PRIVACY POLICY
Last updated: 9 July 2026
Privacy Policy | MySpot
Privacy Policy for the Myspot mobile application — what data we collect, why we process it, and how you can exercise your GDPR rights.
GENERAL INFORMATION
- Version 2.0 · Effective date: 9 July 2026 · A document of „May Spot App" OOD
- This Policy applies to end users of the Myspot mobile application (iOS and Android).
1. CONTROLLER AND CONTACT
- The controller of personal data is „May Spot App" OOD, UIC 207339717, with registered seat and address of management at 5A Lale Str., fl. 4 ("Provider", "Myspot", "we").
- We have appointed a Data Protection Officer (DPO), whom you can contact on any matter relating to the processing of your personal data and the exercise of your rights at: [email protected].
2. WHAT DATA WE COLLECT
- Registration and profile data: name/username, email address, and — where you register via Apple or Google — an identifier and data shared by the respective sign-in provider.
- Reservation data: selected venues and spots, dates, reservation status, issued Tickets, reservation history, and Credits.
- Payment data: processed by Stripe. Myspot receives limited information (for example, the payment result, card type/last digits, transaction identifier) but does not store the full card details.
- Technical and usage data: device/installation identifiers, device type and operating system, application version, events from your use of the Application (e.g. screen views, searches, reservations and payments made), diagnostic data.
- Correspondence: messages you send us (e.g. support enquiries).
- The Application does not use location services and does not collect geolocation data.
3. PURPOSES AND LEGAL BASES FOR PROCESSING
We process your personal data only where we have a legal basis to do so and in accordance with the GDPR, for the following purposes:
- To provide the service — creating and managing an account, processing reservations and payments, issuing Tickets, granting and using Credits, and customer support. This processing is necessary for the performance of the contract with you.
- To comply with our legal obligations — including accounting and tax requirements and the fiscal documents issued for Online Reservations.
- Based on our legitimate interests — for security and the prevention of abuse, for the maintenance and technical functioning of the Application, for analysis and measurement of usage in order to improve the service (for example, which support languages to add and what the adoption rate of new versions is), as well as for measuring the effectiveness of marketing. Where we process data on this basis, you have the right to object (see Section 8).
- We do not carry out email marketing and do not send advertising notifications (push).
5. ANALYTICS, MEASUREMENT, AND ADVERTISING
- The Application uses Firebase Analytics (Google) and Meta App Events (Meta) to understand how the Application is used and to measure the effectiveness of marketing.
- These tools process usage events and identifiers, including data on reservations and payments made (for example, value, currency, and transaction identifier), as well as a user identifier that we associate with the events.
- We use this data for analytics purposes and advertising measurement/attribution. We do not use this data for retargeting or for building advertising audiences.
- Google and Meta act as independent controllers for their own purposes with respect to the data processed through their tools. For more information, see the privacy policies of Google and of Meta.
- Control and opt-out. You can limit these activities through your device settings (e.g. advertising/tracking settings and resetting the advertising identifier), as well as through the controls offered by Google and Meta.
6. CAMERA ACCESS
- The Application requests access to the camera solely to scan QR codes (spot plates and Tickets). We do not capture or store images or video for any other purpose.
7. RETENTION PERIODS
- We retain personal data only for as long as necessary for the purposes for which it was collected:
- account data — while the account is active;
- reservation and payment data — for the period required by accounting and tax legislation;
- technical/analytics data — for a limited period according to the settings of the respective tools;
- support correspondence — for a reasonable period for servicing and the protection of rights.
- After the applicable period expires, data is deleted or anonymised.
8. YOUR RIGHTS
- Under the GDPR you have the right to: access; rectification; erasure ("the right to be forgotten"); restriction of processing; objection to processing based on legitimate interest; portability of data; as well as the right to withdraw your consent at any time where processing is based on consent (without affecting the lawfulness of processing before the withdrawal).
- Rights are exercised at [email protected]. We will respond within the time limits set by the GDPR.
- You have the right to lodge a complaint with the supervisory authority — the Commission for Personal Data Protection (CPDP), Sofia — or with the supervisory authority of your habitual residence.
9. RELATIONSHIP WITH MERCHANTS
- With respect to the data processed through the Application, Myspot is the controller. We do not provide your personal data to Merchants through the Application (see Section 4.2).
- If you provide data directly to a Merchant (for example, during on-site service), the Merchant is a separate controller for that data and is independently responsible for compliance with applicable data protection legislation.
10. SECURITY
- We apply appropriate technical and organisational measures to protect data, including encrypted storage, storage of credentials/tokens in a secure device store (Keychain), as well as mechanisms for protection against abuse and verification of application integrity (e.g. Firebase App Check).
- No method of transmission or storage is completely secure; we cannot guarantee absolute security.
11. ACCOUNT DELETION
- You can delete your account directly in the Application (via the profile screen) or by requesting deletion at [email protected].
- Upon deletion, we remove or anonymise your data, except where we are required to retain it by law (for example, accounting and tax obligations).
12. CHILDREN
- The content of the Application is suitable for all ages. However, creating an account and making reservations and payments requires the User to be at least 18 years old (or to use the Application with the consent and under the supervision of a parent or guardian). The Application is not directed at children, and we do not knowingly collect children's personal data. If you believe that a child has provided us with personal data, contact us at [email protected] and we will delete it.
13. CHANGES TO THE POLICY
- We may update this Policy. For material changes, we will notify you through the Application or by email. The current version is always available in the Application.
14. CONTACT
- „May Spot App" OOD, UIC 207339717 · [email protected].