Privacy Policy
This Policy explains what data we process, why we use it, and how you can exercise your rights.
This Policy applies to the Popusti MK mobile application, the popustimk.app website, customer support, and deletion requests.
1. Who is responsible for the data
The controller of personal data is Stefan Rafailovski, who operates the service under the name Popusti MK.
For questions, requests, or to exercise your rights, write to kontaktpopusti@gmail.com.
2. What data we process
Depending on how you use the service, we may process:
- Account and identity: an automatically created anonymous Firebase identifier; Google may provide a user identifier, name, email address, and profile photograph when you choose Google Sign-In; Apple may provide a user identifier, name, and email address or Apple relay email address when you choose Sign in with Apple; as well as an email address and data for a business account created with email/password and business-verification data. The password is processed by Firebase Authentication and cannot be read by Popusti MK.
- Settings and use: language, selected city and categories, hidden businesses, saved offers, searches, and interactions with offers. Saved offers and some settings remain only on the device. When you enable notifications, your selected city, categories, and hidden-business identifiers are synchronised with Firebase to determine what should not be sent to you. Search text is sent to Firebase to return results, but is not recorded in a separate Popusti MK search history.
- Device, diagnostics, and notifications: platform, installation identifier, Firebase identifier, Expo push token, language, city and notification categories, hidden businesses, app version, and basic technical and security data such as IP address, request time, operating-system version, and delivery, update, or failure data when the provider creates such a record.
- Location: precise location is used only when you expressly request the “My location” feature and grant system permission. Popusti MK does not intentionally save a consumer’s precise location to their account. The map provider may receive the IP address and information about the displayed map area. Addresses and precise markers entered by businesses are stored and may be displayed publicly with their offers.
- Business data: business name and private contact and verification information, such as contact person, email address, and telephone number. This information is not displayed publicly unless the business separately enters it as public profile information.
- Public business content: the designated public business name, address and contact details, website, social-media profiles, logo, photographs, prices, terms, dates, and offer locations that the business submits for publication.
- Selected photographs: only when an authorised business user selects a logo or offer image, the app requests system access to selected photographs or to the photo library, depending on the platform. Only images expressly selected by the user are read and uploaded to Firebase Storage; Popusti MK does not inspect the entire library for other purposes.
- Reports and offer activations: offer identifier, reason, and voluntarily entered details in a report, as well as pseudonymised records of activated offers needed for limits, abuse prevention, and business records.
- Purchases: product, transaction identifier and date, store, purchase or refund status, and promotion-credit balance. On supported mobile versions, RevenueCat receives a Firebase user identifier and basic app, product, and transaction data for signed-in users, even when the user has not completed a purchase. Payment-card data is processed by Google Play or the Apple App Store; Popusti MK does not receive it.
- Support and website: the content and metadata of an email sent voluntarily, and ordinary server logs when the website is opened.
We receive data directly from you, from the device and app, from Google or Apple when you choose to sign in, from the Apple App Store or Google Play and RevenueCat for purchases, and from Businesses that submit public offers. We do not request health or biometric data, or access to your contact lists, private messages on the device, audio, or payment-card data.
What is required and what is optional: the guest technical identifier and basic network records are needed for the app to work without a named account. Google or Apple sign-in is optional for browsing, but required to activate offers and retain history. Location, notifications, reports, and photo selection are optional; if you do not provide them, only the corresponding feature will be unavailable. Contact and verification details are required for a business application, while a selected image and public details are required only when the Business wants to publish the corresponding content. Transaction data is created automatically if a business user initiates a purchase or refund.
3. Why we use the data
We use data to:
- create and protect accounts;
- display, search, save, and activate offers;
- verify businesses and publish their content;
- purchase, grant, and verify promotion credits;
- send notifications selected by the user;
- moderate reports and prevent fraud, duplicate activation, and abuse;
- provide customer support, resolve disputes, and comply with legal obligations;
- maintain, secure, and improve the service.
The legal basis depends on the specific purpose:
- Performance of the service and steps taken at your request: a guest session, sign-in, displaying and searching offers, activations and history, a business application, publishing content, support you have requested, and processing promotion credits.
- Consent: system permission for precise location, optional push notifications, and access to photographs where the platform requires consent. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legitimate interests: account and infrastructure security, preventing fraud and duplicate activation, limiting abuse, moderating reports, diagnostics, and defending legal claims. These interests apply only where they are not overridden by your rights and reasonable expectations.
- Legal obligation and legal claims: minimum records that must remain for accounting, a purchase, a refund, an order from a competent authority, or the establishment, exercise, or defence of a legal claim.
Popusti MK does not sell personal data and does not use it for advertising across different applications or services.
4. Providers and recipients
Data may be processed by the following providers only to the extent required for their function:
- Google/Firebase: Firebase Authentication and Google Sign-In, Firestore, Cloud Functions, Firebase Storage, Firebase Cloud Messaging for Android notifications, and technical infrastructure; Google Play for purchases;
- Apple: Sign in with Apple; Apple Push Notification service (APNs), which for iOS receives the push token, technical data, and content needed to deliver the notification; and the Apple App Store for purchases;
- RevenueCat: Firebase user identifier for signed-in users on supported mobile versions, product and transaction verification, and promotion-credit management;
- Expo: delivery of push notifications to APNs or Firebase Cloud Messaging, app updates, and basic technical and diagnostic installation data;
- OpenFreeMap and its infrastructure partners, including Cloudflare where used: delivery of map styles and tiles;
- Namecheap: hosting of the public website;
- Google/Gmail: receipt and delivery of messages sent to the contact address.
When you choose external directions, a website, social profile, telephone number, or email address for a Business, your device connects directly to OpenStreetMap, the relevant provider, or the Business under their own rules.
We limit providers and other recipients to the data needed for the stated function. For every recipient with whom we share user data, we require, through the contractual commitments available to us, our selection of providers, and applicable law, the same or equivalent protection of user data as the protection described in this Policy. Processors must additionally act according to our instructions, confidentiality obligations, and appropriate security measures. If the required protection cannot be ensured, we must stop the sharing or apply another valid protective mechanism. We may also disclose data where legally required or reasonably necessary to protect users, the service, or legal claims.
5. International transfers
Some providers operate in the European Economic Area, the United States of America, and other countries. For processing that we commission, Google/Firebase incorporates its Data Processing and Security Terms and standard contractual clauses, while RevenueCat incorporates its Data Processing Addendum with standard contractual clauses. In its Privacy Policy, Expo states that it uses standard contractual clauses and other applicable mechanisms for international transfers. These instruments are used together with access controls, encrypted transmission, and data minimisation.
Apple, Google Play, external maps, and websites that you open may process data directly under their own terms and transfer mechanisms. For information about which document and mechanism applies to a specific transfer controlled by Popusti MK, or for an available copy of the relevant safeguard, write to kontaktpopusti@gmail.com.
6. How long we retain data
We retain active-account data while the account is active and for as long as necessary for the stated purposes.
- Local settings remain on the device until you delete them, clear the app data, or uninstall the app.
- The guest Firebase identifier has no automatic expiry in the current version: it remains until the session is linked to a sign-in or is deleted following a verified request. If notifications are enabled for a guest or a report is submitted, associated server records may remain after uninstalling because uninstalling by itself does not send a deletion request.
- The push token is removed from the active record when notifications are disabled; the installation record is deleted when the account is deleted or when it is determined that the token or installation is no longer valid and the record is not needed for security.
- Business profiles, offers, and photographs are retained while active. Following a closure request, they are retained only while there is an active Offer, an unfinished refund/chargeback, an open dispute, or a specific legal obligation; they are then deleted or irreversibly anonymised.
- Reports and support messages are retained until the case is closed, and then only if they are connected to repeated abuse, an open dispute, or a limitation period for the establishment, exercise, or defence of a legal claim. The project’s standard Google Cloud
_Defaultoperational log bucket is configured for 30 days, while required Google Cloud audit logs in_Requiredare retained for 400 days. Another provider’s security record is deleted or aggregated when its documented retention period expires or when the specific security event ends, whichever occurs first, unless the law requires longer retention. - Minimum transaction, refund, security, and pseudonymised records receive a deletion date based on the latest applicable deadline for a refund or chargeback, an active dispute, fraud prevention, proof of a transaction, or statutory recordkeeping. They are not used to recreate a profile and are removed when that criterion no longer applies.
- After operational deletion, isolated provider backups may be removed gradually. For certain Firebase services, complete removal from active and backup systems may take up to 180 days.
When data is no longer needed, we delete or permanently anonymise it.
7. Deleting an account or specific data
A signed-in user can select Settings → Delete account.
A request can also be sent without the app through the account-deletion page or to kontaktpopusti@gmail.com.
For an ordinary user account, we delete authentication, push tokens, reports, and other data directly linked to the account. If a minimum activation record must remain temporarily under the criteria in section 6, we separate it from the account and replace the direct identifier with a restricted pseudonymous key. We continue to treat a pseudonymised record as protected data; we do not claim it is anonymous until relinking has been made irreversibly impossible.
For a business account, the request begins a verified closure process: offer activations are paused, and the profile, offers, photographs, and associated data are deleted or anonymised after active offers, credits, refunds, disputes, and mandatory records have been resolved.
We respond to a rights request without undue delay and within one month. Where the complexity or number of requests permits a legal extension, the deadline may be extended by no more than two additional months, and during the first month we will inform you of the reason and the new deadline. We carry out deletion that meets the legal requirements within 30 days; a specific record remains only where a legal exception applies, such as mandatory recordkeeping, an active dispute, or the need to establish, exercise, or defend a legal claim.
If you use the app only as a guest, you can remove local data by clearing the app data or uninstalling it. For guest server records arising from notifications or a report, write to us; because a guest session is not linked to a verified name or email address, we may request technical verification from the same device or other reasonable information, and we may be unable to identify a record without such verification.
8. Your rights
In accordance with applicable law, you may request information and access, rectification, erasure, restriction of processing, data portability, or object to processing, and you may withdraw consent for future processing. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Notifications and direct communication: you may object and disable notifications at any time in Settings or in the device’s system settings. This will not affect your ability to browse Offers.
We do not make decisions with legal or similarly significant effects based solely on automated profiling.
To submit a request, write to kontaktpopusti@gmail.com. We may request reasonable identity verification, but never a password, OTP code, or payment-card data.
If you believe your rights have been infringed, you may contact the Personal Data Protection Agency.
9. Security
We use encrypted transmission, access controls, server-side checks, limited permissions, and pseudonymised or hashed identifiers where appropriate. No system can guarantee absolute security.
10. Users under 18
Popusti MK is intended only for persons aged 18 or older. We do not actively verify age and do not knowingly collect data from persons under 18. If we learn that such a person has created an account, we will take reasonable steps to delete it.
11. Website and email
The current static website does not use analytics or advertising tools and has no web form. The hosting infrastructure may process ordinary server logs, such as IP address, time, requested address, and browser type, to deliver and protect the site. If you select a link to a Business, map, social network, or other external site, that party processes the direct visit under its own policy.
If you voluntarily email us, the sender’s address, content, and ordinary metadata are processed by your email provider and by Google/Gmail for receipt and response.
12. Changes
This Policy may be updated when the service, providers, or legal obligations change. The new date will be published on this page.
13. Other languages
The full Policy is also available in Macedonian and Albanian. The Macedonian version is authoritative unless mandatory law requires otherwise.