Privacy Policy
Last updated:
This Privacy Policy explains what personal data Spicy Travel collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. We wrote it in plain language on purpose.
The data controller for Spicy Travel is SPIDER SERVICE SRL, a company established in Romania ("we", "us"). You can reach us using the details in the Contact us section below.
Data we collect, and why
We collect only the data the app needs to work and to improve. What we actually collect depends on the features below that are turned on in this app. If a section below does not appear, we do not collect that data.
Usage analytics (Firebase Analytics)
When this is enabled, we use Google Firebase Analytics to understand how the app is used so we can improve it. Through this service we may process:
- Device and advertising identifiers (for example a resettable app-instance ID and, where applicable, an advertising ID);
- Approximate location derived from your IP address (city/region level);
- Usage events — which screens you open and which features you use.
This data is processed by Google as our service provider. It is used to measure and improve the app and is not sold. The same disclosures appear on the app’s Apple App Privacy label and Google Play Data Safety section on the respective store listings.
Crash and stability reporting (Firebase Crashlytics)
To find and fix crashes, we use Firebase Crashlytics. When the app crashes or hits a serious error, we may collect:
- Crash logs and stack traces describing what went wrong;
- Device metadata — device model, operating-system version, app version, and the state of the app at the time of the crash;
- A random install identifier (install UUID) that lets us group reports from the same installation.
These reports are processed by Google as our service provider, used only to diagnose and fix problems, and are not sold.
App integrity and anti-abuse (Firebase App Check)
To protect our service from abuse — spam, scraping, and fraudulent requests — we use Firebase App Check. App Check relies on Apple’s App Attest / DeviceCheck to confirm that requests genuinely come from an untampered copy of our app before our backend answers them. For this it processes:
- A device-generated attestation and a short-lived App Check token tied to the app installation (not to you personally).
App Check does not identify you, is not used for advertising, and the tokens are used only to verify app integrity. Apple and Google act as our service providers for this attestation, and this data is not sold.
Location (used on your device only)
The in-app map uses your device location to show where you are and what’s nearby while you plan and explore. We request “When In Use” access only, and:
- your location is used on your device to draw the map and rank nearby spots;
- we do not send your precise location to our servers, we do not store it, and we do not sell it or use it for advertising;
- you can grant or revoke this permission at any time in your device settings — the rest of the app works without it.
How we use your data
We use the data above to provide and operate the app, keep it secure, fix crashes and bugs, and understand and improve how it is used. We do not use it for advertising, and we do not use it to make decisions about you that produce legal effects.
Who we share it with (recipients)
We do not sell your personal data. We share it only with the service providers that make the app run, acting on our instructions:
- Google / Firebase — usage analytics, crash reporting, and app-integrity checks (App Check).
- Apple — App Store payment processing for subscriptions, and app distribution.
We may also disclose data if required by law, or to protect our rights, users, and the public. Some providers are located outside your country; where that involves an international transfer, we rely on appropriate safeguards (such as standard contractual clauses).
How we keep it secure
Data is encrypted in transit (HTTPS/TLS). Access is limited to what's needed to run the service. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard measures.
How long we keep it (retention) and deletion
We keep personal data only as long as we need it for the purposes above, then delete or anonymize it. Crash and analytics data are retained for a limited period under the relevant provider's default retention settings. You can request deletion of your data at any time:
- Or email us at spiderservicedev@gmail.com and we'll handle it.
Revoking consent and your choices
Where we rely on your consent (for example, analytics in regions that require it), you can change your mind at any time through the in-app privacy controls or your device settings.
Your rights in the EEA, UK, and Switzerland (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR / UK GDPR gives you rights over your personal data. We process your data on these legal bases (Art. 6): to perform our contract with you (to run the app), with your consent (for example, analytics or personalized ads where required), and for our legitimate interests (keeping the app secure and working). Where required, we obtain consent through a consent prompt and you can withdraw it at any time.
You have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to processing;
- data portability — receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing; and
- lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact us using the details in the “Contact us” section below. We respond within the time limits the law requires.
Your rights in California (CCPA / CPRA)
If you are a California resident, the CCPA, as amended by the CPRA, gives you rights over your personal information. You have the right to:
- know what personal information we collect, use, and disclose, and to access it;
- delete the personal information we hold about you;
- correct inaccurate personal information;
- opt out of the “sale” or “sharing” of personal information; and
- not be discriminated against for exercising your rights.
We do not sell your personal information for money. Some advertising or analytics features may count as “sharing” for cross-context behavioral advertising under California law; where they do, you can opt out through the in-app privacy controls or the request methods in the “Contact us” section. We do not knowingly process the data of consumers under 16 without the required consent.
To exercise these rights, contact us using the details below. We will verify your request and respond within the statutory timeframe.
Children
This app is not directed to children under the age of 13 (or the equivalent minimum age in your country), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we'll delete it.
Changes to this policy
We may update this policy as the app or the law changes. We'll revise the "Last updated" date above and, for material changes, provide a more prominent notice.
Contact us
Questions or requests about your data? Reach the controller of Spicy Travel, SPIDER SERVICE SRL:
- Email: spiderservicedev@gmail.com
- Address: SPIDER SERVICE SRL, Romania