Privacy Policy
ChocoShare Effective Date: [June 30, 2026] Last Updated: [June 30, 2026]
1. Introduction
ChocoShare ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the ChocoShare mobile and web application (the "Service").
This Policy applies to all users globally, with specific provisions for users in the European Union / European Economic Area (GDPR) and the United States (COPPA, CCPA).
Please read this Policy carefully. By using the Service, you acknowledge you have read and understood this Privacy Policy.
2. Data Controller
ChocoShare is the data controller responsible for your personal information.
ChocoShare Email: [support@chocoshare.com] Data Protection Officer (DPO): [support@chocoshare.com]
Our servers are primarily located in the European Union. If you are located outside the EU, your data may be transferred to and processed in the EU.
3. Information We Collect
3.1 Information You Provide Directly
- Name — provided during account registration.
- Email Address — used to create and manage your account and communicate with you.
3.2 Information Collected Automatically
- Location Data — we collect approximate location data to facilitate device discovery and file sharing between nearby devices. Precise location is only collected with your explicit permission.
- Usage and Analytics Data — including device type, operating system, browser type, IP address, pages visited, features used, session duration, and crash reports. This data helps us improve the Service.
- Log Data — server logs including timestamps, error data, and request/response information.
3.3 Information We Do NOT Collect
- Payment Information — payment processing is handled entirely by Polar.sh. We do not receive, store, or process your credit card or payment details. Please review Polar.sh's Privacy Policy for details.
- File Content — we do not read, scan, or retain the content of files you share, beyond what is necessary to transmit them.
4. How We Use Your Information
We use your information for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) | |---|---|---| | Provide and operate the Service | Name, Email, Location | Performance of a Contract | | Enable file sharing between devices | Location Data | Performance of a Contract | | Send account-related notifications | Email | Performance of a Contract | | Improve and analyze the Service | Usage & Analytics | Legitimate Interests | | Ensure security and prevent fraud | All data | Legitimate Interests | | Comply with legal obligations | All data | Legal Obligation | | Send marketing communications (opt-in only) | Email | Consent |
5. Legal Basis for Processing (GDPR)
If you are located in the European Union or EEA, we process your personal data under the following legal bases under the General Data Protection Regulation (GDPR):
- Performance of a Contract (Art. 6(1)(b)) — processing necessary to provide you with the Service.
- Legitimate Interests (Art. 6(1)(f)) — for analytics, security, and improving the Service, where such interests are not overridden by your rights.
- Legal Obligation (Art. 6(1)(c)) — where we are required to process data to comply with law.
- Consent (Art. 6(1)(a)) — for optional features such as marketing emails or precise location access. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Sharing of Your Information
We do not sell your personal information. We may share your data in the following limited circumstances:
6.1 Service Providers (Data Processors)
We work with trusted third-party vendors who process data on our behalf, including:
- Polar.sh — payment processing (they do not receive your file or usage data).
- Cloud infrastructure providers — for hosting and storage (servers primarily in the EU).
- Analytics providers — for aggregated usage analytics.
All processors are bound by data processing agreements and are required to maintain appropriate security measures.
6.2 Legal Requirements
We may disclose your information if required to do so by law, court order, or government authority, or to protect the rights, property, or safety of ChocoShare, our users, or the public.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
7. International Data Transfers
Our servers are primarily located in the European Union. If you are located outside the EU (including the United States), your personal data may be transferred to and stored in the EU.
For transfers from the EU to third countries (e.g., to US-based sub-processors), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Adequacy decisions where applicable.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy:
- Account data (name, email): Retained for the duration of your account, plus up to 90 days after deletion for backup and fraud prevention purposes.
- Location data: Not stored persistently; used transiently during file sharing sessions.
- Analytics data: Retained in aggregated or anonymized form for up to 24 months.
- Legal compliance data: Retained for as long as required by applicable law.
You may request deletion of your data at any time (see Your Rights below).
9. Your Rights
9.1 Rights Under GDPR (EU/EEA Users)
If you are in the EU or EEA, you have the following rights:
- Right of Access — request a copy of the personal data we hold about you.
- Right to Rectification — request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten") — request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction — request that we limit how we use your data.
- Right to Data Portability — receive your data in a structured, machine-readable format.
- Right to Object — object to processing based on legitimate interests, including for direct marketing.
- Right to Withdraw Consent — where processing is based on consent, withdraw it at any time.
- Right to Lodge a Complaint — you have the right to lodge a complaint with your local EU supervisory authority (e.g., your national Data Protection Authority).
9.2 Rights Under CCPA (California Users)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, share, or sell.
- Request deletion of your personal information.
- Opt out of the sale of personal information (we do not sell personal information).
- Non-discrimination for exercising your privacy rights.
To submit a request, contact us at [support@chocoshare.com].
9.3 How to Exercise Your Rights
Submit requests by emailing [support@chocoshare.com]. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
10. Children's Privacy (COPPA)
10.1 Users Under 13 (United States — COPPA)
ChocoShare is available to users of all ages. For users in the United States under the age of 13, we comply with the Children's Online Privacy Protection Act (COPPA).
We do not knowingly collect personal information from children under 13 without verifiable parental consent. If we learn that we have collected personal data from a child under 13 without parental consent, we will promptly delete that information.
Parents or guardians who believe their child under 13 has created an account may contact us at [support@chocoshare.com] to request removal.
10.2 Users Under 16 (EU — GDPR)
For users in EU member states where the age of digital consent is 16 (or the applicable age in their country), parental or guardian consent is required for creating an account and using the Service.
11. Cookies and Tracking Technologies
We use cookies and similar technologies on our web application to:
- Keep you logged in (essential cookies);
- Remember your preferences (functional cookies);
- Analyze usage and improve the Service (analytics cookies).
On your first visit to our web app, you will be asked to consent to non-essential cookies. You can manage cookie preferences at any time through your browser settings or our in-app cookie preferences panel.
Our mobile app does not use browser cookies but may use equivalent device identifiers for analytics purposes.
12. Security
We implement industry-standard security measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS);
- Encryption of data at rest;
- Access controls limiting who can access your data;
- Regular security assessments.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
13. Third-Party Links and Services
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent in-app notice at least 30 days before the changes take effect (or as required by applicable law). The updated Policy will be identified by a revised "Last Updated" date.
15. Contact Us
For any privacy-related questions, requests, or concerns, please contact:
ChocoShare Privacy Team Email: [support@chocoshare.com]
Data Protection Officer (DPO): Email: [support@chocoshare.com]
This Privacy Policy was last updated on [June 30, 2026].