§ 1. Controller and scope
- The controller of data relating to Umovi technologies is UMOVI PROSTA SPÓŁKA AKCYJNA, with its registered office in Tarnowskie Góry, at ul. Henryka Sienkiewicza 49, 42-600 Tarnowskie Góry, Polska, hereinafter “Umovi”. Privacy contact: privacy@umovi.app.
- This Policy covers the Umovi public website, Client and Provider web applications and mobile applications to the extent that they use technologies that store information on a device or access information stored there.
- The Privacy Policy also describes the specific purposes, legal bases, recipients, retention periods and data subject rights.
§ 2. Categories of technologies
- Necessary technologies enable the requested feature, security, login, session maintenance and storage of a privacy choice, language, theme or other preference expressly selected by the User. They are used without consent only within the statutory exemption.
- Campaign measurement links an arrival from an identified campaign source to a later event. It may operate only after consent where the technology is not necessary.
- Product analytics helps understand how features are used and identify problems. It is optional and requires prior consent where it stores or reads information on the device or relies on GDPR consent.
- Functional device permissions, such as location, camera, calendar or notifications, are activated at the User’s request and require the appropriate system permission. They do not constitute marketing consent.
- Umovi does not currently use an external advertising pixel or external analytics tool on its public website. Displaying an optional category in the consent panel does not itself mean that events are sent to an external supplier.
§ 3. Public website technologies
| Name or identifier | Type | Purpose and category | Supplier / recipient | Period |
|---|---|---|---|---|
| umovi-privacy-consent:v1 | browser local storage | stores a pseudonymous acknowledgement identifier, policy version, category choices and validity dates; necessary | Umovi | until validUntil, currently 180 days, then until overwritten or deleted by the User |
| privacy settings acknowledgement record | Umovi database | verifies that the choice is current and supports accountability; necessary | Umovi, AWS infrastructure | valid for 180 days; evidence retained after expiry in accordance with the Privacy Policy |
| umovi-theme:v1 | browser local storage | remembers the selected light or dark theme; necessary for the requested preference | Umovi | until changed or deleted by the User |
| language in the URL path | page address, not a cookie | opens the appropriate language version; necessary | Umovi and standard infrastructure logs | for the duration of the request; log entry subject to security retention |
| campaign parameters in the URL | address and application storage, if the feature is active | campaign measurement; optional | Umovi | 7-day attribution window |
| product analytics events | request to Umovi, if the feature is connected | product analytics; optional | currently no external recipient and no active event transmission on the public website | a specific period will be stated only once implemented, before activation |
- Umovi does not store the IP address, user-agent, language or geolocation in the choice acknowledgement record itself. Limited technical data may separately appear in security logs handling the request.
- If local storage is blocked, the server-side acknowledgement record may remain the source for the decision, but the User may be asked to choose again when the identifier is unavailable.
§ 4. Application and mobile device technologies
| Technology or permission | Purpose | Supplier / recipient | How to control it |
|---|---|---|---|
| session token and secure system storage | login, session refresh and Account protection | Umovi; Apple or Android system storage | log out, revoke the session or uninstall the application |
| Apple Push Notification service | delivers notifications on iOS | Apple Distribution International Limited and Apple entities | system notification settings and Account settings |
| Firebase Cloud Messaging | delivers notifications on Android | Google Ireland Limited and Google entities | system notification settings and Account settings |
| MapKit | maps and location on the web or iOS | Apple Distribution International Limited and Apple entities | refuse location access, search manually, use system settings |
| Google Maps Platform and Places | maps, place search and distance on Android | Google Ireland Limited and Google entities | refuse location access, search manually, use system settings |
| device location | shows nearby services and calculates distance | Umovi and the map supplier for the application interface used | one-time or ongoing choice in system settings |
| camera and photo library | QR scanning or choosing a file or photo | Umovi; the device’s operating system | system permissions; the feature operates only after User action |
| calendar | adds a Booking to the device calendar | the device’s operating system; Umovi does not read the entire calendar if the feature only saves an event | system permissions |
- Precise location is not stored in the profile or as a history. Coordinates may be sent for an individual search request.
- The notification token identifies an application installation, not the contents of the address book. Marketing notifications remain subject to the appropriate consent and settings; operational messages may be necessary for Bookings or security.
§ 5. Consent and managing choices
- On the first visit or following a policy change, Umovi displays a panel with equally prominent buttons to reject and accept optional categories and an option to make detailed choices.
- Optional technologies remain disabled until valid consent is given. No response, scrolling, continued use or closing the panel do not constitute consent.
- The choice can be changed at any time using the “Privacy settings” button in the website footer. Withdrawal is as easy as giving consent and blocks future use of the relevant category.
- The User may also delete site data in browser settings, which may remove the theme, privacy choice or session. Mobile application permissions are changed in system settings.
- Umovi honours the choice linked to the current policy version and validity date. After 180 days or a material change of purpose, it may request a new decision.
§ 6. External suppliers and future changes
- Map, login and notification suppliers may use their own necessary identifiers or technologies within their services. Their full names and roles are listed in the Privacy Policy.
- Before activating a new analytics, marketing, personalisation or social tool, Umovi will add the supplier’s full name, identifiers, events, data, retention period, transfer and legal basis to the table and configure blocking until consent is given.
- Umovi will not use the general term “partners” instead of identifying a specific recipient where its identity is known and data are disclosed to it.
- A change to a necessary technology may be implemented without consent if it remains within the statutory exemption. A change to an optional purpose requires updated information and, where necessary, renewed consent.
§ 7. Rights and contact
- In relation to data generated through technologies, the User may exercise the rights described in the Privacy Policy, in particular access, erasure, restriction, objection and withdrawal of consent.
- Questions or requests may be sent to privacy@umovi.app. A complaint may be lodged with the President of the Polish Personal Data Protection Office.
- The current version and date of this Policy are published on this page. Umovi gives notice of a material change to optional measurement before it is activated.