Overview
Chabatrading ("we," "us," "our," or "Company") is a UK-based research and development team operating from the University of Stirling Innovation Park. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website chabatrading.com, use any of our mobile applications published on the Apple App Store, Google Play Store, or any other distribution platform, or engage with our services (collectively, the "Services").
We are committed to protecting your privacy and handling your data transparently, in full compliance with the United Kingdom General Data Protection Regulation ("UK GDPR"), the European Union General Data Protection Regulation ("EU GDPR"), the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), the Lei Geral de Proteção de Dados ("LGPD") of Brazil, the Personal Information Protection and Electronic Documents Act ("PIPEDA") of Canada, Australia's Privacy Act 1988, the Personal Data Protection Act ("PDPA") of Singapore, and other applicable data protection laws worldwide.
Our Commitment: We follow a "local-first" architecture philosophy across all our products. Where technically feasible, your data resides on your device rather than on our servers. Cloud sync, when available, is opt-in, end-to-end encrypted, and you retain the encryption keys.
Definitions
For the purposes of this Privacy Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or erasure.
- "Controller" means the entity that determines the purposes and means of processing Personal Data. Chabatrading is the Controller for data processed on our website and within our published applications.
- "Processor" means an entity that processes Personal Data on behalf of the Controller.
- "User," "you," "your" refers to any individual accessing or using our Services.
- "Services" refers collectively to our website, mobile applications, and any related products.
- "Device" refers to any device used to access our Services, including smartphones, tablets, and computers.
- "Application" or "App" refers to any software published by Chabatrading on app distribution platforms.
Data We Collect
1. Data You Provide Directly
When you voluntarily submit information through our contact forms, newsletter sign-ups, or direct communications, we collect:
- Identity Data: First name, last name, username, or similar identifier.
- Contact Data: Email address, postal address, telephone number.
- Professional Data: Company name, job title, professional background (only when relevant to inquiries).
- Communication Data: The content of messages, feedback, support requests, and any attachments you choose to send.
- Marketing Data: Your preferences in receiving marketing communications from us and our third parties.
2. Data Collected Automatically
When you interact with our website or applications, we may automatically collect:
- Technical Data: IP address (anonymised where possible), browser type and version, operating system, device identifiers, mobile network information.
- Usage Data: Information about how you use our Services, including pages visited, time spent, navigation paths, click patterns, feature usage, and interaction timestamps.
- Performance Data: Crash logs, error reports, and performance metrics that help us diagnose issues and improve our Services.
3. Data Collected in Our Mobile Applications
Our mobile applications are built on a local-first architecture, which means most user-generated content (notes, documents, recordings, configurations, etc.) is stored exclusively on your device and is never transmitted to our servers unless you explicitly enable a sync feature. The data our applications may process on-device or sync (when explicitly enabled) includes:
- User-created content (encrypted at rest with keys held only by you)
- Application preferences and settings
- Optional cloud-encrypted backups (when user opts in)
- Anonymous, aggregated usage analytics (opt-in only, with no personal identifiers)
How We Use Data
We use your Personal Data only for purposes that are lawful, fair, and transparent. These purposes include:
- Service Provision: To operate, maintain, and improve our website and applications.
- Communications: To respond to your inquiries, send administrative information, and (with your consent) provide updates about our Services.
- Personalisation: To tailor content and features to your preferences.
- Analytics: To understand usage patterns and optimise user experience.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Security: To detect, prevent, and address fraud, security risks, and technical issues.
- Business Operations: For internal record-keeping, auditing, and analytics.
Legal Basis for Processing (GDPR)
Under the UK GDPR and EU GDPR, we process your Personal Data under the following legal bases:
| Legal Basis | Purpose |
|---|---|
| Consent (Art. 6(1)(a)) | Marketing communications, non-essential cookies, optional analytics |
| Contract (Art. 6(1)(b)) | Service provision, fulfilling your requests, project engagements |
| Legal Obligation (Art. 6(1)(c)) | Tax records, regulatory compliance, responding to lawful requests |
| Legitimate Interests (Art. 6(1)(f)) | Website security, fraud prevention, B2B communications, anonymised analytics |
| Vital Interests (Art. 6(1)(d)) | Emergency situations involving safety |
| Public Task (Art. 6(1)(e)) | Where applicable to research collaborations |
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to operate, analyse, and improve our Services. Cookies are small text files placed on your device. We categorise the cookies we use as follows:
Strictly Necessary Cookies
These cookies are essential for the website to function. They enable basic features such as page navigation, form submissions, and security. The website cannot function properly without these cookies.
Performance & Analytics Cookies
These cookies collect aggregated, anonymised information about how visitors use our website, helping us understand traffic patterns and improve user experience. We use Plausible Analytics (cookieless, privacy-first) as our primary analytics tool, which does not require cookies and does not collect personal data.
Functionality Cookies
These cookies remember choices you make (such as your preferred language) and provide enhanced, personalised features.
Targeting & Marketing Cookies
We do not use advertising or marketing cookies on our website. We do not engage in behavioural advertising or cross-site tracking on our web properties.
You can control cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Note that disabling cookies may affect the functionality of certain parts of our Services.
Advertising & Ad Networks in Our Applications
Some of our free mobile applications integrate third-party advertising networks to support ongoing development. These advertising networks may display advertisements within the apps. All advertising integrations are designed with strict privacy safeguards in compliance with Google Play Store policies, Apple App Store guidelines, GDPR, CCPA, and applicable regional regulations.
Important: Some of our apps are paid, ad-free applications. For ad-supported apps, you will always see a clear indication in the app store listing and within the app itself. Ad-supported apps always provide an in-app purchase option to remove ads and unlock premium features.
Advertising Compliance Framework
For all ad-supported applications, we implement the following compliance measures:
- Consent Management: We use Google's User Messaging Platform (UMP) SDK and equivalent consent frameworks to obtain explicit user consent before displaying personalised ads. For users in the European Economic Area (EEA), the United Kingdom, and other regions requiring prior consent, non-personalised ads are shown until consent is granted.
- Age-Appropriate Advertising: All ad requests include the
TAG_FOR_CHILD_DIRECTED_TREATMENTandMAX_AD_CONTENT_RATINGsignals as appropriate, in compliance with COPPA and Google Play Families Policy. - Data Minimisation: We do not share Personal Data with ad networks beyond what is strictly necessary for ad delivery.
- No Sensitive Data: Our apps never share sensitive data categories (health data, biometric data, financial account details) with ad networks.
- User Controls: Users can reset their advertising identifier (IDFA on iOS, GAID on Android) at any time through their device settings.
- Family-Friendly Standards: For apps in designed-for-families categories, we use only contextual (non-personalised) ads.
Types of Advertisements We Display
Our ad-supported applications may display the following types of advertisements, all provided by certified ad networks that comply with applicable platform policies and privacy laws:
1. Banner Ads
Static or animated banner advertisements displayed at fixed positions within the app interface (typically at the top or bottom of the screen). Banner ads are non-intrusive and allow users to continue using app features uninterrupted.
2. Interstitial Ads
Full-screen advertisements displayed at natural transition points within the app (e.g., between levels, after completing a task, or before accessing premium content). Interstitial ads can be dismissed with a clear close button and are never displayed in a way that interrupts critical user actions.
3. Rewarded Video Ads
Opt-in video advertisements that users can choose to watch in exchange for in-app rewards (such as unlocking premium features, extra content, virtual currency, or removing temporary limitations). Rewarded video ads are always user-initiated — we never auto-play them without explicit consent.
4. Native Ads
Ads that match the visual design and format of the surrounding content. Native ads are always clearly labelled as "Sponsored," "Advertisement," or "Promoted" to maintain transparency.
5. App Open Ads
Advertisements displayed when users open or return to the app. App open ads can be dismissed and are designed to load quickly without delaying access to app content.
6. Splash Ads
Short advertisements shown during app launch, similar to app open ads. Splash ads include a clear skip option and never block critical app functionality.
For each ad type, we ensure:
- Clear visual indicators that content is an advertisement
- Easy dismissal with a clearly visible close button
- Compliance with platform-specific frequency capping
- No deceptive practices (no "forced clicks" or hidden ad elements)
- Respect for user experience (no excessive ad density)
Advertising Partners & Networks
To support our ad-supported free applications, we may integrate with the following certified advertising networks and mediation platforms. Each partner is selected for its compliance with industry privacy standards, including GDPR, CCPA, COPPA, and platform-specific policies:
Primary Ad Networks
- Google AdMob (Google Mobile Ads SDK) — Google's mobile advertising platform for in-app ads. AdMob is a certified Google service that complies with GDPR and CCPA. Users can opt out of personalised ads through Google's Ads Settings.
- Google Ad Manager — Google's ad management platform for publishers, providing access to multiple ad exchanges.
- Google AdSense — For web-based advertising integrations where applicable.
Major Ad Networks & Exchanges
- Meta Audience Network (Facebook) — Meta's mobile ad network.
- Unity Ads — Unity Technologies' advertising platform, especially for games.
- AppLovin (MAX) — AppLovin's mobile ad mediation platform.
- ironSource — IronSource's ad mediation platform (now part of Unity).
- Vungle — Vungle's in-app video advertising platform.
- Chartboost — Chartboost's mobile games ad network.
- Tapjoy — Tapjoy's rewarded advertising platform.
- InMobi — InMobi's mobile ad platform.
- Pangle (Bytedance) — Pangle's ad network.
- Mintegral — Mintegral's programmatic ad platform.
- Liftoff (Vungle) — Liftoff's mobile ad solutions.
- AdColony — AdColony's in-app advertising platform.
- MyTarget — Mail.ru Group's advertising platform.
- Yandex Ads — Yandex's advertising platform.
- Smaato — Smaato's programmatic ad exchange.
- PubMatic — PubMatic's programmatic advertising platform.
- OpenX — OpenX's programmatic ad exchange.
- Index Exchange — Index Exchange's ad exchange.
- Criteo — Criteo's retargeting platform.
- TabMoond (Taboola) — Taboola's content discovery platform.
- Outbrain — Outbrain's content recommendation platform.
- Verizon Media / Yahoo Ads — Verizon Media's advertising solutions.
- Amazon Publisher Services / APS — Amazon's publisher services and ad exchange.
- Snap Audience Network — Snap's advertising network.
- Twitter (X) Ads — Twitter's advertising platform.
- LinkedIn Ads — LinkedIn's advertising platform.
- Reddit Ads — Reddit's advertising platform.
- TikTok Ads (Pangle) — TikTok's advertising platform via Pangle.
Ad Mediation & Mediation Partners
- AppLovin MAX — Mediation platform.
- Google AdMob Mediation — Built-in mediation.
- ironSource LevelPlay — Mediation platform.
Attribution & Analytics Partners
For measuring ad performance, we may integrate with the following attribution providers (with appropriate user consent and platform compliance):
- AppsFlyer — Mobile attribution and marketing analytics.
- Adjust — Mobile attribution platform.
- Kochava — Attribution and analytics.
- Branch — Attribution and deep linking.
- Tenjin — Mobile game analytics.
- Singular — Attribution platform.
Ad Network Privacy Practices
Each of these advertising partners has its own privacy practices. We encourage you to review their privacy policies:
- Google: policies.google.com/privacy
- Meta: facebook.com/privacy/policy
- Unity: unity.com/legal/privacy-policy
- AppLovin: applovin.com/privacy
- Vungle: vungle.com/privacy
For users in the EEA, UK, California, or other regions with consent requirements, these partners operate on a non-personalised basis until the user has granted consent through our consent management platform.
App Store Compliance
Our applications are published on multiple platforms, and we maintain strict compliance with each platform's policies:
Apple App Store Compliance
All our iOS applications comply with Apple's App Store Review Guidelines, including:
- Guideline 5.1.1 (Privacy): We collect only data necessary for functionality and obtain consent before collection.
- Guideline 1.4.1 (Safety - Physical Harm): Apps that may be used by minors do not contain inappropriate advertising.
- App Tracking Transparency (ATT): Where applicable, we use Apple's ATT framework to request user permission before accessing the IDFA for advertising purposes.
- Privacy Nutrition Labels: We accurately disclose all data collection practices in App Store Connect.
- SKAdNetwork: Where applicable, we integrate with Apple's SKAdNetwork for conversion tracking without compromising user privacy.
Google Play Store Compliance
All our Android applications comply with Google Play policies, including:
- User Data Policy: We comply with all requirements for data collection disclosure, consent, and minimisation.
- Families Policy: For apps designed for children or with broad audience appeal, we comply with COPPA and Google Play's families requirements.
- Ads Policy: We comply with Google Play's ad policies, including restrictions on ad placement, content, and behaviour.
- Data Safety Form: We accurately complete and maintain Google Play's Data Safety Form.
- Personalised Ads: We obtain explicit user consent before enabling personalised advertising in all regions requiring it.
Other Distribution Platforms
For applications distributed through alternative platforms (Samsung Galaxy Store, Huawei AppGallery, Amazon Appstore, Microsoft Store, etc.), we maintain equivalent compliance with each platform's privacy and data handling requirements.
Data Sharing
We do not sell your Personal Data to third parties. We share data only in the following limited circumstances:
- Service Providers: With vetted third-party processors (hosting, analytics, support) bound by data processing agreements.
- Advertising Networks: With ad networks only as described above, with appropriate consent.
- Legal Requirements: When required by law, court order, or governmental authority.
- Safety: To protect the rights, property, or safety of Chabatrading, our users, or others.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.
- With Your Consent: In any other case where you have explicitly authorised sharing.
Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Account / Contact Data: Duration of relationship plus 7 years for tax/legal records.
- Analytics Data: Aggregated and anonymised where possible; raw data deleted within 26 months.
- Application Local Data: Controlled by you — you may delete at any time.
- Marketing Data: Until you unsubscribe, then promptly removed.
- Legal/Financial Records: As required by applicable law (typically 6-7 years).
When Personal Data is no longer needed, we securely delete or anonymise it.
International Data Transfers
As a UK-based company with global users, we may transfer Personal Data to countries outside your country of residence. When we do so, we ensure appropriate safeguards are in place:
- Adequacy Decisions: We rely on UK and EU adequacy decisions where available.
- Standard Contractual Clauses (SCCs): We use the EU Commission's 2021 SCCs and the UK International Data Transfer Addendum.
- Binding Corporate Rules: Where applicable.
- Explicit Consent: In specific cases with your explicit consent.
Within our applications, the local-first architecture means that most user content never leaves your device, minimising cross-border transfer concerns.
Age Restrictions
Our Services are not directed to children under the age of 13 (or older where required by local law, such as under 16 in the EEA/UK under GDPR, under 14 in Spain, under 14 in South Korea under PIPA, under 18 in certain jurisdictions for advertising-related services).
For applications designed for or likely to be accessed by children, we:
- Limit advertising to contextual (non-personalised) ads only.
- Do not request or collect Personal Data beyond a persistent identifier.
- Comply fully with COPPA (US), GDPR-K (EU/UK), and equivalent regional laws.
- Clearly indicate in the app store listing if the app is part of a Designed for Families program.
If you believe we have inadvertently collected information from a child, please contact us at contact@chabatrading.com for prompt deletion.
Your Rights
Regardless of where you live, you have the following rights regarding your Personal Data:
- Right of Access: Request a copy of the Personal Data we hold about you.
- Right of Rectification: Request correction of inaccurate or incomplete data.
- Right of Erasure ("Right to be Forgotten"): Request deletion of your Personal Data.
- Right to Restrict Processing: Request that we limit how we process your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time.
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority.
To exercise any of these rights, email contact@chabatrading.com with the subject line starting with "Privacy Request:". We respond to all valid requests within 30 days (or sooner as required by law).
Regional Rights & Specific Jurisdictions
European Economic Area (EEA) & United Kingdom
You have the rights described above under GDPR. You may also lodge a complaint with your local data protection authority. For UK residents, the relevant authority is the Information Commissioner's Office (ICO) at ico.org.uk.
California (USA)
Under the CCPA/CPRA, you have additional rights:
- Right to know what Personal Data is collected, used, shared, or sold.
- Right to delete Personal Data collected from you.
- Right to opt-out of the sale or sharing of Personal Data. (Note: we do not sell Personal Data.)
- Right to correct inaccurate Personal Data.
- Right to limit use of sensitive Personal Data.
- Right to non-discrimination for exercising your CCPA rights.
California residents may exercise these rights by contacting contact@chabatrading.com or calling our toll-free number available upon request.
Brazil (LGPD)
Under the LGPD, you have rights similar to GDPR, including access, correction, anonymisation, portability, deletion, and information about sharing. The Brazilian Data Protection Authority (ANPD) oversees LGPD compliance.
Canada (PIPEDA)
Under PIPEDA, you have the right to access your Personal Data and challenge its accuracy. The Office of the Privacy Commissioner of Canada handles complaints.
Australia (Privacy Act 1988)
Under the Privacy Act, you have rights regarding access, correction, and complaint processes administered by the Office of the Australian Information Commissioner (OAIC).
Singapore (PDPA)
Under the PDPA, you have rights to access and correct Personal Data, and to opt out of marketing communications. The Personal Data Protection Commission (PDPC) oversees compliance.
European Union — ePrivacy Directive
We comply with the ePrivacy Directive (2002/58/EC as amended) regarding electronic communications, including the use of cookies and similar technologies. Consent is obtained before storing non-essential cookies on user devices.
United States — COPPA (Children's Online Privacy Protection Act)
For our apps that may be used by children under 13, we comply with COPPA. We do not collect personal information from children under 13 without verifiable parental consent, and our ad-supported kids' apps use only contextual ads.
United States — CAN-SPAM Act
Our marketing emails comply with CAN-SPAM requirements, including clear identification, opt-out mechanisms, and honouring unsubscribe requests within 10 business days.
Security Measures
We implement robust technical and organisational measures to protect your Personal Data, including:
- Encryption in Transit: TLS 1.3 for all web traffic.
- Encryption at Rest: AES-256 encryption for stored data.
- Access Controls: Role-based access with multi-factor authentication.
- Regular Audits: Periodic security audits and penetration testing.
- Incident Response: Documented breach notification procedures (within 72 hours where required by GDPR).
- Employee Training: Regular privacy and security training for all team members.
- Vendor Management: Due diligence on all third-party processors.
Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Children's Privacy
We take children's privacy especially seriously:
- Under 13 (COPPA / GDPR): We do not knowingly collect Personal Data from children under 13 without verifiable parental consent. Our apps likely to be used by children are designed to comply with COPPA.
- Under 16 (UK/EU GDPR): In the UK and EU, the age of digital consent is generally 16 (or lower where set by member state law, typically 13-16).
- Designed for Families Apps: For apps in Google Play's Designed for Families program, we use only contextual (non-personalised) advertising and limit data collection to essential functionality.
- Parental Controls: We provide tools and instructions for parents to review, modify, or delete their children's information.
- Reporting Concerns: Parents who believe their child has provided us with Personal Data can contact us for immediate investigation and deletion.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will:
- Post the updated policy on this page with a revised "Last Updated" date.
- For material changes, notify users via email or in-app notification (where you have provided contact details or use our app).
- Maintain a changelog of significant updates.
- Obtain renewed consent where required by applicable law.
We encourage you to review this policy periodically to stay informed about how we protect your data.
Contact Us About Privacy
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection team:
Chabatrading — Data Protection
Email: contact@chabatrading.com (Subject line must start with "Privacy Request:")
Address: University of Stirling Innovation Park, United Kingdom
Response Time: Within 30 days (typically faster)
For users in the EEA/UK, you also have the right to lodge a complaint with your national data protection authority. For UK residents, the Information Commissioner's Office (ICO) can be contacted at ico.org.uk.