Privacy Policy
This privacy policy applies to the mobile app aggreTrade, also named “Aggre Trade Pro - Bitcoin" (the “App"). Ismail Turan-Atmaca is the provider and data controller. You can use the App without a named user account, but its market-data, alert, push-notification and advertising functions still process personal and pseudonymous data.
Summary
- No named account: The App does not ask for your name, email address or password. It does, however, create a random user identifier for alert and push-notification functions.
- Operator backend: It processes connection data, the pseudonymous user identifier, a push token, timestamps and alert, condition and notification rules.
- Push notifications: Firebase Cloud Messaging and Firebase Installations process technical device, app and installation data.
- Advertising: Google Mobile Ads may process data including the IP address, approximate location, app interactions, diagnostics and device or advertising identifiers. Personalized, non-personalized or limited ads may be served depending on consent, region and technical availability.
- No Firebase Analytics: The reviewed App version does not include the Firebase Analytics, Crashlytics or Performance Monitoring SDK. The Google Mobile Ads SDK may still process diagnostic data.
- Important security notice: The reviewed App version still connects to the operator backend without TLS. Request contents transmitted to that backend are therefore not encrypted in transit. See “Data security" below.
1. Controller and contact details
Ismail Turan-Atmaca
Postal address: see the German imprint
Email: supportepiclappscom
You can also use this contact for requests relating to access, deletion, objection or any other data-protection matter.
2. Scope and terminology
This policy describes processing by the App and the operator services it contacts. Processing that occurs when you merely visit this website is described in the general website privacy policy. Personal data may include online identifiers such as IP addresses, installation identifiers, advertising IDs and push tokens where they relate to an identified or identifiable person.
3. Overview of processing
- Locally on the device: data including your watchlist, display and language settings, consent status and local copies of alert and condition settings.
- On the operator backend: technical connection and request data, a random user identifier, the FCM push token, registration and activity timestamps, price-alert rules, condition rules and notification subscriptions.
- At Google Firebase: a Firebase installation identifier, app version, the Firebase user agent containing technical device data, the push token and message data required for delivery.
- At Google Mobile Ads: depending on the platform, consent and configuration, data including the IP address and approximate location derived from it, app and ad interactions, diagnostic information, advertising and other device identifiers and information about ads displayed.
The App does not request a real name, email address, telephone number, payment details or password for an aggreTrade account. The operator does not provide a named or cross-device aggreTrade profile.
4. Market and chart data through the operator backend
The App obtains market, trade and chart data through an aggregation service controlled by the operator. This technically involves data including the IP address, time, requested function or resource and connection or device information. The backend obtains public market data from connected market sources; your device does not establish a direct connection to your personal exchange account for this purpose.
- Purposes: providing the market and chart functions you selected, load management, troubleshooting, availability, and detecting misuse or attacks.
- Legal basis: Article 6(1)(b) GDPR for the requested App function and Article 6(1)(f) GDPR for secure, stable and misuse-resistant backend operation.
- Legitimate interests: functionality, IT security, troubleshooting and preventing abusive automated access.
5. Pseudonymous registration, alert and condition rules
The App registers the device for server-based alerts without a name or email address. The backend creates a random user identifier and associates the current FCM push token with it. If you use alert or condition functions, data including the following may be stored:
- random user identifier and FCM push token
- registration, update and last-activity timestamps
- selected market asset and alert type
- target, reference and status values of a price-alert rule
- identifiers and status of a condition or movement rule selected by you
This data is required to monitor rules on the server, associate them with a device and trigger a notification when the condition is met. This is pseudonymous processing; without additional information, the operator generally cannot associate the identifier with your name.
- Legal basis: Article 6(1)(b) GDPR because the processing is required for the alert or notification function you activated.
- Device access: Where local storage or access to device information is strictly necessary for the service you expressly requested, section 25(2)(2) TDDDG.
6. Push notifications using Firebase Cloud Messaging
Price and condition alerts are delivered through Firebase Cloud Messaging (FCM), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the operating system, the visible notification permission is requested when you activate a relevant function. You can revoke a permission in the system settings.
According to Google, FCM automatically processes the app version and the Firebase user agent. The user agent may contain the operating system, device model, brand, form factor, installation source and the Firebase SDKs in use and their versions. FCM also depends on Firebase Installations, which creates a Firebase installation identifier. The FCM push token is also transmitted to the operator backend so it can send alerts configured by you to the device.
- Purposes: technical registration, token updates, delivery and management of notifications expressly activated by you, and service security and stability.
- Legal basis: Article 6(1)(b) GDPR; section 25(2)(2) TDDDG for strictly necessary local access.
The reviewed App version does not include Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config or Firebase In-App Messaging. Google explains Firebase processing in Firebase Privacy and Security and its Firebase data-disclosure guide for Android.
7. Advertising and consent management through Google AdMob
The App is partly funded by banner ads from Google AdMob / Google Mobile Ads. The provider is Google Ireland Limited. Depending on the processing, other Google entities, ad buyers and ad-technology providers used by Google may be recipients.
Before requesting an ad, the App updates the consent status through Google's User Messaging Platform (UMP). If Google requires a consent message or privacy options for your region, the App presents the available choices. Ads are requested only once the SDK reports that ad requests are permitted. You can reopen the privacy options provided by Google under “Privacy and Ads", where they are available to you.
Google may serve personalized, non-personalized or limited ads depending on your choice, region, platform and technical availability. Non-personalized and limited ads are not free of data processing: they may still use the IP address, general location, device and app information, interactions, anti-fraud signals and identifiers for delivery, frequency capping, measurement and billing.
Google identifies the following categories for the Mobile Ads SDK in particular:
- IP address and approximate location derived from it
- app and ad interactions, such as app launches, taps and ad views
- diagnostic and performance data, such as app launch time, hang rate and energy use; on iOS, non-user-related crash logs may also be processed
- advertising ID, app-set ID, iOS device or developer-bounded identifiers and, where applicable, other device or account identifiers
- information about ads viewed
- Purposes: ad delivery and personalization, reach and performance measurement, billing, analytics, fraud prevention, security and troubleshooting.
- Consent: Where legally required, Article 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw consent for future processing using the available privacy options; this does not affect the lawfulness of prior processing.
- Processing without consent: Only where legally permitted, limited processing required for delivery, security and fraud prevention may rely on Article 6(1)(f) GDPR. Access to a device without consent is then limited to a statutory exception under section 25(2) TDDDG.
- Roles: Google states that Google and the app provider each act as independent controllers for certain AdMob processing.
Further information: How Google uses data from apps that use Google services, Google advertising technologies, Mobile Ads data disclosure for Android and Mobile Ads data disclosure for iOS.
8. Recipients and processors
Depending on the function used, data may be sent to the following recipient categories:
- technical hosting and infrastructure providers for the operator backend acting as processors
- Google Ireland Limited and affiliated Google entities for Firebase Cloud Messaging, Firebase Installations, UMP and Google Mobile Ads
- for advertising, ad buyers, ad-technology providers and their service providers used by Google, depending on your choice and the ad served
- public authorities or other bodies where required by law or a valid order
The operator does not intend to disclose data for unrelated purposes, including selling names, email addresses or alert rules created by you.
9. Transfers to third countries
Google services may process data outside the European Economic Area, including in the United States. Google states that it uses the EU-US Data Privacy Framework for certified US entities and, where that framework does not apply, safeguards including the European Commission's Standard Contractual Clauses. Different government access rights and remedies may nevertheless apply in third countries.
Information about the safeguards used by Google: Google Data Transfer Frameworks.
10. Retention periods and deletion criteria
- Local data: until you delete it in the App or system settings, reset the App data or uninstall the App.
- Pseudonymous registration: while required for an active alert and push-notification association, until a deletion request has been validly associated with it, or until the record is deleted after the purpose ends.
- Alert and condition rules: until you remove the relevant rule, configured automatic deletion applies, a validly associated deletion request is implemented, or the data is no longer required for the function.
- Notification subscriptions: until the token is unregistered, automatic deletion following the last activity applies, a validly associated deletion request is implemented, or the purpose ends.
- Technical logs: only for as long as required for operation, troubleshooting, security and abuse prevention; evidence relating to a specific security incident may be required for longer.
- Google data: according to the relevant Google product, account and deletion rules. You can also manage device or advertising identifiers through your operating system's privacy and advertising settings.
Statutory retention or evidence obligations and the establishment, exercise or defence of legal claims may prevent immediate deletion of individual records. Processing will then be restricted to the required purpose.
11. Your rights
Subject to the statutory requirements, your rights include:
- access (Article 15 GDPR)
- rectification (Article 16 GDPR)
- erasure (Article 17 GDPR)
- restriction of processing (Article 18 GDPR)
- data portability (Article 20 GDPR)
- objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR)
- withdrawal of consent for the future (Article 7(3) GDPR)
Because aggreTrade does not maintain a named account, the operator may be unable to associate a request with a pseudonymous record using your email address alone. We request only the information required for secure association and to prevent unauthorised deletion. Do not send passwords, complete push tokens or other secrets by email. The procedure is explained on the data access and deletion page.
12. Right to lodge a complaint
Under Article 77 GDPR, you may lodge a complaint with a data-protection supervisory authority, in particular in the country of your habitual residence, place of work or place of the alleged infringement. The authority generally responsible for the controller is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Website: baden-wuerttemberg.datenschutz.de
13. Data security
According to Google, connections between the App and Google services are encrypted in transit using HTTPS/TLS. The reviewed App version still uses HTTP without TLS for the connection to the operator backend. This affects more than public market data: the pseudonymous user identifier, FCM push token and alert, condition and subscription data may also be included in these requests. Network operators or other parties on the transmission path could therefore read or alter unencrypted content.
This transparency notice does not resolve the technical risk. Until an App version with end-to-end TLS protection is released, do not use aggreTrade to configure alerts or push notifications over untrusted or open networks. Migrating the backend to HTTPS and releasing an updated App version are required to provide appropriate transport protection.
14. No automated decision-making under Article 22 GDPR
The operator does not use the data described above to make solely automated decisions that produce legal effects concerning you or similarly significantly affect you. Automatic triggering of a market alert configured by you is an App function selected by you.
15. Changes to this policy
We update this policy when App functions, recipients, the law or technical processing change. The version published here applies. Where required, material changes will also be identified in the App and will not retrospectively create a new legal basis.