RooPouch

Privacy notice

In force: 11 September 2026 · RooPouch 1.0

RooPouch is a loyalty-card wallet. It is built to work without an account, entirely on your own device, by default. This notice describes what data the app handles, where it is stored, and how you can have it deleted.

1. The controller

Nowu e.U.
Dr.-Natterer-Gasse 2-4/8/R1, 1020 Vienna, Austria
Company register number: 654383d
Email: [email protected]

RooPouch is operated by Nowu e.U. For any question about data protection, this address reaches us.

2. What the app stores on your device

Without an account (guest use), all data stays on your device and never leaves it:

The app does not send this data to a server, does not share it with third parties, and does not put it into the operating system's own cloud backup either (on Android, cloud backup and device transfer are explicitly turned off).

3. Camera

Camera access is requested only to scan a barcode or QR code. The app takes and stores no photographs, uploads no images, and never opens a link on its own from a scanned code. Camera permission can be refused at any time — you can also type the code in by hand.

4. Location

Using location is optional and has to be switched on separately for each card. If you switch it on, the app saves the approximate position of that moment alongside the card, so it can later bring that card forward when you are nearby. The position stays on the device, is not sent to a server, and is not synchronised into the account wallet. The app requests coarse location only, never precise GPS. Refusing location permission affects nothing else in the app.

5. If you create an account (optional cloud backup)

An account is only needed if you want to reach your cards on another device. In that case we handle:

Storage and authentication run through Supabase, in a European Union (Frankfurt) data centre. Row-level security means only your own account can reach your rows. Transfer runs over an encrypted (HTTPS) connection.

6. What we do not do

7. How long we keep it

Data on the device stays until you delete it — card by card in the app, or all at once by removing the app. Data belonging to an account is handled until the account is deleted.

8. Your rights

Under the GDPR you may request a copy of the data held about you, its correction or erasure, a restriction of processing, and you may object to the processing. To delete an account — together with every card in it — write to [email protected]; we act on the request within 30 days.

The controller is a business registered in Austria, so the supervisory authority is the Austrian data protection authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna). You may also complain to the authority where you live: in Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).

9. Children

The app is not made for children and does not knowingly collect data about users under 13.

10. Changes to this notice

If this notice changes materially, the amended text is published on this page and the date above is updated.

This is a translation. In case of any discrepancy, the Hungarian version prevails.