Data safety
This page summarises what data the Oglasna deska app collects, who it is shared with and how it is protected. It mirrors the Data safety section of our Google Play listing. The full description of processing is in our Privacy Policy.
Summary: we do not sell data, we do not use it for advertising and we do not
track you across apps. All data transfer is encrypted. You can
permanently delete your account and data at any time.
Data collected and shared
"Collected" means the data is sent from your device to our server. "Shared" means it is transferred to a third party. "Optional" means the app works even if you do not provide it.
| Data type | Collected | Shared | Purpose | Optional |
|---|---|---|---|---|
| E-mail address | Yes | No | User account, sign-in, service notices | No (for an account) |
| Name, surname, display name | Yes | No | Showing the advertiser to other users | Yes |
| Phone number | Yes | No | Contacting the advertiser, if you publish it in a listing | Yes |
| Approximate location (town) | Yes | No | Finding nearby listings, stating the location in a listing | Yes |
| Photos | Yes | No | Showing the item in a listing | Yes |
| In-app messages | Yes | No | Communication between buyer and seller | Yes |
| User-generated content (listings) | Yes | Published publicly | Publishing the listing on oglasna-deska.si | Yes |
| App interactions and search history | Yes | No | App functionality, saved searches, usage statistics | Yes |
| Crash logs and diagnostics | Yes | No | Fixing errors and keeping the app stable | No |
| Notification device identifier (token) | Yes | Yes – Google (FCM) | Delivering push notifications | Yes |
| IP address | Yes | No | Security, abuse prevention, server logs | No |
What we do not collect
- the advertising identifier (Android Advertising ID) or cross-app tracking data;
- contacts, calendar, SMS messages or call logs;
- the list of installed apps;
- precise location in the background;
- payment card or financial data;
- health data or other special categories of personal data;
- biometric data, audio recordings or screen recordings.
Security practices
| Encryption in transit | Yes – all traffic uses HTTPS (TLS 1.2 or newer) |
|---|---|
| Encryption at rest | Yes – encrypted volumes and backups |
| Data deletion available | Yes – in the app and via a web request |
| Selling of data | No |
| Third-party ad networks | No |
| Password storage | Salted hashes only; we cannot recover passwords |
| Independent security review | Not performed |
| Target audience | General audience, 16+; the app is not intended for children |
Third parties processing data
| Recipient | Purpose | Data transferred |
|---|---|---|
| Google Ireland Limited – Firebase Cloud Messaging | Delivering push notifications to Android devices | Device token, notification content |
| Google Ireland Limited – Google Play | App distribution, crash reports submitted by Android | Installation data and system-supplied diagnostics |
| EU-based hosting provider | Running our servers and database | All service data, as a contracted processor |
Your control over the data
- Notifications: turn them off in the app or in your Android settings.
- Permissions: camera, photos and location can be revoked at any time in device settings.
- Access and export: request a copy of your data at info@mibesis.com.
- Deletion: see the account and data deletion instructions.
To report a security vulnerability, write to info@mibesis.com. Reports are handled confidentially.