Privacy Policy
1. Introduction
This Privacy Policy explains how Ratr collects, uses and protects personal data during the beta program.
2. Data Controller
During the beta phase, Ratr is operated by Levente Juhasz, an individual (the "Controller"), reachable at ratrmedia@gmail.com.
All questions about this Privacy Policy, all data subject requests (access, correction, deletion, restriction, portability, objection, withdrawal of consent) and all privacy complaints should be sent to this address. We aim to respond within 30 days.
3. Data We Collect
Account Data:
- email address;
- username;
- profile information;
- profile photo (optional).
User Content:
- ratings;
- reviews;
- comments;
- photos;
- videos;
- profile content.
Location Data:
- location voluntarily attached to posts;
- local discovery information.
Technical Data:
- device information;
- operating system;
- application version;
- crash reports;
- log data;
- push notification tokens (used to deliver notifications via Firebase Cloud Messaging).
Analytics Data:
- Firebase Analytics;
- Firebase Crashlytics;
- platform usage information.
4. Purposes of Processing
We process data to:
- operate the service;
- authenticate users;
- store content;
- moderate content;
- improve functionality;
- measure engagement;
- prevent abuse;
- comply with legal obligations.
5. Legal Basis
Processing may be based on:
- consent;
- service provision;
- legitimate interests;
- legal obligations.
6. Affiliate Links
Ratr may display affiliate links. When users click affiliate links, affiliate partners may receive information necessary for referral attribution and commission tracking. Ratr may receive commissions from purchases made through such links.
7. Data Sharing
Data may be shared with:
- Firebase;
- Google Cloud services;
- analytics providers;
- hosting providers;
- legal authorities where legally required.
Ratr does not sell personal data.
8. Data Storage and International Transfers
Primary application data (Firestore, Firebase Storage) is hosted in a European region (europe-west3, Frankfurt).
Some service providers, including Google LLC (Firebase Authentication, Firebase Cloud Messaging, Firebase Analytics, Firebase Crashlytics), may process personal data outside the EEA / UK / Switzerland — typically in the United States.
Where data is transferred internationally, we rely on the following safeguards under Chapter V of the GDPR / UK GDPR and Article 16 of the Swiss FADP:
- For transfers from the EEA and the United Kingdom: the European Commission's Standard Contractual Clauses (SCCs), supplemented by the UK International Data Transfer Addendum where applicable.
- For transfers from Switzerland: the Swiss-US Data Privacy Framework, and Swiss-recognised SCCs for transfers to other third countries.
A copy of the safeguards relied on can be requested by emailing ratrmedia@gmail.com.
9. Data Retention
We retain personal data only for as long as is reasonably necessary for the purposes set out in Section 4. Indicative retention periods:
- Account data (profile, username, email): retained until you delete your account, plus up to 30 days in encrypted backups.
- User content (ratings, comments, photos, videos): retained until you delete the content or your account, plus up to 30 days in encrypted backups.
- Server and application logs: typically retained for up to 90 days for security, debugging and abuse prevention.
- Analytics data: retained per Firebase Analytics defaults (up to 14 months).
- Push notification tokens: removed when invalid or on sign-out.
When you delete your account, your account data and user content are purged from active systems within 30 days, save where we are required to retain specific records to comply with legal obligations or to resolve disputes.
10. User Rights
Users may request:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection;
- withdrawal of consent.
11. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority — in particular:
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Netherlands: Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl
- Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) — naih.hu
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
You may also lodge a complaint with the supervisory authority in any EU/EEA country in which you reside or work.
12. Account Deletion
Users may request deletion of their account and personal data. Certain records may be retained where legally required.
13. Security
Reasonable technical and organisational measures are used to protect personal data.
14. Age Restriction
Ratr is not intended for users under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from a person under 16, please contact us at ratrmedia@gmail.com and we will delete it.
15. Changes
This Privacy Policy may be updated during the beta phase.
← Back to ratrmedia.com