Legal
Privacy policy
How PortaMi handles your data.
Last updated: [DATE ON PUBLISH]
Draft — not yet in force
This document is a working draft under legal review and is not legally binding yet. Some details are still to be confirmed and appear as highlighted placeholders. Please check back before relying on it.
PortaMi (“PortaMi”, “we”, “us”) helps you discover food & drink places in Milan and other cities. This Privacy Policy explains what personal data we process, why, on what legal basis, who we share it with, and the rights you have. It applies to the PortaMi mobile app (iOS and Android).
1. Who is responsible for your data (Data Controller)
The data controller is [LEGAL ENTITY / SOLE TRADER NAME], [REGISTERED ADDRESS], [VAT / TAX ID IF ANY]. You can contact us about privacy at [PRIVACY CONTACT EMAIL].
2. What data we collect and why
We only collect what the app needs to work. We do not sell your data, and we do not use it for cross-app/cross-site advertising tracking (no advertising identifiers, no ad SDKs).
| Data | What it is | Why we process it | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account identity — email, name, Firebase user ID, and (if your provider supplies it) profile picture URL | Provided when you sign in with Google or Apple | To create and secure your account, sign you in, and personalise your experience | Performance of a contract (Art. 6(1)(b)) — providing the service you asked for |
| Precise location (GPS latitude/longitude) | Requested from your device when you use location-based features | To recommend places near you (“close to me” / nearby) | Consent (Art. 6(1)(a)) — you grant the OS location permission; you can revoke it any time |
| Food preferences (e.g. vegan, vegetarian, gluten-free, and your interaction-derived tastes) | Settings you choose, plus signals from how you use the app | To personalise recommendations (the “Portami” suggestion engine) | Performance of a contract / legitimate interests (Art. 6(1)(b)/(f)) |
| Interaction data | Which places you view, favourite, add to collections, open in Maps, call, share, or that are shown to you, with timestamps and a session id | To power and improve recommendations and measure which suggestions work | Legitimate interests (Art. 6(1)(f)) — improving the service |
| Collections & favourites | Lists you create, places you save, and any notes/ratings you add | To provide the collections and favourites features | Performance of a contract (Art. 6(1)(b)) |
| Crash & performance diagnostics | Crash reports (via Firebase Crashlytics) and app performance traces (via Firebase Performance Monitoring) | To find and fix bugs and keep the app fast and stable | Legitimate interests (Art. 6(1)(f)) |
| Technical data | Network connectivity status, device/OS information inherent to using a mobile app | To operate the app and diagnose problems | Legitimate interests (Art. 6(1)(f)) |
We do not collect: payment data (the app has no payments), contacts, photos, microphone, calendar, or health data.
3. Location, specifically
- We request precise location only while you use the app (foreground). We do not track your location in the background.
- You can use much of the app without granting location; location-based recommendations simply won’t be available.
- You can grant or revoke location permission at any time in your device settings.
5. Where your data is processed (international transfers)
Your data is primarily processed in the European Union ([confirm Firestore region — project uses europe-west1]). Some Google/Apple services may process limited data outside the EU; where they do, transfers are covered by appropriate safeguards (e.g. the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework).
6. How long we keep your data
- Account data is kept while your account exists.
- When you delete your account in the app, we mark it deleted and revoke your sessions; [RETENTION WINDOW — specify the concrete window for fully purging account and interaction data].
- Diagnostics(crash/performance) are retained per Firebase’s default retention.
7. Your rights
Under the GDPR you have the right to: access your data; correct it; delete it (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent (e.g. location) at any time without affecting prior processing.
- You can delete your account directly in the app (Settings → account deletion).
- For any other request, contact [PRIVACY CONTACT EMAIL]. We will respond within the time the GDPR requires (generally one month).
- You also have the right to lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
8. Children
PortaMi is not directed to children. We do not knowingly collect data from anyone under [AGE THRESHOLD]. If you believe a child has provided us data, contact us and we will delete it.
9. Security
Account tokens are stored in the device’s encrypted secure storage. Backend access is protected by Firebase Authentication and Security Rules. We restrict access to personal data to what the service requires. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.
10. Local storage on your device (not cookies)
The app is a native mobile app and does notuse web cookies. It stores some data locally on your device (e.g. cached preferences and your sign-in session) using the operating system’s standard storage. This stays on your device and is cleared when you sign out or delete the app, except as needed to keep you signed in.
11. Changes to this policy
We may update this policy. We will post the new version with an updated “Last updated” date and, for material changes, notify you in the app.
12. Contact
Questions or requests: [PRIVACY CONTACT EMAIL] — [LEGAL ENTITY NAME], [ADDRESS].