Legal
Privacy Policy
Effective date: June 22, 2026 Last updated: June 22, 2026
1. Who we are
Data controller: 90 Labs LLC (“Majat”, “we”, “us”), registered in the Republic of Kosova. Contact email: majat@90labs.llc Postal address: Ismail Raka 209, 71000 Kaçanik, Kosova
If you have questions about this policy, want to exercise your rights, or wish to file a complaint, contact us first using the email above.
2. Scope
This policy applies to the Majat mobile application (“the App”) on iOS and Android, and to any related backend services we operate. It does not apply to third-party services that you reach by tapping links inside the App (those have their own policies).
3. Information we collect
3.1 Information you give us directly
- Account details: email address, first and last name, phone number (optional), gender, date of joining, profile picture, cover picture.
- Profile location: the city and country you choose during onboarding (Albania and Kosova at launch).
- Authentication credentials: for email/password sign-in. We do not see your password — Firebase Authentication hashes it server-side. For Google Sign-In and Sign in with Apple we receive only the basic profile data those providers return (email, name, opaque user ID).
- Hikes and expeditions you create: title, description, route, dates, photos, meeting points.
- Chat messages: text you send in organization, hike, or expedition chats.
- Reviews: star rating and comment after a hike.
3.2 Information collected automatically
- Device information: Firebase Cloud Messaging registration token (so we can deliver push notifications), device type, operating system version. We do not collect IP addresses for tracking.
- Crash reports (only if you consent): stack traces and device state at the moment of a crash, sent to Firebase Crashlytics. Helps us fix bugs.
- Analytics events (only if you consent): events such as “hike_viewed”, “hike_joined”, “country_changed”, with no personal content. Sent to Firebase Analytics.
- Subscription state: RevenueCat tells us whether your premium subscription is active, the product ID, and expiry. We do not see your card or billing details — those stay with Apple or Google.
3.3 Location
The App requests foreground location permission only (when in use). Your precise GPS location is read on the device when:
- you ask the App to suggest hikes near you,
- you set or move a meeting point on the map,
- you record a completed route.
The location is sent to our backend only when you save a hike or meeting point you create. It is never collected in the background, and we have no way to track you when the App is closed.
For geocoding (converting coordinates ↔ city names), we send anonymous coordinates to OpenStreetMap’s Nominatim service. No personal data is sent.
4. Why we use your information
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account | Account details | Contract performance |
| Show hikes, let you join, manage participants | Account details, location, hike data | Contract performance |
| Deliver chat messages and notifications | Chat content, FCM token | Contract performance |
| Bill subscriptions and gate premium features | Subscription state | Contract performance |
| Diagnose crashes and improve the App | Crash reports | Consent (Art. 6(1)(a)) |
| Understand feature usage | Analytics events | Consent (Art. 6(1)(a)) |
| Prevent fraud, abuse, and spam | Account details, rate-limit data | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations | Various | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent for crash reporting and analytics at any time in Settings → Privacy.
5. Sharing your information
We do not sell your personal data. We share data only with the following processors, all under written data-processing agreements:
| Recipient | Purpose | Location |
|---|---|---|
| Google LLC (Firebase Auth, Firestore, Realtime Database, Storage, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, App Check, Remote Config) | Backend hosting and core platform services | EU + United States |
| RevenueCat, Inc. | Subscription state management | United States |
| Apple Inc. | Push notification delivery (iOS), App Store payment processing | EU + United States |
| Google LLC (separate from Firebase) | Push notification delivery (Android), Play Store payment processing | EU + United States |
| OpenStreetMap Foundation (Nominatim) | Coordinates ↔ city name conversion (no personal data sent) | EU |
For transfers outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses (SCCs).
We may also disclose data when legally required (court order, lawful authority request) or to protect the rights and safety of our users.
6. How long we keep your data
| Data | Retention |
|---|---|
| Account profile | Until you delete the account |
| Hike, expedition, organization data | Until the creator deletes it; soft-deleted entries are anonymized after 30 days |
| Chat messages | 90 days after the related hike/expedition ends; permanent for organization chats unless you leave |
| Crash reports | 90 days |
| Analytics events | 14 months |
| Subscription state | Until you cancel + 12 months for accounting |
| FCM token | Until logout or token rotation |
7. Your rights
Under the GDPR and Kosova’s Law No. 06/L-082 on Protection of Personal Data, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (“right to be forgotten”) — you can do this yourself in Settings → Delete account;
- Restrict or object to certain processing;
- Portability — receive your data in a structured, machine-readable format;
- Withdraw consent for analytics/crashlytics at any time in Settings;
- Lodge a complaint with the Information and Privacy Agency of Kosova (Agjencia për Informim dhe Privatësi) at https://aip.rks-gov.net, or with your local EU supervisory authority.
To exercise any right except deletion (which is built into the App), email majat@90labs.llc. We respond within 30 days.
8. Account deletion
You can delete your account from Settings → Delete account. When you confirm:
- Your authentication record is removed from Firebase Authentication.
- Your user document is removed from Firestore.
- Hikes you created, organization records you own, and chat messages you sent are anonymized (your name replaced with “Deleted user”) rather than deleted, so participants who joined those hikes still have a coherent history.
- Your photos in Firebase Storage are deleted.
- Subscription receipts retained for 12 months for accounting compliance, then deleted.
Deletion is irreversible.
9. Security
We rely on Firebase’s encryption-at-rest and TLS-in-transit, role-based Firestore security rules (publicly viewable at firestore.rules in our source repository), Firebase App Check to attest only legitimate clients can talk to our backend, and rate limiting on sensitive operations. No system is perfectly secure; if you become aware of a vulnerability, please email majat@90labs.llc.
10. Children
Majat is not intended for users under 13 years old. We do not knowingly collect data from children under 13. If you believe a child has registered, contact us and we will delete the account.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated in the App (banner or in-app notification) at least 14 days before they take effect. The “Last updated” date at the top of this document always reflects the current version.
12. Contact
Questions, complaints, or requests:
- Email: majat@90labs.llc
- DPO email: majat@90labs.llc
- Postal: Ismail Raka 209, 71000 Kaçanik, Kosova