Privacy Policy — SliceBill
Last updated: May 30, 2025
1. Data Controller
The controller of your personal data is DARDAN SP. Z O.O., a company registered in Poland, with its registered office at ul. Lewandowskiej 68, 43-143 Lędziny, Poland (NIP: 6462933321, KRS: 0000497120).
Contact: [email protected]
2. What Data We Collect
Data you provide voluntarily
- Email address — when you create an account or sign in with Google
- Display name / nickname — chosen by you in app settings
- Profile avatar — optional, chosen by you (Dicebear generated or uploaded)
- Expense and group data — names, amounts, currencies, member names you enter
Data collected automatically
- Firebase Authentication logs — sign-in events, IP address, device type
- Firebase Firestore access logs — database read/write timestamps (server-side, no analytics tracking)
- Language preference — stored locally on your device
We do not use advertising trackers, third-party analytics platforms (such as Google Analytics), or sell your data to any third party.
3. Why We Process Your Data (Legal Basis)
- Contract performance (Art. 6(1)(b) GDPR) — to provide the SliceBill service, including account management, expense syncing, and group collaboration.
- Consent (Art. 6(1)(a) GDPR) — for optional features such as push notifications. You may withdraw consent at any time in app settings.
- Legitimate interest (Art. 6(1)(f) GDPR) — for service security monitoring and fraud prevention.
4. How Long We Keep Your Data
- Account and expense data is retained as long as your account is active.
- After account deletion, your personal data is deleted within 30 days, except where a longer retention is required by law.
- Local-only data (groups created without an account) is stored only on your device and is not transmitted to our servers.
5. Data Sharing
We share your data only with:
- Google Firebase (Google LLC) — our backend infrastructure provider for authentication, database, and hosting. Data may be processed in the EU or US under Google's data processing agreement and Standard Contractual Clauses.
We do not share your data with any other third parties.
6. Your Rights Under GDPR
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time (for consent-based processing)
- Lodge a complaint with the Polish supervisory authority (UODO): uodo.gov.pl
To exercise your rights, contact us at [email protected].
7. Data Security
We implement appropriate technical measures to protect your data, including encrypted transport (HTTPS/TLS), Firebase Security Rules limiting data access to authenticated owners, and time-limited invite tokens for group sharing.
8. Children
SliceBill is not intended for users under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date above. Continued use of SliceBill after changes constitutes acceptance of the updated policy.
10. Contact
DARDAN SP. Z O.O.
ul. Lewandowskiej 68, 43-143 Lędziny, Poland
Email: [email protected]