Legal
Privacy Policy
Last updated: August 25, 2026
1. Introduction
This Privacy Policy explains how PONTIO S.R.L. ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Pontio website, the Pontio mobile application, and related services (collectively, the "Service").
Pontio is a service marketplace that connects consumers ("Consumers") with service providers ("Providers"). The app is available on Android (app.pontio) and iOS (app.pontio.Pontio).
This Privacy Policy is an information notice about how we process personal data when you use Pontio. Where a specific feature relies on your consent, we will ask for that consent separately.
2. Definitions
For the purposes of this Privacy Policy:
- "Personal data" means any information relating to an identified or identifiable natural person, as defined in Art. 4(1) GDPR.
- "Processing" means any operation or set of operations performed on personal data, whether or not by automated means, as defined in Art. 4(2) GDPR.
- "Controller" means the entity that determines the purposes and means of the processing (Art. 4(7) GDPR).
- "Processor" means an entity that processes personal data on behalf of a controller (Art. 4(8) GDPR).
- "Sub-processor" means a third party engaged by a processor or controller to carry out specific processing on the controller's behalf.
- "Independent controller" means a third party that determines the purposes and means of processing independently, even when receiving personal data through our integration.
- "Data subject" means the identified or identifiable natural person to whom personal data relates — in the context of the Service, typically a Consumer, a Provider, or a website visitor.
- "Service" has the meaning given in Section 1 above.
- "ANSPDCP" means the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, Romania's supervisory authority for data protection.
3. Data Controller
The data controller responsible for your personal data is:
PONTIO S.R.L.
Legal form: Limited liability company (S.R.L.)
Registered office: Str. Cal Brăii nr. 26B, Lupeni, jud. Hunedoara, 335600, România
Trade Register no.: J2026050521007
Tax identification number (CUI): 55450878
Email: pontio.app@gmail.com
4. Data We Collect
We collect only the data necessary to operate the marketplace and fulfill our obligations to you.
| Data | Required? | Purpose | Retention |
|---|---|---|---|
| Email address | Yes | Account creation, login, password reset, waitlist notifications | Until account deletion or waitlist unsubscription |
| Display name | Yes | Profile display, booking records | Until account deletion |
| Phone number | Optional | Phone sign-in, provider contact info | Until account deletion |
| Profile photo | Optional | Avatar in app | Until account deletion (stored in Firebase Storage) |
| Address / location (free text) | Optional (Providers only) | Service location display — not GPS, just a text field | Until account deletion |
| Payment information | Conditional | Stripe handles all card data end-to-end — we never see or store PAN/CVV | Per Stripe's retention policy |
| Stripe Connect account details | Providers only | Payout processing for service providers | Per Stripe's retention policy |
| FCM registration token | Yes (automatic) | Push notification delivery, one token per device | Until logout or account deletion |
| Booking history | Yes | Service fulfillment, dispute resolution | Retained after account deletion for tax, accounting, and legal compliance (up to 10 years under Romanian Law 82/1991); identifiers are minimized or access-restricted where compatible with those duties |
| Reviews | Yes | Marketplace transparency | Retained after deletion; the public author name may be replaced with "Deleted user" where compatible with legal, transparency, and dispute-handling needs |
5. Data We Do NOT Collect
We want to be transparent about data we explicitly do not access or store:
- Precise GPS location (we do not request location permissions)
- Camera or raw photos (we use the OS sandboxed photo picker — no camera permission)
- Device identifiers beyond the FCM token
- Analytics or crash data (Firebase Analytics is explicitly disabled)
- Advertising identifiers
- Contact list, call logs, or SMS
- Biometric data (facial, fingerprint, voice, or similar)
- Health, political, religious, or other special-category data under Art. 9 GDPR
6. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b) GDPR) — Processing necessary to provide the Service: account creation, booking management, payment facilitation, push notifications for booking updates.
- Legitimate interest (Art. 6(1)(f) GDPR) — Marketplace integrity: fraud prevention, review authenticity, platform security (Firebase App Check attestation, Cloudflare Turnstile), pre-launch marketing-attribution measurement. Our legitimate interests do not override your fundamental rights; you have the right to object on grounds relating to your particular situation (see Section 18).
- Legal obligation (Art. 6(1)(c) GDPR) — Retention of booking and payment records for tax and accounting obligations after account deletion, and compliance with lawful requests from competent authorities.
- Consent (Art. 6(1)(a) GDPR) — Optional processing such as social login via Google, Apple, or Facebook, and joining the pre-launch waitlist. Where you give consent, you may withdraw it at any time (see Section 18).
Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018 implementing GDPR, and Romanian Law no. 506/2004 on electronic communications privacy. Retention of accounting and fiscal records is carried out in accordance with Romanian Accounting Law no. 82/1991.
7. Third-Party Services (Sub-processors)
We share data with the following third-party services that act as our sub-processors to operate the platform:
| Service | Data Shared | Purpose | Transfer Safeguard |
|---|---|---|---|
| Firebase Authentication (Google) | Email, phone, OAuth tokens | User authentication | EU-US Data Privacy Framework (DPF) |
| Firebase Firestore (Google) | All profile, booking, and review fields | Primary database | EU-US DPF |
| Firebase Cloud Messaging (Google) | FCM token, notification content | Push notification delivery | EU-US DPF |
| Firebase Storage (Google) | Profile photos, provider verification documents | File storage | EU-US DPF |
| Firebase App Check (Google) | Device attestation tokens | Backend abuse prevention | EU-US DPF |
| Cloudflare (Turnstile, Pages, D1) | Email, IP address, Turnstile token, attribution parameters | Bot protection, site hosting, waitlist storage | EU processing where available; Standard Contractual Clauses otherwise |
| MeiliSearch (self-hosted) | Search queries, service titles | Marketplace search | Within our own EU-region infrastructure |
Google services (Firebase) are governed by Google's data processing terms. Cloudflare is governed by its standard data processing addendum. MeiliSearch is self-hosted and data does not leave our infrastructure. A copy of the relevant transfer safeguards (for example, the applicable Standard Contractual Clauses) can be requested by contacting us at pontio.app@gmail.com.
8. Independent Controllers
The following services act as independent data controllers (not sub-processors) for the personal data they receive through our integrations. Their processing is governed by their own privacy policies, which you should review:
- Stripe — processes payment card data and billing information for card payments. Stripe acts as an independent controller for payment data it processes.
- Stripe Connect — processes bank account, tax identifier, and KYC documents for Provider payouts.
- Google Sign-In (Google) — email, name, avatar URL for social login.
- Apple Sign-In (Apple) — email (optionally via Apple's private-relay address) and name, when enabled for social login.
- Meta / Facebook Login — email and name for social login.
9. Sharing Between Consumers and Providers
When a Consumer and a Provider interact through the Service (for example, by initiating a Booking), certain data is shared between them to allow the service to be delivered:
- From the Consumer to the Provider: display name, profile photo (if any), the details of the service requested, any location or scheduling information the Consumer provides for the Booking, and any messages the Consumer sends through the in-app chat.
- From the Provider to the Consumer: display name, profile photo (if any), service description and pricing, the Provider's publicly available ratings and reviews, and any messages the Provider sends through the in-app chat.
- Payment data is not shared between Consumers and Providers. Payments are handled by Stripe as an independent controller.
- After a Booking is completed, each party may leave a review of the other. Reviews are subject to the moderation and authenticity rules in our Terms of Service.
Consumers and Providers are each independent controllers for the personal data they learn about the other party through the Service and must use that data only for the purpose of the Booking, unless a separate lawful basis applies.
10. Messaging and Chat Privacy
The Service provides an in-app messaging channel that lets Consumers and Providers communicate about Bookings. The following applies to messages sent through that channel:
- Messages are stored on our infrastructure (Firebase Firestore) and are accessible to the sender and the recipient. We do not routinely read messages.
- We may access, review, or moderate messages where we reasonably believe this is necessary to prevent fraud or abuse; to comply with a legal obligation or a lawful request from competent authorities; to respond to a user report; or to enforce our Terms of Service.
- Messages are retained for the duration of the related Booking and for a reasonable period afterwards for dispute-resolution, fraud-prevention, and legal-compliance purposes, subject to the retention rules in Section 13.
- Sharing personal contact information, payment details, or other data off-platform in order to circumvent the Service is prohibited under our Terms of Service and may result in account measures.
11. Cookies, localStorage, and Similar Technologies
We use a small, limited set of browser storage technologies on the Pontio website. We do not use advertising cookies such as Google Analytics or Meta Pixel.
- Cloudflare Web Analytics — a privacy-preserving measurement tool. It sets no cookies, stores no identifiers on your device, does not fingerprint you, and does not track you across sites; we see only aggregate statistics (page views, referrers, countries). Legal basis: legitimate interest (Art. 6(1)(f) GDPR); because it stores nothing on your device, no ePrivacy consent is required.
- Cloudflare Turnstile — Turnstile is a bot-protection challenge that may set short-lived cookies in your browser to verify that your waitlist submission is not made by an automated bot. Turnstile is considered strictly necessary for the security of the Service. Legal basis: legitimate interest (Art. 6(1)(f) GDPR); corresponding ePrivacy basis: "strictly necessary" under Romanian Law no. 506/2004.
- Language preference cookie (
lang) — when you select a site language, we set alangcookie for up to one year so the correct locale loads on return visits. Strictly necessary for the site's bilingual function. - Attribution localStorage (
__pontio_waitlist_attribution_v1) — if you arrive at pontio.app through a marketing link that contains UTM parameters or a referral code, we store those parameters in your browser's localStorage. When you submit the waitlist form, we attach them to your submission so we can measure which marketing channels convert. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — measuring pre-launch channel performance. You can clear this at any time through your browser's site-data controls.
If we introduce additional third-party analytics or advertising technologies in the future, we will update this section, provide an appropriate consent mechanism where required by law, and give you the ability to manage your preferences.
12. Website and Waitlist Processing
When you visit pontio.app or submit the waitlist form, we process a limited set of data specifically for the pre-launch phase:
- Waitlist email address — collected to notify you when bookings open. Legal basis: consent (Art. 6(1)(a) GDPR). Stored in Cloudflare D1 (EU region). Deleted on request to pontio.app@gmail.com.
- Attribution parameters — as described in Section 11 above.
- Turnstile token — bot-protection token verified server-side against Cloudflare before a waitlist submission is accepted.
- IP address — transiently observed by Cloudflare during form submission for fraud prevention; not stored in our waitlist database.
13. Data Retention
- Active accounts — All profile data retained while the account is active.
- After account deletion — Profile, consumer/provider records, FCM tokens, notifications, waitlist entries, inquiries, and published services are deleted immediately.
- Legal retention — Bookings, payments, and reviews are retained for tax, accounting, and legal obligations for up to 10 years in accordance with Romanian Accounting Law no. 82/1991 and related compliance requirements. Where compatible with those obligations and with the integrity of the relevant record, we may minimize certain identifiers, restrict access to them, or pseudonymize them after account deletion. Public-facing review author names may be replaced with "Deleted user".
- Messaging — chat messages are retained for the duration of the related Booking plus up to 12 months for dispute-resolution and fraud-prevention purposes, unless a longer retention is required by law.
- Waitlist — waitlist emails are retained until you ask us to unsubscribe you or until we notify you of launch and you no longer wish to receive communications.
- Security logs — operational security logs are retained for up to 12 months.
14. Security Measures
We implement the following measures to protect your data:
- All network traffic is encrypted via TLS 1.2+.
- Firebase App Check attestation on every API call (Play Integrity on Android, AppAttest on iOS).
- Firestore security rules enforce per-user ownership on all collections.
- Firebase Storage rules enforce per-user path isolation with file size and type limits.
- Payment secrets are stored only in Firebase Functions Secret Manager (never on-device).
- Local session data is excluded from Android auto-backup and device-to-device transfer.
- Administrative access to production systems requires multi-factor authentication.
- Access to personal data is limited to personnel who need it to operate the Service.
15. Security Incident Procedure
We maintain procedures to detect, investigate, and respond to security incidents affecting personal data. In line with Art. 33 and Art. 34 GDPR:
- Where a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify ANSPDCP without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
- Where a personal-data breach is likely to result in a high risk to the rights and freedoms of natural persons, we will communicate the breach to the affected data subjects without undue delay, in clear and plain language, describing the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
- Communications about breaches will include a point of contact, including our email address pontio.app@gmail.com.
- We maintain an internal register of all personal-data breaches, including their facts, effects, and remedial action taken, in line with Art. 33(5) GDPR.
16. Account Deletion
You can delete your account at any time from Settings → "Delete my account" within the app.
- Confirmation: Requires typing "DELETE" to confirm (double-confirmation).
- Timing: Deletion is immediate — there is no cooling-off period.
- What is removed: User profile, consumer/provider record, FCM tokens, notifications, waitlist entries, inquiries, published services (for Providers), and Stripe Connect account (revoked).
- What is retained: Bookings, payments, and reviews — for legal, tax, accounting, and dispute-handling obligations. Where compatible with those obligations, we may minimize certain identifiers, restrict access to them, or pseudonymize them after deletion, including replacing the public display of a review author's name with "Deleted user".
- Notifications: Consumers with active bookings from a deleted Provider are notified via push notification.
17. Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access — You can view your data in-app via the profile screen.
- Right to rectification — You can edit your data in-app via profile edit.
- Right to erasure — You can delete your account from Settings → Delete Account.
- Right to data portability — Not yet available as a self-service feature. Manual requests can be made via pontio.app@gmail.com.
- Right to withdraw consent — Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where technically available, you can withdraw consent through the same in-app setting or feature used to give it; alternatively, you may contact us at pontio.app@gmail.com.
- Right to object — Where we process your personal data on the basis of our legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. We will stop that processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims. To exercise this right, contact us at pontio.app@gmail.com.
- Right to restriction of processing — Contact us at pontio.app@gmail.com.
- Right not to be subject to automated decisions (Art. 22 GDPR) — see Section 19 below.
- Right to lodge a complaint — You may lodge a complaint with your local supervisory authority. For Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at www.dataprotection.ro.
18. How We Handle Your Rights Requests
In line with Art. 12(3) GDPR, we will respond to requests to exercise your rights without undue delay and in any event within one month of receiving the request. That period may be extended by up to two further months where necessary, taking into account the complexity and number of the requests. Where we extend the period, we will inform you within the first month of receipt, together with the reasons for the delay.
We may request specific information from you to confirm your identity before responding to a request, in order to prevent unauthorized disclosure of personal data. If we refuse to act on a request, we will inform you without delay and at the latest within one month of receipt, including the reasons for not acting and the possibility of lodging a complaint with ANSPDCP or seeking a judicial remedy.
Communications and actions taken under Articles 15 to 22 GDPR are provided free of charge, save where a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request, in accordance with Art. 12(5) GDPR.
19. Automated Decision-Making and Profiling
We do not carry out solely automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR. In particular, decisions such as suspending an account, removing Content, or limiting access to a feature are reviewed by humans before they take effect or are subject to human review on appeal.
We may use limited profiling for operational purposes — for example, displaying Providers in a ranked order in search results, flagging suspicious activity for human review, or prioritizing which messages are surfaced in the app. Such profiling does not, on its own, produce legal or similarly significant effects on you. Where applicable, we describe the main parameters of ranking in our Terms of Service.
20. Marketing Communications and Opt-Out
We do not currently run a marketing programme beyond sending waitlist-related updates to the email address you provided when joining the waitlist. These updates are about the Pontio launch, major product milestones, and ways to help us test the Service.
- Opt-out: Every waitlist-related email contains an unsubscribe link. You may also unsubscribe at any time by contacting pontio.app@gmail.com.
- Right to object to direct marketing: Under Art. 21(2) GDPR, you have an absolute right to object at any time to the processing of your personal data for direct-marketing purposes.
- Transactional communications: Certain communications are necessary for the performance of these Terms (for example, booking confirmations, security alerts, legal notices) and cannot be opted out of while you have an active account.
21. Children's Privacy
Pontio is not intended for children. Where processing is based on consent in connection with information society services offered directly to a child, such processing is lawful only if the child is at least 16 years old, or if consent is given or authorised by the holder of parental responsibility as required by applicable law. If we learn that personal data has been collected in breach of this rule, we will delete it without undue delay.
22. International Data Transfers
Where personal data is transferred outside the EEA, we rely on a lawful transfer mechanism under Chapter V GDPR, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or the EU-US Data Privacy Framework, as applicable to the relevant recipient:
- Google (Firebase) — transfers are covered by the EU-US Data Privacy Framework, where Google LLC is certified.
- Stripe — transfers are covered by the EU-US Data Privacy Framework, where Stripe is certified, supplemented by Standard Contractual Clauses as applicable.
- Cloudflare — where we use Cloudflare's EU data locality features, data is processed within the EU. Where transfers outside the EEA are necessary, they are covered by Standard Contractual Clauses.
- Apple and Meta — where used for social login, these providers act as independent controllers under their own transfer safeguards.
You may request information about the safeguard used for a specific transfer, and a copy of the relevant safeguard where available, by contacting us at pontio.app@gmail.com.
23. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app and updating the "Last updated" date at the top of this page. Where a change materially affects your rights, we will provide advance notice by email where we have your contact details or by prominent in-app notification. The updated policy will apply from its stated effective date.
24. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
PONTIO S.R.L.
Legal form: Limited liability company (S.R.L.)
Registered office: Str. Cal Brăii nr. 26B, Lupeni, jud. Hunedoara, 335600, România
Trade Register no.: J2026050521007
Tax identification number (CUI): 55450878
Email: pontio.app@gmail.com