Privacy Policy
Last updated: 12 March 2026
NanaShop ("we", "us", "our") is an AI-powered mobile shopping assistant app. This Privacy Policy explains what personal data we collect, how we use it, and your rights. By using NanaShop, you agree to this policy.
1. Who We Are
NanaShop is a mobile application available on Android and iOS, built with Flutter and powered by Google Firebase.
2. Data We Collect
Account & Identity Data
-
Full name, email address, and profile photo collected via Google Sign-In and Firebase Authentication
Shopping & App Activity
-
Products viewed, searched, added to cart, and ordered — stored in Cloud Firestore
-
AI preference history and personalised recommendation data
Device Identifiers
Yes — NanaShop does collect the following device identifiers automatically through Firebase:
-
Firebase Installation ID (FID) — a unique identifier assigned to your app installation by Firebase, used by Firebase Cloud Messaging, Analytics, and App Check
-
Advertising Identifier (IDFA/GAID) — collected by Firebase Analytics on Android (Google Advertising ID) and iOS (IDFA) to help measure app usage and ad performance
-
FCM Registration Token — a device-specific token used to deliver push notifications to your device
These are collected automatically when you use the app and cannot be disabled without turning off the relevant Firebase services.
Usage & Analytics Data
-
App events, session duration, screen views, device model, OS version, and language — collected via Firebase Analytics
Voice Input
-
Voice queries processed via on-device speech-to-text — audio is not sent to our servers
Local Storage
-
Cached data stored on-device using SQLite (Drift) for offline functionality
3. How We Use Your Data
-
To authenticate you securely via Google Sign-In and Firebase Auth
-
To power AI-driven personalised product recommendations
-
To sync your shopping data across devices via Cloud Firestore
-
To send you push notifications via Firebase Cloud Messaging
-
To analyse app performance and improve the experience via Firebase Analytics
-
To protect the app from abuse using Firebase App Check
-
To maintain offline functionality through local device storage
4. Third-Party Services
NanaShop uses the following third-party services, each governed by their own privacy policies:
-
Google Firebase (Auth, Firestore, Analytics, Messaging, App Check) — firebase.google.com/support/privacy
-
Google Sign-In — policies.google.com/privacy
-
Google Analytics for Firebase — policies.google.com/privacy
-
Google APIs (AI features) — policies.google.com/privacy
5. Device Identifiers — Google Play Data Safety
In accordance with Google Play's Data Safety requirements, NanaShop collects the following device identifiers:
IdentifierCollected ByPurpose
Firebase Installation IDFirebase CoreApp services, messaging, analytics
Advertising ID (GAID/IDFA)Firebase AnalyticsApp analytics and measurement
FCM Registration TokenFirebase MessagingPush notifications
These identifiers are shared with Google Firebase. They are not used for advertising purposes by NanaShop directly and are not sold to third parties.
6. Data Storage & Security
Your data is stored securely in Google Cloud (Firebase) infrastructure with:
-
Encryption in transit via TLS
-
Encryption at rest by Google Cloud
-
Firebase App Check to prevent unauthorised API access
-
Local data stored on-device via SQLite, inaccessible to other apps
7. Data Retention
-
Account & shopping data: Retained while your account is active; deleted within 30 days of an account deletion request
-
Analytics & identifier data: Retained per Firebase's default settings (up to 14 months)
-
Local/cached data: Cleared on app uninstall or account deletion
8. Your Rights
-
Access the personal data we hold about you
-
Correct inaccurate data via your account settings
-
Delete your account and all associated data — visit our Account Deletion page
-
Opt out of push notifications via your device settings
-
Limit ad tracking via your device's advertising settings (iOS: Settings → Privacy → Tracking; Android: Settings → Google → Ads)
-
Revoke Google Sign-In access at myaccount.google.com/permissions
9. Children's Privacy
NanaShop is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at omar.al.qweider@oltrelabs.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or by email. Continued use of NanaShop after changes constitutes your acceptance of the updated policy.