Settings

Privacy Policy

Last updated: 5 April 2026

This Privacy Policy describes how MINOMO collects, uses and protects the personal data of consumer App users.

Data Deletion Instructions

You can delete your MINOMO account and all associated personal data at any time, directly from the app:

  1. Open the MINOMO app on your device (or visit app.minomo.io)
  2. Go to Settings (gear icon)
  3. Scroll to the bottom and find the Account section
  4. Tap Delete my account, then type DELETE to confirm
  5. Your account is immediately marked for deletion: personal data is anonymised, active sessions are revoked and followed merchants / loyalty data unlinked

If you can no longer sign in, email [email protected] from the address registered on the account and we will process the deletion for you.

1. Data Controller

AVi Kairos Srl

Strada Lungă 188, Corp C2, Ap. 2, Brașov 500051, Romania

CUI: 52477194 | J08/68/2025 | EUID: ROONRC.J2025068492002

Privacy email: [email protected]

Data Protection Officer (DPO): [email protected]

2. Scope

This Privacy Policy applies to:

For merchants, City Agents and Country Managers, please refer to the Privacy Policy on minomo.io.

3. Personal data collected

3.1 Voluntarily provided data

DataWhen collected
Email addressAccount registration
Preferred languageProfile settings
Selected city/locationApp settings (Discovery and localised notifications)
Interest categoriesApp settings (e.g. Food & Drink, Shopping, Beauty)
Push notification preferencesPush enable/disable, merchant mute
Followed merchantsFollow action in the App

3.2 Automatically collected data

DataPurpose
Device identifier (device_id)Unique device identification
Device name, OS, browserUser experience optimisation
Push endpoint and encryption keysPush notification delivery (WebPush protocol)
Native push token (iOS/Android)Push notifications via native app
Last access date and timeActive device management
Push delivery statisticsService quality monitoring

3.3 Loyalty programme data

DataPurpose
Loyalty card QR codeCard identification at the merchant
Points balance and transaction historyLoyalty points management
Visits and spending amountsPoints calculation per merchant rules
Generated and redeemed vouchersBenefit tracking

3.4 MINA virtual guide data

DataPurpose
MINA feature usage historyVirtual guide service delivery
Generated content (tours, suggestions)Experience personalisation

3.5 Browsing and analytics data

DataPurpose
Pages visited and links clickedInternal analytics, service improvement
IP address (anonymised)Approximate geolocation, security
Browser user-agentTechnical statistics, compatibility
HTTP referrerTraffic source analysis
Country, city, time zoneLocalised content

3.6 Data NOT collected

The App does not collect:

4. Purposes and legal basis for processing

PurposeLegal basis (GDPR)
Account creation and managementPerformance of contract (Art. 6.1.b)
Push notifications from followed merchantsPerformance of contract (Art. 6.1.b)
Broadcast push notifications (MINOMO network)Consent (Art. 6.1.a)
Loyalty programme (points, vouchers)Performance of contract (Art. 6.1.b)
MINA virtual guide (AI)Performance of contract (Art. 6.1.b)
Content personalisationLegitimate interest (Art. 6.1.f)
Analytics and service improvementLegitimate interest (Art. 6.1.f)
Security, fraud preventionLegitimate interest (Art. 6.1.f)
Legal obligationsLegal obligation (Art. 6.1.c)
Service communicationsLegitimate interest (Art. 6.1.f)

Where processing is based on consent, the user may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.

5. Data sharing with third parties

5.1 Service providers

ProviderServiceLocation
Amazon Web ServicesCloud storage, CDN (CloudFront)EU (Germany)
HetznerInfrastructure hostingGermany
CloudflareCDN and securityUSA (with EU safeguards)
PaddlePayment processing (MoR)United Kingdom

5.2 Merchants

When a user follows a merchant or participates in a Loyalty programme, the merchant has access to:

The merchant does not have access to: user email, device identifier, or other personal data.

5.3 No data selling

MINOMO does not sell users' personal data to third parties.

6. Data transfers outside the EU

Primary storage is in the European Union (Germany). Some providers may process data outside the EEA, with safeguards:

7. Data retention

Data typeRetention period
Account dataAccount duration + 5 years after deletion
Device and push dataAccount duration or until device removal
Loyalty dataAccount duration + 5 years
Server logs12 months
Analytics data26 months (then anonymised)
Consent records3 years from last interaction or until withdrawal

8. Cookies and tracking technologies

8.1 Cookies used

CookieTypePurposeDuration
SessionNecessaryAuthenticationSession
CSRF tokenNecessarySecuritySession
Cookie consentNecessaryPreferences182 days

8.2 LocalStorage

KeyPurpose
minomo_device_idDevice identification
themeLight/dark theme preference
minomo_langPreferred language

8.3 Service Worker

The App uses a Service Worker for PWA functionality: caching static resources for offline use and receiving push notifications in the background.

9. User rights

In accordance with the GDPR (EU Regulation 2016/679):

RightDescription
Access (Art. 15)Obtain a copy of your personal data
Rectification (Art. 16)Correct inaccurate or incomplete data
Erasure (Art. 17)Request erasure of data ("right to be forgotten")
Restriction (Art. 18)Restrict processing in certain circumstances
Portability (Art. 20)Receive data in a structured, machine-readable format
Objection (Art. 21)Object to processing based on legitimate interest
Withdraw consent (Art. 7.3)Withdraw consent at any time

To exercise your rights:

Response within 30 days, extendable by 60 days in complex cases.

9.1 Complaint to supervisory authority

Romania — ANSPDCP

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București

Tel: +40.318.059.211 · Email: [email protected]

Italy — Italian Data Protection Authority (Garante)

Piazza Venezia 11, 00187 Roma

Tel: +39 06 696771 · Email: [email protected]

For other EU countries: list of authorities.

10. Data security

11. Processing of minors' data

The App is not intended for minors under 16. MINOMO does not knowingly collect personal data of minors under 16. For users aged 16 to 18, data processing is lawful insofar as consent is given or authorised by the holder of parental responsibility, in accordance with Art. 8 of the GDPR. Contact [email protected] to report concerns.

12. Changes to this Policy

MINOMO may update this Privacy Policy to reflect regulatory or operational changes. Material changes will be communicated via an in-app notification or email.

13. Contact

AVi Kairos Srl

Strada Lungă 188, Corp C2, Ap. 2, Brașov 500051, Romania

Privacy: [email protected]

DPO: [email protected]

Data Request Form: minomo.io