Privacy Policy (Personal Data Processing Policy)

Version 1.0 · Effective {{EFFECTIVE_DATE}} · Permanent address: https://{{DOMAIN}}/privacy-en · This is a courtesy translation of the Russian version, which is legally controlling in case of any discrepancy.

1. General

1.1. This Policy is adopted under Art. 18.1(2) of Russian Federal Law No. 152-FZ “On Personal Data” (the “Personal Data Law”) and describes how personal data of users of the “Cashback” mobile application (the “App”) is processed and protected.

1.2. Data controller (operator): {{COMPANY_REQUISITES}} (the “Operator”, “we”).

1.3. Privacy contact: {{SUPPORT_EMAIL}}.

1.4. By using the App you confirm that you have read this Policy. Processing relies on the legal bases listed in section 4; where the basis is consent, it is given by the specific user actions described in this Policy (registering, enabling a permission, confirming an image upload).

1.5. This Policy covers data received in connection with the App and the {{DOMAIN}} website. Third-party services (including banking apps) are governed by their own documents.

2. Terms

“User” — an individual using the App. “Anonymous profile” — an account created automatically and tied to an installation identifier. “Registered profile” — an account to which the User has attached a contact identifier (phone, e-mail, Telegram account, or another available method). Other terms have the meanings given by the Personal Data Law.

3. Account modes

3.1. Anonymous profile. Created automatically on first launch; tied to a pseudonymous installation identifier (UUID) and a technical identifier of the App instance on the device. No name, phone number or other contact data is required; the App is fully functional.

3.2. Registered profile. Optional, typically used to transfer data to another device. One contact identifier is requested: mobile phone number (confirmed by an SMS code), e-mail address, Telegram account, or other methods available in the App at the time.

4. Data, purposes, legal bases and retention

DataPurposeLegal basisRetention
Installation UUID, technical device identifieranonymous profile operation, data syncperformance of the Terms of Serviceuntil account deletion
Phone number (stored encrypted; only last 4 digits displayed) / e-mail / Telegram identifiersigning in, data transfer, access recoveryperformance of the Terms of Serviceuntil account deletion
User-entered card details: bank, last 4 digits, cashback categories and termsthe App's core function — picking the best cardperformance of the Terms of Serviceuntil account deletion
Location (coordinates), incl. background geofencing; recommendation history with coordinatescashback hints near stores, arrival notificationsconsent — given by enabling the location permission, revocable in device settings at any timeuntil account deletion
Map contributions (coordinates, name, category of a place)maintaining the shared places databaseperformance of the Terms of Serviceindefinitely; after account deletion — anonymized only (8.4)
Push token, platformnotification deliveryconsent — the notifications permission, revocable in device settingsuntil account deletion or permission revocation
Technical and analytics data: device model, OS and App version, usage events, search query text (incl. recognized voice input), session idproduct improvement, bug fixing; production of anonymized aggregated usage statistics (such statistics contain no user identifiers and cannot identify you)consent (expressed by using the App after reading this Policy)raw events — max 180 days; afterwards only aggregated statistics without user identifiers
Voluntarily shared bank app screenshotsrecognition model improvement (section 6)separate consent per imagemax {{ML_RETENTION}}

We process no special categories of personal data and no biometric data, sell no data, and make no decisions with legal effects based solely on automated processing.

5. Data that never leaves your device

5.1. Screenshot recognition (OCR). Cashback categories are recognized from bank app screenshots on the device. The images themselves are not sent to the Operator; only technical metadata about the result (success/failure, technical metrics without image content) reaches the server.

5.2. Voice input. Speech is recognized on-device by the operating system. Audio recordings are never sent to the Operator; only the recognized query text reaches the server.

5.3. The App never requests or stores full card numbers (PAN), CVC/CVV codes, expiry dates, account access, or account transactions.

6. Voluntary screenshot sharing for model training

6.1. From time to time the App may offer to share individual screenshots of the cashback categories page to improve the recognition model. Sharing happens only with the User's explicit consent for each specific image; declining does not limit the App.

6.2. Before sending, make sure the screenshot contains nothing you do not want to share (name, balance, account numbers). Shared images are used solely for training and evaluating the recognition model, access to them is restricted, they are stored no longer than {{ML_RETENTION}} and then destroyed. Consent can be withdrawn, and specific images destroyed early, by writing to {{SUPPORT_EMAIL}}.

7. Disclosure to third parties

7.1. We do not sell personal data and do not share it for advertising. Data is disclosed only to the extent necessary for the App to work:

RecipientDataPurpose
2GIS LLC, Russiaquery coordinatesnearby business search
Yandex LLC, Russia (optional)query coordinatesnearby business search
OpenStreetMap Foundation / Nominatimcoordinates and query text without any user identifiers, sent from the Operator's servergeocoding and address suggestions
Google LLC (FCM), Apple Inc. (APNs)device push tokennotification delivery
An SMS delivery provider (to be named in this section before SMS sending starts)phone number, SMS text with the codelogin code delivery

7.2. Processors acting on the Operator's instructions are bound by confidentiality and Art. 19 of the Personal Data Law. The current list of recipients is maintained on this page.

7.3. Data may be disclosed to state authorities only on the grounds and in the manner provided by Russian law.

8. Storage, localization, cross-border transfer and destruction

8.1. Localization. Personal data of Russian citizens is recorded, systematized, accumulated, stored, updated and retrieved using databases located in the Russian Federation (Art. 18(5) of the Personal Data Law).

8.2. Cross-border transfer. To deliver push notifications, the device push token is transferred to Google LLC and Apple Inc. (USA). No other personal data leaves Russia: OpenStreetMap/Nominatim requests are made by the Operator's server and contain no user identifiers. A cross-border transfer notification is filed with Roskomnadzor under Art. 12 of the Personal Data Law.

8.3. Account deletion. Available in the App (“More” → “Delete account”) or by writing to {{SUPPORT_EMAIL}} (with account ownership confirmation). The account is deactivated immediately (access and sessions terminated), and the personal data relating to it — including contact identifiers, card details, location history and analytics events — is irreversibly destroyed on the Operator's servers within 30 (thirty) days.

8.4. Map contributions remain after account deletion in anonymized form: the link between the record and the User is destroyed irreversibly and cannot be restored. The basis for keeping anonymized records is the Terms of Service (user content license).

8.5. Once the processing purposes are achieved or no longer needed, data is destroyed within 30 days unless the law provides otherwise.

9. Your rights

9.1. You may: obtain information about the processing of your data (Art. 14); demand rectification, blocking or destruction of data that is incomplete, outdated, inaccurate or unlawfully obtained; withdraw consent; demand that processing stop in the cases provided by law; and complain to Roskomnadzor (pd.rkn.gov.ru) or a court.

9.2. Requests are accepted at {{SUPPORT_EMAIL}}. We respond within 10 business days; the term may be extended by up to 5 business days with a reasoned notice.

9.3. Withdrawal of consent does not affect the lawfulness of prior processing and does not prevent processing on other legal grounds (e.g., performance of the Terms of Service until the account is deleted).

10. Security measures

We apply the legal, organizational and technical measures required by Arts. 18.1–19 of the Personal Data Law, including: encryption of the phone number at rest; storage of verification codes only in irreversibly hashed form; TLS transport encryption; access control and logging; a designated person responsible for data processing; internal policies and compliance checks.

11. Identifiers; no ad tracking

The App uses a pseudonymized analytics identifier solely for its own product statistics. It contains no advertising networks or third-party analytics SDKs, does not track you across third-party apps or websites, and builds no advertising profiles. The {{DOMAIN}} website uses no cookies requiring consent.

12. Children

The App is not directed at children under 14, and we do not knowingly collect their data. Users aged 14–18 use the App with the consent of their legal representatives. If you become aware of a child's data provided without such consent, contact {{SUPPORT_EMAIL}} — the data will be destroyed.

13. Changes

We may amend this Policy. The new version is published at https://{{DOMAIN}}/privacy-en with its effective date; material changes are additionally announced in the App.

14. Operator details

{{COMPANY_REQUISITES}}
E-mail: {{SUPPORT_EMAIL}}