Legal
We believe in radical transparency. This policy explains exactly what data we collect, why we collect it, and how we protect it. We never sell your data. We never use it for advertising.
PalPal (" we ," " us ," " our ") operates palpal.live and a suite of associated productivity applications. We are the data controller for personal information collected through our Services.
We are committed to protecting your personal data and processing it in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.
When you sign in with Google, we receive from Google the following account information:
| Data Field | Purpose | Stored? |
|---|---|---|
| Google Account ID (UID) | Uniquely identify your PalPal account | Yes — in Firestore |
| Email address | Account identification and communication | Yes — in Firestore |
| Display name | Personalise the user interface | Yes — in Firestore |
| Profile photo URL | Display your avatar in the app | URL reference only |
We do
not
request or receive access to your Gmail, Google Drive, Google Calendar, contacts, or any
other Google service data. Our OAuth scopes are limited to
openid
,
email
, and
profile
.
We use the information we collect exclusively to:
We do not use your data for advertising, profiling, or any purpose beyond operating and improving PalPal Services.
PalPal uses Google Sign-In (OAuth 2.0) via Firebase Authentication. This is our only supported authentication method. When you choose to sign in with Google:
Scopes requested: We only request the minimum OAuth scopes required:
openid
— Confirms your identity
email
— Your Google email address
profile
— Your name and profile photo
You can review and revoke PalPal's access to your Google Account at any time at myaccount.google.com/permissions . Revoking access will sign you out of PalPal but will not delete your stored data (you must contact us separately to delete your data).
We do not sell your personal information. We share your data only in the following limited circumstances:
Your data is stored in Google Firebase Firestore , a cloud database operated by Google Cloud Platform. Firebase provides enterprise-grade security including:
We implement additional security measures including strict Firestore Security Rules that ensure users can only access their own data. No PalPal employee can read your app data unless required for critical support purposes, and only with your explicit permission.
Despite these measures, no method of transmission or storage is 100% secure. We encourage you to use a strong, unique password for your Google account.
We retain your personal data for as long as your account is active or as needed to provide our Services. Specifically:
Upon account deletion request, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business interests (e.g., fraud prevention).
Depending on your location, you may have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request that we delete your personal data ("right to be forgotten").
Receive your data in a structured, machine-readable format.
Object to the processing of your data in certain circumstances.
Request that we restrict processing of your data.
To exercise any of these rights, contact us via our support page . We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
We use minimal cookies and local storage, limited to:
We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies. We do not participate in any ad networks.
You can clear cookies at any time through your browser settings. Clearing authentication cookies will sign you out of PalPal.
Our Services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately and we will delete that information promptly.
Users between the ages of 13 and 18 should use our Services only with parental or guardian consent. Parents or guardians who become aware that their child has provided personal information without consent should contact us.
Our Services are operated from and data is stored in servers managed by Google Cloud Platform, which may process data in multiple regions globally, including the United States and European Economic Area (EEA).
By using our Services, you consent to the transfer of your information to these regions. Google Firebase complies with applicable data transfer mechanisms including Standard Contractual Clauses (SCCs) for GDPR compliance.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where appropriate, notify registered users by email or in-app notice.
We encourage you to review this Policy periodically. Your continued use of our Services after any changes constitutes your acceptance of the updated Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
We take all privacy inquiries seriously and will respond within 30 days.
We take your privacy seriously. Our team is happy to answer any questions you have about how we handle your data.
Contact Our Team