Effective date: 10 August 2026

Version: 1.0

Last updated: 10 August 2026

​

This Privacy Notice explains how WoffApp collects, uses, shares, and protects personal data when you use the WoffApp mobile application for iOS and Android (the "App") and the website https://woffapp.com (the "Site", together with the App, the "Service").

We wrote this document to be read, not just stored. If anything is unclear, please write to info@woffapp.com.

​

1. Who processes your data

The data controller ("we") is:

Data Controller [LEGAL_ENTITY_NAME]

Registered office [REGISTERED_ADDRESS]

VAT / tax code [VAT_NUMBER]

Email (privacy, data subject rights and support) info@woffapp.com

Data Protection Officer (DPO) [DPO_CONTACT_OR: "Not appointed. The conditions of Art. 37 GDPR do not apply."]

​

We are established in Italy and the Service is aimed at users in the European Economic Area. Processing is governed by Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 and subsequent amendments ("Privacy Code").

2. What WoffApp does in terms of privacy

WoffApp is a location-based social app dedicated to dog owners.

Four concepts are enough to understand this notice:

  • Service locations are permanent and curated points of interest (drinking fountains, bins, shops, vets, dog areas, dog sitters, grooming, trainers, kennels). They are places, not people.
  • Dog spots are temporary markers you create at your current location. They are visible to other users within about 5 km and are deleted 72 hours after creation, or earlier if you remove them.
  • Sniffs are light social reactions that a user's dog sends to another user's dog's dog spot.
  • Challenges are weekly and monthly neighbourhood leaderboards calculated from your spots and sniffs within an area of about 10 km.

The most relevant privacy consequence: when you create a dog spot, you deliberately publish an approximate real location where you and your dog were, making it visible to nearby strangers for up to 72 hours. Section 6.5 explains this in detail. We ask you to read it.

3. Summary Table

What we process

Perchè

Legal basis

For how long

Account: email, password, Firebase user ID, login provider

Create and protect your account

Contract (Art. 6(1)(b))

Until account deletion

Profile: display name, language, city, notification preferences

Make the App work as you configured it

Contract

Until account deletion

Dog profiles: name, birth date, breed, sex, likes, dislikes, description, photos

Main function requested by you

Contract

Until account deletion

Device location while using the App

Show map, find nearby places, create spots

Consent (Art. 6(1)(a)) via system permission

Not stored as raw coordinate; see 6.4

Device location in background, only if you enable nearby spot alerts

Notify you when a dog spot appears near you

Consent (Art. 6(1)(a))

Not stored as raw coordinate; see 12.3

Dog spot: coordinate, geohash, times

Main function

Contract

Deleted permanently after 72 hours or upon removal

Sniffs and social history

Main function and challenges

Contract

Until dog or account deletion

Facts, scores and challenge leaderboards

Gamification

Contract

Rolling windows plus 21 days; see 9

Notification token, installation ID, platform, categories

Deliver notifications you have enabled

Consent + contract

Until logout, token change or deactivation

Crash and error diagnostics

Keep the App working

Legitimate interest (Art. 6(1)(f))

90 days with provider

App integrity attestations

Prevent abuse and fraud

Legitimate interest

Short duration, managed by provider

Place proposals and moderation logs

Maintain the place directory

Legitimate interest

Until record removal; audits remain

Subscription status

Remove ads for subscribers

Contract

Subscription duration plus legal terms

Advertising identifiers

Show ads to non-subscribers

Consent

According to provider policy

4. What we do not collect

To set expectations precisely:

  • We do not see or store your password. It is transmitted directly to Firebase Authentication, which stores it with hashing and salting.
  • We do not see or store your payment card data. Purchases are fully managed by Apple and Google within the store payment screen.
  • We do not collect background location by default. The App requests location only "while using the app". Background location is used solely for optional nearby spot alerts described in section 12.3, which require a separate permission you can refuse or revoke without losing any other function.
  • We do not process special categories of data under Art. 9 GDPR (health, biometrics, religion, political opinions, sexual orientation, etc.). We ask you not to enter such information in the dog's free description.
  • We do not perform automated decision-making with legal effects under Art. 22 GDPR. Challenge leaderboards are automated calculations but do not produce legal or similarly significant effects.
  • We do not sell your personal data nor share it with data brokers.

5. Private, public and pseudonymous data in WoffApp

WoffApp separates what you enter from what other users can see. This separation is enforced by the server, not just the interface.

Private, only yours. Your email address, your Firebase user ID, account settings, notification tokens, your dogs' private cards, original uploaded photos, exact coordinates of your spots, private progress counters in challenges, and the list of sniffs sent and received.

Published to other users, in pseudonymous form. When you register a dog and create a spot, the server generates a public projection of the dog from the private card. This projection contains an opaque public identifier not linked to your account, plus name, breed, sex, birth date, likes, dislikes, description and sanitized copies of gallery photos. It deliberately excludes your user ID, email address, the dog's private ID, original photo storage paths and any precise location other than the spot you chose to publish.

Important consequence: the projection is pseudonymous, not anonymous. If you give the dog an identifying name, describe where you live in free text or upload a photo showing your house number, other users can recognise you. Treat description and gallery as a public post.

6. What we collect, in detail

6.1 Account and authentication

At registration, we process your email address and a password. The password exists only within the login interaction and the request to Firebase Authentication; we do not create separate copies or logs. Firebase Authentication stores the account identity, an anonymous Firebase user ID (UID), the authentication provider used, login times and token claims. Where the App offers Google or Apple login, we also process the OAuth credential returned by the provider and the email address the provider communicates to us. With Apple, you can choose to hide your address, in which case we receive only a private forwarding address: emails we send you then pass through Apple's forwarding service. Firebase Authentication and the operating system may store session credentials in device memory areas managed by the SDK and system. Logout revokes the App's powers and asks Firebase to disconnect the session, but we cannot and do not claim to physically delete that cache managed by the provider.

6.2 Profile and settings

We store a cloud profile document containing your UID, display name, email address, optional profile photo URL, app language, city, notification preferences and creation date, plus copies of your role (regular user or administrator) and subscription status. This allows your settings to survive a reinstall.

6.3 Dog profiles and photos

For each registered dog, we store: name (mandatory) and optionally birth date, breed (free text), sex, likes, dislikes, a description and an ordered photo gallery whose first image is the profile photo. We do not collect your age; the dog's age is derived from the birth date.

Photos are selected from the gallery or camera via the operating system selector. We receive only the images you choose. Originals are stored in Firebase Storage under your account. A server-side process generates sanitized public copies (a full version up to 5 MiB and a thumbnail up to 512 KiB), which are those actually loaded by other users. Uploads are limited to 20 MiB per image.

Note on photo metadata: WoffApp does not remove EXIF metadata from uploaded image bytes. If your camera inserts GPS coordinates in photos, those coordinates may travel with the image. If this concerns you, disable geolocation in the camera app or use photos without it. If a dog card references an image hosted outside our infrastructure, opening it causes an HTTPS request to that third-party server, which will see your IP address and normal request metadata. Removing the URL stops future requests but cannot delete that server's logs. Using the system share panel on a photo exports a copy to the app or person you select. We cannot recall or delete that copy.

6.4 Location

By default, the App uses location only while you are using it. It requests "while using the app" permission on both platforms. The only exception is the optional nearby spot alerts feature described in section 12.3, which requests separate permission.

What happens on a location detection:

  • The precise sample and its accuracy remain in memory to centre the map, understand which dog spot or service you are near and place a new spot.
  • We do not store the raw coordinate as a permanent log of where you are.
  • We send derived data to our servers to query nearby content: bounded geohash intervals derived from your location, visible map portion boundaries, selected category filters and a query fingerprint. These data end up in normal server request logs and are sufficient to indicate the general area you were viewing.
  • Google Maps SDK and your device's location services are separate entities operating under their own policies (section 8).

You can revoke location permission at any time from the operating system settings. The App remains usable, but map-centred discovery and spot creation stop working. Creating a dog spot is a distinct and deliberate act of publication. See 6.5.

6.5 Dog spot

When you create a dog spot, we store its coordinate, a geohash, creation time, expiry time at 72 hours, dog's sex, dog's opaque public ID, your user ID on the private card and a sniff counter.

  • Other users within about 5 km can see the spot on the map.
  • The spot is deleted permanently 72 hours after creation, or immediately if you remove it. There is no hidden archive of expired spots.
  • A dog can have up to five active spots simultaneously.
  • Spots are not editable after creation.
  • Records derived from a spot for challenge calculation survive the spot itself; see section 9.

Do not create a spot at your home, workplace, a school or any place whose exposure could put you or others at risk. A sequence of spots at the same place at the same time reveals a habit. The "Best Routine" and "Early Bird" challenges exist precisely because these patterns are readable.

6.6 Sniffs and social history

Sending a sniff creates a record linking your dog to the spot and the target dog, with a time. Both parties maintain aggregated counters (sent, received, last sent, last received) that feed the best friends view and challenges. The sniff history is permanent: it is kept until the dog or account involved is deleted. Expired spots do not delete received sniffs.

6.7 Challenges and leaderboards

Challenges are calculated server-side from immutable "facts" (a sniff occurred, a spot was created, a contribution to a service was accepted). The catalogue includes: Neighbour's Administrator, Most Popular, Most Friendly, Best Routine, Early Bird, Most Active, Adventurer, Best Woffer and other entries shown in the App. Privacy-relevant elements:

  • Leaderboards are limited to a neighbourhood cell of about 10 km derived from the spot's location, not a municipality or address.
  • Public leaderboards expose only the rule, time window, ordered membership index, score and a safe snapshot of leading dogs, which uses the same pseudonymous public projection described in section 5. They do not expose user IDs or email addresses.
  • Your detailed progress counters are readable only by you and the server.
  • The Adventurer challenge needs a "home" reference. The server sets it once, from your oldest stored spot, and stores it as a versioned privacy cell ID of about 5 km – never a raw home coordinate. Removing that spot does not move the reference; only deleting the dog or account removes it.

Challenges are added and withdrawn over time. New challenges reuse the same facts and pseudonymous projections described here; a challenge requiring a new data category would first require an update to this notice.

6.8 Service locations, proposals and moderation

The service location directory is curated. Any user can propose a new place or a modification and can support an existing proposal.

When you use the place search field, the typed text, search session token, app language and visible map portion are sent to Google Places to get suggestions, and the chosen place is resolved into a place ID, formatted address and structured address components.

Reverse geocoding sends a coordinate to Google to get a readable address. Google retains these requests according to its policy; we cannot delete them. Moderation logs keep author ID, supporter IDs, proposals, decision, reviewer, times and a request digest. These logs serve to verify contested decisions later and are kept even after the proposal is resolved.

Accepted contributions also feed the "Neighbour's Administrator" challenge, which stores the number of accepted contributions and up to ten contribution lines, visible only to you.

6.9 Push notifications

If you authorise notifications, we register a device installation: an installation ID generated by the App, platform, app version, distributed language, notification permission status, enabled categories and the push token issued by your platform's notification service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) with its hash. The server maintains a delivery log with event IDs, emission and expiry times, recipient hashes and recipient IDs, so a new attempt does not duplicate a notification. Current notification types: a spot you created was published, you received a sniff, a sent sniff was confirmed, new nearby service content. Resolving a notification in a readable card involves further reads: the exact spot, public projection and sender dog's thumbnail and an address obtained by reverse geocoding from Google for the spot's coordinate.

Some installation-level values (installation ID, operation generation counter and flag recording that the notification prompt was already shown) intentionally survive logout and are deleted by removing App data or uninstalling it, not by signing out. You can disable categories in the App Settings and disable notifications entirely from the operating system settings.

6.10 Local storage on your device

The App stores a small set of values in the device preference store: whether you completed the tutorial, chosen language, a per-account copy of your notification setting, preferred challenge and short-term records of undelivered commands (parts of owner and scope keys as hashes, a command ID and a time, kept for up to seven days). The built-in Firestore offline cache also stores copies of documents you viewed and pending writes, so the App works offline. This cache is managed by the Firebase SDK. Logout isolates it so data from another account cannot be shown, but we do not claim to physically delete it on logout. Uninstalling the App or deleting its data removes it.

6.11 Diagnostics, crash reporting and analytics

  • Crash and error reporting (Sentry). Enabled only in release builds and limited to errors. The only user context attached is your Firebase UID. Exception values are scrubbed and we do not send breadcrumbs, request bodies, screenshots, session recordings or profiling. Native crashes are handled by the Sentry SDK according to its limited error-only configuration with personal data disabled.
  • Product analytics (Firebase Analytics / GA4). Analytics are only metadata: the App can send typed categories such as screen name, outcome category and bounded duration, to help us understand which parts of the App are used and where they fail. Your identity, content, coordinates, tokens, entity IDs and raw error texts are excluded by design: there is no code path in the App that can insert them into an analytics event.
  • Performance measurements. A small number of local measurements (app start, map camera attachment, marker drawing, panel opening) are written on the Dart VM timeline on the device. They contain no identity, are not stored by the App and are not transmitted to anyone.
  • Debug logs. A bounded in-memory log buffer exists only in development builds. It is not present in published store builds.

6.12 App integrity

Firebase App Check, together with Google Play Integrity on Android and Apple App Attest on iOS, produces short-lived attestations proving requests come from an authentic, unmodified copy of the App. We do not keep any attestation logs. These tokens are anti-abuse measures and never alone confer authorization.

6.13 Remote configuration

Firebase Remote Config delivers typed configuration parameters (feature flags and similar) to the App. It fetches configuration and reports parameter keys and model version. No personal data is sent for this purpose.

6.14 In-app feedback

If you send feedback from within the App, we receive your message, feedback category, an optional attached screenshot, your email address, user ID, app version, platform and language, to help us understand the issue and respond.

7. Legal bases for processing

Purpose

Legal basis

Creation and management of the account; provision of map, dog profiles, spots, sniffs, challenges and activated notifications

Performance of a contract, art. 6(1)(b) GDPR

Access to device location, camera and photo library; delivery of push notifications; personalised advertising

Consent, art. 6(1)(a) GDPR, given via system permission or an in-app command and revocable at any time

Service security and availability: abuse prevention, App Check attestation, rate limiting, content moderation, crash and error diagnostics, fraud prevention

Legitimate interest, art. 6(1)(f) GDPR. Our interest is a service free from spam, abuse or defects; we have assessed that this does not override your rights, as the data involved is minimal and not used for profiling you

Subscription management and compliance with tax, accounting and consumer protection obligations

Contract and legal obligation, arts. 6(1)(b) and 6(1)(c) GDPR

Response to legitimate authority requests and legal defence

Legal obligation and legitimate interest, arts. 6(1)(c) and 6(1)(f) GDPR

When processing is based on consent, withdrawing it is as simple as giving it (disable the permission in the operating system or the toggle in Settings) and does not affect the lawfulness of processing already carried out.

8. Who we share data with

We do not sell personal data. We share it with the following categories of recipients.

8.1 Other WoffApp users

As described in section 5: the public projection of your dog, your active spots within about 5 km and your position in public leaderboards.

8.2 Data processors and sub-processors

Recipient

Role

Data involved

Location

Safeguards

Google Ireland Ltd / Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check

Hosting, database, storage, server logic, push transport

Virtually all Service data

Firestore and Cloud Functions operate in europe-west3 (Frankfurt, Germany). Other Firebase components and support may involve processing in the USA

Google Cloud Data Processing Addendum; EU Standard Contractual Clauses; EU-US Data Privacy Framework

Google Ireland Ltd / Google LLC - Google Maps Platform (Maps SDK, Places, Geocoding)

Map rendering, place search, address resolution

View boundaries, coordinates, typed queries, session tokens, IP address

Global

Google Maps Platform Terms; Google Privacy Policy

Google LLC - Play Integrity

Integrity attestation on Android

Device and app integrity signals

Global

Google Play Terms

Apple Inc. / Apple Distribution International Ltd - App Attest, App Store, APNs

Integrity on iOS, distribution, push transport

Attestation signals, purchase logs, push tokens

Global

Apple Privacy Policy

Functional Software Inc. (Sentry)

Crash and error diagnostics

Firebase UID, cleaned exception stack traces, release and device context

United States, with EU data region available

Sentry DPA; EU Standard Contractual Clauses

RevenueCat Inc. (v. 12.1)

Subscription management

Firebase UID, pseudonymous user ID, store receipt and subscription status

United States

RevenueCat DPA; EU Standard Contractual Clauses

Google Ireland Ltd - AdMob (v. 12.2)

Advertising

Advertising ID, ad interaction data, approximate location, device data

Global

Google Ads Data Processing Terms

Each acts as our processor, or as an independent controller in limited cases where the provider determines its own purposes (notably Google Maps, Apple and Google as store operators, and advertising providers). We maintain an updated list of sub-processors, available on request at info@woffapp.com.

8.3 Other disclosures

We may disclose data to professional advisors, to a buyer in case of merger or acquisition (with notice), and to public authorities when a valid legal obligation requires it.

9. How long we keep data

Data

Retention

Account, profile, notification preferences

Until account deletion

Dog profiles and original photos

Until deletion of the dog or account

Public projections and sanitized photos

Deleted upon deletion of the original dog; a cleanup queue reconciles derived copies

Dog spots

Permanently deleted 72 hours after creation, or immediately upon removal

Sniffs, counters and social history

Until deletion of the involved dog or account

Challenge facts derived from spots

Until the closure of the last weekly or monthly window consuming them, plus 21 days, then automatically deleted; also deleted upon deletion of spots, dog or account

Leaderboard entries, boards and scores

For the weekly or monthly window plus 21 days

"Home" Adventurer reference (5 km privacy cell)

Until deletion of the dog or account

Service proposals and moderation logs

Retained after resolution, as an audit trail of the decision

Notification installation, push token and delivery log

Until logout, permission revocation, token rotation or entry expiration

Local logs of pending commands

Maximum 7 days

Crash and error events

90 days at the provider

Server request logs (including Google Cloud logs)

According to provider default, typically 30 days

Purchase and billing documents

10 years, as required by Italian tax law

Offline Firestore cache on your device

Until app data deletion or uninstallation

When a retention period is set by a provider we do not control, we declare it, instead of promising deletion we cannot perform.

10. Data deletion

10.1 Deleting a single dog

Deleting a dog removes its private profile, photos, public projection and spots, and cancels progress in challenges that dog contributed to. Your other dogs and their spots remain unaffected.

10.2 Deleting the account

You can delete your WoffApp account and all associated data from Settings -> Account -> Delete account in the app. You can also request deletion by writing to info@woffapp.com from the registered account email: we will complete it within 30 days. Deletion is a phased server-side process. It removes the profile, dogs, their photos and public projections, all their spots, sniff records, challenge progress and references, notification installations and finally the Firebase Authentication identity. It is irreversible. What deletion cannot reach, honestly stated:

  • Photos exported via the sharing panel to another person or app.
  • Request and delivery logs already acquired by Google (Maps, Places, Cloud Messaging, Cloud Logging) and other providers, which expire according to their own cycles.
  • Documents we are legally required to retain, such as purchase invoices.
  • Aggregate or anonymised statistics no longer attributable to you.
  • Firebase SDK cache on a device where the app is still installed: delete app data or uninstall.

10.3 Web deletion path

For store compliance, an account deletion request page is available at https://woffapp.com/account-deletion and works without installing the app.

11. Your rights

Under arts. 15 to 22 GDPR you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate data and complete incomplete data;
  • obtain data deletion ("right to be forgotten"), as described in section 10;
  • obtain processing restriction in cases under art. 18;
  • portability: receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on our legitimate interest, for reasons related to your particular situation, and object at any time and without reason to processing for direct marketing purposes;
  • withdraw consent at any time, without affecting prior lawfulness;
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects (we do not perform such).

To exercise these, write to info@woffapp.com. We will respond within one month, extendable by two months for complex requests, and inform you if an extension is needed. We may ask you to verify your identity, but only proportionately.

Right to complain.

If you believe your data processing is unlawful, you may complain to the Italian supervisory authority:

Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 RomePhone: +39 06 696771Email: garante@gpdp.it - PEC: protocollo@pec.gpdp.itWebsite: https://www.garanteprivacy.it

You may also contact the supervisory authority of your EU country of residence or work, or take legal action.

12. Subscriptions, advertising and nearby spot alerts

These three areas involve data processors and permissions not used by the rest of the app, so are described separately. Availability depends on your platform, geographic area and app version.

12.1 Premium subscription and payments

WoffApp offers an optional recurring subscription that removes advertising. Purchases are made via Apple App Store and Google Play, which handle payment. We never receive your card number, bank details or billing address. Rights management is handled by RevenueCat, which receives your Firebase UID or a pseudonymous user ID, store receipt and resulting status (active, expired, grace period, billing issue), so the subscription follows you across devices and reinstallations. Our servers keep only the resulting status, linked to your account. Apple and Google act as independent controllers for the transaction and keep purchase records according to their policies and timelines. Tax documents we must retain follow the times indicated in section 9.

12.2 Advertising

Free accounts see banner ads provided by Google AdMob, shown when opening a marker. Active subscribers see no ads.

Before requesting any ad:

  • on iOS we present the App Tracking Transparency prompt and request only non-personalised ads, unless you authorise tracking;
  • in the EEA and UK we present a consent management platform certified by Google and compliant with the IAB Transparency and Consent Framework, showing non-personalised ads to those who do not consent.

Refusing means continuing to see ads, but chosen without profiling. AdMob may process your advertising ID, ad interactions, approximate location and device info per Google's policies. You can reset or clear your advertising ID anytime in device settings.

12.3 Nearby spot alerts and background location

Nearby spot alerts notify you when a dog spot appears near you while the app is closed. To do this, the app registers geographic regions with the operating system - up to 20 regions on iOS and 100 on Android, each with a radius of about 100 m - and the OS wakes the app when you enter one. Regions are chosen from spots near you and deregistered when those spots expire. This requires background location permission ("Always" on iOS, "Allow all the time" on Android), a significantly more invasive step than foreground location described in point 6.4. Consequently:

  • strictly optional: the app explains what it does before the system prompt appears;
  • refusing or later revoking permission in system settings costs you nothing in the rest of the app;
  • alerts stop immediately when you revoke permission or disable the feature.

Background location is evaluated on your device against registered regions. As with foreground location, we do not keep raw coordinates as a permanent log of places you have been.

13. Minors

WoffApp is not intended for anyone under 16 years old. We do not knowingly collect personal data of minors under 16. By creating an account you confirm you are at least 16. If you believe a minor under 16 has created an account, write to info@woffapp.com and we will promptly delete the account and related data. The 16-year threshold is a deliberate choice: it is the maximum digital consent age allowed by art. 8 GDPR, thus valid in every EEA country regardless of local age.

14. Security

We protect data, among other means, with:

  • HTTPS/TLS for all network traffic and encryption at rest of data stored on Google Cloud infrastructure;
  • server-side authorization: Firestore security rules and authenticated server functions are the authorization boundary. The app does not decide what you can read or write, the server does;
  • minimum privilege service identity for server functions;
  • Firebase App Check attestation as an additional layer against automated abuse;
  • rate limits on abuse-prone operations;
  • secret management: server credentials reside in a secret manager and never appear in the app or any app request;
  • privacy by design: public projections described in section 5 are generated by the server so private identifiers never reach other users.

No system is perfectly secure. In case of a personal data breach posing a risk to your rights and freedoms, we will notify the Supervisory Authority within 72 hours as required by art. 33 GDPR and inform you directly in cases foreseen by art. 34.

15. International transfers

Our main archives (Cloud Firestore and Cloud Functions) are located in europe-west3 (Frankfurt, Germany), inside the EEA. Some providers listed in point 8.2 are established in the United States or operate globally. When personal data is transferred outside the EEA, the transfer is based on:

  • a European Commission adequacy decision, including the EU-US Data Privacy Framework where the recipient is certified; or
  • the European Commission Standard Contractual Clauses, supplemented by technical and organisational measures where our transfer assessment identifies them as necessary.

You may request copies of applicable safeguards by writing to info@woffapp.com.

16. Changes to this privacy notice

We may update this notice as WoffApp evolves. The version number and effective date at the top of the document always identify the current text.

  • For minor changes (clarifications, corrections, new providers of the same type) we will update the document and date.
  • For substantial changes (a new purpose, a new data category, a new disclosure or anything requiring consent) we will inform you in the app or by email at least 30 days in advance and, where required by law, seek your consent before the change takes effect.

Previous versions are archived at https://woffapp.com/legal/archive.

17. Contacts

Privacy, data subject rights and support: info@woffapp.com

Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]

This notice is published in Italian and English. In case of discrepancy, for users residing in Italy the Italian version prevails.

Privacy policy

Ita

Eng

Effective date: 10 August 2026

Version: 1.0

Last updated: 10 August 2026

​

This Privacy Notice explains how WoffApp collects, uses, shares, and protects personal data when you use the WoffApp mobile application for iOS and Android (the "App") and the website https://woffapp.com (the "Site", together with the App, the "Service").

We wrote this document to be read, not just stored. If anything is unclear, please write to info@woffapp.com.

​

1. Who processes your data

The data controller ("we") is:

Data Controller [LEGAL_ENTITY_NAME]

Registered office [REGISTERED_ADDRESS]

VAT / tax code [VAT_NUMBER]

Email (privacy, data subject rights and support) info@woffapp.com

Data Protection Officer (DPO) [DPO_CONTACT_OR: "Not appointed. The conditions of Art. 37 GDPR do not apply."]

​

We are established in Italy and the Service is aimed at users in the European Economic Area. Processing is governed by Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 and subsequent amendments ("Privacy Code").

2. What WoffApp does in terms of privacy

WoffApp is a location-based social app dedicated to dog owners.

Four concepts are enough to understand this notice:

  • Service locations are permanent and curated points of interest (drinking fountains, bins, shops, vets, dog areas, dog sitters, grooming, trainers, kennels). They are places, not people.
  • Dog spots are temporary markers you create at your current location. They are visible to other users within about 5 km and are deleted 72 hours after creation, or earlier if you remove them.
  • Sniffs are light social reactions that a user's dog sends to another user's dog's dog spot.
  • Challenges are weekly and monthly neighbourhood leaderboards calculated from your spots and sniffs within an area of about 10 km.

The most relevant privacy consequence: when you create a dog spot, you deliberately publish an approximate real location where you and your dog were, making it visible to nearby strangers for up to 72 hours. Section 6.5 explains this in detail. We ask you to read it.

3. Summary Table

What we process

Perchè

Legal basis

For how long

Account: email, password, Firebase user ID, login provider

Create and protect your account

Contract (Art. 6(1)(b))

Until account deletion

Profile: display name, language, city, notification preferences

Make the App work as you configured it

Contract

Until account deletion

Dog profiles: name, birth date, breed, sex, likes, dislikes, description, photos

Main function requested by you

Contract

Until account deletion

Device location while using the App

Show map, find nearby places, create spots

Consent (Art. 6(1)(a)) via system permission

Not stored as raw coordinate; see 6.4

Device location in background, only if you enable nearby spot alerts

Notify you when a dog spot appears near you

Consent (Art. 6(1)(a))

Not stored as raw coordinate; see 12.3

Dog spot: coordinate, geohash, times

Main function

Contract

Deleted permanently after 72 hours or upon removal

Sniffs and social history

Main function and challenges

Contract

Until dog or account deletion

Facts, scores and challenge leaderboards

Gamification

Contract

Rolling windows plus 21 days; see 9

Notification token, installation ID, platform, categories

Deliver notifications you have enabled

Consent + contract

Until logout, token change or deactivation

Crash and error diagnostics

Keep the App working

Legitimate interest (Art. 6(1)(f))

90 days with provider

App integrity attestations

Prevent abuse and fraud

Legitimate interest

Short duration, managed by provider

Place proposals and moderation logs

Maintain the place directory

Legitimate interest

Until record removal; audits remain

Subscription status

Remove ads for subscribers

Contract

Subscription duration plus legal terms

Advertising identifiers

Show ads to non-subscribers

Consent

According to provider policy

4. What we do not collect

To set expectations precisely:

  • We do not see or store your password. It is transmitted directly to Firebase Authentication, which stores it with hashing and salting.
  • We do not see or store your payment card data. Purchases are fully managed by Apple and Google within the store payment screen.
  • We do not collect background location by default. The App requests location only "while using the app". Background location is used solely for optional nearby spot alerts described in section 12.3, which require a separate permission you can refuse or revoke without losing any other function.
  • We do not process special categories of data under Art. 9 GDPR (health, biometrics, religion, political opinions, sexual orientation, etc.). We ask you not to enter such information in the dog's free description.
  • We do not perform automated decision-making with legal effects under Art. 22 GDPR. Challenge leaderboards are automated calculations but do not produce legal or similarly significant effects.
  • We do not sell your personal data nor share it with data brokers.

5. Private, public and pseudonymous data in WoffApp

WoffApp separates what you enter from what other users can see. This separation is enforced by the server, not just the interface.

Private, only yours. Your email address, your Firebase user ID, account settings, notification tokens, your dogs' private cards, original uploaded photos, exact coordinates of your spots, private progress counters in challenges, and the list of sniffs sent and received.

Published to other users, in pseudonymous form. When you register a dog and create a spot, the server generates a public projection of the dog from the private card. This projection contains an opaque public identifier not linked to your account, plus name, breed, sex, birth date, likes, dislikes, description and sanitized copies of gallery photos. It deliberately excludes your user ID, email address, the dog's private ID, original photo storage paths and any precise location other than the spot you chose to publish.

Important consequence: the projection is pseudonymous, not anonymous. If you give the dog an identifying name, describe where you live in free text or upload a photo showing your house number, other users can recognise you. Treat description and gallery as a public post.

6. What we collect, in detail

6.1 Account and authentication

At registration, we process your email address and a password. The password exists only within the login interaction and the request to Firebase Authentication; we do not create separate copies or logs. Firebase Authentication stores the account identity, an anonymous Firebase user ID (UID), the authentication provider used, login times and token claims. Where the App offers Google or Apple login, we also process the OAuth credential returned by the provider and the email address the provider communicates to us. With Apple, you can choose to hide your address, in which case we receive only a private forwarding address: emails we send you then pass through Apple's forwarding service. Firebase Authentication and the operating system may store session credentials in device memory areas managed by the SDK and system. Logout revokes the App's powers and asks Firebase to disconnect the session, but we cannot and do not claim to physically delete that cache managed by the provider.

6.2 Profile and settings

We store a cloud profile document containing your UID, display name, email address, optional profile photo URL, app language, city, notification preferences and creation date, plus copies of your role (regular user or administrator) and subscription status. This allows your settings to survive a reinstall.

6.3 Dog profiles and photos

For each registered dog, we store: name (mandatory) and optionally birth date, breed (free text), sex, likes, dislikes, a description and an ordered photo gallery whose first image is the profile photo. We do not collect your age; the dog's age is derived from the birth date.

Photos are selected from the gallery or camera via the operating system selector. We receive only the images you choose. Originals are stored in Firebase Storage under your account. A server-side process generates sanitized public copies (a full version up to 5 MiB and a thumbnail up to 512 KiB), which are those actually loaded by other users. Uploads are limited to 20 MiB per image.

Note on photo metadata: WoffApp does not remove EXIF metadata from uploaded image bytes. If your camera inserts GPS coordinates in photos, those coordinates may travel with the image. If this concerns you, disable geolocation in the camera app or use photos without it. If a dog card references an image hosted outside our infrastructure, opening it causes an HTTPS request to that third-party server, which will see your IP address and normal request metadata. Removing the URL stops future requests but cannot delete that server's logs. Using the system share panel on a photo exports a copy to the app or person you select. We cannot recall or delete that copy.

6.4 Location

By default, the App uses location only while you are using it. It requests "while using the app" permission on both platforms. The only exception is the optional nearby spot alerts feature described in section 12.3, which requests separate permission.

What happens on a location detection:

  • The precise sample and its accuracy remain in memory to centre the map, understand which dog spot or service you are near and place a new spot.
  • We do not store the raw coordinate as a permanent log of where you are.
  • We send derived data to our servers to query nearby content: bounded geohash intervals derived from your location, visible map portion boundaries, selected category filters and a query fingerprint. These data end up in normal server request logs and are sufficient to indicate the general area you were viewing.
  • Google Maps SDK and your device's location services are separate entities operating under their own policies (section 8).

You can revoke location permission at any time from the operating system settings. The App remains usable, but map-centred discovery and spot creation stop working. Creating a dog spot is a distinct and deliberate act of publication. See 6.5.

6.5 Dog spot

When you create a dog spot, we store its coordinate, a geohash, creation time, expiry time at 72 hours, dog's sex, dog's opaque public ID, your user ID on the private card and a sniff counter.

  • Other users within about 5 km can see the spot on the map.
  • The spot is deleted permanently 72 hours after creation, or immediately if you remove it. There is no hidden archive of expired spots.
  • A dog can have up to five active spots simultaneously.
  • Spots are not editable after creation.
  • Records derived from a spot for challenge calculation survive the spot itself; see section 9.

Do not create a spot at your home, workplace, a school or any place whose exposure could put you or others at risk. A sequence of spots at the same place at the same time reveals a habit. The "Best Routine" and "Early Bird" challenges exist precisely because these patterns are readable.

6.6 Sniffs and social history

Sending a sniff creates a record linking your dog to the spot and the target dog, with a time. Both parties maintain aggregated counters (sent, received, last sent, last received) that feed the best friends view and challenges. The sniff history is permanent: it is kept until the dog or account involved is deleted. Expired spots do not delete received sniffs.

6.7 Challenges and leaderboards

Challenges are calculated server-side from immutable "facts" (a sniff occurred, a spot was created, a contribution to a service was accepted). The catalogue includes: Neighbour's Administrator, Most Popular, Most Friendly, Best Routine, Early Bird, Most Active, Adventurer, Best Woffer and other entries shown in the App. Privacy-relevant elements:

  • Leaderboards are limited to a neighbourhood cell of about 10 km derived from the spot's location, not a municipality or address.
  • Public leaderboards expose only the rule, time window, ordered membership index, score and a safe snapshot of leading dogs, which uses the same pseudonymous public projection described in section 5. They do not expose user IDs or email addresses.
  • Your detailed progress counters are readable only by you and the server.
  • The Adventurer challenge needs a "home" reference. The server sets it once, from your oldest stored spot, and stores it as a versioned privacy cell ID of about 5 km – never a raw home coordinate. Removing that spot does not move the reference; only deleting the dog or account removes it.

Challenges are added and withdrawn over time. New challenges reuse the same facts and pseudonymous projections described here; a challenge requiring a new data category would first require an update to this notice.

6.8 Service locations, proposals and moderation

The service location directory is curated. Any user can propose a new place or a modification and can support an existing proposal.

When you use the place search field, the typed text, search session token, app language and visible map portion are sent to Google Places to get suggestions, and the chosen place is resolved into a place ID, formatted address and structured address components.

Reverse geocoding sends a coordinate to Google to get a readable address. Google retains these requests according to its policy; we cannot delete them. Moderation logs keep author ID, supporter IDs, proposals, decision, reviewer, times and a request digest. These logs serve to verify contested decisions later and are kept even after the proposal is resolved.

Accepted contributions also feed the "Neighbour's Administrator" challenge, which stores the number of accepted contributions and up to ten contribution lines, visible only to you.

6.9 Push notifications

If you authorise notifications, we register a device installation: an installation ID generated by the App, platform, app version, distributed language, notification permission status, enabled categories and the push token issued by your platform's notification service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) with its hash. The server maintains a delivery log with event IDs, emission and expiry times, recipient hashes and recipient IDs, so a new attempt does not duplicate a notification. Current notification types: a spot you created was published, you received a sniff, a sent sniff was confirmed, new nearby service content. Resolving a notification in a readable card involves further reads: the exact spot, public projection and sender dog's thumbnail and an address obtained by reverse geocoding from Google for the spot's coordinate.

Some installation-level values (installation ID, operation generation counter and flag recording that the notification prompt was already shown) intentionally survive logout and are deleted by removing App data or uninstalling it, not by signing out. You can disable categories in the App Settings and disable notifications entirely from the operating system settings.

6.10 Local storage on your device

The App stores a small set of values in the device preference store: whether you completed the tutorial, chosen language, a per-account copy of your notification setting, preferred challenge and short-term records of undelivered commands (parts of owner and scope keys as hashes, a command ID and a time, kept for up to seven days). The built-in Firestore offline cache also stores copies of documents you viewed and pending writes, so the App works offline. This cache is managed by the Firebase SDK. Logout isolates it so data from another account cannot be shown, but we do not claim to physically delete it on logout. Uninstalling the App or deleting its data removes it.

6.11 Diagnostics, crash reporting and analytics

  • Crash and error reporting (Sentry). Enabled only in release builds and limited to errors. The only user context attached is your Firebase UID. Exception values are scrubbed and we do not send breadcrumbs, request bodies, screenshots, session recordings or profiling. Native crashes are handled by the Sentry SDK according to its limited error-only configuration with personal data disabled.
  • Product analytics (Firebase Analytics / GA4). Analytics are only metadata: the App can send typed categories such as screen name, outcome category and bounded duration, to help us understand which parts of the App are used and where they fail. Your identity, content, coordinates, tokens, entity IDs and raw error texts are excluded by design: there is no code path in the App that can insert them into an analytics event.
  • Performance measurements. A small number of local measurements (app start, map camera attachment, marker drawing, panel opening) are written on the Dart VM timeline on the device. They contain no identity, are not stored by the App and are not transmitted to anyone.
  • Debug logs. A bounded in-memory log buffer exists only in development builds. It is not present in published store builds.

6.12 App integrity

Firebase App Check, together with Google Play Integrity on Android and Apple App Attest on iOS, produces short-lived attestations proving requests come from an authentic, unmodified copy of the App. We do not keep any attestation logs. These tokens are anti-abuse measures and never alone confer authorization.

6.13 Remote configuration

Firebase Remote Config delivers typed configuration parameters (feature flags and similar) to the App. It fetches configuration and reports parameter keys and model version. No personal data is sent for this purpose.

6.14 In-app feedback

If you send feedback from within the App, we receive your message, feedback category, an optional attached screenshot, your email address, user ID, app version, platform and language, to help us understand the issue and respond.

7. Legal bases for processing

Purpose

Legal basis

Creation and management of the account; provision of map, dog profiles, spots, sniffs, challenges and activated notifications

Performance of a contract, art. 6(1)(b) GDPR

Access to device location, camera and photo library; delivery of push notifications; personalised advertising

Consent, art. 6(1)(a) GDPR, given via system permission or an in-app command and revocable at any time

Service security and availability: abuse prevention, App Check attestation, rate limiting, content moderation, crash and error diagnostics, fraud prevention

Legitimate interest, art. 6(1)(f) GDPR. Our interest is a service free from spam, abuse or defects; we have assessed that this does not override your rights, as the data involved is minimal and not used for profiling you

Subscription management and compliance with tax, accounting and consumer protection obligations

Contract and legal obligation, arts. 6(1)(b) and 6(1)(c) GDPR

Response to legitimate authority requests and legal defence

Legal obligation and legitimate interest, arts. 6(1)(c) and 6(1)(f) GDPR

When processing is based on consent, withdrawing it is as simple as giving it (disable the permission in the operating system or the toggle in Settings) and does not affect the lawfulness of processing already carried out.

8. Who we share data with

We do not sell personal data. We share it with the following categories of recipients.

8.1 Other WoffApp users

As described in section 5: the public projection of your dog, your active spots within about 5 km and your position in public leaderboards.

8.2 Data processors and sub-processors

Recipient

Role

Data involved

Location

Safeguards

Google Ireland Ltd / Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check

Hosting, database, storage, server logic, push transport

Virtually all Service data

Firestore and Cloud Functions operate in europe-west3 (Frankfurt, Germany). Other Firebase components and support may involve processing in the USA

Google Cloud Data Processing Addendum; EU Standard Contractual Clauses; EU-US Data Privacy Framework

Google Ireland Ltd / Google LLC - Google Maps Platform (Maps SDK, Places, Geocoding)

Map rendering, place search, address resolution

View boundaries, coordinates, typed queries, session tokens, IP address

Global

Google Maps Platform Terms; Google Privacy Policy

Google LLC - Play Integrity

Integrity attestation on Android

Device and app integrity signals

Global

Google Play Terms

Apple Inc. / Apple Distribution International Ltd - App Attest, App Store, APNs

Integrity on iOS, distribution, push transport

Attestation signals, purchase logs, push tokens

Global

Apple Privacy Policy

Functional Software Inc. (Sentry)

Crash and error diagnostics

Firebase UID, cleaned exception stack traces, release and device context

United States, with EU data region available

Sentry DPA; EU Standard Contractual Clauses

RevenueCat Inc. (v. 12.1)

Subscription management

Firebase UID, pseudonymous user ID, store receipt and subscription status

United States

RevenueCat DPA; EU Standard Contractual Clauses

Google Ireland Ltd - AdMob (v. 12.2)

Advertising

Advertising ID, ad interaction data, approximate location, device data

Global

Google Ads Data Processing Terms

Each acts as our processor, or as an independent controller in limited cases where the provider determines its own purposes (notably Google Maps, Apple and Google as store operators, and advertising providers). We maintain an updated list of sub-processors, available on request at info@woffapp.com.

8.3 Other disclosures

We may disclose data to professional advisors, to a buyer in case of merger or acquisition (with notice), and to public authorities when a valid legal obligation requires it.

9. How long we keep data

Data

Retention

Account, profile, notification preferences

Until account deletion

Dog profiles and original photos

Until deletion of the dog or account

Public projections and sanitized photos

Deleted upon deletion of the original dog; a cleanup queue reconciles derived copies

Dog spots

Permanently deleted 72 hours after creation, or immediately upon removal

Sniffs, counters and social history

Until deletion of the involved dog or account

Challenge facts derived from spots

Until the closure of the last weekly or monthly window consuming them, plus 21 days, then automatically deleted; also deleted upon deletion of spots, dog or account

Leaderboard entries, boards and scores

For the weekly or monthly window plus 21 days

"Home" Adventurer reference (5 km privacy cell)

Until deletion of the dog or account

Service proposals and moderation logs

Retained after resolution, as an audit trail of the decision

Notification installation, push token and delivery log

Until logout, permission revocation, token rotation or entry expiration

Local logs of pending commands

Maximum 7 days

Crash and error events

90 days at the provider

Server request logs (including Google Cloud logs)

According to provider default, typically 30 days

Purchase and billing documents

10 years, as required by Italian tax law

Offline Firestore cache on your device

Until app data deletion or uninstallation

When a retention period is set by a provider we do not control, we declare it, instead of promising deletion we cannot perform.

10. Data deletion

10.1 Deleting a single dog

Deleting a dog removes its private profile, photos, public projection and spots, and cancels progress in challenges that dog contributed to. Your other dogs and their spots remain unaffected.

10.2 Deleting the account

You can delete your WoffApp account and all associated data from Settings -> Account -> Delete account in the app. You can also request deletion by writing to info@woffapp.com from the registered account email: we will complete it within 30 days. Deletion is a phased server-side process. It removes the profile, dogs, their photos and public projections, all their spots, sniff records, challenge progress and references, notification installations and finally the Firebase Authentication identity. It is irreversible. What deletion cannot reach, honestly stated:

  • Photos exported via the sharing panel to another person or app.
  • Request and delivery logs already acquired by Google (Maps, Places, Cloud Messaging, Cloud Logging) and other providers, which expire according to their own cycles.
  • Documents we are legally required to retain, such as purchase invoices.
  • Aggregate or anonymised statistics no longer attributable to you.
  • Firebase SDK cache on a device where the app is still installed: delete app data or uninstall.

10.3 Web deletion path

For store compliance, an account deletion request page is available at https://woffapp.com/account-deletion and works without installing the app.

11. Your rights

Under arts. 15 to 22 GDPR you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate data and complete incomplete data;
  • obtain data deletion ("right to be forgotten"), as described in section 10;
  • obtain processing restriction in cases under art. 18;
  • portability: receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on our legitimate interest, for reasons related to your particular situation, and object at any time and without reason to processing for direct marketing purposes;
  • withdraw consent at any time, without affecting prior lawfulness;
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects (we do not perform such).

To exercise these, write to info@woffapp.com. We will respond within one month, extendable by two months for complex requests, and inform you if an extension is needed. We may ask you to verify your identity, but only proportionately.

Right to complain.

If you believe your data processing is unlawful, you may complain to the Italian supervisory authority:

Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 RomePhone: +39 06 696771Email: garante@gpdp.it - PEC: protocollo@pec.gpdp.itWebsite: https://www.garanteprivacy.it

You may also contact the supervisory authority of your EU country of residence or work, or take legal action.

12. Subscriptions, advertising and nearby spot alerts

These three areas involve data processors and permissions not used by the rest of the app, so are described separately. Availability depends on your platform, geographic area and app version.

12.1 Premium subscription and payments

WoffApp offers an optional recurring subscription that removes advertising. Purchases are made via Apple App Store and Google Play, which handle payment. We never receive your card number, bank details or billing address. Rights management is handled by RevenueCat, which receives your Firebase UID or a pseudonymous user ID, store receipt and resulting status (active, expired, grace period, billing issue), so the subscription follows you across devices and reinstallations. Our servers keep only the resulting status, linked to your account. Apple and Google act as independent controllers for the transaction and keep purchase records according to their policies and timelines. Tax documents we must retain follow the times indicated in section 9.

12.2 Advertising

Free accounts see banner ads provided by Google AdMob, shown when opening a marker. Active subscribers see no ads.

Before requesting any ad:

  • on iOS we present the App Tracking Transparency prompt and request only non-personalised ads, unless you authorise tracking;
  • in the EEA and UK we present a consent management platform certified by Google and compliant with the IAB Transparency and Consent Framework, showing non-personalised ads to those who do not consent.

Refusing means continuing to see ads, but chosen without profiling. AdMob may process your advertising ID, ad interactions, approximate location and device info per Google's policies. You can reset or clear your advertising ID anytime in device settings.

12.3 Nearby spot alerts and background location

Nearby spot alerts notify you when a dog spot appears near you while the app is closed. To do this, the app registers geographic regions with the operating system - up to 20 regions on iOS and 100 on Android, each with a radius of about 100 m - and the OS wakes the app when you enter one. Regions are chosen from spots near you and deregistered when those spots expire. This requires background location permission ("Always" on iOS, "Allow all the time" on Android), a significantly more invasive step than foreground location described in point 6.4. Consequently:

  • strictly optional: the app explains what it does before the system prompt appears;
  • refusing or later revoking permission in system settings costs you nothing in the rest of the app;
  • alerts stop immediately when you revoke permission or disable the feature.

Background location is evaluated on your device against registered regions. As with foreground location, we do not keep raw coordinates as a permanent log of places you have been.

13. Minors

WoffApp is not intended for anyone under 16 years old. We do not knowingly collect personal data of minors under 16. By creating an account you confirm you are at least 16. If you believe a minor under 16 has created an account, write to info@woffapp.com and we will promptly delete the account and related data. The 16-year threshold is a deliberate choice: it is the maximum digital consent age allowed by art. 8 GDPR, thus valid in every EEA country regardless of local age.

14. Security

We protect data, among other means, with:

  • HTTPS/TLS for all network traffic and encryption at rest of data stored on Google Cloud infrastructure;
  • server-side authorization: Firestore security rules and authenticated server functions are the authorization boundary. The app does not decide what you can read or write, the server does;
  • minimum privilege service identity for server functions;
  • Firebase App Check attestation as an additional layer against automated abuse;
  • rate limits on abuse-prone operations;
  • secret management: server credentials reside in a secret manager and never appear in the app or any app request;
  • privacy by design: public projections described in section 5 are generated by the server so private identifiers never reach other users.

No system is perfectly secure. In case of a personal data breach posing a risk to your rights and freedoms, we will notify the Supervisory Authority within 72 hours as required by art. 33 GDPR and inform you directly in cases foreseen by art. 34.

15. International transfers

Our main archives (Cloud Firestore and Cloud Functions) are located in europe-west3 (Frankfurt, Germany), inside the EEA. Some providers listed in point 8.2 are established in the United States or operate globally. When personal data is transferred outside the EEA, the transfer is based on:

  • a European Commission adequacy decision, including the EU-US Data Privacy Framework where the recipient is certified; or
  • the European Commission Standard Contractual Clauses, supplemented by technical and organisational measures where our transfer assessment identifies them as necessary.

You may request copies of applicable safeguards by writing to info@woffapp.com.

16. Changes to this privacy notice

We may update this notice as WoffApp evolves. The version number and effective date at the top of the document always identify the current text.

  • For minor changes (clarifications, corrections, new providers of the same type) we will update the document and date.
  • For substantial changes (a new purpose, a new data category, a new disclosure or anything requiring consent) we will inform you in the app or by email at least 30 days in advance and, where required by law, seek your consent before the change takes effect.

Previous versions are archived at https://woffapp.com/legal/archive.

17. Contacts

Privacy, data subject rights and support: info@woffapp.com

Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]

This notice is published in Italian and English. In case of discrepancy, for users residing in Italy the Italian version prevails.

Privacy policy

Ita

Eng

Effective date: 10 August 2026

Version: 1.0

Last updated: 10 August 2026

​

This Privacy Notice explains how WoffApp collects, uses, shares, and protects personal data when you use the WoffApp mobile application for iOS and Android (the "App") and the website https://woffapp.com (the "Site", together with the App, the "Service").

We wrote this document to be read, not just stored. If anything is unclear, please write to info@woffapp.com.

​

1. Who processes your data

The data controller ("we") is:

Data Controller [LEGAL_ENTITY_NAME]

Registered office [REGISTERED_ADDRESS]

VAT / tax code [VAT_NUMBER]

Email (privacy, data subject rights and support) info@woffapp.com

Data Protection Officer (DPO) [DPO_CONTACT_OR: "Not appointed. The conditions of Art. 37 GDPR do not apply."]

​

We are established in Italy and the Service is aimed at users in the European Economic Area. Processing is governed by Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 and subsequent amendments ("Privacy Code").

2. What WoffApp does in terms of privacy

WoffApp is a location-based social app dedicated to dog owners.

Four concepts are enough to understand this notice:

  • Service locations are permanent and curated points of interest (drinking fountains, bins, shops, vets, dog areas, dog sitters, grooming, trainers, kennels). They are places, not people.
  • Dog spots are temporary markers you create at your current location. They are visible to other users within about 5 km and are deleted 72 hours after creation, or earlier if you remove them.
  • Sniffs are light social reactions that a user's dog sends to another user's dog's dog spot.
  • Challenges are weekly and monthly neighbourhood leaderboards calculated from your spots and sniffs within an area of about 10 km.

The most relevant privacy consequence: when you create a dog spot, you deliberately publish an approximate real location where you and your dog were, making it visible to nearby strangers for up to 72 hours. Section 6.5 explains this in detail. We ask you to read it.

3. Summary Table

What we process

Perchè

Legal basis

For how long

Account: email, password, Firebase user ID, login provider

Create and protect your account

Contract (Art. 6(1)(b))

Until account deletion

Profile: display name, language, city, notification preferences

Make the App work as you configured it

Contract

Until account deletion

Dog profiles: name, birth date, breed, sex, likes, dislikes, description, photos

Main function requested by you

Contract

Until account deletion

Device location while using the App

Show map, find nearby places, create spots

Consent (Art. 6(1)(a)) via system permission

Not stored as raw coordinate; see 6.4

Device location in background, only if you enable nearby spot alerts

Notify you when a dog spot appears near you

Consent (Art. 6(1)(a))

Not stored as raw coordinate; see 12.3

Dog spot: coordinate, geohash, times

Main function

Contract

Deleted permanently after 72 hours or upon removal

Sniffs and social history

Main function and challenges

Contract

Until dog or account deletion

Facts, scores and challenge leaderboards

Gamification

Contract

Rolling windows plus 21 days; see 9

Notification token, installation ID, platform, categories

Deliver notifications you have enabled

Consent + contract

Until logout, token change or deactivation

Crash and error diagnostics

Keep the App working

Legitimate interest (Art. 6(1)(f))

90 days with provider

App integrity attestations

Prevent abuse and fraud

Legitimate interest

Short duration, managed by provider

Place proposals and moderation logs

Maintain the place directory

Legitimate interest

Until record removal; audits remain

Subscription status

Remove ads for subscribers

Contract

Subscription duration plus legal terms

Advertising identifiers

Show ads to non-subscribers

Consent

According to provider policy

4. What we do not collect

To set expectations precisely:

  • We do not see or store your password. It is transmitted directly to Firebase Authentication, which stores it with hashing and salting.
  • We do not see or store your payment card data. Purchases are fully managed by Apple and Google within the store payment screen.
  • We do not collect background location by default. The App requests location only "while using the app". Background location is used solely for optional nearby spot alerts described in section 12.3, which require a separate permission you can refuse or revoke without losing any other function.
  • We do not process special categories of data under Art. 9 GDPR (health, biometrics, religion, political opinions, sexual orientation, etc.). We ask you not to enter such information in the dog's free description.
  • We do not perform automated decision-making with legal effects under Art. 22 GDPR. Challenge leaderboards are automated calculations but do not produce legal or similarly significant effects.
  • We do not sell your personal data nor share it with data brokers.

5. Private, public and pseudonymous data in WoffApp

WoffApp separates what you enter from what other users can see. This separation is enforced by the server, not just the interface.

Private, only yours. Your email address, your Firebase user ID, account settings, notification tokens, your dogs' private cards, original uploaded photos, exact coordinates of your spots, private progress counters in challenges, and the list of sniffs sent and received.

Published to other users, in pseudonymous form. When you register a dog and create a spot, the server generates a public projection of the dog from the private card. This projection contains an opaque public identifier not linked to your account, plus name, breed, sex, birth date, likes, dislikes, description and sanitized copies of gallery photos. It deliberately excludes your user ID, email address, the dog's private ID, original photo storage paths and any precise location other than the spot you chose to publish.

Important consequence: the projection is pseudonymous, not anonymous. If you give the dog an identifying name, describe where you live in free text or upload a photo showing your house number, other users can recognise you. Treat description and gallery as a public post.

6. What we collect, in detail

6.1 Account and authentication

At registration, we process your email address and a password. The password exists only within the login interaction and the request to Firebase Authentication; we do not create separate copies or logs. Firebase Authentication stores the account identity, an anonymous Firebase user ID (UID), the authentication provider used, login times and token claims. Where the App offers Google or Apple login, we also process the OAuth credential returned by the provider and the email address the provider communicates to us. With Apple, you can choose to hide your address, in which case we receive only a private forwarding address: emails we send you then pass through Apple's forwarding service. Firebase Authentication and the operating system may store session credentials in device memory areas managed by the SDK and system. Logout revokes the App's powers and asks Firebase to disconnect the session, but we cannot and do not claim to physically delete that cache managed by the provider.

6.2 Profile and settings

We store a cloud profile document containing your UID, display name, email address, optional profile photo URL, app language, city, notification preferences and creation date, plus copies of your role (regular user or administrator) and subscription status. This allows your settings to survive a reinstall.

6.3 Dog profiles and photos

For each registered dog, we store: name (mandatory) and optionally birth date, breed (free text), sex, likes, dislikes, a description and an ordered photo gallery whose first image is the profile photo. We do not collect your age; the dog's age is derived from the birth date.

Photos are selected from the gallery or camera via the operating system selector. We receive only the images you choose. Originals are stored in Firebase Storage under your account. A server-side process generates sanitized public copies (a full version up to 5 MiB and a thumbnail up to 512 KiB), which are those actually loaded by other users. Uploads are limited to 20 MiB per image.

Note on photo metadata: WoffApp does not remove EXIF metadata from uploaded image bytes. If your camera inserts GPS coordinates in photos, those coordinates may travel with the image. If this concerns you, disable geolocation in the camera app or use photos without it. If a dog card references an image hosted outside our infrastructure, opening it causes an HTTPS request to that third-party server, which will see your IP address and normal request metadata. Removing the URL stops future requests but cannot delete that server's logs. Using the system share panel on a photo exports a copy to the app or person you select. We cannot recall or delete that copy.

6.4 Location

By default, the App uses location only while you are using it. It requests "while using the app" permission on both platforms. The only exception is the optional nearby spot alerts feature described in section 12.3, which requests separate permission.

What happens on a location detection:

  • The precise sample and its accuracy remain in memory to centre the map, understand which dog spot or service you are near and place a new spot.
  • We do not store the raw coordinate as a permanent log of where you are.
  • We send derived data to our servers to query nearby content: bounded geohash intervals derived from your location, visible map portion boundaries, selected category filters and a query fingerprint. These data end up in normal server request logs and are sufficient to indicate the general area you were viewing.
  • Google Maps SDK and your device's location services are separate entities operating under their own policies (section 8).

You can revoke location permission at any time from the operating system settings. The App remains usable, but map-centred discovery and spot creation stop working. Creating a dog spot is a distinct and deliberate act of publication. See 6.5.

6.5 Dog spot

When you create a dog spot, we store its coordinate, a geohash, creation time, expiry time at 72 hours, dog's sex, dog's opaque public ID, your user ID on the private card and a sniff counter.

  • Other users within about 5 km can see the spot on the map.
  • The spot is deleted permanently 72 hours after creation, or immediately if you remove it. There is no hidden archive of expired spots.
  • A dog can have up to five active spots simultaneously.
  • Spots are not editable after creation.
  • Records derived from a spot for challenge calculation survive the spot itself; see section 9.

Do not create a spot at your home, workplace, a school or any place whose exposure could put you or others at risk. A sequence of spots at the same place at the same time reveals a habit. The "Best Routine" and "Early Bird" challenges exist precisely because these patterns are readable.

6.6 Sniffs and social history

Sending a sniff creates a record linking your dog to the spot and the target dog, with a time. Both parties maintain aggregated counters (sent, received, last sent, last received) that feed the best friends view and challenges. The sniff history is permanent: it is kept until the dog or account involved is deleted. Expired spots do not delete received sniffs.

6.7 Challenges and leaderboards

Challenges are calculated server-side from immutable "facts" (a sniff occurred, a spot was created, a contribution to a service was accepted). The catalogue includes: Neighbour's Administrator, Most Popular, Most Friendly, Best Routine, Early Bird, Most Active, Adventurer, Best Woffer and other entries shown in the App. Privacy-relevant elements:

  • Leaderboards are limited to a neighbourhood cell of about 10 km derived from the spot's location, not a municipality or address.
  • Public leaderboards expose only the rule, time window, ordered membership index, score and a safe snapshot of leading dogs, which uses the same pseudonymous public projection described in section 5. They do not expose user IDs or email addresses.
  • Your detailed progress counters are readable only by you and the server.
  • The Adventurer challenge needs a "home" reference. The server sets it once, from your oldest stored spot, and stores it as a versioned privacy cell ID of about 5 km – never a raw home coordinate. Removing that spot does not move the reference; only deleting the dog or account removes it.

Challenges are added and withdrawn over time. New challenges reuse the same facts and pseudonymous projections described here; a challenge requiring a new data category would first require an update to this notice.

6.8 Service locations, proposals and moderation

The service location directory is curated. Any user can propose a new place or a modification and can support an existing proposal.

When you use the place search field, the typed text, search session token, app language and visible map portion are sent to Google Places to get suggestions, and the chosen place is resolved into a place ID, formatted address and structured address components.

Reverse geocoding sends a coordinate to Google to get a readable address. Google retains these requests according to its policy; we cannot delete them. Moderation logs keep author ID, supporter IDs, proposals, decision, reviewer, times and a request digest. These logs serve to verify contested decisions later and are kept even after the proposal is resolved.

Accepted contributions also feed the "Neighbour's Administrator" challenge, which stores the number of accepted contributions and up to ten contribution lines, visible only to you.

6.9 Push notifications

If you authorise notifications, we register a device installation: an installation ID generated by the App, platform, app version, distributed language, notification permission status, enabled categories and the push token issued by your platform's notification service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) with its hash. The server maintains a delivery log with event IDs, emission and expiry times, recipient hashes and recipient IDs, so a new attempt does not duplicate a notification. Current notification types: a spot you created was published, you received a sniff, a sent sniff was confirmed, new nearby service content. Resolving a notification in a readable card involves further reads: the exact spot, public projection and sender dog's thumbnail and an address obtained by reverse geocoding from Google for the spot's coordinate.

Some installation-level values (installation ID, operation generation counter and flag recording that the notification prompt was already shown) intentionally survive logout and are deleted by removing App data or uninstalling it, not by signing out. You can disable categories in the App Settings and disable notifications entirely from the operating system settings.

6.10 Local storage on your device

The App stores a small set of values in the device preference store: whether you completed the tutorial, chosen language, a per-account copy of your notification setting, preferred challenge and short-term records of undelivered commands (parts of owner and scope keys as hashes, a command ID and a time, kept for up to seven days). The built-in Firestore offline cache also stores copies of documents you viewed and pending writes, so the App works offline. This cache is managed by the Firebase SDK. Logout isolates it so data from another account cannot be shown, but we do not claim to physically delete it on logout. Uninstalling the App or deleting its data removes it.

6.11 Diagnostics, crash reporting and analytics

  • Crash and error reporting (Sentry). Enabled only in release builds and limited to errors. The only user context attached is your Firebase UID. Exception values are scrubbed and we do not send breadcrumbs, request bodies, screenshots, session recordings or profiling. Native crashes are handled by the Sentry SDK according to its limited error-only configuration with personal data disabled.
  • Product analytics (Firebase Analytics / GA4). Analytics are only metadata: the App can send typed categories such as screen name, outcome category and bounded duration, to help us understand which parts of the App are used and where they fail. Your identity, content, coordinates, tokens, entity IDs and raw error texts are excluded by design: there is no code path in the App that can insert them into an analytics event.
  • Performance measurements. A small number of local measurements (app start, map camera attachment, marker drawing, panel opening) are written on the Dart VM timeline on the device. They contain no identity, are not stored by the App and are not transmitted to anyone.
  • Debug logs. A bounded in-memory log buffer exists only in development builds. It is not present in published store builds.

6.12 App integrity

Firebase App Check, together with Google Play Integrity on Android and Apple App Attest on iOS, produces short-lived attestations proving requests come from an authentic, unmodified copy of the App. We do not keep any attestation logs. These tokens are anti-abuse measures and never alone confer authorization.

6.13 Remote configuration

Firebase Remote Config delivers typed configuration parameters (feature flags and similar) to the App. It fetches configuration and reports parameter keys and model version. No personal data is sent for this purpose.

6.14 In-app feedback

If you send feedback from within the App, we receive your message, feedback category, an optional attached screenshot, your email address, user ID, app version, platform and language, to help us understand the issue and respond.

7. Legal bases for processing

Purpose

Legal basis

Creation and management of the account; provision of map, dog profiles, spots, sniffs, challenges and activated notifications

Performance of a contract, art. 6(1)(b) GDPR

Access to device location, camera and photo library; delivery of push notifications; personalised advertising

Consent, art. 6(1)(a) GDPR, given via system permission or an in-app command and revocable at any time

Service security and availability: abuse prevention, App Check attestation, rate limiting, content moderation, crash and error diagnostics, fraud prevention

Legitimate interest, art. 6(1)(f) GDPR. Our interest is a service free from spam, abuse or defects; we have assessed that this does not override your rights, as the data involved is minimal and not used for profiling you

Subscription management and compliance with tax, accounting and consumer protection obligations

Contract and legal obligation, arts. 6(1)(b) and 6(1)(c) GDPR

Response to legitimate authority requests and legal defence

Legal obligation and legitimate interest, arts. 6(1)(c) and 6(1)(f) GDPR

When processing is based on consent, withdrawing it is as simple as giving it (disable the permission in the operating system or the toggle in Settings) and does not affect the lawfulness of processing already carried out.

8. Who we share data with

We do not sell personal data. We share it with the following categories of recipients.

8.1 Other WoffApp users

As described in section 5: the public projection of your dog, your active spots within about 5 km and your position in public leaderboards.

8.2 Data processors and sub-processors

Recipient

Role

Data involved

Location

Safeguards

Google Ireland Ltd / Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check

Hosting, database, storage, server logic, push transport

Virtually all Service data

Firestore and Cloud Functions operate in europe-west3 (Frankfurt, Germany). Other Firebase components and support may involve processing in the USA

Google Cloud Data Processing Addendum; EU Standard Contractual Clauses; EU-US Data Privacy Framework

Google Ireland Ltd / Google LLC - Google Maps Platform (Maps SDK, Places, Geocoding)

Map rendering, place search, address resolution

View boundaries, coordinates, typed queries, session tokens, IP address

Global

Google Maps Platform Terms; Google Privacy Policy

Google LLC - Play Integrity

Integrity attestation on Android

Device and app integrity signals

Global

Google Play Terms

Apple Inc. / Apple Distribution International Ltd - App Attest, App Store, APNs

Integrity on iOS, distribution, push transport

Attestation signals, purchase logs, push tokens

Global

Apple Privacy Policy

Functional Software Inc. (Sentry)

Crash and error diagnostics

Firebase UID, cleaned exception stack traces, release and device context

United States, with EU data region available

Sentry DPA; EU Standard Contractual Clauses

RevenueCat Inc. (v. 12.1)

Subscription management

Firebase UID, pseudonymous user ID, store receipt and subscription status

United States

RevenueCat DPA; EU Standard Contractual Clauses

Google Ireland Ltd - AdMob (v. 12.2)

Advertising

Advertising ID, ad interaction data, approximate location, device data

Global

Google Ads Data Processing Terms

Each acts as our processor, or as an independent controller in limited cases where the provider determines its own purposes (notably Google Maps, Apple and Google as store operators, and advertising providers). We maintain an updated list of sub-processors, available on request at info@woffapp.com.

8.3 Other disclosures

We may disclose data to professional advisors, to a buyer in case of merger or acquisition (with notice), and to public authorities when a valid legal obligation requires it.

9. How long we keep data

Data

Retention

Account, profile, notification preferences

Until account deletion

Dog profiles and original photos

Until deletion of the dog or account

Public projections and sanitized photos

Deleted upon deletion of the original dog; a cleanup queue reconciles derived copies

Dog spots

Permanently deleted 72 hours after creation, or immediately upon removal

Sniffs, counters and social history

Until deletion of the involved dog or account

Challenge facts derived from spots

Until the closure of the last weekly or monthly window consuming them, plus 21 days, then automatically deleted; also deleted upon deletion of spots, dog or account

Leaderboard entries, boards and scores

For the weekly or monthly window plus 21 days

"Home" Adventurer reference (5 km privacy cell)

Until deletion of the dog or account

Service proposals and moderation logs

Retained after resolution, as an audit trail of the decision

Notification installation, push token and delivery log

Until logout, permission revocation, token rotation or entry expiration

Local logs of pending commands

Maximum 7 days

Crash and error events

90 days at the provider

Server request logs (including Google Cloud logs)

According to provider default, typically 30 days

Purchase and billing documents

10 years, as required by Italian tax law

Offline Firestore cache on your device

Until app data deletion or uninstallation

When a retention period is set by a provider we do not control, we declare it, instead of promising deletion we cannot perform.

10. Data deletion

10.1 Deleting a single dog

Deleting a dog removes its private profile, photos, public projection and spots, and cancels progress in challenges that dog contributed to. Your other dogs and their spots remain unaffected.

10.2 Deleting the account

You can delete your WoffApp account and all associated data from Settings -> Account -> Delete account in the app. You can also request deletion by writing to info@woffapp.com from the registered account email: we will complete it within 30 days. Deletion is a phased server-side process. It removes the profile, dogs, their photos and public projections, all their spots, sniff records, challenge progress and references, notification installations and finally the Firebase Authentication identity. It is irreversible. What deletion cannot reach, honestly stated:

  • Photos exported via the sharing panel to another person or app.
  • Request and delivery logs already acquired by Google (Maps, Places, Cloud Messaging, Cloud Logging) and other providers, which expire according to their own cycles.
  • Documents we are legally required to retain, such as purchase invoices.
  • Aggregate or anonymised statistics no longer attributable to you.
  • Firebase SDK cache on a device where the app is still installed: delete app data or uninstall.

10.3 Web deletion path

For store compliance, an account deletion request page is available at https://woffapp.com/account-deletion and works without installing the app.

11. Your rights

Under arts. 15 to 22 GDPR you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate data and complete incomplete data;
  • obtain data deletion ("right to be forgotten"), as described in section 10;
  • obtain processing restriction in cases under art. 18;
  • portability: receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on our legitimate interest, for reasons related to your particular situation, and object at any time and without reason to processing for direct marketing purposes;
  • withdraw consent at any time, without affecting prior lawfulness;
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects (we do not perform such).

To exercise these, write to info@woffapp.com. We will respond within one month, extendable by two months for complex requests, and inform you if an extension is needed. We may ask you to verify your identity, but only proportionately.

Right to complain.

If you believe your data processing is unlawful, you may complain to the Italian supervisory authority:

Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 RomePhone: +39 06 696771Email: garante@gpdp.it - PEC: protocollo@pec.gpdp.itWebsite: https://www.garanteprivacy.it

You may also contact the supervisory authority of your EU country of residence or work, or take legal action.

12. Subscriptions, advertising and nearby spot alerts

These three areas involve data processors and permissions not used by the rest of the app, so are described separately. Availability depends on your platform, geographic area and app version.

12.1 Premium subscription and payments

WoffApp offers an optional recurring subscription that removes advertising. Purchases are made via Apple App Store and Google Play, which handle payment. We never receive your card number, bank details or billing address. Rights management is handled by RevenueCat, which receives your Firebase UID or a pseudonymous user ID, store receipt and resulting status (active, expired, grace period, billing issue), so the subscription follows you across devices and reinstallations. Our servers keep only the resulting status, linked to your account. Apple and Google act as independent controllers for the transaction and keep purchase records according to their policies and timelines. Tax documents we must retain follow the times indicated in section 9.

12.2 Advertising

Free accounts see banner ads provided by Google AdMob, shown when opening a marker. Active subscribers see no ads.

Before requesting any ad:

  • on iOS we present the App Tracking Transparency prompt and request only non-personalised ads, unless you authorise tracking;
  • in the EEA and UK we present a consent management platform certified by Google and compliant with the IAB Transparency and Consent Framework, showing non-personalised ads to those who do not consent.

Refusing means continuing to see ads, but chosen without profiling. AdMob may process your advertising ID, ad interactions, approximate location and device info per Google's policies. You can reset or clear your advertising ID anytime in device settings.

12.3 Nearby spot alerts and background location

Nearby spot alerts notify you when a dog spot appears near you while the app is closed. To do this, the app registers geographic regions with the operating system - up to 20 regions on iOS and 100 on Android, each with a radius of about 100 m - and the OS wakes the app when you enter one. Regions are chosen from spots near you and deregistered when those spots expire. This requires background location permission ("Always" on iOS, "Allow all the time" on Android), a significantly more invasive step than foreground location described in point 6.4. Consequently:

  • strictly optional: the app explains what it does before the system prompt appears;
  • refusing or later revoking permission in system settings costs you nothing in the rest of the app;
  • alerts stop immediately when you revoke permission or disable the feature.

Background location is evaluated on your device against registered regions. As with foreground location, we do not keep raw coordinates as a permanent log of places you have been.

13. Minors

WoffApp is not intended for anyone under 16 years old. We do not knowingly collect personal data of minors under 16. By creating an account you confirm you are at least 16. If you believe a minor under 16 has created an account, write to info@woffapp.com and we will promptly delete the account and related data. The 16-year threshold is a deliberate choice: it is the maximum digital consent age allowed by art. 8 GDPR, thus valid in every EEA country regardless of local age.

14. Security

We protect data, among other means, with:

  • HTTPS/TLS for all network traffic and encryption at rest of data stored on Google Cloud infrastructure;
  • server-side authorization: Firestore security rules and authenticated server functions are the authorization boundary. The app does not decide what you can read or write, the server does;
  • minimum privilege service identity for server functions;
  • Firebase App Check attestation as an additional layer against automated abuse;
  • rate limits on abuse-prone operations;
  • secret management: server credentials reside in a secret manager and never appear in the app or any app request;
  • privacy by design: public projections described in section 5 are generated by the server so private identifiers never reach other users.

No system is perfectly secure. In case of a personal data breach posing a risk to your rights and freedoms, we will notify the Supervisory Authority within 72 hours as required by art. 33 GDPR and inform you directly in cases foreseen by art. 34.

15. International transfers

Our main archives (Cloud Firestore and Cloud Functions) are located in europe-west3 (Frankfurt, Germany), inside the EEA. Some providers listed in point 8.2 are established in the United States or operate globally. When personal data is transferred outside the EEA, the transfer is based on:

  • a European Commission adequacy decision, including the EU-US Data Privacy Framework where the recipient is certified; or
  • the European Commission Standard Contractual Clauses, supplemented by technical and organisational measures where our transfer assessment identifies them as necessary.

You may request copies of applicable safeguards by writing to info@woffapp.com.

16. Changes to this privacy notice

We may update this notice as WoffApp evolves. The version number and effective date at the top of the document always identify the current text.

  • For minor changes (clarifications, corrections, new providers of the same type) we will update the document and date.
  • For substantial changes (a new purpose, a new data category, a new disclosure or anything requiring consent) we will inform you in the app or by email at least 30 days in advance and, where required by law, seek your consent before the change takes effect.

Previous versions are archived at https://woffapp.com/legal/archive.

17. Contacts

Privacy, data subject rights and support: info@woffapp.com

Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]

This notice is published in Italian and English. In case of discrepancy, for users residing in Italy the Italian version prevails.

Privacy policy

Ita

Eng