SHUPU
ES EN

Privacy Policy — SHUPU App

Version: 2026-09-07-v0.2 Last updated: 7 September 2026

0. Controller

The controller’s tax identity and registered office will be published when sole-trader or company registration is in place. A private home address is not published.

This Policy applies to the mobile app (iOS/Android) and the merchant web panel (owner.shupu.ai), for the two profiles in the Terms: Client User and Merchant User (owner / manager / staff).

1. Purpose

It explains which personal data SHUPU processes, for what purpose, on which legal basis, for how long, with whom it is shared, and what rights you have.

2. What data we collect

2.1 Client User

2.2 Merchant User (owner / manager / staff)

2.3 What we do not do

3. Purposes and legal bases

Purpose Data Legal basis (GDPR art. 6)
Account, offers, redemptions and community Sign-up, profile, chat, activity Contract (6.1.b)
Map, neighborhood and nearby offers On-device GPS and lat/lng in queries; persisted neighborhood Contract; system location permission is additional
Proximity offers (BLE beacons) Beacon detection, RSSI, session Contract; system Bluetooth/location permission
Loyalty (points, stamps, levels) Activity and redemptions Contract
Merchant subscription Plan and payment via Stripe Contract
Push notifications Device token Consent (revocable in system settings)
Product improvement Usage events Legitimate interest (6.1.f)
Security and abuse Logs, hashed IP in BLE audit Legitimate interest
Tax and legal duties (merchants) Identification and billing Legal obligation (6.1.c)

You can revoke location, Bluetooth and notification permissions in the phone settings. That does not delete the account; it may block features that depend on those permissions (consistent with §4.4 of the Terms).

4. Who we share data with

SHUPU uses these processors or providers to run the service. Data is not sold for advertising:

5. International transfers

Some of these providers may process data outside the European Economic Area (in particular the United States). That is covered by their own mechanisms (standard contractual clauses and, where applicable, the EU–US Data Privacy Framework). You can ask for more detail at shupucompany@gmail.com.

6. How long we keep data

7. Your rights

You can exercise access, rectification, erasure, objection, restriction and portability by writing to shupucompany@gmail.com. We will respond within the one-month legal deadline. If you disagree with the outcome, you may complain to the AEPD (www.aepd.es).

Taking a merchant offline: the owner can take the merchant offline from the app. It disappears from the map and Explore; SHUPU can restore it, the owner cannot.

Deleting a User account: there is no “delete my account” button in the app today. A SHUPU admin can block access. To delete your account, email shupucompany@gmail.com. If you own a merchant, it must be taken offline or transferred before the personal account is deleted.

8. Bluetooth beacons and location

Beacon detection means near a merchant, not an exact street address. GPS is used on the phone for the map and to resolve neighborhood or nearby offers; we do not build a movement history.

9. Loyalty and reputation

Points, stamps and level are computed from your activity on SHUPU. A merchant does not see your reputation or your activity at other merchants, nor personal data of other merchants’ customers in a joint offer or Shupu Day, beyond what is already visible in normal use of the app (§7.5 of the Terms).

10. Chat and content you post

Group messages and photos are kept while the account is active or until you delete them. SHUPU may moderate or remove content that breaks the rules, and provides reporting. We do not pre-screen all content (§5 of the Terms).

11. Children

SHUPU is for people aged 18 or over (§4.1 of the Terms). We do not intentionally process data of younger people. If we detect a minor’s account, we may suspend or cancel it.

12. Security

Access is authenticated with signed JWT tokens. Traffic is encrypted (HTTPS/TLS). We take periodic backups; you remain responsible for data you manage as a merchant (catalogue, offers), consistent with §17 of the Terms.

13. Merchant web panel

The panel (owner.shupu.ai) uses browser local storage to keep you signed in. It is not used for advertising or cross-site tracking.

14. Maps (Mapbox)

Map views use Mapbox and OpenStreetMap data. The Mapbox SDK may send anonymous usage data; you can manage that telemetry from the map ℹ️ button or on Mapbox’s website. Details are also in Settings → About in the app.

15. Changes to this Policy

We may update it if the law or the service changes. Substantial changes to how we process data will be communicated expressly, in line with §19 of the Terms.

16. Contact

Questions about this Policy: shupucompany@gmail.com.


Internal annex — remaining gaps (not published to Mongo or the app)

  1. Complete controller identity (§0) when the sole trader/company is registered.
  2. Keep DPA evidence for Atlas, Google Cloud, Cloudflare, Upstash, Stripe, Resend, Firebase/FCM, Mapbox, Google and Apple.
  3. Link each provider’s transfer tool in §5 (SCCs / DPF).
  4. Implement analytics TTL to match the 24-month cap in §6.
  5. Self-service User account deletion (equivalent to merchant take-offline). Until then, the channel is email. Panel SHUPU can already lock people (deletedAt on auth).
  6. Portability: downloadable export; today it is handled by hand.
  7. Records of processing (GDPR art. 30) via AEPD Facilita — internal.
  8. Public HTML URL for store listings (L.12): GET /config/public/legal is JSON, not a page.
  9. Lawyer/advisor review (L.5 / L.10).