Privacy Policy
Information notice on the processing of personal data pursuant to EU Regulation 2016/679 (GDPR) and Legislative Decree 196/2003
Ultimo aggiornamento: 4 July 2026
1. Data Controller
The data controller is Smart Building Srl — registered office: Via Sandro Botticelli 80, 10154 Turin (TO), Italy — VAT/Tax code 11233710018 — REA TO-1300630 — certified email (PEC): [email protected]. Project lead and data protection contact person: Federico Tassara ([email protected]). Dedicated privacy contact: [email protected].
For any request regarding your personal data, including deletion of your account, you may write to the address indicated above or visit the Account Area of the website or the app.
2. Personal Data Collected
Oraloco collects the following personal data in the course of your use of the application and the website:
- Registration and profile data: name, email address, unique user identifier (user ID). If you sign in with Google, we receive your Google profile (name, email, profile picture).
- Push notification token: the device token generated by Expo (provided by APNs or FCM) for sending push notifications. You can disable them from your device settings.
- Diagnostic and crash logs: anonymous technical data and stack traces collected by Sentry in the event of application errors. They may include information about the device, the operating system version and the error path.
- In-app purchase history: information about purchases of virtual currency (Gems) through Google Play or the App Store, managed by RevenueCat. We do not store payment data — this remains with Google/Apple.
- User-generated content: predictions made, chosen nickname, scores and rankings.
- Usage data: aggregated information about interaction with the app (pages visited, features used), collected in anonymous or aggregated form.
- Website browsing data: technical cookies and, only subject to your consent, analytics and advertising cookies (Google Analytics 4 loaded via Cloudflare Zaraz). See the Cookie Policy for details.
3. Purposes and Legal Basis of Processing
The data is processed for the following purposes:
- Provision of the service (basis: performance of the contract): account management, saving of predictions, calculation of scores and rankings.
- Push notifications (basis: consent): sending updates on transfers, results and new content. Consent may be withdrawn at any time from the device settings.
- Diagnostics and security (basis: legitimate interest): detection and resolution of bugs, monitoring of application stability through Sentry.
- Purchase management (basis: performance of the contract): processing of in-app purchases through RevenueCat.
- Legal obligations (basis: legal obligation): retention of the data necessary to comply with tax or regulatory obligations.
- Game-related communications (basis: legitimate interest): push notifications about game events and activity reminders (for example nudges to come back after a period of inactivity). You can turn them off at any time in your device's notification settings: once you opt out, sending stops.
4. Service Providers (Sub-processors)
Oraloco relies on the following third-party providers, each of which processes data in compliance with the GDPR and under adequate contractual safeguards:
- Clerk (clerk.com) — authentication and management of user accounts.
- Sentry (sentry.io) — collection of error logs and application diagnostics.
- RevenueCat (revenuecat.com) — management of in-app purchases and subscriptions.
- Expo / EAS — distribution of the application and sending of push notifications through APNs (Apple) and FCM (Google).
- Cloudflare R2 (cloudflare.com) — storage of static assets (profile pictures, media content).
- Cloudflare (cloudflare.com) — CDN, security and website tag management (Zaraz).
- Google Ireland Ltd — Google Analytics 4 (website statistics, enabled only after consent: see the Cookie Policy) and Firebase Cloud Messaging for delivering push notifications on Android.
- Better Stack (betterstack.com) — centralised collection of server technical logs.
- Stripe (stripe.com) — processing of any payments made via the web.
- Resend (resend.com) — sending the emails generated by the website contact form.
Data is not disclosed to third parties for marketing or commercial profiling purposes.
5. Data Transfers Outside the EU
Some of the providers listed above are based in the United States or process data outside the European Economic Area (in particular Clerk, Sentry, RevenueCat, Expo, Cloudflare, Google, Better Stack, Stripe and Resend).
Transfers take place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission and, where the provider adheres to it, the EU-U.S. Data Privacy Framework. You can request a copy of the safeguards applied by writing to [email protected].
7. Retention Period
Personal data is retained for the time strictly necessary for the purposes for which it was collected:
- Active account: for the entire duration of the contractual relationship (use of the app).
- Deleted account: following a deletion request, the data is anonymized within a grace period of 30 days (to allow for reconsideration), after which it is permanently deleted (hard-delete).
- Diagnostic logs: retained by Sentry for a maximum of 90 days.
- Tax data: retained for the periods provided for by applicable law (up to 10 years).
8. Rights of the Data Subject
As a data subject, you have the right to:
- Access: obtain confirmation of the processing and a copy of your data (Art. 15 GDPR).
- Rectification: correct inaccurate data (Art. 16 GDPR).
- Erasure: request the deletion of your data (Art. 17 GDPR) — see section 9.
- Restriction: restrict processing in certain cases (Art. 18 GDPR).
- Portability: receive your data in a structured format (Art. 20 GDPR).
- Objection: object to processing based on legitimate interest (Art. 21 GDPR).
- Withdrawal of consent: withdraw the consent given at any time, without affecting the lawfulness of prior processing.
To exercise your rights, write to [email protected]. You also have the right to lodge a complaint with the Italian Data Protection Authority (Autorità Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it).
9. How to Delete Your Data and Your Account
You may request the deletion of your account and all associated data at any time, following one of the methods below:
- From the app: go to Profile → Settings → Delete account.
- From the website: log in to your account area and follow the guided procedure.
- By email: write to [email protected] with the subject “Account deletion”, indicating your registered email.
After the request, your account is suspended immediately (you can no longer log in or make new predictions). You have a 30-day grace period during which you can cancel the deletion by logging in to the app. Once the 30 days have elapsed, all personal data is permanently and irreversibly deleted.
Note: certain accounting data may be retained for the period required by law even after the deletion of the account.
10. Data Security
Oraloco adopts appropriate technical and organizational measures to protect personal data from unauthorized access, loss, destruction or disclosure. All communications between the app/website and our servers take place through HTTPS/TLS (encryption in transit). Data at rest is protected by the infrastructure of certified service providers (Clerk, Cloudflare R2).
11. Minors
Oraloco is intended for users aged 16 years or older. If we believe that a user is under 16 years of age, we will proceed to delete the account.
12. Changes to the Privacy Policy
We reserve the right to modify this policy. Substantial changes will be notified through push notification or email. Continued use of the app after notification constitutes acceptance of the changes.