CYNQOR Privacy Policy
Version: 1.3
Effective date: August 5, 2026
1. Who we are
CYNQOR is a mobile platform for browsing products, placing orders, and messaging between buyers and the store. Privacy contact: privacy@cynqor.app.
2. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Account | Firebase Auth account ID, phone number (sign-in system only) | Sign-in |
| Profile | Username, display name, profile photo, role | Public profile, access control |
| Sizes | User size profile | Size selection, order display |
| Orders | Items, status, address, totals, receipts | Order fulfillment |
| Messages | Direct messages (user chats) | User communication |
| User-generated content | Products, news feed posts (store owner) | Catalog and feed |
| Reports | User reports / complaints | Safety and moderation |
| Blocks | Blocked-user list | Limit interaction |
| Technical | Firebase Crashlytics (crashes), Firebase Performance, Firebase App Check, FCM push tokens | Stability, security, notifications |
We do not sell personal data for advertising.
3. Legal bases
- Contract performance (orders, delivery, external payment).
- Legitimate interests (safety, moderation, fraud prevention).
- Consent where required separately.
4. Storage location
Data is hosted on Google Firebase (Firestore, Authentication, Storage). Project region is set in the Firebase console.
5. Retention
- Profile and messages while the account is active.
- Orders for accounting and disputes. After account deletion, order PII is anonymized (name, phone, address, sizes, receipts); buyer identifier and line items are retained for records.
- Reports until resolved and for a reasonable archive period.
6. Account deletion
Deletion is available in the app: Settings → Account management → Delete account (platform owner accounts excluded).
*Permanently deleted:*
- Firebase Authentication account;
- user profile;
- cart, likes, favorites, block list, push tokens;
- AI assistant chat history;
- avatar and payment receipt files in cloud storage (Firebase Storage);
- username in the username registry (released for reuse);
- follows and followers (social graph).
*Anonymized (no identifying data):*
- buyer orders (name, phone, address, measurements);
- chat metadata (display name replaced with “Deleted user”).
*Retained for legitimate purposes:*
- direct message text (for the other participant’s history);
- products and news feed posts created as shop content;
- technical account-deletion record (no personal data).
Deletion is irreversible. Confirmation and SMS re-authentication are required if the session is older than 5 minutes.
7. Your rights
You may request access, correction, or deletion. Account deletion is in app Settings (see §6). Contact: privacy@cynqor.app.
8. Reports and moderation
Reports store: your account ID, target type/id, reason, description, timestamp. Only the platform Owner can access the moderation queue.
9. Blocking
Blocking creates an entry in your block list. Reported users are not automatically notified of a report.
10. Diagnostics and analytics
On mobile apps (iOS/Android) we use Firebase Crashlytics and Firebase Performance to detect crashes and slowdowns. Separate marketing or ad analytics SDKs are not used. The web app may not include all the same diagnostics.
11. Third parties
- Google LLC (Firebase) — hosting.
- Payment partners (e.g. Kaspi) — payment outside the app via link/QR.
12. Children
Not intended for users under 13 (or local legal age).
13. Changes
We publish updates with a new date. Material changes may be announced in the app.
Russian version: PRIVACY_POLICY.ru.md