Federal Law No. 152-FZ “On Personal Data” (the “Personal Data Law”) and describes how personal data of users of the “Cashback” mobile application (the “App”) is processed and protected.
1.2. Data controller (operator): {{COMPANY_REQUISITES}} (the “Operator”, “we”).
1.3. Privacy contact: {{SUPPORT_EMAIL}}.
1.4. By using the App you confirm that you have read this Policy. Processing relies on the legal bases listed in section 4; where the basis is consent, it is given by the specific user actions described in this Policy (registering, enabling a permission, confirming an image upload).
1.5. This Policy covers data received in connection with the App and the {{DOMAIN}} website. Third-party services (including banking apps) are governed by their own documents.
“User” — an individual using the App. “Anonymous profile” — an account created automatically and tied to an installation identifier. “Registered profile” — an account to which the User has attached a contact identifier (phone, e-mail, Telegram account, or another available method). Other terms have the meanings given by the Personal Data Law.
3.1. Anonymous profile. Created automatically on first launch; tied to a pseudonymous installation identifier (UUID) and a technical identifier of the App instance on the device. No name, phone number or other contact data is required; the App is fully functional.
3.2. Registered profile. Optional, typically used to transfer data to another device. One contact identifier is requested: mobile phone number (confirmed by an SMS code), e-mail address, Telegram account, or other methods available in the App at the time.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Installation UUID, technical device identifier | anonymous profile operation, data sync | performance of the Terms of Service | until account deletion |
| Phone number (stored encrypted; only last 4 digits displayed) / e-mail / Telegram identifier | signing in, data transfer, access recovery | performance of the Terms of Service | until account deletion |
| User-entered card details: bank, last 4 digits, cashback categories and terms | the App's core function — picking the best card | performance of the Terms of Service | until account deletion |
| Location (coordinates), incl. background geofencing; recommendation history with coordinates | cashback hints near stores, arrival notifications | consent — given by enabling the location permission, revocable in device settings at any time | until account deletion |
| Map contributions (coordinates, name, category of a place) | maintaining the shared places database | performance of the Terms of Service | indefinitely; after account deletion — anonymized only (8.4) |
| Push token, platform | notification delivery | consent — the notifications permission, revocable in device settings | until account deletion or permission revocation |
| Technical and analytics data: device model, OS and App version, usage events, search query text (incl. recognized voice input), session id | product improvement, bug fixing; production of anonymized aggregated usage statistics (such statistics contain no user identifiers and cannot identify you) | consent (expressed by using the App after reading this Policy) | raw events — max 180 days; afterwards only aggregated statistics without user identifiers |
| Voluntarily shared bank app screenshots | recognition model improvement (section 6) | separate consent per image | max {{ML_RETENTION}} |
We process no special categories of personal data and no biometric data, sell no data, and make no decisions with legal effects based solely on automated processing.
5.1. Screenshot recognition (OCR). Cashback categories are recognized from bank app screenshots on the device. The images themselves are not sent to the Operator; only technical metadata about the result (success/failure, technical metrics without image content) reaches the server.
5.2. Voice input. Speech is recognized on-device by the operating system. Audio recordings are never sent to the Operator; only the recognized query text reaches the server.
5.3. The App never requests or stores full card numbers (PAN), CVC/CVV codes, expiry dates, account access, or account transactions.
6.1. From time to time the App may offer to share individual screenshots of the cashback categories page to improve the recognition model. Sharing happens only with the User's explicit consent for each specific image; declining does not limit the App.
6.2. Before sending, make sure the screenshot contains nothing you do not want to share (name, balance, account numbers). Shared images are used solely for training and evaluating the recognition model, access to them is restricted, they are stored no longer than {{ML_RETENTION}} and then destroyed. Consent can be withdrawn, and specific images destroyed early, by writing to {{SUPPORT_EMAIL}}.
7.1. We do not sell personal data and do not share it for advertising. Data is disclosed only to the extent necessary for the App to work:
| Recipient | Data | Purpose |
|---|---|---|
| 2GIS LLC, Russia | query coordinates | nearby business search |
| Yandex LLC, Russia (optional) | query coordinates | nearby business search |
| OpenStreetMap Foundation / Nominatim | coordinates and query text without any user identifiers, sent from the Operator's server | geocoding and address suggestions |
| Google LLC (FCM), Apple Inc. (APNs) | device push token | notification delivery |
| An SMS delivery provider (to be named in this section before SMS sending starts) | phone number, SMS text with the code | login code delivery |
7.2. Processors acting on the Operator's instructions are bound by confidentiality and Art. 19 of the Personal Data Law. The current list of recipients is maintained on this page.
7.3. Data may be disclosed to state authorities only on the grounds and in the manner provided by Russian law.
8.1. Localization. Personal data of Russian citizens is recorded, systematized, accumulated, stored, updated and retrieved using databases located in the Russian Federation (Art. 18(5) of the Personal Data Law).
8.2. Cross-border transfer. To deliver push notifications, the device push token is transferred to Google LLC and Apple Inc. (USA). No other personal data leaves Russia: OpenStreetMap/Nominatim requests are made by the Operator's server and contain no user identifiers. A cross-border transfer notification is filed with Roskomnadzor under Art. 12 of the Personal Data Law.
8.3. Account deletion. Available in the App (“More” → “Delete account”) or by writing to {{SUPPORT_EMAIL}} (with account ownership confirmation). The account is deactivated immediately (access and sessions terminated), and the personal data relating to it — including contact identifiers, card details, location history and analytics events — is irreversibly destroyed on the Operator's servers within 30 (thirty) days.
8.4. Map contributions remain after account deletion in anonymized form: the link between the record and the User is destroyed irreversibly and cannot be restored. The basis for keeping anonymized records is the Terms of Service (user content license).
8.5. Once the processing purposes are achieved or no longer needed, data is destroyed within 30 days unless the law provides otherwise.
9.1. You may: obtain information about the processing of your data (Art. 14); demand rectification, blocking or destruction of data that is incomplete, outdated, inaccurate or unlawfully obtained; withdraw consent; demand that processing stop in the cases provided by law; and complain to Roskomnadzor (pd.rkn.gov.ru) or a court.
9.2. Requests are accepted at {{SUPPORT_EMAIL}}. We respond within 10 business days; the term may be extended by up to 5 business days with a reasoned notice.
9.3. Withdrawal of consent does not affect the lawfulness of prior processing and does not prevent processing on other legal grounds (e.g., performance of the Terms of Service until the account is deleted).
We apply the legal, organizational and technical measures required by Arts. 18.1–19 of the Personal Data Law, including: encryption of the phone number at rest; storage of verification codes only in irreversibly hashed form; TLS transport encryption; access control and logging; a designated person responsible for data processing; internal policies and compliance checks.
The App uses a pseudonymized analytics identifier solely for its own product statistics. It contains no advertising networks or third-party analytics SDKs, does not track you across third-party apps or websites, and builds no advertising profiles. The {{DOMAIN}} website uses no cookies requiring consent.
The App is not directed at children under 14, and we do not knowingly collect their data. Users aged 14–18 use the App with the consent of their legal representatives. If you become aware of a child's data provided without such consent, contact {{SUPPORT_EMAIL}} — the data will be destroyed.
We may amend this Policy. The new version is published at https://{{DOMAIN}}/privacy-en with its effective date; material changes are additionally announced in the App.
{{COMPANY_REQUISITES}}
E-mail: {{SUPPORT_EMAIL}}