PRIVACY POLICY FOR THE “BAOOLE” APP
Effective Date: April 27, 2026
Last Updated: April 27, 2026
---
## 1. Introduction
This Privacy Policy describes how Alessandro Dari (“Data Controller,” “we,” “us”) collects, uses, stores, and protects the personal data of users of the Baoole mobile app (“App” or “Service”).
The App is intended exclusively for users of legal age (18+) and may only be used in Italy.
By using the App, you accept this Privacy Policy. If you do not accept this Policy, please do not use the App.
---
## 2. Data Controller
Alessandro Dari
Tax ID: DRALSN68B03D612L
Email: info@baoole.com
No Data Protection Officer (DPO) has been appointed.
---
## 3. Types of personal data processed
### 3.1 Data provided directly by the user
- First name
- Last name
- Password (encrypted)
- Date of birth
- Profile photo (uploaded via camera or gallery)
- Social profile information via Google or Apple Sign-In
- Username (if applicable)
### 3.2 Data collected automatically
- IP address
- Unique device identifiers (IDFA, Google Advertiser ID)
- Device information (model, operating system, app version)
- Technical logs (crashes, errors, system activity)
- Usage data (sessions, duration, app opens, features used)
- Approximate location data (IP-based)
### 3.3 User-generated data
- Messages sent in the internal chat
- Profile photo
- Participation in Private Leagues
- Game predictions
- Any content uploaded to the App
---
## 4. Purposes of processing and legal bases
| Purpose | Legal basis |
|------- --|----------------|
| Account registration and management | Performance of the contract |
| Authentication (email/Google/Apple) | Performance of the contract |
| App operation and participation in Private Leagues | Performance of the contract |
| Operational communications | Performance of the contract |
| Statistical analysis and service improvement | Consent |
| Personalized advertising (AdMob, Google Ads) | Consent |
| Promotional push notifications | Consent |
| Management of future payments and subscriptions | Performance of the contract |
| Security, abuse prevention, logging | Legitimate interest |
| Publication of anonymous league table excerpts | Legitimate interest |
| Legal compliance | Legal obligation |
---
## 5. Cookies and Tracking Technologies
The App uses tracking tools for:
- Authentication
- Analytics (Google Analytics, Firebase)
- Advertising (AdMob, Google Ads)
- Security and fraud prevention
For all tracking, analytics, and advertising activities, explicit consent is required via a banner or equivalent mechanisms.
---
## 6. External Services and Third Parties
### 6.1 Authentication
- Google Sign-In
- Apple Sign-In
### 6.2 Databases and Storage
- Firebase Firestore
- Firebase Storage
### 6.3 Analytics
- Google Analytics
- Firebase Analytics
### 6.4 Advertising
- Google Ads (AdSense)
- AdMob by Google
### 6.5 Payments
- Apple Store In-App Payments
- Google Play In-App Payments
### 6.6 Development and Infrastructure
- FlutterFlow
All providers act as Data Processors pursuant to Article 28 of the GDPR.
---
## 7. International Transfers
Some services (Google, Firebase, AdMob, FlutterFlow) may involve transfers to the United States (USA).
These transfers are carried out via:
- Standard Contractual Clauses (SCCs)
- Additional technical and organizational measures
- Compliance with EU regulations
---
## 8. Data Retention Period
- Account data is retained until the user voluntarily deletes it.
- Technical logs are retained for up to 12 months.
- Payment data will be retained in accordance with tax and accounting obligations.
- Internal chat messages are not deleted but are anonymized.
---
## 9. User Rights
The user may exercise the following rights:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Data portability
- Withdrawal of consent
- Complaint to the Data Protection Authority
### How to exercise your rights
- By email: info@baoole.com
- Through the app’s internal account deletion feature
Average response time: 4–5 business days.
---
## 10. Account Deletion
When the user deletes the account:
- All personal data is permanently deleted
- Messages sent in the internal chat remain but are anonymized
- Data portability is not provided
---
## 11. Data Security
The Data Controller implements appropriate technical and organizational measures, including:
- Password encryption
- Secure connections (HTTPS/TLS)
- Access controls on Firebase
- Security logging
- Periodic backups
---
## 12. Profiling and Automated Decision-Making
The App does not make automated decisions that produce legal effects or have significant effects on the user.
---
## 13. Marketing Communications
The App sends promotional push notifications on average 1–2 times a day, only with prior consent.
No promotional emails are sent.
---
## 14. Data Breaches
In the event of a personal data breach:
- The Data Controller will notify the Data Protection Authority within 72 hours
- Users will be informed when the breach involves high risks
---
## 15. Supervisory Authority
The user may file a complaint with:
Data Protection Authority (Italy)
---
## 16. Future Payments and Subscriptions
When subscriptions and payments are introduced:
- The necessary data will be processed for contractual purposes
- Payments will be handled by Apple and Google
- The Data Controller does not store payment card data
---
## 17. Publication of Anonymous Excerpts from Leaderboards
The Data Controller may publish anonymous excerpts from leaderboards and game statistics.
---
## 18. Changes to the Privacy Policy
The Data Controller may amend this Policy. Changes will be communicated via:
- Notification within the App
- Update of the effective date
---
## 19. Language and Territorial Scope
This Privacy Policy is written in Italian and applies to users located in Italy.