How Mundia collects, uses, and protects your personal data.
The Mundia application is developed and managed independently.
For privacy-related requests: it.mundia.travel@gmail.com
Collected at account creation:
| Field | Required | Purpose |
|---|---|---|
| Yes | Account identification, OTP verification, password reset | |
| Password | Yes | Authentication (server-side hashed, never in plain text) |
| Username | Yes | Unique public identifier |
Collected after email verification (optional, updatable):
| Field | Purpose |
|---|---|
| Display name | Profile personalisation |
| Profile photo | Visual identity, stored on CDN |
| Bio | Public presentation |
| City / Location | Content personalisation |
| Countries visited | Passport feature, gamification |
For users with a business role:
| Field | Purpose |
|---|---|
| Business name | Public business profile |
| Description | Public visibility |
| Category | Search and filters |
| Address + GPS coordinates | Distance from users, map display |
| Logo | Visual identity |
| Menu (categories and items) | Storefront feature |
| Tags | Search and filters |
When location is collected:
Mode: only on explicit user request — no background tracking.
EXIF extraction: the app can extract GPS coordinates from photo EXIF metadata, with reverse geocoding to obtain address/city. The user can edit or remove the location before saving.
Permissions requested:
ACCESS_FINE_LOCATION — Android (precise GPS)ACCESS_COARSE_LOCATION — Android (network)NSLocationWhenInUseUsageDescription — iOSImages are compressed locally before upload.
| Type | Content |
|---|---|
| Travel diaries | Text, images, location, date/time, costs (currency + amount), collaborators |
| Travel guides | Title, text, images/video, geographic metadata |
| Comments / Likes / Saves | Interactions with others' content |
| Business feedback | Rating (liked: boolean) |
| User / content reports | Reason (spam, harassment, inappropriate, fake profile) + description |
Automatically collected server-side based on activity:
| Data | Storage | Purpose |
|---|---|---|
| JWT Access Token | SecureStore (iOS/Android) | API authentication |
| Refresh Token (per account) | SecureStore | Session renewal |
| Active accounts list | SecureStore (encrypted key) | Multi-account switching |
| Active account ID | SecureStore | Current session |
On web (fallback): AsyncStorage (not encrypted).
Collected internally (no third-party analytics SDKs):
| Event | Data sent |
|---|---|
| Guide view | Duration (seconds), device type (mobile/tablet), platform (ios/android/web) |
| Mission claim | Latitude, longitude, method (gps/photo) |
Not present: Firebase Analytics, Amplitude, Mixpanel, Sentry, or other third-party tracking libraries in the frontend.
| Purpose | Legal basis | Data involved |
|---|---|---|
| Account creation and management | Contract performance | Email, username, password |
| Authentication and session security | Legitimate interest | JWT, refresh token |
| Experience personalisation | Contract performance | Profile, preferences |
| Travel diary feature | Contract performance | Text, photos, location, date |
| Travel guide feature | Contract performance | Text, photos, location |
| Gamification and missions | Contract performance | Location, activity, XP |
| Push notifications | Consent | Push token, language |
| Content moderation | Legitimate interest (safety) | UGC, user reports |
| Nearby business search | Contract performance | Instant location |
| Internal guide analytics | Legitimate interest | View duration, device type |
| Business profile and storefront | Contract performance | Business data |
| Data type | Retention period |
|---|---|
| Account and profile | Until account deletion |
| Diaries and guides | Until the user or content is deleted |
| JWT Access Token | Short-lived (expires, renewed via refresh token) |
| Refresh Token | Until explicit logout or revocation |
| Push token | Until logout or device change |
| Moderation logs | Defined by server policy |
Users have the right to:
| Right | How to exercise it |
|---|---|
| Access | Full profile available in-app settings |
| Rectification | Edit profile via in-app settings |
| Erasure | Delete account via in-app settings — removes account and all data |
| Portability | Request via email to the data controller |
| Objection | Request via email to the data controller |
| Revoke notification consent | Disable in device settings; or log out to remove push token |
To exercise your rights: it.mundia.travel@gmail.com
Measures implemented:
Age requirements are defined by Apple App Store and Google Play Store policies. We do not knowingly collect data from minors. If a minor's account is identified, it will be deleted.
| Permission | Reason |
|---|---|
| NSLocationWhenInUseUsageDescription | Location for diaries, guides, missions and nearby business search |
| NSMicrophoneUsageDescription | Audio recording for travel diary |
| NSPhotoLibraryAddUsageDescription | Saving exported guides to gallery |
| NSPhotoLibraryUsageDescription | Photo selection for profile, diaries, guides |
| NSCameraUsageDescription | Photos for diaries and guides |
| NSFaceIDUsageDescription | Data protection with Face ID (SecureStore) |
| Permission | Reason |
|---|---|
| ACCESS_FINE_LOCATION | Precise GPS for missions and geotagging |
| ACCESS_COARSE_LOCATION | Approximate location |
| RECORD_AUDIO | Audio for travel diary |
| CAMERA | Photos for diaries and guides |
| READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE | Photo selection |
| WRITE_EXTERNAL_STORAGE | Saving exported videos |
Data may be transferred to and stored on servers located outside the EU (Google Cloud). Transfers are carried out in accordance with the safeguards provided by the GDPR (Standard Contractual Clauses or equivalent).
Material changes to this policy will be communicated via:
For complaints or reports, you may also contact the data protection authority (DPA) of your country of residence.