Legal Document

Privacy Policy

Effective Date: 01 January 2026 Last Updated: 01 January 2026 Version: 1.0

Plain-language summary: GetNear is a hyperlocal marketplace connecting buyers and sellers. We collect your location, contact details, and usage data to make this work. We do not sell your personal data. We do not facilitate payments. All transactions occur offline between you and the other party.

01

Information We Collect

We collect information you provide directly, information generated automatically when you use GetNear, and information from third-party services you connect to your account.

1.1 Information You Provide

Category Specific Data Who Provides
Account credentials Email address, password (hashed), or Google OAuth token All users
Identity Display name, phone number (OTP-verified) All users
Seller profile Shop name, owner name, address, product categories, keyword tags, shop photo Sellers
Inquiry content Product name, description, categories, keywords, optional product image Buyers
Blood donation Self-declared blood group, willingness to donate, transport preference; no medical records collected Donors (voluntary)
Reports Reason category, optional free-text description of reported content All users

1.2 Information Collected Automatically

  • GPS location — captured at the moment a buyer submits an inquiry or a seller creates their profile. We do not continuously track your location in the background.
  • FCM device token — a Firebase Cloud Messaging identifier used exclusively to route push notifications to your device. This is not a persistent device identifier for tracking purposes.
  • Usage events — actions such as inquiry_created, seller_response_submitted, visit_marked, and deal_marked are logged to Firebase Analytics to help us improve the platform.
  • Crash and diagnostic data — collected via Firebase Crashlytics to detect and fix application errors. This includes device model, Android version, and a stack trace of the error.

1.3 Information from Third Parties

If you sign in with Google, we receive your Google account's display name, email address, and profile photo URL from Google's OAuth 2.0 service. We do not receive or store your Google password.

02

How We Use Your Information

Purpose Data Used Legal Basis
Authenticating your account Email, password / Google credential, phone OTP Contract performance
Matching buyer inquiries to nearby sellers Inquiry GPS location, categories, keywords; seller location, categories, keywords Contract performance
Delivering push notifications FCM device token, inquiry summary data Contract performance
Displaying your seller profile to buyers Shop name, address, categories, photo, phone number (to authenticated buyers only) Contract performance
Matching blood donation requests Blood group, location, transport preference Consent (voluntary opt-in)
Spam and misuse prevention Phone OTP, inquiry submission timestamps, report data Legitimate interest
Analytics and product improvement Aggregated, anonymised usage events Legitimate interest
Legal compliance and dispute resolution Audit trail records, report history Legal obligation

We do not use your personal data for targeted advertising and we do not profile you for marketing purposes.

03

Blood Donation Feature

Important: The blood donation feature is entirely voluntary. GetNear is a connectivity platform only — we connect willing donors with requesters. We are not a medical service provider.

Users who opt into the blood donation feature self-declare that they are:

  • At least 18 years of age
  • In good health and fit to donate (self-assessed; not medically verified by GetNear)
  • Donating voluntarily without monetary compensation

GetNear collects only your blood group, your willingness status, and whether you require transport assistance. We do not collect, store, or share any medical history, health records, or clinical data. Actual donation eligibility must be confirmed by a qualified medical professional at the time of donation.

Donor contact details are shared only with the requester who initiates contact via the platform, and only for the purpose of facilitating the voluntary donation. GetNear does not verify the accuracy of any self-declared health information.

Emergency requests (such as urgent blood requirements) are displayed to nearby users matching the blood group. Your location is used to determine proximity; precise coordinates are not shared with requesters — only an approximate distance.

04

How We Share Your Information

We do not sell, rent, or trade your personal data. We share information only in the following circumstances:

4.1 Within the Platform

  • Seller shop profiles (name, address, categories, phone number, verified status) are visible to authenticated buyers who are viewing a response to an active inquiry.
  • Buyer inquiry details (product name, category, keywords, optional image) are visible to sellers who are matched to the inquiry.
  • Blood donor contact details are shared only with the verified requester.

4.2 Service Providers (Sub-processors)

Provider Purpose Data Shared
Google Firebase Authentication, database, storage, notifications, analytics, crash reporting All app data (stored on Firebase infrastructure)
Google Sign-In OAuth 2.0 social login Name, email (from your Google account)
Google Play App distribution Download and install events (managed by Google)

All service providers are bound by data processing agreements and are required to process data only as instructed by us.

4.3 Legal Requirements

We may disclose personal data if required to do so by law, court order, or to protect the rights, property, or safety of GetNear, our users, or the public.

4.4 What We Never Share

  • Passwords or authentication tokens
  • FCM device tokens (used only for notification routing)
  • Internal Firebase UIDs
  • Location history or movement patterns
  • Any data with advertisers or data brokers
05

Data Retention

Data Type Retention Period
Active user account data Until you request account deletion
Closed and expired inquiries Minimum 30 days after closure/expiry, then may be archived or deleted
Admin audit trail records Minimum 90 days
Crash and diagnostic logs (Crashlytics) 90 days (Google's default retention)
Firebase Analytics events 14 months (Google's default retention)
Blood donation request records Deleted upon request fulfilment or expiry (whichever is sooner)
Report records Minimum 30 days; longer if dispute is ongoing
Deleted account data Permanently purged within 30 days of deletion request
06

Security

We implement the following technical and organisational measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher; no plaintext HTTP communication is permitted.
  • Firebase Firestore security rules enforce role-based access control at the database level.
  • Passwords are never stored by GetNear; Firebase Authentication manages credential storage securely using industry-standard hashing.
  • Authentication tokens are never stored in plaintext on device storage.
  • Firebase Cloud Storage rules restrict uploads to authenticated users only, with a 5 MB file size limit and JPEG/PNG MIME type enforcement.
  • Idle sessions exceeding 30 days are automatically revoked server-side.
  • All admin actions are logged to a tamper-evident audit trail.

While we take all reasonable steps to protect your data, no system is 100% secure. If you suspect unauthorised access to your account, please contact us immediately.

07

Your Rights

You have the following rights regarding your personal data. To exercise any of these rights, contact us at the address in Section 11.

Right What it means How to exercise
Access Request a copy of the personal data we hold about you Email request to our privacy contact
Correction Request correction of inaccurate or incomplete data Update via the app's profile settings, or email us
Deletion Request deletion of your account and all associated personal data Use the in-app 'Delete Account' feature, or see our Account Deletion guide
Restriction Request we restrict processing of your data in certain circumstances Email request to our privacy contact
Portability Request a structured, machine-readable export of your data Email request to our privacy contact
Withdraw consent Withdraw consent for optional processing (e.g., blood donation feature) Email us your request

We will respond to verified requests within 30 days. We may need to verify your identity before processing requests.

08

Children's Privacy

GetNear is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. The blood donation feature is accessible only to users who self-declare they are 18 years of age or older.

If you believe a child under 13 has provided personal data through our application, please contact us immediately and we will delete the data.

09

Third-Party Services

GetNear integrates with the following third-party services. Their use of your data is governed by their own privacy policies, which we encourage you to review:

GetNear does not control the data practices of these third-party services and is not responsible for their privacy practices beyond what is governed by our data processing agreements with them.

10

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send a push notification to all registered users
  • Require acknowledgement of updated terms on next app launch for material changes

Continued use of the GetNear application after the effective date of changes constitutes acceptance of the updated policy.

11

Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

Privacy Contact

GetNear Privacy Team

Email: getnear.net@gmail.com

Subject line: Privacy Request – [Your Name]

We aim to respond to all privacy-related requests within 30 days.