Privacy Policy for DealVala
Last updated: August 6, 2025
Effective date: August 6, 2025
DealVala (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our
mobile application (the “App”).
1. Information We Collect
1.1 Information You Provide Directly
- Account Credentials: Email address and password (securely hashed by Supabase).
- Profile Details: First name, last name, phone number (optional), and profile picture (avatar) you upload.
- Preferences: Your selected banks and card types (saved to your profile).
- Saved Deals: IDs of the discounts you bookmark.
1.2 Automatically Collected Information
- Device & App Data: Device model, OS version, unique installation identifier (via expo-constants & expo-updates), app version, and timestamps of your sessions.
- Crash logs and performance metrics: Collected by expo-updates to diagnose issues.
1.3 File & Media Data
- Avatar Upload: When you pick an image from your gallery (via expo-image-picker), we read it with expo-file-system and upload it to our Supabase Storage.
2. How We Use Your Information
- Authentication & Profile Management: To register you, log you in, and maintain your profile.
- Personalization: To show discounts matching your chosen banks, cards, city, or search filters.
- Saving & Syncing: To store your saved deals and preferences so they persist across devices.
- Crash Reporting & Improvement: To diagnose issues, improve stability, and plan features.
3. Sharing & Disclosure
- Service Providers: We share only necessary data with Supabase (auth, database, storage) and Expo (crash reporting).
- Legal Requirements: We may disclose data if required by law or to protect our rights.
- Business Transfers: In the event of a merger or acquisition, your data may be transferred under the same commitments.
We do not sell, rent, or trade your personal information.
4. App Permissions
- Access Media Library: To let you choose an avatar image.
- Read Files: To convert selected images into base64 for upload.
- Open Web Sessions: To handle Google OAuth login via expo-web-browser.
You can revoke these permissions in your device’s Settings, though core features (profile picture, Google sign-in) may no longer work.
5. Data Retention & Deletion
- Account & Profile Data: Retained until you delete your account.
- Saved Deals & Preferences: Retained until you un-save them or delete your account.
- Crash Logs: Retained up to 90 days for diagnostics.
- Avatar Images: Stored in Supabase; removed when you replace them or delete your account (within 30 days).
To delete your data, email us (see Section 8). We will honor requests within 30 days.
6. Security Measures
We implement industry-standard safeguards, including:
- Encryption of data in transit (HTTPS/TLS).
- Secure credential storage (hashed passwords via Supabase).
- Access controls on our Supabase database and storage buckets.
- Regular dependency updates and security audits.
However, no system is perfectly secure. Please notify us immediately if you suspect any vulnerability.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct or update inaccurate information.
- Delete your data or account.
- Restrict or object to certain processing activities.
To exercise these rights, contact us as described below. We will respond within 30 days.
8. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your data, please contact us at:
Thank you for trusting DealVala. We’re committed to keeping your savings secure and your privacy respected.