1. INTRODUCTION
Welcome to Crave ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data.
This privacy policy explains how we collect, use, and safeguard your information when you use our mobile application.
2. INFORMATION WE COLLECT
2.1 Information You Provide
- Email address (for account creation)
- Display name and profile photo (optional)
- Wishlist names and categories
- Product information (names, URLs, prices, images)
- Collaborator invitations
2.2 Automatically Collected Information
- Device information (iOS version, device model)
- Usage data (features used, app interactions)
- Log data (timestamps, errors, performance metrics)
- IP address (for security purposes)
2.3 Information from Third Parties
- Apple Sign-In credentials (if you choose this login method)
- Product information scraped from public websites (when you add items)
3. HOW WE USE YOUR INFORMATION
We use your information to:
- Provide and maintain the app's functionality
- Create and manage your account
- Enable wishlist sharing and collaboration features
- Send notifications (with your permission)
- Improve app performance and user experience
- Prevent fraud and ensure security
- Comply with legal obligations
4. DATA STORAGE AND SECURITY
4.1 Where Your Data is Stored
- All data is stored on Google Firebase servers (USA)
- Data is encrypted in transit (HTTPS/TLS)
- Data is encrypted at rest
4.2 Security Measures
- Authentication required for all sensitive operations
- Role-based access control for collaborators
- Rate limiting to prevent abuse
- Regular security audits
- Firestore Security Rules to protect your data
5. DATA SHARING
We do NOT sell your personal information. We share data only in these limited circumstances:
5.1 With Your Consent
- When you share a wishlist publicly via link
- When you add collaborators to your wishlists
5.2 Service Providers
- Firebase (Google Cloud) - hosting and authentication
- Apple - Sign in with Apple authentication
- Cloud Functions - backend processing
5.3 Legal Requirements
- To comply with legal obligations
- To protect our rights and safety
- In response to valid legal requests
6. YOUR PRIVACY RIGHTS
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your data (data portability)
- Opt-out of notifications
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us at: [YOUR EMAIL]
7. DATA RETENTION
- Active accounts: Data retained while account is active
- Deleted accounts: Data deleted within 30 days
- Backups: Retained for up to 90 days for recovery purposes
- Legal holds: Data retained as required by law
8. COOKIES AND TRACKING
We do not use cookies in the mobile app. Our web-based wishlist sharing pages may use:
- Session cookies (for authentication)
- Analytics cookies (with your consent)
9. CHILDREN'S PRIVACY
Our app is not intended for children under 13. We do not knowingly collect data from children under 13. If you
believe we have collected data from a child, please contact us immediately.
10. THIRD-PARTY SERVICES
Our app uses these third-party services:
- Firebase Authentication
- Cloud Firestore
- Firebase Cloud Storage
- Firebase Cloud Messaging
- SDWebImage (image caching)
Each service has its own privacy policy:
- Google/Firebase: https://firebase.google.com/support/privacy
- Apple: https://www.apple.com/legal/privacy/
11. INTERNATIONAL DATA TRANSFERS
Your data may be transferred to and processed in countries outside your residence, including the United States. We
ensure appropriate safeguards are in place.
12. AFFILIATE LINKS
When you add items from Amazon, we may add our affiliate tag to links. This helps support the app but does not affect
your privacy or the price you pay.
13. CHANGES TO THIS POLICY
We may update this policy occasionally. We will notify you of significant changes via:
- In-app notification
- Email (if you provided one)
- App Store update notes
Continued use after changes constitutes acceptance.
14. CALIFORNIA PRIVACY RIGHTS (CCPA)
California residents have additional rights:
- Right to know what data is collected
- Right to delete data
- Right to opt-out of data sales (we don't sell data)
- Right to non-discrimination
15. GDPR COMPLIANCE (EU/EEA)
For EU/EEA residents:
- Legal basis: Consent, contract performance, legitimate interests
- Data controller: [YOUR COMPANY NAME]
- DPO contact: [YOUR EMAIL]
- Right to lodge complaint with supervisory authority
16. CONTACT US
For privacy questions or concerns:
Email: [YOUR EMAIL]
Address: [YOUR COMPANY ADDRESS]
Response time: Within 30 days
17. CONSENT
By using Crave, you consent to this privacy policy.