PRIVACY NOTICE
Service Application: Phone Number Tracker: Location (“Service”)
Data Controller Entity: ONSOFFOUR OÜ (Address: Rotermanni tn 6, 1011 Tallinn, Estonia)
Contact Email: info@onsof-four.com
Last Updated: September 11, 2026
1. ACCESS ELIGIBILITY & MANDATORY PROTOCOLS
1.1 Legal Acceptance: By accessing the Service, you confirm that you have read, understood, and consented to this policy and the associated data processing routines.
1.2 Mandatory Exit Conditions: If you do not accept these terms, you must immediately:
- Delete your user account and request data erasure via info@onsof-four.com.
- Cancel all active auto-renewing subscriptions.
- Uninstall and remove the application from all owned devices.
1.3 Age Requirement: Access is restricted to individuals aged 18 or older. We do not knowingly process data from minors. If minor data collection is identified, contact info@onsof-four.com for immediate removal.
1.4 Data Minimization Standard: Collection is limited strictly to data necessary for operational purposes, maintaining accuracy and integrity.
2. DATA COLLECTION & PROCESSING MODULES
Module A: Directly Provided Data
- Account Identifiers: Name, phone number, and age provided during registration, newsletter sign-up, or support contact.
- Location Sharing Information: Precise (GPS coordinates) and approximate (IP-based) location data, collected actively or in the background based on system permissions to enable location sharing.
- Support Inquiries: Information provided directly when contacting the support team.
Module B: Automatically Telemetered Data
- Technical Device Parameters: IP address, time zone, language settings, device model/type, OS version, hardware ID, ISP, mobile carrier, and unique identifiers (IDFA/GAID).
- Usage & Log Analytics: Views, features accessed, session duration, interaction frequency, and app performance logs (crashlytics, diagnostics).
- Attribution Data: Referring application, URL, or advertisement information used to locate the Service.
- Cookies & Tracking Software: Embedded SDKs and cookies used for traffic analysis, ad optimization, and chat features.
- Meta Pixel Integration: Direct integration with Facebook servers to track user actions, measure ad campaign performance, and personalize ad content based on consent.
Module C: Third-Party Financial & Store Data
- Subscription Records: Transaction IDs, subscription duration, expiration dates, product types, purchase amounts, and payment methods received from payment processors. (Full credit card numbers are never stored or accessed).
- Apple App Store Consumption Data: Data provided by Apple including account tenure, App Account Token (UUID), lifetime spending/refunds, consumption status, platform, and play time for fraud prevention and refund verification.
Module D: Strictly Excluded Categories
- We do not collect special categories of data such as race, ethnicity, political opinions, religious/philosophical beliefs, trade union membership, genetic/biometric data, health/sex life details, or criminal record history.
3. PROCESSING PURPOSES & LAWFUL BASES
Operational Purpose | Primary Data Utilized | Legal Basis (GDPR / Privacy Laws) |
Profile Creation & User Identification | Identifiers, Name, Email | Contract Performance / User Consent |
Core Location Tracking & Sharing | GPS Geolocation, IP Address | Contract Performance / User Consent |
Service Improvement & Telemetry | Device Data, Usage Logs, Diagnostics | Contract Performance / Legitimate Interest |
Subscription Verification & Management | Transaction & Subscription Records | Contract Performance / User Consent |
Fraud Prevention & Refund Verification | App Store Consumption Information | Legitimate Interest / User Consent |
Targeted Marketing & Attribution | Referral Data, Device Identifiers | Legitimate Interest / User Consent |
Legitimate Interest Scope: Used for measured app promotion, user behavior analysis, targeted ad delivery, legal defense against claims, and enforcement of terms.
4. DATA SHARING & THIRD-PARTY ECOSYSTEM
Data is processed by vetted third-party vendors strictly bound by confidentiality and operational instructions:
- Infrastructure & Analytics: Apple Inc., Google LLC (Firebase & Google Analytics), Amplitude Inc., Functional Software Inc. (Sentry), AppsFlyer Ltd., Meta Platforms Inc., TikTok Inc., Snap Inc., Amazon Web Services, Microsoft (Bing), Supabase Inc., Upstash Inc., 84codes AB (CloudAMQP), Elasticsearch B.V., Fly.io Inc., Artia International S.R.L. (IP-API).
- Legal Disclosures: Data may be disclosed to law enforcement, legal bodies, or regulatory authorities to satisfy statutory mandates or protect core legal rights.
- Corporate Transactions: Personal data may be transferred as part of business assets during a merger, acquisition, asset sale, or restructuring.
5. INTERNATIONAL DATA TRANSFERS & RETENTION
- Cross-Border Transfers: Data transferred outside the EEA is protected using European Commission Standard Contractual Clauses (SCCs) or Adequacy Decisions.
- Security Controls: SSL encryption, restricted access permissions, and formal breach notification procedures are maintained.
- Retention Logic: Data is kept only as long as necessary to maintain active accounts, resolve disputes, satisfy tax/legal obligations, or enforce agreements.
6. REGIONAL USER RIGHTS GUIDELINES
Requests to exercise privacy rights can be sent to info@onsof-four.com. Identity verification requires account details (e.g., account creation date, subscription purchase date, email).
A. EEA & UK Residents
- Available Rights: Access, Rectification, Erasure ("To Be Forgotten"), Processing Restriction, Data Portability, Objection, and Consent Withdrawal.
- Regulatory Oversight: File complaints directly with your local DPA or the UK Information Commissioner's Office (www.ico.org.uk / 0303 123 1113).
B. United States Residents
- Response Timelines: Handled within 30–60 days, with potential 30-day extensions. Unresolved issues may be directed to the Federal Trade Commission (FTC).
- State-by-State Rights Summary:
- Access & Deletion & Portability: California, Colorado, Connecticut, Indiana, Iowa, Montana, Tennessee, Texas, Utah, Virginia.
- Data Correction & Automated Decision Opt-Out: California, Colorado, Connecticut, Indiana, Montana, Tennessee, Texas, Virginia.
- Targeted Advertising / Sales Opt-Out: Available across applicable state regimes.
- California Specifics: Opt-out of sensitive data processing, Private Right of Action for data breaches, and annual "Shine the Light" requests via subject line "Request for California Shine the Light Privacy Information".
- Do Not Track (DNT): Automated browser DNT signals are not currently supported.
C. Canadian Residents
- Subject to federal and provincial privacy laws (including PIPEDA). Complaints may be directed to the Office of the Privacy Commissioner of Canada.