NearGo PRIVACY POLICY
Version: 1.2 Effective date: 3 June 2026
1. INTRODUCTION
Podjetniški Projektni Center ANAplus d.o.o. (hereinafter "NearGo" or "we") respects your privacy and is committed to protecting your personal data in accordance with:
- The General Data Protection Regulation (GDPR, EU Regulation 2016/679)
- All applicable data protection regulations
2. DATA CONTROLLER
Personal data controller:
Podjetniški Projektni Center ANAplus d.o.o. Ljubljanska cesta 11, 3000 Celje, Slovenia
Email: info@getneargo.com Phone: +386 40 642 239
3. DATA WE COLLECT
3.1 Data you provide yourself
At registration:
- Email address
- Password (stored encrypted)
- First name and last name (optional)
- Phone number (optional)
- Year of birth (for age verification)
During use:
- Profile settings (interests, categories)
- Ratings and reviews
- Wishlist (favorites list)
- Purchase history
Vendor accounts (additional):
- Company name
- Tax number
- Registered address
- Bank account / IBAN (for payouts)
- Company contact details
3.2 Data collected automatically
Technical data:
- IP address
- Device type (iOS, Android)
- Operating system version
- Application version
- Device identifier (Device ID)
Usage patterns:
- Offer views
- Clicks and interactions
- Usage times
- Crash reports
Location data:
- GPS location (only with explicit permission)
- City location (based on IP)
- Search radius (user-defined)
3.3 Data from third-party sources
- Social login data (Google, Apple) — in accordance with their policies
- Payment data via Stripe (NearGo does NOT have access to full card details)
4. PURPOSES OF DATA PROCESSING
4.1 Legal bases for processing
We process your data on the following legal bases:
a) Contractual obligation (Art. 6/1/b GDPR):
- Service provision
- Payment processing
- Sending transactional emails
b) Legal obligation (Art. 6/1/c GDPR):
- Retention of accounting records (10 years)
- Anti-money laundering
- Tax obligations
c) Legitimate interest (Art. 6/1/f GDPR):
- Service improvement
- Fraud prevention
- System security
d) Consent (Art. 6/1/a GDPR):
- Marketing communications
- Push notifications
- Location data
- Cookies (analytical)
4.2 Specific purposes
| Purpose | Data category | Legal basis |
|---|---|---|
| Registration and login | Email, password | Contract |
| Purchase processing | Payment data | Contract |
| Offer personalization | Location, interests | Consent |
| Sending notifications | Email, push tokens | Contract/consent |
| Marketing | Email, profile data | Consent |
| Accounting | Identification, transactions | Law |
| Fraud prevention | IP, device, behavior | Legitimate interest |
| Application improvement | Anonymous usage statistics | Legitimate interest |
5. SHARING DATA WITH THIRD PARTIES
5.1 Our data processors
The following providers have access to some of your data to provide the service:
| Provider | Service | Data shared | Location |
|---|---|---|---|
| Supabase | Database, authentication, storage | Profile, email, content, session | EU |
| Stripe | Payments (coupons/services/subscriptions/featured) and Connect KYC for providers | Amount, currency, email, offer ID; for providers also KYC data | EU/USA |
| Expo | Push notifications | Device push token, platform | EU/USA |
| Google Sign-In | Authentication | OAuth identity (email, name) | USA |
| Apple Sign-In | Authentication | OAuth identity (email, name on first sign-in) | USA |
| Google Maps | Maps | Device location (to display the map) | USA |
| Resend | Sending email | Email address, message content | EU (Ireland) |
| Anthropic | AI features (search, descriptions, translations) | Search query / offer text | USA |
| Apple IAP | In-app purchases (Premium) | Purchase receipt, transaction ID | USA |
| Google Play Billing | In-app purchases (Premium) | Purchase token, transaction ID | USA |
| EU VIES | VAT verification (providers) | VAT number | EU |
| OSM Nominatim | Geocoding | Address/city search string (no identity) | EU |
Ticketmaster is not a processor of your personal data. We use it as an external source of event information (search/discovery): when you search, only search parameters (location, keywords) are sent, without your personal data. Any purchase at Ticketmaster takes place on their external page; NearGo does not process their payments.
5.2 Transfers outside the EU
Some processors are located outside the EU (mainly the USA). Transfers are safeguarded by:
- EU Standard Contractual Clauses
- EU-US Data Privacy Framework
- Other safeguards in accordance with GDPR
5.3 Disclosure to authorities
We may disclose your data to:
- Competent authorities upon their lawful request
- In court proceedings
- Where there is suspicion of a criminal offense
6. DATA RETENTION PERIOD
| Data category | Retention period |
|---|---|
| Active user accounts | While the account is active |
| Deleted accounts | 30 days (for potential restoration) |
| Accounting data | 10 years (legal obligation) |
| Communication history | 2 years |
| Marketing data | Until consent is withdrawn |
| Anonymous statistics | Indefinite |
7. YOUR RIGHTS
In accordance with the GDPR, you have the following rights:
7.1 Right of access (Art. 15)
You may request a copy of all personal data we hold about you.
7.2 Right to rectification (Art. 16)
You may request correction of inaccurate or incomplete data.
7.3 Right to erasure "right to be forgotten" (Art. 17)
You may request the deletion of your data, except in cases of:
- Statutory retention obligation (accounting)
- Necessary for the defense of legal claims
7.4 Right to restriction of processing (Art. 18)
You may request a temporary restriction of data processing.
7.5 Right to data portability (Art. 20)
You may request your data in a structured format for transfer.
7.6 Right to object (Art. 21)
You may object to the processing of your data, especially for marketing purposes.
7.7 Right to withdraw consent
You may withdraw given consent at any time.
7.8 How to exercise rights
Send requests to: info@getneargo.com Phone: +386 40 642 239 Response time: 30 days (extendable to 60 days) Cost: free of charge (except for manifestly unfounded requests)
7.9 Right to lodge a complaint
You have the right to lodge a complaint with the competent data protection supervisory authority in your country of residence. List of EU authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en
8. DATA SECURITY
8.1 Technical measures
- HTTPS/TLS encryption of all connections
- Password encryption with bcrypt
- Row-Level Security (RLS) in the database
- Regular security audits
- Data backup
8.2 Organizational measures
- Restricted employee access to data
- Clean desk policy
- Regular training
- NDA agreements signed
8.3 Breach notification
In the event of a security breach that may affect your data:
- We notify the competent supervisory authority within 72 hours
- We notify affected users (if the risk is high)
9. CHILDREN
NearGo does NOT collect data from children under 13. The application is intended for users over the age of 18.
If we discover that we have unknowingly collected data from a child, we delete it immediately.
10. POLICY CHANGES
This Privacy Policy may change. We will inform you of material changes:
- By email
- Through an in-app notification
- 30 days before the effective date
11. CONTACT
Email: info@getneargo.com Phone: +386 3 898 00 24, +386 40 642 239
Podjetniški Projektni Center ANAplus d.o.o. Ljubljanska cesta 11, 3000 Celje, Slovenia VAT ID: SI16311647 Registration No.: 6452515000 IBAN: SI56 2900 0005 1317 804 (Unicredit Banka Slovenija)
Podjetniški Projektni Center ANAplus d.o.o. Ljubljanska cesta 11, 3000 Celje, Slovenia
Translation in progress
This document is currently being translated. Please refer to the Slovenian version for the latest information.
For questions, contact: Email: info@getneargo.com Phone: +386 40 642 239