PuckApp
Privacy Policy

PuckApp Privacy Policy

Last updated: 11 September 2026

PuckApp has not launched yet (target: soon). This document describes the intended data-processing rules and takes effect once the app becomes available.

This policy explains what personal data the PuckApp mobile app (“PuckApp”, “the app”) and its backend service collect, why, who it is shared with, and the rights you have.

Who is responsible for your data

The data controller for PuckApp is SG Software Development (Szymon Gaweł), based in Poland. For any privacy question or request, contact puckapp@sgsoftware.pl.

What we collect and why

We collect only what the app needs to work. We do not sell personal data, and we do not use it to train AI models.

DataWhyLegal basis (GDPR Art. 6)
Email address and password (stored only as a salted hash)Account creation, sign-in, account-related messagesPerformance of a contract — Art. 6(1)(b)
Display name and household membershipRecognising who triggered an action at homeArt. 6(1)(b)
NFC tag configuration (names, assigned actions)Running the action you programmed when a tag is tappedArt. 6(1)(b)
Event history (which tag, when, by whom)Showing notifications and the task list to household membersArt. 6(1)(b)
Push notification tokenDelivering the notifications you opted intoConsent — Art. 6(1)(a)
PuckApp PRO subscription status (if you use it)Unlocking full app functionalityArt. 6(1)(b)
IP address, request metadata and server logsSecurity, abuse prevention and debuggingLegitimate interest — Art. 6(1)(f)

Who we share data with

We share data only with service providers needed to run PuckApp, under data processing agreements — including our hosting provider and our push-notification provider. We will name these providers specifically here before launch. We may also disclose data where required by law, or to establish, exercise or defend legal claims.

International transfers

Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or another GDPR transfer mechanism. Contact us for detail on a specific provider.

How long we keep data

  • Account and configuration data — kept while your account exists, normally erased within 30 days of deletion.
  • Event history — kept while the account exists, unless you clear it sooner in the app.
  • Server logs — typically 30–90 days.
  • Backups — deleted data also disappears from backups on the backup rotation cycle, within about 35 days.

Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw consent at any time. You can delete your account in the app or via the deletion page. For any other request, email puckapp@sgsoftware.pl.

If you believe we have handled your data unlawfully, you may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

Security

Passwords are stored only as salted hashes. Data is encrypted in transit with TLS. Access to production systems is limited to what is needed to operate the service. No system is perfectly secure, but we take reasonable measures to protect your data.

Children

PuckApp is meant for household members who create their own account, and is not directed to children below the age of digital consent in their country. If you believe a child has provided us data without guardian consent, contact us and we will delete it.

Changes to this policy

We may update this policy. The “Last updated” date always reflects the current version, and we will notify you in the app or by email of material changes before they take effect.

Contact

SG Software Development (Szymon Gaweł) puckapp@sgsoftware.pl