Privacy Policy

1. Introduction

This Privacy Policy explains how appavailability.com (the “Site”), operated by NASTASIU HOLDING SRL (the “Operator”, “we”, “us”), collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian data protection legislation.

Effective date: July 31, 2026

2. Data Controller

The data controller responsible for your personal data is:

NASTASIU HOLDING SRL
EUID: ROONRC.J2021002796227
DUNS: 448860249
VAT ID: RO44775939
Email: andrew@appavailability.com

3. Data We Collect

3.1 iOS App Store Checker

When you use the iOS App Store Checker, we collect the following data for each analysis:

  • The App Store URL or App ID you submit.
  • Your IP address, approximate location (country, city, region as provided by network headers), browser user agent, referrer URL, and preferred language.

This data is included in notification emails sent to the Operator to monitor usage and detect abuse. No personal data is sent to Apple. Only the App ID and country codes are used to query Apple's public APIs.

Checks made without an account are not stored in a database; the data above appears only in those notification emails. Checks you run while signed in are also saved to your account so you can revisit the report, as described in Section 3.5.

3.2 Referral Tracking

If you arrive at the Site via a link containing a ?ref= parameter, the referral source value along with your IP address, user agent, referrer, and language are sent to the Operator via email. This is used to understand how visitors discover the Site.

3.3 Analytics

The Site uses Google Analytics 4 (GA4) with Consent Mode v2. Before you grant consent, GA4 operates in cookieless mode: it sends anonymous pings to Google without setting cookies or using identifiers. After you explicitly accept analytics via the cookie banner, GA4 sets standard analytics cookies and collects usage data such as pages visited, session duration, and device information.

Advertising features are permanently disabled. The ad_storage, ad_user_data, and ad_personalization consent signals remain denied at all times.

3.4 Server Logs and Rate Limiting

Your IP address is used for rate limiting to prevent abuse of the Site's services. Rate limit data is held in server memory only and is automatically cleared after the rate limit window expires (up to 24 hours). IP addresses may also appear in standard server logs managed by the hosting provider.

3.5 Account and Usage Data (Registered Users)

If you create an account, we collect and store the following to provide your account and the credit-based checking service:

  • Your email address and, if you provide one, your display name.
  • A unique account identifier and authentication data managed by Google Firebase Authentication.
  • Your plan, your credit balance, and a ledger of credit transactions (grants, usage, and adjustments).
  • Reports of checks you run while signed in (the apps and storefronts checked and their results), so you can revisit them.

This account and usage data is stored in Google Cloud Firestore and processed by Google Cloud Functions. This infrastructure is hosted within the European Union: the Cloud Functions run in Google's europe-west3 (Frankfurt, Germany) region, and the Cloud Firestore database is located in the European Union. See Section 9 for more on data location and international transfers.

3.6 Payment and Billing Data (Paid Plans)

If you subscribe to a paid plan, payment is processed by Stripe, which acts as merchant of record for the transaction. Stripe collects the data needed to take the payment and to meet its own tax and anti-fraud obligations, which typically includes your name, billing address and country, your email address, any tax identification number you provide, and your payment card or other payment method details.

We never receive or store your full card details. What we store on our side is limited to the information needed to run your subscription: your Stripe customer and subscription identifiers, your plan, the billing interval, the subscription status and the date your access runs to. We also receive, and may retain in our administrative records, the billing country, billing name and amount associated with a payment.

Because Stripe is the merchant of record, it acts as an independent controller for the payment itself, under its own privacy policy, and not solely as our processor.

3.7 Scheduled Monitoring and Alert Emails

If you enable monitoring for a saved app, we store the monitoring configuration (the app, the storefronts you selected, the frequency, whether alerts are switched on, and when the next check is due), the results of each scheduled check, and a record of the changes detected between one check and the next.

When a change is detected and alerts are enabled, we send an email to your account email address. These are service messages tied to a feature you switched on, not marketing. You can stop them at any time by turning off alerts or monitoring for that app. Outbound email is delivered through our email infrastructure as described in Section 6.

4. Legal Basis for Processing

Under GDPR Article 6, we process your personal data on the following legal bases:

  • Consent (Art. 6(1)(a)): for analytics cookies (Google Analytics 4). You can withdraw consent at any time by clearing your browser storage or declining via the cookie banner.
  • Legitimate interest (Art. 6(1)(f)): for security measures including rate limiting, HMAC token validation, and security event logging. Our legitimate interest is to protect the Site from abuse and ensure its availability.
  • Performance of a contract (Art. 6(1)(b)): to create and operate your account and provide the credit-based checking service you register for, including the account and usage data stored in Google Firebase (Section 3.5), to take payment and manage your subscription (Section 3.6), and to run the scheduled checks and alert emails you enable (Section 3.7).
  • Legal obligation (Art. 6(1)(c)): to keep the accounting and tax records required of us in relation to payments, for the period required by applicable Romanian and EU law. This is why some billing records are retained even after an account is deleted (Section 7).

5. Cookies and Local Storage

Cookies

The Site itself does not set any cookies. If you accept analytics via the cookie banner, Google Analytics 4 sets the following cookies:

  • _ga: distinguishes users (expires after 2 years).
  • _ga_*: maintains session state (expires after 2 years).

These cookies are only set after you explicitly grant consent. If you decline, no cookies are set.

Local Storage

The Site uses browser local storage for the following purposes. This data is stored only on your device and is never sent to our servers:

  • analytics-consent: stores your cookie consent preference.
  • appStoreCheckHistory: stores your recent iOS App Store Checker search history (app names and IDs only, up to 20 entries).

6. Third-Party Services

We use the following third-party services that may process data:

ServicePurposeData Shared
Google Analytics 4Usage analyticsCookieless pings before consent; standard analytics data after consent
Apple APIsApp data retrievalApp ID and country codes only (no personal data)
Google Firebase (Authentication, Firestore, Cloud Functions)Accounts, database, and backend for the credit-based serviceAccount email and identifier, plan and credit balance, usage and transaction history, and reports of signed-in checks. Stored in the EU (europe-west3, Frankfurt).
StripePayment processing and subscription billing, as merchant of recordName, billing address and country, email address, any tax identification number, and payment method details. Collected by Stripe; we never receive full card details.
Email delivery (Firebase Trigger Email extension and our SMTP provider)Sending account, billing and availability alert emailsYour email address and the contents of the message being sent
DataHost (hosting)Web hosting infrastructure and outbound mailAll data passes through their servers as part of hosting

7. Data Retention

  • Rate limit data: held in server memory only, automatically cleared after the rate limit window expires (maximum 24 hours).
  • Server logs: managed and retained by the hosting provider (DataHost) according to their policies.
  • Notification emails: retained by the Operator in their email account.
  • Analytics data: retained by Google according to the GA4 data retention settings configured by the Operator.
  • Account and usage data: stored in Google Firestore (in the European Union) for as long as your account remains active. When you delete your account from your settings the data is erased immediately, subject to the billing records exception below. If you ask us to delete it by email instead, we act within 30 days.
  • Billing and accounting records: records of payments, invoices and the data they contain are retained for the period required by Romanian and EU accounting and tax law, which is longer than the 30 day account deletion window above and applies even after you close your account. Stripe retains its own transaction records under its own policy.
  • Monitoring data: monitor configurations, scheduled check results and detected changes are retained while monitoring is enabled and are removed with your account data when the account is deleted.

Anonymous checks made without an account are not stored in a database; the data described in Section 3.1 appears only in notification emails. Account and usage data for registered users is stored in Google Firestore as described in Section 3.5.

8. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to erasure: request deletion of your personal data.
  • Right to restriction: request that we limit processing of your data.
  • Right to data portability: request your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interest.
  • Right to withdraw consent: withdraw your analytics consent at any time by clearing browser storage or declining cookies.

To exercise any of these rights, contact us at andrew@appavailability.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP).

9. International Data Transfers

Some of the third-party services we use are based in the United States:

  • Google (Analytics): transfers are covered under the EU-US Data Privacy Framework.

Your account and usage data held in Google Firebase (Authentication, Firestore, and Cloud Functions) is stored and processed within the European Union: the Cloud Functions run in the europe-west3 (Frankfurt, Germany) region and the Firestore database is located in the European Union. Google acts as our processor. To the extent Google's global operations may involve access from outside the EU, such transfers are covered by the EU-US Data Privacy Framework and/or Standard Contractual Clauses.

Stripe, which processes payments for paid plans, is a US-headquartered company that operates through European entities and may process payment data both inside and outside the European Union. Stripe relies on the EU-US Data Privacy Framework and/or Standard Contractual Clauses for such transfers, as set out in its own privacy policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the effective date at the top of this page. We encourage you to review this page periodically.

11. Contact

For any questions or requests regarding this Privacy Policy or your personal data, contact us at andrew@appavailability.com.