This policy describes what personal data the Bloter application ("the app") collects, for what purposes, on what legal basis, and what rights you have. The data controller is Bloter ("we"). Processing complies with the Personal Data Protection Act of the Republic of Serbia and, for users in the EU, with the GDPR. For any questions: office@bloter.rs.
Account data - at registration: email address and password (the password is held by our authentication provider in protected form - we never have access to it) and the username you choose. When signing in with Google/Facebook/Apple we receive only your email address from the provider.
Content you publish - posts (listings) with photos, comments, reviews, and messages and images exchanged with other users. The essential data of posts is, by the nature of the service, publicly visible to all users of the app.
Order fulfilment data - when you send an order request, the data you enter in the form (address, city, phone number, note) is forwarded to the user you are dealing with - that is its only purpose. Providing it is voluntary.
Profile settings - city and the common description shown on your posts, if you enter them.
Technical data - if you enable push notifications: a device delivery identifier (push token) and basic device information (model name, operating system), plus your notification settings.
Usage data (internal) - statistics linking search and post views to orders, to understand how users find posts. Sent only to our server; never shared with third parties.
Analytics (Google Firebase Analytics) - anonymous usage statistics: which screens you visit and which features you use (search, posting, orders), aggregated per app installation. These events do NOT contain your email, username or message content, and we do not use them to identify individuals.
Website statistics (Google Analytics) - on the bloter.rs website we measure visits (visit counts, where visitors come from, device type and approximate location derived from the IP address, at city or region level), and clicks on the app download button. The data is used in aggregate only and is not linked to your account in the app.
Waiting list - if you leave your email address in the waiting-list form on the website (Google Forms), we use it only to tell you when the app becomes available. We send nothing else and share the address with no one. You can ask for it to be deleted at any time at office@bloter.rs.
Cookies and your consent - cookies are set ONLY after you accept them on the bar shown on your first visit. Until you answer, and if you decline, Google Analytics sets no cookies. With your consent, Google's advanced features are also enabled (Google Signals: demographics, interests and remarketing). You can change your choice at any time via "Kolačići" in the page footer.
Crash reports (Google Firebase Crashlytics) - a technical report when the app stops unexpectedly (device model, OS version, technical error trace), used to fix bugs.
Advertising (Google AdMob) - when displaying ads, Google may process the device advertising identifier and ad interaction data (section 4).
Approximate location (from the IP address) - Google's services (Firebase Analytics and AdMob) derive an approximate, city- or region-level location from the IP address, for usage statistics and more relevant ads. We do not use GPS and do not collect your precise location.
Server logs - for security and troubleshooting, the server infrastructure keeps technical access records (including IP address), retained for a limited time and used for no other purpose.
Only on your device (never sent to us): recent search history and the local list of received notifications. Removed by uninstalling the app.
The app does NOT collect: precise (GPS) location, contacts, or payment data - no payments are made through the app.
| Purpose | Legal basis |
|---|---|
| Providing the service: account, posts, messaging, orders, notifications | performance of contract (Terms of Use) |
| Security, abuse prevention, troubleshooting | legitimate interest |
| Internal and anonymous usage statistics | legitimate interest; for EU users - consent |
| Displaying ads that fund the app | legitimate interest; ad personalisation in the EU - consent |
| Complying with requests of competent authorities | legal obligation |
We do not sell your data and do not use it for decisions producing legal effects on you without human involvement.
Users in the EU/EEA are shown a consent dialog on first launch: analytics and personalised ads operate only with consent, and the choice can be changed at any time via My profile → Privacy settings. Withholding consent does not restrict use of the app.
App data is primarily stored in the European Union. Google services (analytics, ads, push, crash reports) may also process data in the USA - transfers rely on safeguards applied by Google (standard contractual clauses / the EU-US Data Privacy Framework).
Communication between the app and the server is encrypted (TLS/HTTPS); data is stored on protected infrastructure with access control; passwords never touch our servers (Amazon Cognito). No system is absolutely secure - in the event of a data breach posing a risk to your rights, we will notify you and the supervisory authority without delay.
The app is intended for adults (18+). We do not knowingly collect data of minors; such an account will be deleted as soon as we become aware of it.
We will notify you of substantial changes through the app before they take effect; changes in your favour or required for legal compliance apply immediately. The current version, with its last-updated date, is always available on this page.
Bloter - office@bloter.rs