Privacy Policy
This policy explains what personal data Free to Take processes, why, and your rights. The service is provided by the developer DinaSimple (“we”). Contact: freetotakedeveloper@gmail.com.
1. Data we process
| Data | Why |
|---|---|
| Account: email address, name and profile photo from the sign-in provider you choose (Google or Facebook), a user ID | Create and secure your account, show your nickname and avatar to people you exchange items with |
| Profile: nickname, avatar you upload | Show who is giving or requesting an item |
| Giveaways: title, description, photos, category, pickup times, the meetup point you type in | Publish your giveaway; the exact meetup point is shown only to the person you approve |
| Requests: chosen pickup time and your note | Let the giver choose a recipient |
| Chat messages (text only) between approved participants | Arrange the pickup; chats become read-only after the meeting |
| Ratings after a completed exchange | Build trust between users |
| Favourites, notification preferences | Features you use in the app |
| Advertising ID and consent choice (Android) | Show ads via Google AdMob according to your consent |
| Purchase status (e.g. “remove ads”) | Unlock purchases via RevenueCat and Google Play Billing |
We do not access your device GPS location, contacts or call history, and we never ask for apartment, floor or entrance numbers.
2. Legal bases (GDPR)
- Contract — providing the service you sign up for (account, giveaways, requests, chat).
- Consent — personalised advertising (you can change it in the consent dialog at any time).
- Legitimate interest — security, abuse prevention and keeping the service working.
- Legal obligation — where the law requires us to keep or disclose data.
3. Service providers
- Supabase — database, authentication and file storage (servers in the EU, Frankfurt).
- Google — Google Sign-In, Google Play, AdMob advertising and consent (UMP).
- Meta — Facebook Login.
- RevenueCat — management of in-app purchases.
Providers process data on our behalf or as independent controllers under their own policies. Some may transfer data outside the EU under appropriate safeguards such as Standard Contractual Clauses.
4. Google user data
When you sign in with Google we receive only your name, email address and profile picture (scopes openid, email, profile) to create your account. Free to Take's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data or use it for advertising.
5. Retention
- Account and profile — until you delete your account.
- Giveaways — active up to 14 days, then archived; removed when you delete your account.
- Chats — read-only after the meeting; deleted when you delete your account.
- Technical logs — kept by our hosting provider for a limited period for security.
6. Your rights
You can request access, correction, deletion, restriction, objection and a copy of your data (portability). Write to freetotakedeveloper@gmail.com. You can also complain to your data-protection authority (in Spain: Agencia Española de Protección de Datos, aepd.es).
7. Children
Free to Take is not intended for children under 16. We do not knowingly collect their data.
8. Security
Data is encrypted in transit (HTTPS), access is restricted by row-level security, and exact meetup points are only released to approved participants. No online service can guarantee absolute security.
9. Changes
We will update this page and the date above when this policy changes, and notify you in the app about important changes.
