1. Introduction
The Penelope Group LLC ("Company," "we," "us," or "our") operates the MagiPulse mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
By downloading, accessing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the App and its features.
- Create and manage your account and authenticate your identity.
- Personalize your experience within the App.
- Analyze usage trends and improve App performance, stability, and features.
- Diagnose technical problems and fix crashes.
- Communicate with you about updates, security alerts, and support.
- Comply with legal obligations and enforce our Terms of Service.
- Protect against fraud, unauthorized access, and illegal activity.
- Deliver push notifications, wait time alerts, itinerary updates, and other notifications you have elected to receive.
We do not sell your personal information to third parties. We do not use your data for targeted advertising.
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we process your personal data under the following legal bases:
- Consent: Where you have given explicit consent (e.g., location data, marketing communications). You may withdraw consent at any time.
- Contract: Processing necessary to provide the App and fulfill our obligations to you (e.g., account creation, core features).
- Legitimate Interests: Processing necessary for our legitimate business interests (e.g., analytics, security, fraud prevention), provided those interests do not override your fundamental rights.
- Legal Obligation: Processing required to comply with applicable law.
5. How We Share Your Information
We do not sell, rent, or trade your personal information. We may share data only in the following circumstances:
- Service Providers: Trusted third-party vendors who process data on our behalf (hosting, analytics, authentication), bound by contractual obligations to protect your data.
- Legal Requirements: When required by law, regulation, legal process, or enforceable governmental request.
- Safety & Rights: To protect the rights, property, or safety of our users, the public, or our Company.
- Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets. You will be notified before your data is transferred and becomes subject to a different privacy policy.
- With Your Consent: In any other case, only with your explicit consent.
6. Third-Party Services
Our App integrates with the following third-party services, each governed by their own privacy policies:
Google Analytics for Firebase
We use Firebase Analytics to collect anonymized usage data and crash reports. Firebase may collect device identifiers and IP addresses (which Google may truncate). For more information, see Firebase Privacy Information and Google's Privacy Policy.
Push Notification Services
To deliver push notifications, we use third-party notification service providers,
including Expo and platform notification services such as Apple Push Notification Service (APNs).
These providers may process device push notification tokens solely for the purpose of delivering
notifications requested by you. We do not use push notification tokens for advertising purposes,
and we do not sell or share them with third parties except as necessary to provide notification services.
Social Login Providers
We only receive the information you authorize during the login process. We encourage you to review the privacy policies of these providers.
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Specifically:
- Account Data: Retained while your account is active and for up to 30 days after deletion to allow for recovery.
- Analytics Data: Retained in anonymized/aggregated form for up to 26 months (per Firebase defaults), after which it is automatically deleted.
- Support Communications: Retained for up to 2 years for quality assurance and legal purposes.
- Legal Obligations: Certain data may be retained longer if required by applicable law (e.g., tax, fraud prevention).
- Push Notification Tokens: Retained only for as long as necessary to provide notification services or until notifications are disabled, the App is uninstalled, or the associated account is deleted.
When data is no longer needed, we securely delete or anonymize it.
8. Data Security
We implement industry-standard technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Secure authentication mechanisms including OAuth 2.0 for social logins.
- Regular security assessments and vulnerability monitoring.
- Access controls limiting employee access to personal data on a need-to-know basis.
While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly notifying affected users and relevant authorities in the event of a data breach, in accordance with applicable law.
9. Your Rights & Choices
Regardless of your location, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your personal data, subject to legal retention requirements.
- Withdraw Consent: Revoke consent for data processing at any time (this does not affect prior lawful processing).
- Device Permissions: Control location, camera, and photo library access through your device's settings at any time.
- Opt-Out of Analytics: You may disable analytics data collection by contacting us at TPGLLC.Support@gmail.com.
To exercise any of these rights, contact us at TPGLLC.Support@gmail.com. We will respond within 30 days (or sooner if required by law).
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request the categories and specific pieces of personal information we have collected, the sources of collection, the business purposes, and the categories of third parties with whom we share data.
- Right to Delete: You may request deletion of your personal information, with certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit use of sensitive data to what is necessary to provide the App.
To submit a request, email TPGLLC.Support@gmail.com with the subject line "California Privacy Request." We will verify your identity before processing your request.
11. European Privacy Rights (GDPR)
If you are in the EEA or UK, you have the following additional rights under the General Data Protection Regulation:
- Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Restriction of Processing: Request that we restrict processing of your data under certain circumstances.
- Object to Processing: Object to processing based on legitimate interests or for direct marketing purposes.
- Lodge a Complaint: File a complaint with your local Data Protection Authority (DPA).
Our lawful bases for processing are detailed in Section 4. To exercise your GDPR rights, contact us at TPGLLC.Support@gmail.com.
12. Children's Privacy (COPPA)
This section is particularly important. Our App may be used by children under 13, and we comply with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations.
12.1 Parental/Guardian Consent
We do not knowingly collect personal information from children under 13 without verified parental or guardian consent. Before collecting, using, or disclosing personal information from a child under 13, we will:
- Provide direct notice to parents/guardians about the data we collect and how it is used.
- Obtain verifiable parental consent before collecting personal information from the child.
12.2 Data Minimization for Children
For users we know to be under 13, we limit data collection to what is strictly necessary for the child to participate in the App's core activities. We do not:
- Require a child to disclose more information than is reasonably necessary.
- Use children's personal data for behavioral advertising or profiling.
- Share children's personal data with third parties except as necessary to provide the App's functionality or as required by law.
12.3 Parental Rights
Parents and guardians have the right to:
- Review the personal information we have collected from their child.
- Request deletion of their child's personal information.
- Refuse further collection or use of their child's information.
- Consent to collection and use without consenting to disclosure to third parties.
To exercise these rights, contact us at TPGLLC.Support@gmail.com with the subject line "COPPA Parental Request."
12.4 Safety Measures
We maintain reasonable procedures to protect the confidentiality, security, and integrity of children's personal information, including restricting access to authorized personnel only.
13. International Data Transfers
Your information may be transferred to and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer data internationally, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Data Processing Agreements with all third-party service providers.
- Ensuring an adequate level of protection as required by applicable data protection laws.
By using the App, you acknowledge that your data may be processed in the United States.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Notify you via in-app notification, email, or other prominent means prior to the changes taking effect.
- Where required by law (especially for children's data), obtain renewed consent before applying material changes.
We encourage you to review this Privacy Policy periodically. Continued use of the App after changes constitutes acceptance of the revised policy.