Privacy Policy — SHUPU App
Version: 2026-09-07-v0.2 Last updated: 7 September 2026
0. Controller
- Service: SHUPU
- Privacy contact: shupucompany@gmail.com
- Supervisory authority: Spanish Data Protection Agency (AEPD), www.aepd.es
The controller’s tax identity and registered office will be published when sole-trader or company registration is in place. A private home address is not published.
This Policy applies to the mobile app (iOS/Android) and the merchant web
panel (owner.shupu.ai), for the two profiles in the Terms: Client User and
Merchant User (owner / manager / staff).
1. Purpose
It explains which personal data SHUPU processes, for what purpose, on which legal basis, for how long, with whom it is shared, and what rights you have.
2. What data we collect
2.1 Client User
- Sign-up: nickname and email. Client registration does not require a phone number. You can also sign in with Google or Sign in with Apple; in that case we receive that account’s identifier and, if the provider sends them, email and display name.
- Profile and activity: profile photo if you upload one, favourites, offer subscriptions, viewed offers, redemptions, local events, points and reputation level.
- Location: for Neighborhood, Explore and distances, the app may read the device GPS (with system permission) and send it in one-off server queries (e.g. nearby merchants or neighborhood resolution). We do not store a continuous coordinate history. The zone we persist is the neighborhood or district, not the street or building number.
- BLE proximity: detected beacon identifier, signal strength (RSSI) and timestamp, for the detection session (typical expiry 48 hours). Beacon lookup audit stores a hash of the IP, not the IP in the clear.
- Community: chat messages, group membership, group photos and content you post.
- Technical: device push token, device type and session identifier.
2.2 Merchant User (owner / manager / staff)
- Business identification: trade name, address, venue coordinates, activity, ownership and, when provided, tax ID.
- Merchant contact: phone number (required when creating a merchant) and details of people with panel access (owner, manager, staff roles).
- Billing: plan and subscription status. SHUPU does not store card data; Stripe processes payments.
- Merchant content: photos, logos, texts and videos on listings and offers (licence in §9 of the Terms).
- Analytics for their own business: views, redemptions and offer performance.
2.3 What we do not do
- We do not use a client’s phone number as a way to search for or invite other users.
- We do not sell data to advertising intermediaries.
- We do not continuously track GPS position on our servers.
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Account, offers, redemptions and community | Sign-up, profile, chat, activity | Contract (6.1.b) |
| Map, neighborhood and nearby offers | On-device GPS and lat/lng in queries; persisted neighborhood | Contract; system location permission is additional |
| Proximity offers (BLE beacons) | Beacon detection, RSSI, session | Contract; system Bluetooth/location permission |
| Loyalty (points, stamps, levels) | Activity and redemptions | Contract |
| Merchant subscription | Plan and payment via Stripe | Contract |
| Push notifications | Device token | Consent (revocable in system settings) |
| Product improvement | Usage events | Legitimate interest (6.1.f) |
| Security and abuse | Logs, hashed IP in BLE audit | Legitimate interest |
| Tax and legal duties (merchants) | Identification and billing | Legal obligation (6.1.c) |
You can revoke location, Bluetooth and notification permissions in the phone settings. That does not delete the account; it may block features that depend on those permissions (consistent with §4.4 of the Terms).
4. Who we share data with
SHUPU uses these processors or providers to run the service. Data is not sold for advertising:
- MongoDB Atlas — main database (accounts, profiles, chat, offers, beacons, configuration).
- Google Cloud (Cloud Run and file storage) — backend and images (offers, merchants, chat).
- Cloudflare (Workers and Pages) —
api.shupu.ai,go.shupu.aiand theowner.shupu.aipanel. - Upstash (Redis) — cache and short-lived session data.
- Stripe — merchant subscription payments and billing.
- Resend — transactional email (verification, account notices).
- Firebase Cloud Messaging (Google) — push notifications.
- Mapbox — Neighborhood maps; the SDK may process on-device location and map telemetry (adjustable from the map ℹ️ button).
- Google Sign-In and Apple — if you sign in with those accounts, the identity provider confirms your identifier.
5. International transfers
Some of these providers may process data outside the European Economic Area (in particular the United States). That is covered by their own mechanisms (standard contractual clauses and, where applicable, the EU–US Data Privacy Framework). You can ask for more detail at shupucompany@gmail.com.
6. How long we keep data
- Active account: for as long as the account exists.
- After closure or an erasure request: we block access immediately or as soon as we handle the request. We keep only what is needed for claims and legal duties, typically up to 12 months, unless the law requires longer.
- Merchant billing: tax and commercial retention (in practice 4 to 6 years).
- BLE session detections: expire around 48 hours.
- Captured-offer wallet: typical expiry 48 hours.
- Product analytics events: at most 24 months.
7. Your rights
You can exercise access, rectification, erasure, objection, restriction and portability by writing to shupucompany@gmail.com. We will respond within the one-month legal deadline. If you disagree with the outcome, you may complain to the AEPD (www.aepd.es).
Taking a merchant offline: the owner can take the merchant offline from the app. It disappears from the map and Explore; SHUPU can restore it, the owner cannot.
Deleting a User account: there is no “delete my account” button in the app today. A SHUPU admin can block access. To delete your account, email shupucompany@gmail.com. If you own a merchant, it must be taken offline or transferred before the personal account is deleted.
8. Bluetooth beacons and location
Beacon detection means near a merchant, not an exact street address. GPS is used on the phone for the map and to resolve neighborhood or nearby offers; we do not build a movement history.
9. Loyalty and reputation
Points, stamps and level are computed from your activity on SHUPU. A merchant does not see your reputation or your activity at other merchants, nor personal data of other merchants’ customers in a joint offer or Shupu Day, beyond what is already visible in normal use of the app (§7.5 of the Terms).
10. Chat and content you post
Group messages and photos are kept while the account is active or until you delete them. SHUPU may moderate or remove content that breaks the rules, and provides reporting. We do not pre-screen all content (§5 of the Terms).
11. Children
SHUPU is for people aged 18 or over (§4.1 of the Terms). We do not intentionally process data of younger people. If we detect a minor’s account, we may suspend or cancel it.
12. Security
Access is authenticated with signed JWT tokens. Traffic is encrypted (HTTPS/TLS). We take periodic backups; you remain responsible for data you manage as a merchant (catalogue, offers), consistent with §17 of the Terms.
13. Merchant web panel
The panel (owner.shupu.ai) uses browser local storage to keep you signed
in. It is not used for advertising or cross-site tracking.
14. Maps (Mapbox)
Map views use Mapbox and OpenStreetMap data. The Mapbox SDK may send anonymous usage data; you can manage that telemetry from the map ℹ️ button or on Mapbox’s website. Details are also in Settings → About in the app.
15. Changes to this Policy
We may update it if the law or the service changes. Substantial changes to how we process data will be communicated expressly, in line with §19 of the Terms.
16. Contact
Questions about this Policy: shupucompany@gmail.com.
Internal annex — remaining gaps (not published to Mongo or the app)
- Complete controller identity (§0) when the sole trader/company is registered.
- Keep DPA evidence for Atlas, Google Cloud, Cloudflare, Upstash, Stripe, Resend, Firebase/FCM, Mapbox, Google and Apple.
- Link each provider’s transfer tool in §5 (SCCs / DPF).
- Implement analytics TTL to match the 24-month cap in §6.
- Self-service User account deletion (equivalent to merchant take-offline).
Until then, the channel is email. Panel SHUPU can already lock people
(
deletedAton auth). - Portability: downloadable export; today it is handled by hand.
- Records of processing (GDPR art. 30) via AEPD Facilita — internal.
- Public HTML URL for store listings (L.12):
GET /config/public/legalis JSON, not a page. - Lawyer/advisor review (L.5 / L.10).