Privacy Policy
This Privacy Policy explains how evvnly collects, uses, and protects your personal data when you use our app and website, and the rights you have under the EU General Data Protection Regulation (“GDPR”). Your data is yours: we never sell it or use it to build advertising profiles, and you can export or delete it at any time.
1. Data controller
The controller of your personal data is Rather Active - Unipessoal, Lda, a company incorporated in Portugal, with its registered office at Rua Dom António de Sousa Barroso, 9, 2730-254 Valejas, Portugal and tax/registration number (NIPC) 517304198. For any privacy question or to exercise your rights, contact us at hello@ratheractive.tech.
If you are located in the United Kingdom, our processing of your personal data is also governed by the UK GDPR and the UK Data Protection Act 2018; references in this policy to the GDPR include the UK GDPR.
2. What data we collect
We collect only what we need to run evvnly:
- Account data — your email address and authentication identifiers. If you sign in with a third-party provider (such as Google or Apple), we receive a basic identifier and the email associated with that account.
- Profile data — your display name, and optionally a profile photo and short bio that you choose to add.
- Expense and group data — the groups you create or join, the people in them, expenses, amounts, currencies, descriptions, balances, settlements, and any receipt images or comment photos you upload.
- Purchase and billing data — when you buy evvnly Plus, we receive and keep a record of the transaction (such as the plan, amount, currency, date, and the store or payment-partner transaction identifier) so we can grant your Plus entitlement, support you, and keep the tax and accounting records Portuguese law requires. Your full card or payment-instrument details are handled by our payment partners (Paddle on the web, Google Play on Android), not by us.
- Device and notification data — a push-notification token for the devices where you enable notifications.
- Technical and connection data — such as your IP address and basic request information, used to keep the Service secure and to prevent abuse and fraud (for example, rate-limiting sign-in attempts).
- Diagnostic data — technical data such as app version and crash/error reports, used to keep the Service working and to fix problems. We do not currently use a third-party usage-analytics provider. If we later add analytics to understand how evvnly is used and improve it, it will be privacy-respecting and first-party, never sold or used to build advertising profiles, and we will name the provider in the “Service providers and partners” section below.
- Waitlist data — if you join our pre-launch waitlist, we collect your email address so we can tell you when evvnly launches and apply any early-access offer. We keep it until launch and offer fulfilment, then delete it if you have not created an account.
We do not ask for or intentionally collect special-category data (such as health or political data). Please do not put such information into expense descriptions or notes.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Create and manage your account; provide the core expense-splitting features | Performance of a contract |
| Process evvnly Plus purchases and keep tax/accounting records | Performance of a contract; legal obligation |
| Send service messages (e.g. group invites, verification, account notices) | Performance of a contract |
| Send push notifications you have enabled | Consent |
| Diagnose crashes and errors to keep the Service stable | Legitimate interests |
| Keep the Service secure and prevent abuse or fraud | Legitimate interests |
| Add you to our pre-launch waitlist and tell you when evvnly launches, including any early-access offer | Consent (you can withdraw it at any time by unsubscribing or emailing us) |
Where we rely on consent, you can withdraw it at any time (for example, by turning off notifications in your settings). Where we rely on legitimate interests, we have weighed those interests against your rights. Where a purchase is involved, our Refund Policy and Terms of Service also apply.
4. Service providers and partners
We share data with a small set of trusted providers. Most act as our processors — they handle your data only on our documented instructions and only as needed to run evvnly:
- Google Firebase Authentication — sign-in and account security.
- Google Cloud Firestore — storage of your profile, group, and expense data.
- Google Cloud Storage — storage of profile photos, receipt images, and photos you attach to comments.
- Google Cloud Platform (GCP) — hosting of our backend services.
- Firebase Cloud Messaging (FCM) — delivery of push notifications.
- Firebase Crashlytics — crash and error reporting.
- Resend — delivery of transactional emails.
- Cloudflare Pages — hosting and delivery of our marketing website, including the pre-launch waitlist form.
Our payment partners are independent controllers, not our processors: when you buy evvnly Plus on the web, Paddle (Paddle.com Market Limited) is the Merchant of Record and seller of record, and for in-app purchases on Android Google (Google Play Billing) is the seller. Each receives the name, contact, and billing/payment data needed to take payment, invoice, handle taxes, and process refunds, and handles that data under its own privacy policy (Paddle, Google).
We do not sell your personal data, and we do not share it with third parties for their own advertising.
5. International transfers
Some of our providers (including Google, Cloudflare, Resend, and Paddle) are based in, or may process data in, countries outside the European Economic Area, such as the United States or the United Kingdom. Where data is transferred outside the EEA, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or an applicable adequacy decision — so that your data keeps an equivalent level of protection. For personal data of UK users transferred outside the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, a UK adequacy decision, or the UK Extension to the EU-US Data Privacy Framework, as applicable. You can request a copy of the safeguards we rely on by emailing us at hello@ratheractive.tech.
6. How long we keep it
We keep your personal data for as long as your account is active. When you delete your account, we delete your personal data from our live systems, except where we must keep limited records to meet a legal obligation (for example, billing and tax records for paid purchases, which Portuguese law generally requires us to keep for up to 10 years). Crash and error reports and technical and connection logs (such as IP address) are kept only for a limited period — typically up to 90 days — after which they are deleted or kept only in aggregated, non-identifying form. Backups are cycled out on a rolling basis.
Some shared content (such as an expense you added to a group) may remain visible to other members of that group after you leave or delete your account, because it forms part of their shared record — but it will no longer be linked to your profile.
7. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- data portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, where processing is based on consent.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.
You can export your data and delete your account directly in the app (Settings → Privacy), or request deletion by email — see Delete your account and data. For any other request, email hello@ratheractive.tech and we will respond within the time limits set by the GDPR.
If you believe we have mishandled your data, you can lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD) — https://www.cnpd.pt — or with the authority in your EU country of residence. If you are in the UK, you may instead complain to the UK Information Commissioner’s Office (ICO) — https://ico.org.uk.
8. Security
We use technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and reputable infrastructure providers. No system is perfectly secure, but we take reasonable steps to protect your data and to respond promptly if something goes wrong.
9. Cookies and local storage
We use only storage that is strictly necessary to run evvnly — for example, to keep you signed in (Firebase Authentication) and to protect the website from abuse (Cloudflare). We do not use advertising or third-party usage-analytics cookies, so no cookie-consent banner is required. If we ever add non-essential cookies or first-party analytics, we will ask for your consent first and update this policy.
10. United States
Do Not Track and cross-site tracking. Some web browsers can send a “Do Not Track” (DNT) signal. Because there is no common industry standard for how online services should interpret DNT signals, we do not currently respond to them. We do not allow third parties to collect personally identifiable information about your online activities across different websites or services through your use of evvnly.
US state privacy laws. We do not “sell” your personal information or “share” it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act (CCPA) and similar US state privacy laws. We are not currently a “business” or “controller” subject to the CCPA or comparable US state privacy laws — including those of Virginia, Colorado, Connecticut, and Texas — because we do not meet their applicability thresholds (and, in Texas, we qualify for the small-business exemption). Even so, we extend the access, correction, deletion, and data-portability rights described above to all users, including residents of US states, and you can exercise them in the app (Settings → Privacy) or by emailing hello@ratheractive.tech. We will not discriminate against you for exercising these rights.
11. Children
evvnly is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change, we will update the version and effective date above and, where appropriate, notify you in the app or by email.
13. Language versions
This Privacy Policy is available in several languages. The English version is the original version and prevails in the event of any discrepancy between language versions, unless the mandatory consumer-protection law of your country of habitual residence provides otherwise.
14. Contact
For any privacy question or request, email us at hello@ratheractive.tech.