Privacy Policy
Last updated: April 10, 2026
We are Museum App Inc. ("Museum App", "we", "our"), a company registered in the State of Texas, United States.
Administrative office:
7971 Riviera Blvd Ste 204
Miramar, FL 33023
United States
1. Who We Are and Who This Policy Applies To
This Privacy Policy applies to our website (https://museum.app), mobile applications (iOS and Android), and all related services we offer to our users.
By using Museum App, you accept the practices described in this Privacy Policy. If you do not agree, please do not use our services.
2. Key Definitions
- Personal Data: Information that identifies or can identify a natural person.
- Processing: Any operation performed on personal data (collection, use, storage, transfer, deletion, etc.).
- Controller / Data Controller: Entity that determines the purposes and means of processing (usually, Museum App Inc.).
- Processor / Data Processor: Entity that processes data on behalf of the controller (for example, hosting, email, payment providers).
3. Data We Collect
3.1 Information You Provide Directly
Registration and account:
- Full name and username
- Email address
- Password (stored via cryptographic hash, never in plain text)
- Country of residence
- Preferred language
- Date of birth (for age verification and experience personalization)
- Gender (optional)
Public profile and content:
- Profile picture or avatar
- Biography and public description
- Country (visible on your public profile)
- Links to social networks or personal websites
- Collecting category preferences
- Photos and descriptions of collectible items
- Posts, comments, public and private messages
- Virtual museums, sections and organized content
- Collectible search/wishlist lists
Contact information and preferences:
- Phone number and country code (optional)
- Privacy preferences (public/private account, hide last seen, show/hide collectibles cabinet)
- System preferences: currency, measurement system, weight system, date and time format, decimal separators
- Notification and alert settings
Subscriptions and billing:
- Subscription plan (Free, Premium, Premium Max)
- Payment and invoice history
- Customer ID in Stripe (our payment processor)
- Last 4 card digits and transaction information (provided by Stripe; <strong>we do not store full card data</strong>)
- Preferred billing currency
Support and communications:
- Messages sent to technical support
- Attachments, screenshots and receipts
- Communication metadata (date, time, subject)
- Reports of inappropriate content or users
3.2 Information Collected Automatically
When you use Museum App, we automatically collect certain technical and usage information:
Technical and device data:
- IP address (with partial truncation when appropriate for privacy reasons)
- Approximate geolocation (country and city) derived from your IP address using the MaxMind GeoLite2 database (local lookup; database is downloaded periodically from MaxMind, Inc., USA — IP addresses are not transferred per request)
- Unique device identifiers
- Operating system and version
- Device type (mobile, tablet, desktop)
- Web browser and version (user agent)
- Mobile app version
- Browser or operating system language
- Time zone setting
- Screen resolution
Usage and activity data:
- Pages visited and time spent
- Actions performed in the application (publish, comment, like, save, share, follow users)
- Interaction events (clicks, scrolling, searches)
- Active session duration
- Last connection and activity status (lastSeen)
- Post, collectibles, and museum section views (with duration metrics)
- Navigation history within the platform
- Technical errors, crashes and application performance
Security and authentication:
- Login history (LoginHistory): device, approximate geographic location, access date and time
- Session tokens and authentication cookies (managed by NextAuth)
- Changes to sensitive account data (email, password, username, biography) with historical record for security
- Failed or suspicious access attempts
Cookies and similar technologies:
We use cookies and similar technologies (localStorage, sessionStorage) to improve your experience. For more information, see our Cookie Policy.
3.3 Information from Third Parties
Third-party authentication (Single Sign-On):
- First and last name
- Email address
- Profile picture (Google) or email relay (Apple)
- External provider user ID
Payment processing (Stripe):
- Customer ID (Stripe Customer ID)
- Subscription status (active, canceled, expired)
- Last 4 card digits and card type (Visa, Mastercard, etc.)
- Transaction history (amounts, dates, payment statuses)
- Billing events (renewals, payment failures, refunds)
Advertising and analytics:
- We request your prior consent when legally required
- We receive aggregated metrics of impressions, clicks and conversions
- Providers use cookies and tracking technologies according to your consent preferences
- Premium subscribers do not see display ads
3.4 Special Categories of Personal Data and Sensitive Data
Museum App does NOT intentionally request or collect special categories of personal data in accordance with GDPR/UK GDPR (racial or ethnic origin, political opinions, religious beliefs, health information, sexual orientation, genetic or biometric data).
We expressly prohibit users from uploading, posting or processing through the Service any content containing:
- Biometric data (facial recognition, fingerprints, iris scans, facial geometry, etc.) without adequate legal basis and explicit consent
- Special categories of personal data from third parties
- Medical, financial or minors' information without authorization
Content that violates this prohibition may be removed without prior notice, and the responsible account may be suspended or permanently deleted. For more information, see our Terms and Conditions.
4. How We Use Your Personal Data
4.1 Service Provision and Management
- Create, manage and authenticate your user account
- Enable publication, editing and management of collectibles, posts and virtual museums
- Enable social features: follow users, like, comment, save content, share posts, create reposts
- Real-time private messaging (1-to-1 chat) via WebSocket/Socket.io
- Manage collectible search/wishlist lists
- Personalize your experience according to your preferences (language, theme, currency, formats)
- Remember your privacy and account settings
4.2 Security and Protection
- Secure authentication and prevention of unauthorized access
- Detection and prevention of fraud, spam, abuse and malicious activity
- Content moderation and user report review
- Protect the integrity and security of the platform
- Send security notifications via email: new devices detected, password changes, email address changes, suspicious access attempts
- Maintain audit logs (LoginHistory, sensitive data changes) for security investigations
4.3 Product Improvement and Development
- Aggregated analytics and usage statistics (without individual identification)
- Technical bug fixes and performance improvements
- A/B testing to optimize features
- Development of new features and improvements
- Research and analysis of collecting trends
4.4 Communications
- <strong>Transactional communications (mandatory):</strong> registration confirmations, password reset, account change notifications, security alerts, payment confirmations
- <strong>Service notifications:</strong> social activity (new followers, likes, comments, mentions, private messages), saved content updates
- <strong>Technical support:</strong> query responses and assistance
- <strong>Important notices:</strong> changes to Terms and Conditions, Privacy Policy, scheduled maintenance
- <strong>Marketing communications (optional, with opt-in):</strong> newsletters, product news, promotions, educational collecting content
4.5 Billing and Subscriptions
- Process Premium and Premium Max subscription payments
- Manage automatic renewals, upgrades, downgrades and cancellations
- Issue invoices and electronic receipts
- Provide billing and payment support
- Comply with tax and accounting obligations
4.6 Special Tools and Features
- <strong>Collection value calculator:</strong> estimate total collection value based on data you provide (not constituting professional appraisal)
- <strong>Lot price calculator:</strong> calculate price paid for item lots
- <strong>Content metrics:</strong> post and collectible views, viewing duration, engagement
- <strong>Recommendations:</strong> suggest relevant users, categories or content based on your interests
4.7 Advertising (web and mobile applications)
Museum App may display advertising through networks such as Google AdSense (web) and Google AdMob (mobile applications). Advertising availability may vary depending on your geographic location and account settings. When advertising is active in your region:
- In the EU/EEA and United Kingdom: We request your explicit consent before using non-essential cookies/SDKs or personalizing ads. If you do not give consent, we show non-personalized ads and apply Limited Ads when appropriate
- In the United States: We respect privacy signals such as Global Privacy Platform (GPP) and Global Privacy Control (GPC), and offer opt-out controls for "sale/sharing" where state laws apply (CCPA/CPRA, Virginia, Colorado, Connecticut, Texas)
- We use a Consent Management Platform (CMP) compatible with IAB TCF 2.2 standards to manage your advertising and cookie preferences
- We offer contextual (non-personalized) ads as an alternative when you do not consent to personalized advertising
- Full details about partner categories, advertising purposes and cookie durations are available in our Cookie Policy
Legal basis in EEA/United Kingdom: The legal basis for using advertising cookies/SDKs and personalized ads is your consent (art. 6.1.a GDPR). If you deny or withdraw it, we will only serve non-personalized ads and limit identifiers according to Limited Ads policies.
4.8 Legal Compliance
- Comply with valid requests from competent authorities
- Defend our legal rights in judicial or administrative proceedings
- Enforce our Terms and Conditions
- Prevent illegal or harmful activities
4.9 Analysis and Predictive Tools (Future)
In the future, Museum App may develop market analysis and value prediction tools using completely anonymized collectible pricing data.
- Market value estimates for similar collectibles
- Historical price trends in the collectibles market
- Predictive tools based on aggregated market data
- All such analysis would be performed exclusively with completely anonymized data, with no possibility of identifying individual users or collectibles
5. Legal Basis for Processing (GDPR/UK GDPR)
5.1 Consent
We obtain your explicit and informed consent for:
- Non-essential cookies and personalized advertising (via TCF 2.2 compliant CMP)
- Marketing communications by email (you can unsubscribe at any time)
- Sharing data with certain third parties outside strictly operational scope
5.2 Contract Performance
Processing is necessary to fulfill the contract you have with us (Terms and Conditions):
- Create and manage your account
- Provide service features (posts, collectibles, museums, chat, search lists)
- Process subscriptions and payments
- Provide technical support
5.3 Legal Obligation
Processing is necessary to comply with applicable legal obligations:
- Retention of financial and billing data for legal periods (e.g., 7 years)
- Response to legitimate requests from competent authorities
- Compliance with tax and accounting regulations
5.4 Vital Interests
In exceptional cases, we may process data to protect the life or physical integrity of a person.
5.5 Legitimate Interests
Processing is necessary for our legitimate interests, provided your rights and freedoms do not override:
- Platform security and fraud/abuse prevention
- Content moderation and policy enforcement
- Non-intrusive aggregated analytics to improve the product
- Technical error detection and performance improvement
- Personalized advertising (when implemented)
- Marketing communications (newsletters, promotions)
- Certain mobile device permissions (camera, photo gallery, push notifications)
- Use of precise location data (if requested in the future)
6. Who We Share Your Personal Data With
Museum App does not sell your personal data to third parties in the traditional sense of the term. However, we share certain information with service providers and in the circumstances described below:
6.1 Service Providers (data processors)
We share data with third parties that provide services on our behalf, under contracts that oblige them to protect your data and use it only for specified purposes:
- Hosting and infrastructure: Digital Ocean (servers and web hosting)
- CDN (Content Delivery Network): Cloudflare (global static content distribution, DDoS protection)
- Payment processing: Stripe Inc. (secure credit card processing, subscription management, billing)
- Transactional email: Amazon Simple Email Service (Amazon Web Services Inc., USA) — sending verification emails, security notifications, invoices, support
- Transactional email fallback: Resend (Resend Inc., USA) — used only when AWS SES is temporarily unavailable, so verification and security emails still reach you. Same data scope as the primary path: recipient address and the contents of the message we send.
- Authentication: NextAuth (session management), Google OAuth (Google login), and Apple Sign-In (Apple ID login)
- Real-time chat: Socket.io (WebSocket self-hosted on our servers, no third-party transfer)
- Image processing: Sharp (local image processing on our servers, no external transfer)
- Geolocation: MaxMind GeoLite2 (local IP-to-location lookup; the GeoLite2 database is downloaded periodically from MaxMind, Inc., USA — IP addresses are not transferred per request)
- Crash reporting and APM: Sentry (Functional Software Inc., USA) — capture of mobile app errors and performance metrics. Authorization headers, JWTs and sensitive query parameters are redacted before transmission; users are identified only by numeric user ID, never by username or email.
6.2 Advertising Networks and Measurement
When advertising is enabled in your region, we may share information with advertising networks (such as Google AdSense, Google AdMob) in accordance with your consent preferences and applicable laws. Shared information may include:
- Device or advertising identifiers (ad IDs, advertising cookies)
- Browsing and usage data (pages visited, interactions, app events), always with regional privacy controls
- Impression, click, conversion and advertising performance metrics
- Approximate demographic information (age, gender, general location) when you have given consent
In the EU/EEA and United Kingdom, this sharing only occurs after obtaining your explicit consent through our CMP. In the United States, we automatically recognize opt-out signals (GPC/GPP) and comply with applicable state laws.
Note for residents of certain U.S. states: Some state laws (CCPA/CPRA California, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA) may consider this sharing as "sale" or "sharing for behavioral advertising". We offer opt-out controls through browser privacy signals (GPC/GPP) and from your account settings (Settings → Privacy → Advertising preferences). For more information, see Section 14 of this Policy.
6.3 Legal Authorities and Regulatory Compliance
We may disclose your personal data when required by law or when we believe in good faith that it is necessary to:
- Comply with court orders, subpoenas, valid government requests
- Enforce our Terms and Conditions
- Protect our rights, property or security, as well as those of our users or the public
- Prevent fraud, abuse or illegal activities
- Cooperate with law enforcement investigations
6.4 Corporate Transfers
In the event of a merger, acquisition, asset sale or corporate restructuring, your personal data may be transferred to the successor entity. We will notify you through prominent notice before your data is transferred and subject to a different Privacy Policy.
6.5 Profile Visibility and Distinction Between Public and Private Data
Museum App is a social network designed to connect collectors and share content. By its nature as a social platform, user profiles are public by design and visible to anyone on the internet, including unregistered users and search engines.
Personal data that is public:
- Your username, profile name and biography
- Your profile picture and virtual museum
- Collectibles you publish in your public collection
- Posts, comments and content you share publicly
- Your follower lists and accounts you follow
- Your public interactions (likes, public comments, reposts)
Legal basis: By creating an account on Museum App, you give your express consent for this information to be public and accessible to anyone, as established in our Terms of Service (Section 8.4).
Private Collection Cabinet (Premium Feature): Users with Premium or Premium Max subscription have access to a private collection cabinet that allows them to store and organize collectibles privately without being visible to other users. This functionality is exclusively available to active premium plan subscribers.
Private data we NEVER share or make public:
- Purchase price and acquisition date of collectibles
- Current estimated value of collectibles
- Personal notes and private documentation
- Invoices and purchase receipts
- Any other sensitive information related to acquisitions
- Private messages and direct conversations
- Privacy settings and account preferences
<strong>Privacy guarantee:</strong> This private data is protected by technical and organizational security measures, and is only accessible by the account owner. <strong>It will never be publicly visible or shared with other users in identifiable form</strong>, regardless of whether the collectible is public or private.
Possible future use of pricing data for predictive tools:
In the future, Museum App <strong>could develop</strong> price prediction and market value estimation tools to benefit the collecting community. If we implement these features, we <strong>could use</strong> purchase price and current value data of collectibles in a <strong>completely anonymous and aggregated</strong> manner to:
- Generate predictive models of market trends
- Calculate value estimates for similar items
- Provide historical price ranges and future projections
- Improve valuation tools and collection calculators
Anonymization commitment:
If we implement these predictive tools in the future, we guarantee that:
- Irreversible anonymization: Data will be processed in such a way that it is technically impossible to trace it to a specific user or individual collectible
- No identification: No user, not even Museum App, will be able to identify where the data used in predictions came from
- Massive aggregation: Data will be combined with information from multiple users and collectibles before any processing
- No individual prices: Individual prices or information that could identify the owner will never be shared publicly
- Legal compliance: This anonymized data will comply with the concept of "anonymous data" under GDPR (Recital 26), will not constitute "personal information" under CCPA §1798.140(o)(2), and will not be considered "personal data" under LGPD Art. 12
Legal basis for future processing:
- GDPR/UK GDPR: Legitimate interest (Art. 6(1)(f)) - Truly anonymized data is not personal data and does not require legal basis under GDPR; additionally, improving the service through statistical analysis benefits the entire community
- CCPA/CPRA: Anonymized data is explicitly excluded from the definition of "personal information" (§1798.140(o)(2))
- LGPD (Brazil): Anonymized data does not constitute personal data and is outside the scope of the law (Art. 12)
- Transparency: We will notify you through an update to this Privacy Policy and prominent notice in the application if we implement these tools in the future, giving you the opportunity to exercise your objection rights before implementation
Your rights: You can exercise your right of access, rectification, deletion, portability, objection and limitation of processing at any time in accordance with section 10 of this Policy. You can delete your account and all your personal data from your account settings at any time.
<strong>Privacy control:</strong> Use the privacy settings available in <strong>Settings → Privacy</strong> to manage your visibility preferences, consents for marketing, analytics and personalized advertising.
7. International Data Transfers
Museum App operates from the United States. We host and process data in the United States and other locations according to our service providers (Digital Ocean, Cloudflare, Stripe, Amazon Web Services, Sentry).
For users in the European Union, the European Economic Area and the United Kingdom:
When we transfer personal data outside the EEA/United Kingdom to countries that do not have an adequacy decision from the European Commission, we apply the following safeguards:
- Standard Contractual Clauses (SCCs): contracts approved by the European Commission that guarantee adequate protection
- United Kingdom: For transfers subject to UK GDPR, we use the International Data Transfer Agreement (UK IDTA) or EU SCCs with the UK Addendum, as appropriate
- Supplementary technical and organizational measures: data encryption in transit and at rest, strict access controls, data minimization
- Transfer Impact Assessment: risk analysis and additional guarantees when necessary
You can request non-confidential copies of the Standard Contractual Clauses, UK IDTA or UK Addendum we have implemented by sending an email to [email protected].
8. How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, unless the law requires or permits a longer retention period:
8.1 Active Account
While your account remains active and you use the service, we retain your personal data to provide you the service.
8.2 Deleted Content or Closed Account
- Operational deletion: Data is deleted from our production systems within approximately 90 days from content deletion or account closure
- Backups: Data may remain in automatic backup copies for an additional period of up to 90 days, after which it is permanently purged
- Exceptions: We may retain certain data longer if:
- It is necessary to comply with legal obligations (invoices, tax records)
- There is a pending legal dispute or resolution procedure
- They are necessary for security, fraud or abuse investigations
- You have specifically requested their retention
8.3 Billing and Transaction Data
Invoices, receipts, payment history and subscription-related data: 5 to 10 years, as required by applicable tax and accounting laws (IRS in the United States, local regulations in other countries).
8.4 Security and Audit Logs
- Login history (LoginHistory): 12 to 24 months
- Access logs and security events: 12 months
- Records of changes to sensitive data (email, password, username): 24 months
8.5 Consent Records and Privacy Preferences
We retain consent status, opt-out and privacy preferences (CMP signals, TCF 2.2 strings, GPP/GPC, cookie choices, advertising preferences) for 24 months or the minimum period required by law, whichever is greater. This retention allows us to comply with advertising network audit requirements and demonstrate valid consent when legally required.
8.6 Retention Criteria
To determine the appropriate retention period, we consider:
- The nature and sensitivity of the data
- The potential risk of harm from unauthorized use or disclosure
- The purposes of processing
- Whether we can fulfill the purposes through other less invasive means
- Applicable legal, regulatory, tax or accounting obligations
You can request detailed information about our criteria and specific retention periods by sending an email to [email protected].
9. Security of Your Data
Museum App implements reasonable technical and organizational measures to protect your personal data according to industry standards:
9.1 Technical Measures
- Encryption: Data in transit via HTTPS/TLS; passwords stored with bcrypt cryptographic hash (never in plain text)
- Secure authentication: Secure session tokens managed by NextAuth, support for two-factor authentication (future)
- Access control: Role-based access, principle of least privilege
- Security monitoring: Detection of unauthorized access, intrusion attempts, suspicious activity
- Backups: Regular automatic backups with encryption and secure storage
- Environment segregation: Separation between production, development and testing
- DDoS protection: Cloudflare for denial of service attack mitigation
9.2 Organizational Measures
- Security and data protection policies
- Staff training and awareness
- Confidentiality agreements with employees and providers
- Security audits and periodic reviews
- Security incident response plan
9.3 Limitations
Despite our efforts, no security system is completely infallible. We cannot guarantee that our systems are invulnerable to all types of cyber attacks, hacking or unauthorized access.
9.4 Security Breach Notification
In the event of a security breach affecting personal data, Museum App will comply with all notification obligations established by applicable laws:
- GDPR/UK GDPR: Notification to the supervisory authority within 72 hours; communication to affected individuals without undue delay when there is high risk
- U.S. state laws: Notification to affected residents according to each state's deadlines
- We will provide information about the nature of the breach, affected data, measures taken and steps you can take to protect yourself
9.5 Your Responsibility
You are responsible for:
- Maintaining the confidentiality of your password and access credentials
- Not sharing your account with third parties
- Notifying us immediately of any unauthorized use of your account by sending an email to [email protected]
- Using strong passwords (minimum 8 characters, combination of letters, numbers and symbols)
- Keeping your device and browser software up to date
For more information about our liability limitations in case of security breaches, see Section 8 of our Terms and Conditions.
10. Protection of Minors
10.1 United States (COPPA)
Museum App does not allow the use of the service to users below the minimum age of digital consent in their jurisdiction — 13 years in most countries (in compliance with the Children's Online Privacy Protection Act, COPPA), and 16 years in the European Economic Area, United Kingdom, and Switzerland (in compliance with GDPR Article 8).
We do not intentionally collect personal information from children below this threshold. If we discover that we have collected data from such a user without verifiable parental consent, we will delete that information from our systems as soon as possible.
10.2 European Union and United Kingdom (GDPR/UK GDPR)
Local minimum ages for digital consent as provided by article 8 of GDPR/UK GDPR apply (between 13 and 16 years depending on the member country). When legally required, Museum App will implement reasonable mechanisms for verifying parental or legal guardian consent.
10.3 Advertising Targeted at Minors
Museum App does not use personalized ads or identifiers for behavioral targeting directed at users we know or reasonably infer to be minors.
We apply family-friendly content policies and targeting limitations in accordance with advertising network policies (Google AdSense/AdMob "Child-directed treatment").
10.4 If You Are a Parent or Legal Guardian
If you believe your minor child has provided personal data to Museum App without your consent, contact us immediately at [email protected]. We will take steps to delete that information as soon as possible.
11. Your Privacy Rights
Depending on your location, you have rights regarding your personal data. The most common include:
- ✓ Access: Obtain a copy of your personal data
- ✓ Rectification: Correct inaccurate or incomplete data
- ✓ Deletion: Request deletion of your data (with certain legal exceptions)
- ✓ Portability: Receive your data in downloadable format
- ✓ Objection: Object to certain data processing
- ✓ Withdraw consent: Cancel previously granted consents
- ✓ Opt-out of advertising: Reject personalized advertising (when implemented)
Applicable laws according to your location
- 🇪🇺 European Union / EEA / United Kingdom: GDPR and UK GDPR grant broad rights including portability, limitation of processing. Additionally, you have the right to file a complaint with your supervisory authority if you consider we have violated your data protection rights, without prejudice to any other administrative or judicial remedy. You can contact authorities directly such as AEPD (Spain), ICO (United Kingdom), or other EU/EEA authorities in your country of residence.
- 🇺🇸 United States: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), TDPSA (Texas), and other state laws grant rights of access, correction, deletion, portability, and opt-out of sale/sharing of data. Include right to non-discrimination and to appeal denials.
- 🇧🇷 Brazil: LGPD grants rights of confirmation, access, correction, anonymization, deletion, portability, information about sharing, and consent revocation.
- Other jurisdictions: If you reside in another country with data protection laws, you may have additional rights. Contact us at [email protected].
12. How to Exercise Your Rights
12.1 From Your Account
Go to Settings → Privacy and Security to:
- View and edit your personal information
- Download your data: Request a complete export including posts, collectibles, messages, comments, activity history, and more (see detailed process below)
- Delete your account permanently
- Manage preferences for privacy, cookies and notifications
📥 Data download process:
- Click "Download my data" in Settings
- You will receive a verification code in your email
- Enter the code to confirm your request
- Your data will be available within a maximum of 30 days
- You will receive an email with download link (valid for 7 days)
- The file includes all your data in downloadable JSON format
Note: You can only have one active request at a time. If you already have one in process, wait for it to complete before requesting another.
12.2 By Email
For special requests (correction of specific data, partial deletion, portability to another service, etc.), send an email to [email protected] indicating:
- Your full name and username
- Email associated with your account
- Right you wish to exercise (access, rectification, deletion, portability, objection)
- Detailed description of your request
Response times: 30-45 days depending on your location (GDPR: 30 days; CCPA: 45 days). We will verify your identity via email code before processing sensitive requests.
12.3 Additional Rights
- Authorized agents: You can designate a legal representative to submit requests on your behalf (requires power of attorney)
- Appeals (U.S.): If we reject your request, you can appeal by writing to [email protected] with subject "Appeal". We will respond within 45 days, or the period required by applicable law
- Privacy signals: We recognize Global Privacy Control (GPC) and Global Privacy Platform (GPP) for automatic advertising opt-out
13. Marketing and Promotional Communications
13.1 Opt-in (prior consent)
For users in the European Union, European Economic Area, United Kingdom and other jurisdictions that require it, we request your explicit consent (opt-in) before sending you marketing communications, such as:
- Newsletters with product news
- Special promotions and offers
- Educational collecting content
- Surveys and user feedback
13.2 Opt-out (unsubscribe)
You can unsubscribe from marketing communications at any time by:
- "Unsubscribe" link in each marketing email
- Account settings: Settings → Notifications → Disable "Promotional emails"
- Email: [email protected] with subject "Unsubscribe marketing"
13.3 Transactional Communications (non-cancelable)
Some communications are essential for service operation and cannot be cancelled while you maintain your active account:
- Registration confirmations and email verification
- Password reset
- Security notifications (new device, account changes)
- Payment confirmations and invoices
- Changes to Terms and Conditions or Privacy Policy
- Account closure or suspension notices
14. Sale and Sharing of Data (U.S.)
Museum App does not sell your personal data in the traditional sense. However, certain U.S. laws (CCPA/CPRA, Virginia, Colorado, Connecticut, Texas, etc.) define "sale" broadly, including sharing data with advertising networks for behavioral advertising.
Since we use advertising that may qualify as "sale" under these laws:
- Automatic opt-out: We recognize privacy preference signals such as Global Privacy Control (GPC) and Global Privacy Platform (GPP)
- Account control: You will be able to manage advertising preferences from Settings → Privacy → Advertising preferences
- Non-discrimination: We will not deny you service or charge different prices for exercising your privacy rights
You can manage these preferences in Settings → Privacy → Advertising preferences or through browser signals (GPC/GPP). We will also provide a "Do not sell/share my personal information" link when required by applicable state law.
15. Automated Decisions and Profiling
Museum App may perform basic profiling to improve your experience, including:
- Classify your collecting thematic preferences based on your activity
- Recommend relevant users, categories or content
- Detect and limit spam, fraud or suspicious activity
- Select contextual or personalized ads (only with your consent when legally required)
We DO NOT make automated decisions that produce significant legal effects on you or similarly affect you without human intervention, unless:
- It is necessary for contract performance with you
- It is authorized by applicable law
- You have given your explicit consent
If you have questions about how we use profiling or automated decisions, contact us at [email protected].
16. Changes to This Privacy Policy
Museum App reserves the right to update or modify this Privacy Policy at any time. When we make changes:
16.1 Notification of Changes
Minor changes: We update the "Last updated" date at the beginning of this Policy
Material changes: We will notify you by:
- Email to your registered address
- Prominent notification in the application (banner or pop-up)
- Notice on our website
16.2 Effective Date
Changes will take effect on the date indicated at the top of this Policy ("Last updated"). Your continued use of the service after the effective date constitutes your acceptance of the changes.
16.3 Version History
You can request previous versions of this Privacy Policy by sending an email to [email protected].
16.4 Third-Party Services - Geolocation
This site uses GeoLite2 Data created by MaxMind, available at https://www.maxmind.com. This service allows us to detect your country of origin to comply with applicable privacy regulations (GDPR, CCPA, LGPD).
17. Contact
If you have questions, comments or concerns about this Privacy Policy or about how we process your personal data, contact us at:
Museum App Inc.
7971 Riviera Blvd Ste 204
Miramar, FL 33023
United States
Contact email: [email protected]
We will do our best to respond to your inquiry within a reasonable timeframe (generally 5-10 business days for general inquiries; specific legal deadlines for privacy rights requests).