Privacy Policy

1. Introduction

This Privacy Policy explains how appavailability.com (the “Site”), operated by NASTASIU HOLDING SRL (the “Operator”, “we”, “us”), collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian data protection legislation.

Effective date: September 29, 2026

2. Data Controller

The data controller responsible for your personal data is:

NASTASIU HOLDING SRL
EUID: ROONRC.J2021002796227
DUNS: 448860249
VAT ID: RO44775939
Email: andrew@appavailability.com

3. Data We Collect

3.1 App Availability Checker

When you use the App Availability Checker, we collect the following data for each analysis:

  • The App Store or Google Play URL, App ID or package name you submit.
  • Your IP address, approximate location (country, city, region as provided by network headers), browser user agent, referrer URL, and preferred language.

This data is included in notification emails sent to the Operator to monitor usage and detect abuse. No personal data is sent to Apple or to Google. Only the app identifier you submit (an App Store ID or a Google Play package name) and country codes are used to query their public endpoints.

Checks made without an account are not stored in a database; the data above appears only in those notification emails. Checks you run while signed in are also saved to your account so you can revisit the report, as described in Section 3.5.

3.2 Referral Tracking

If you arrive at the Site via a link containing a ?ref= parameter, the referral source value along with your IP address, user agent, referrer, and language are sent to the Operator via email. This is used to understand how visitors discover the Site.

3.3 Analytics

The Site uses Google Analytics 4 (GA4) with Consent Mode v2. Before you grant consent, GA4 operates in cookieless mode: it sends anonymous pings to Google without setting cookies or using identifiers. After you explicitly accept analytics via the cookie banner, GA4 sets standard analytics cookies and collects usage data such as pages visited, session duration, and device information.

Advertising features are permanently disabled. The ad_storage, ad_user_data, and ad_personalization consent signals remain denied at all times.

3.4 Server Logs and Rate Limiting

Your IP address is used for rate limiting to prevent abuse of the Site's services. Rate limit data is held in server memory only and is automatically cleared after the rate limit window expires (up to 24 hours). IP addresses may also appear in standard server logs managed by the hosting provider.

3.5 Account and Usage Data (Registered Users)

If you create an account, we collect and store the following to provide your account and the credit-based checking service:

  • Your email address and, if you provide one, your display name.
  • A unique account identifier and authentication data managed by Google Firebase Authentication.
  • Your plan, your credit balance, and a ledger of credit transactions (grants, usage, and adjustments).
  • Reports of checks you run while signed in (the apps and storefronts checked and their results), so you can revisit them.

This account and usage data is stored in Google Cloud Firestore and processed by Google Cloud Functions. This infrastructure is hosted within the European Union: the Cloud Functions run in Google's europe-west3 (Frankfurt, Germany) region, and the Cloud Firestore database is located in the European Union. See Section 9 for more on data location and international transfers.

3.6 Payment and Billing Data (Paid Plans)

If you subscribe to a paid plan, payment is processed by Stripe, which acts as merchant of record for the transaction. Stripe collects the data needed to take the payment and to meet its own tax and anti-fraud obligations, which typically includes your name, billing address and country, your email address, any tax identification number you provide, and your payment card or other payment method details.

We never receive or store your full card details. What we store on our side is limited to the information needed to run your subscription: your Stripe customer and subscription identifiers, your plan, the billing interval, the subscription status and the date your access runs to. We also receive, and may retain in our administrative records, the billing country, billing name and amount associated with a payment.

Because Stripe is the merchant of record, it acts as an independent controller for the payment itself, under its own privacy policy, and not solely as our processor.

3.7 Scheduled Monitoring and Alert Emails

If you enable monitoring for a saved app, we store the monitoring configuration (the app, the storefronts you selected, the frequency, whether alerts are switched on, and when the next check is due), the results of each scheduled check, and a record of the changes detected between one check and the next.

When a check finds a change that matches an alert you set (an app becoming unavailable or available, a rating falling below your threshold, or a chart position leaving the top you chose), we email you. For each monitor you choose whether to also receive a report after every check, and you can turn off every monitor email at once in Settings. These are service messages tied to a feature you switched on, not marketing. Outbound email is delivered through our email infrastructure as described in Section 6.

3.8 Aggregate Usage Statistics

Separately from Google Analytics, we keep our own count of what the Site is used for: how many checks are started and completed, how many reports are exported or shared, how many times the app name checker is used, which App Store and Google Play apps are looked up, and what kind of site each visit came from. This is how we understand which parts of the Site are worth keeping and improving. From time to time we publish some of these counts on the Site, for example how many checks were run, on which store, how many countries they asked about and how often an app was listed everywhere it was checked, always as totals and never which app was looked up or who looked it up.

These records contain no identifier for you or your device. We do not store your IP address, your browser or device details, a session or visitor identifier, a cookie value, or your account identifier against them. Each record holds only the name of the action, the date it happened, and a small set of non-personal facts about it, such as the app identifier, how many countries were checked, and whether the person was signed in. For the app name checker, only the fact that it was used is counted: the name you type is not stored. For a visit, that is the kind of site you arrived from (for example a search engine, an AI assistant or a social site), that site's name when it is one of a fixed list we recognise, and the page you arrived on. The address of the page you came from never leaves your browser: it is reduced there to those words, and nothing else about it is sent to us. Because there is no identifier, these records cannot be traced back to you, linked to your account, or used to follow you between visits.

This counting does not use cookies, so it is not affected by your choice in the cookie banner. So that one action is not counted twice, your browser remembers what it has already reported until you close the tab. That memory stays on your device and holds no identifier. The records are held in Google Cloud Firestore in the European Union and are automatically deleted after 400 days.

4. Legal Basis for Processing

Under GDPR Article 6, we process your personal data on the following legal bases:

  • Consent (Art. 6(1)(a)): for analytics cookies (Google Analytics 4). You can withdraw consent at any time by clearing your browser storage or declining via the cookie banner.
  • Legitimate interest (Art. 6(1)(f)): for security measures including rate limiting, HMAC token validation, and security event logging. Our legitimate interest is to protect the Site from abuse and ensure its availability.
  • Performance of a contract (Art. 6(1)(b)): to create and operate your account and provide the credit-based checking service you register for, including the account and usage data stored in Google Firebase (Section 3.5), to take payment and manage your subscription (Section 3.6), and to run the scheduled checks and alert emails you enable (Section 3.7).
  • Legal obligation (Art. 6(1)(c)): to keep the accounting and tax records required of us in relation to payments, for the period required by applicable Romanian and EU law. This is why some billing records are retained even after an account is deleted (Section 7).

5. Cookies and Local Storage

Cookies

The Site itself does not set any cookies. If you accept analytics via the cookie banner, Google Analytics 4 sets the following cookies:

  • _ga: distinguishes users (expires after 2 years).
  • _ga_*: maintains session state (expires after 2 years).

These cookies are only set after you explicitly grant consent. If you decline, no cookies are set.

Local Storage

The Site uses browser local storage for the following purposes. This data is stored only on your device and is never sent to our servers:

  • analytics-consent: stores your cookie consent preference.
  • appStoreCheckHistory: stores your recent App Availability Checker search history (app names and IDs only, up to 20 entries).

6. Third-Party Services

We use the following third-party services that may process data:

ServicePurposeData Shared
Google Analytics 4Usage analyticsCookieless pings before consent; standard analytics data after consent
Apple APIsApp Store data retrievalApp ID and country codes only (no personal data)
Google PlayGoogle Play data retrievalPackage name and country codes only (no personal data)
Google Firebase (Authentication, Firestore, Cloud Functions)Accounts, database, and backend for the credit-based serviceAccount email and identifier, plan and credit balance, usage and transaction history, and reports of signed-in checks. Stored in the EU (europe-west3, Frankfurt).
StripePayment processing and subscription billing, as merchant of recordName, billing address and country, email address, any tax identification number, and payment method details. Collected by Stripe; we never receive full card details.
Email delivery (Firebase Trigger Email extension and our SMTP provider)Sending account, billing and availability alert emailsYour email address and the contents of the message being sent
DataHost (hosting)Web hosting infrastructure and outbound mailAll data passes through their servers as part of hosting

7. Data Retention

  • Rate limit data: held in server memory only, automatically cleared after the rate limit window expires (maximum 24 hours).
  • Server logs: managed and retained by the hosting provider (DataHost) according to their policies.
  • Notification emails: retained by the Operator in their email account.
  • Analytics data: retained by Google according to the GA4 data retention settings configured by the Operator.
  • Aggregate usage statistics: stored in Google Firestore (in the European Union) and automatically deleted 400 days after they are recorded. They carry no identifier for you or your device (Section 3.8).
  • Account and usage data: stored in Google Firestore (in the European Union) for as long as your account remains active. When you delete your account from your settings the data is erased immediately, subject to the billing records exception below. If you ask us to delete it by email instead, we act within 30 days.
  • Billing and accounting records: records of payments, invoices and the data they contain are retained for the period required by Romanian and EU accounting and tax law, which is longer than the 30 day account deletion window above and applies even after you close your account. Stripe retains its own transaction records under its own policy.
  • Monitoring data: monitor configurations, scheduled check results and detected changes are retained while monitoring is enabled and are removed with your account data when the account is deleted.

Anonymous checks made without an account are not stored in a database; the data described in Section 3.1 appears only in notification emails. Account and usage data for registered users is stored in Google Firestore as described in Section 3.5.

8. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to erasure: request deletion of your personal data.
  • Right to restriction: request that we limit processing of your data.
  • Right to data portability: request your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interest.
  • Right to withdraw consent: withdraw your analytics consent at any time by clearing browser storage or declining cookies.

To exercise any of these rights, contact us at andrew@appavailability.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP).

9. International Data Transfers

Some of the third-party services we use are based in the United States:

  • Google (Analytics): transfers are covered under the EU-US Data Privacy Framework.

Your account and usage data held in Google Firebase (Authentication, Firestore, and Cloud Functions) is stored and processed within the European Union: the Cloud Functions run in the europe-west3 (Frankfurt, Germany) region and the Firestore database is located in the European Union. Google acts as our processor. To the extent Google's global operations may involve access from outside the EU, such transfers are covered by the EU-US Data Privacy Framework and/or Standard Contractual Clauses.

Stripe, which processes payments for paid plans, is a US-headquartered company that operates through European entities and may process payment data both inside and outside the European Union. Stripe relies on the EU-US Data Privacy Framework and/or Standard Contractual Clauses for such transfers, as set out in its own privacy policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the effective date at the top of this page. We encourage you to review this page periodically.

11. Contact

For any questions or requests regarding this Privacy Policy or your personal data, contact us at andrew@appavailability.com.