RAVATA STORE SRL ("RAVATA STORE", "we", "us") respects your privacy. This Privacy Policy explains what personal data we process, why we process it, who we share it with, and what rights you have.
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, or "GDPR") and applicable Romanian data protection law.
1. Scope of this policy
This policy applies to:
- this website and any subdomains operated by RAVATA STORE SRL;
- the mobile applications we publish under our developer accounts on the Apple App Store and Google Play (each, an "App");
- emails and other messages you send to us, for example when you request a quote.
Some of our Apps may include an in-app privacy notice with additional details specific to that App. Where an App-specific notice exists, it applies together with this policy, and the App-specific notice prevails in case of conflict.
This policy does not apply to third-party services, websites or apps that we do not control, including the App Store and Google Play themselves. Apple and Google process your data under their own privacy policies.
Where we build an application for a client and that client operates the app and decides how user data is used, the client acts as the data controller and we act as a processor on their behalf. In that case the client's own privacy policy applies to the app's users.
2. Data we collect
We keep data collection to a minimum. Depending on how you interact with us, we may process the following categories of data.
2.1 Data you give us directly
- Contact data: your name, email address, company name and any other information you choose to include when you write to contact@ravatastore.com.
- Project data: documents, briefs, requirements or materials you send us so we can prepare an offer or deliver a project.
- Support data: the content of messages you send when reporting a problem with one of our Apps, including screenshots you attach.
- Account data: where an App offers user accounts, the identifiers you provide when registering, such as an email address and a password stored only in encrypted (hashed) form.
2.2 Data collected automatically by our Apps
- Device and technical data: device model, operating system and version, language, region, screen characteristics, App version, and a randomly generated installation identifier.
- Crash and diagnostic data: when an App stops unexpectedly, a crash report may be generated. It contains the technical state of the App at the moment of the crash, such as the error type and the sequence of code that was running (a "stack trace"). It is not designed to identify you.
- Usage data: aggregated, non-identifying statistics about which screens and features are used, and how often, so we can decide what to improve.
- Advertising identifiers: in Apps that display advertising, the advertising identifier provided by your device (IDFA on iOS, Advertising ID on Android) may be processed, subject to the permissions described in section 5.
2.3 Data we do not collect
- We do not collect payment card numbers or bank details through our Apps. Payments are handled entirely by Apple or Google (see section 6).
- We do not collect special categories of data (such as health, biometric, religious or political data), unless an App is expressly designed for such a purpose and clearly tells you so before you provide it.
- We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.
3. Purposes and legal bases
Under the GDPR we must have a valid legal basis for every processing activity. The table below sets out ours.
| Why we process the data | Legal basis (GDPR Art. 6) |
|---|---|
| To provide the App and its core features, including accounts and purchased content | Performance of a contract — Art. 6(1)(b) |
| To answer your messages and prepare offers | Steps taken at your request before entering a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| To detect, diagnose and fix crashes and bugs | Legitimate interests in keeping our Apps stable and secure — Art. 6(1)(f) |
| To understand aggregate usage and improve our Apps | Legitimate interests — Art. 6(1)(f); consent where required by local law — Art. 6(1)(a) |
| To display personalised advertising | Your consent — Art. 6(1)(a) |
| To display non-personalised (contextual) advertising | Legitimate interests in funding free Apps — Art. 6(1)(f) |
| To keep accounting records and comply with tax and legal obligations | Legal obligation — Art. 6(1)(c) |
| To establish, exercise or defend legal claims | Legitimate interests — Art. 6(1)(f) |
4. Crash reports and analytics
Our Apps may use standard developer tools to report crashes and measure basic usage. These typically include services provided by Google (such as Firebase Crashlytics and Google Analytics for Firebase) and the diagnostics that Apple and Google make available to developers through App Store Connect and the Google Play Console.
These tools tell us that a specific version of an App crashed on a specific type of device, or that a screen was opened a certain number of times. They are not used to build a profile of you as an individual, and we do not attempt to re-identify users from this data.
On iOS, you can control whether diagnostic data is shared with developers in Settings → Privacy & Security → Analytics & Improvements. On Android, usage and diagnostics sharing is controlled in Settings → Google → Usage & diagnostics.
5. Advertising and Google AdMob
Some of our Apps are free and are funded by advertising. In those Apps we may use Google AdMob, an advertising service provided by Google, to display banner, interstitial or rewarded ads.
To serve and measure ads, AdMob may process your device's advertising identifier, approximate location derived from your IP address, and information about your interaction with the ads. Google may act as an independent controller for some of this processing.
- On iOS, tracking across apps and websites requires your permission. If you decline the App Tracking Transparency prompt, or you have turned off Allow Apps to Request to Track in Settings → Privacy & Security → Tracking, we do not use your advertising identifier for personalised advertising.
- In the EEA, the United Kingdom and Switzerland, Apps that show ads present a consent message before personalised ads are served. You can change your choice at any time from the App's settings screen, where such a screen is provided.
- On Android, you can reset or delete your Advertising ID in Settings → Google → Ads.
- If you refuse personalised advertising, the App will normally continue to work and will show non-personalised, contextual ads instead.
Google's own practices are described in the Google Privacy Policy at policies.google.com/privacy and in the Google advertising information page at policies.google.com/technologies/ads.
6. Purchases and subscriptions
Where an App offers paid content, in-app purchases or subscriptions, the transaction is processed entirely by Apple (App Store) or Google (Google Play), acting as the seller of record.
- We never receive or store your card number, bank details or billing address.
- We receive a purchase receipt or token that confirms an entitlement is active, together with the product identifier and the renewal status. We use it only to unlock the content you paid for and to keep it available across your devices.
- Subscriptions renew automatically unless cancelled. You manage and cancel them in your Apple ID or Google Play account settings, not through us.
- Refund requests are handled by Apple or Google under their own policies. We are happy to support your request, but we cannot process the refund ourselves.
7. Who we share data with
We share personal data only where it is necessary, and only with recipients bound by confidentiality and data protection obligations. These may include:
- Platform providers: Apple and Google, for app distribution, purchases, notifications and diagnostics.
- Infrastructure and hosting providers: for servers, databases, file storage and website hosting.
- Analytics and crash reporting providers: as described in section 4.
- Advertising partners: as described in section 5.
- Professional advisers: accountants, auditors and lawyers, where required.
- Public authorities: where we are legally required to disclose data, for example following a valid request from a competent authority.
- A successor entity: if our business is reorganised, merged or acquired, in which case data may be transferred as part of the transaction.
Where a recipient processes data on our behalf, we put a data processing agreement in place as required by Article 28 GDPR.
8. International transfers
Some of our service providers are established outside the European Economic Area, in particular in the United States. Where personal data is transferred outside the EEA, we rely on an appropriate safeguard recognised by the GDPR, such as an adequacy decision of the European Commission or the European Commission's Standard Contractual Clauses, together with supplementary technical measures where appropriate.
You may request a copy of the relevant safeguards by writing to us at the address in section 16.
9. How long we keep data
- Emails and project correspondence: for as long as the business relationship lasts, and up to 3 years afterwards, unless a longer period is required for legal claims.
- Account data: for as long as your account exists, and deleted or anonymised within 30 days of a deletion request, except where retention is legally required.
- Crash and diagnostic data: normally up to 90 days, in line with the retention settings of the tools we use.
- Aggregated usage statistics: up to 14 months in an aggregated form that no longer identifies individuals.
- Accounting and tax records: for the period required by Romanian law, which is generally 10 years.
When a retention period ends, data is deleted or irreversibly anonymised.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS/TLS), access control on a need-to-know basis, hashed storage of passwords, regular updates of our dependencies, and validation of data received from clients to reduce the risk of common attacks.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and inform affected users without undue delay where the breach is likely to result in a high risk.
11. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data and receive a copy of it;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — have your data deleted where one of the grounds in Article 17 applies;
- Restriction — ask us to limit the processing of your data in certain situations;
- Portability — receive the data you provided in a structured, commonly used, machine-readable format;
- Object — object at any time to processing based on our legitimate interests, and object at any time to direct marketing;
- Withdraw consent — where processing is based on consent, withdraw it at any time, without affecting processing carried out before the withdrawal;
- Not be subject to a decision based solely on automated processing that produces legal effects concerning you. We do not carry out such decision-making.
To exercise any of these rights, write to contact@ravatastore.com. We respond within one month of receiving your request. That period may be extended by two further months for complex requests, in which case we will tell you and explain why. We may ask for information to confirm your identity before acting on a request.
You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania — www.dataprotection.ro, or with the supervisory authority in your country of residence.
12. Children
Our Apps and this website are not directed at children under the age of 16, and we do not knowingly collect personal data from them. Where an App is listed in a child-directed category on the App Store or Google Play, we apply the additional rules those platforms require, including restrictions on advertising and on the collection of identifiers.
If you believe a child has provided us with personal data, write to contact@ravatastore.com and we will delete it.
13. This website
This website is a static presentation site. It does not use analytics cookies, advertising cookies or tracking pixels, and it does not require you to create an account or fill in a form. The only personal data we receive through it is what you choose to send us by email.
Our hosting provider processes standard server request data, such as your IP address and the browser you use, for the purpose of delivering the pages and protecting the service against abuse. This is done on the basis of our legitimate interest in operating a secure website.
The website loads fonts and a stylesheet from third-party content delivery networks (Google Fonts and the Tailwind CSS CDN), which means your browser makes a request to those providers and they receive your IP address as part of that request.
14. App store disclosures
Apple requires developers to publish privacy labels ("Privacy Nutrition Labels") and Google Play requires a "Data safety" section. For each of our Apps, those disclosures are kept consistent with this policy. If a specific App collects more or less data than described here, the App's store listing and its in-app privacy notice reflect that, and take precedence for that App.
15. Changes to this policy
We may update this policy to reflect changes in our Apps, in the services we use, or in the law. The "Last updated" date at the top of the page always shows the current version. If a change materially affects your rights, we will provide a more visible notice, such as an in-app message.
16. Contact us
For any question about this policy or about how we handle your data, contact us at contact@ravatastore.com, or by post at the registered office below.
RAVATA STORE SRL
Str. Principala 44, 617491 Ingaresti, Neamt County, Romania
CUI 43033192 · Trade Register J27/751/2020 · EUID ROONRC.J27/751/2020
Date of incorporation: 2020-09-10
Email: contact@ravatastore.com