CYNQOR Privacy Policy
Version: 1.4
Effective date: August 18, 2026
1. Who we are
CYNQOR is a mobile platform for browsing products, placing orders, and messaging between buyers and the store. Privacy contact: privacy@cynqor.app.
2. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Account | Firebase Auth account ID, phone number, Sign in with Apple | Sign-in |
| Contact info | Email address or a private relay email address provided by Apple (if Apple shares it) | Apple sign-in, account linkage |
| Profile | Username, display name, profile photo, role | Public profile, access control |
| Sizes | User size profile | Size selection, order display |
| Orders | Items, status, address, totals, receipts | Order fulfillment |
| Messages | Direct messages (user chats) | User communication |
| AI assistant messages | Text you send to CYNQOR AI and responses | Product discovery and shopping assistance |
| User-generated content | Products, news feed posts (store owner) | Catalog and feed |
| Reports | User reports / complaints | Safety and moderation |
| Blocks | Blocked-user list | Limit interaction |
| Technical | Firebase Crashlytics (crashes), Firebase Performance, Firebase App Check, FCM push tokens | Stability, security, notifications |
We do not sell personal data for advertising.
3. Authentication and account linking
CYNQOR supports sign-in with a phone number and Sign in with Apple. You may connect both methods to the same CYNQOR account.
When you use Sign in with Apple, Apple may provide an email address or a private relay email address provided by Apple. Apple may not always share an email address.
Authentication data is processed through Firebase Authentication (Google infrastructure).
Phone number and Sign in with Apple may be linked to one CYNQOR account identifier. CYNQOR does not automatically merge separate accounts based only on email, name, or phone number. If a sign-in method is already linked to another account, automatic merge is not performed.
4. Legal bases
- Contract performance (orders, delivery, external payment).
- Legitimate interests (safety, moderation, fraud prevention).
- Consent where required separately.
5. Storage location
Data is hosted on Google Firebase (Firestore, Authentication, Storage). Project region is set in the Firebase console.
6. Retention
- Profile and messages while the account is active.
- Orders for accounting and disputes. After account deletion, order PII is anonymized (name, phone, address, sizes, receipts); buyer identifier and line items are retained for records.
- Reports until resolved and for a reasonable archive period.
7. Account deletion
Deletion is available in the app: Settings → Account management → Delete account (platform owner accounts excluded).
Confirmation is required. Re-authentication may be required (if your session is older than 5 minutes):
- for phone-linked accounts — SMS confirmation;
- for accounts linked with Sign in with Apple — Apple confirmation.
For accounts linked with Sign in with Apple, CYNQOR revokes Sign in with Apple authorization before deleting the account.
*Permanently deleted:*
- Firebase Authentication account;
- user profile;
- cart, likes, favorites, block list, push tokens;
- AI assistant chat history;
- avatar and payment receipt files in cloud storage (Firebase Storage);
- username in the username registry (released for reuse);
- follows and followers (social graph).
*Anonymized (no identifying data):*
- buyer orders (name, phone, address, measurements);
- chat metadata (display name replaced with “Deleted user”).
*Retained for legitimate purposes:*
- direct message text (for the other participant’s history);
- products and news feed posts created as shop content;
- technical account-deletion record (no personal data).
Deletion is irreversible.
8. Your rights
You may request access, correction, or deletion. Account deletion is in app Settings (see §7). Contact: privacy@cynqor.app.
9. Reports and moderation
Reports store: your account ID, target type/id, reason, description, timestamp. Only the platform Owner can access the moderation queue.
10. Blocking
Blocking creates an entry in your block list. Reported users are not automatically notified of a report.
11. Diagnostics and analytics
On mobile apps (iOS/Android) we use Firebase Crashlytics and Firebase Performance to detect crashes and slowdowns. Separate marketing or ad analytics SDKs are not used. The web app may not include all the same diagnostics.
12. Third parties
- Google LLC (Firebase) — hosting and authentication.
- OpenAI and other AI service providers — processing messages sent to CYNQOR AI to generate responses and shopping assistance (as processors acting on our instructions).
- Payment partners (e.g. Kaspi) — payment outside the app via link/QR.
13. Children
Not intended for users under 13 (or local legal age).
14. Changes
We publish updates with a new date. Material changes may be announced in the app.
Russian version: PRIVACY_POLICY.ru.md