Last Updated: August 9, 2026
About This Policy
This Privacy Policy explains how easyDacha C-Corp (“easyDacha,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the easyDacha mobile application and related services (collectively, the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
This Privacy Policy is incorporated into and should be read alongside our Terms of Use.
1. Information We Collect
1.1 Account & Profile Data
Sign-In Methods.
You can create an account or sign in using an email address and password, or through a third-party sign-in provider: Sign in with Apple, Google, or Facebook. When you use a third-party provider, we receive from that provider your name (where available), an email address, a unique user identifier, and, where available, your profile photo. Specifically:
• Apple: your name (at your choice), a unique Apple user identifier, and either your real email or a private relay email (ending in @privaterelay.appleid.com) that forwards to your inbox. Apple provides your email only at first sign-in.
• Google: your name, email address, Google account identifier, and profile photo.
• Facebook: your Facebook user identifier, name, profile photo, and email address only if you grant Facebook permission to share it. If Facebook does not provide an email, we ask you to enter one so we can send you service-related communications.
Authentication is processed through Firebase Authentication (see Section 3). We do not receive your password from third-party sign-in providers.
When you create an account, we collect:
• Name and email address
• Password (stored in hashed, encrypted form; we never store plaintext passwords)
• Garden name — a label you choose for your garden (e.g., “My Backyard”)
• ZIP code — entered when you create a garden, used to calculate frost dates, planting zones, and seasonal task schedules (see Section 1.4)
• Garden content you enter: plant selections, care notes, and observations
1.2 Device & Technical Data
Automatically collected when you use the Service:
• Device identifiers: IDFA (Identifier for Advertisers, iOS), IDFV (Identifier for Vendors, iOS), Android Advertising ID (GAID), and Firebase Installation ID
• Device type, manufacturer, operating system version, and app version
• IP address (used to infer approximate geographic region; not stored long-term)
• Push notification token (used to deliver notifications via Firebase Cloud Messaging)
• App performance data: crash reports, error logs, load times
• Network type (Wi-Fi / cellular)
1.3 Usage & Behavioral Data
How you interact with the Service:
• Feature usage events (e.g., which screens you visit, which features you use, actions you take)
• Session duration, frequency of use, and navigation paths
• In-app interactions: taps, scrolls, and other gestures (captured in aggregated / masked form for UX analysis — see Section 5 for Session Replay details)
• A/B test assignments (which version of a feature or content you see)
1.4 Location Data
We collect two distinct types of location information, with different purposes and different privacy implications:
ZIP Code (Entered Manually)
• You provide your ZIP code when creating a garden in the app.
• We use it to: look up your USDA Hardiness Zone, calculate your last and first frost dates, and generate your personalized planting calendar and task schedule.
• ZIP code is approximate location information. It is not classified as Sensitive Personal Information under California law (CPRA) because it does not identify your precise location.
GPS / Device Location (Permission-Based, Optional)
• With your explicit permission via your device’s system permission dialog, we may access your device’s precise GPS coordinates.
• Precise location is used solely for: real-time weather data and weather-based alerts (frost warnings, heat advisories) delivered via OpenWeatherMap.
• If you deny location permission, the app continues to function without a weather feature.
• You can grant or revoke GPS location permission at any time in your device’s Settings → Privacy → Location Services.
Important: GPS Location is Sensitive Personal Information (California) Under the California Privacy Rights Act (CPRA), precise geolocation data is classified as Sensitive Personal Information. We use your GPS location only to fetch real-time weather data — nothing else. We do not sell or share your precise location for advertising.
California residents have the right to limit our use of Sensitive Personal Information to the purposes described here. See Section 11.2 for how to exercise this right.
We do not track your location in the background. Location is accessed only when the app is in use and only if you have granted permission.
1.5 Payment Information
Payments are processed by third-party providers (Apple In-App Purchase, Google Play Billing, or Stripe). easyDacha does not collect, store, or have access to your full payment card number, CVV, or bank account details. We receive only transaction confirmation, subscription status, and a masked payment reference.
1.6 Garden Content & User-Added Plants
Content you create within the Service:
• Garden plans and layouts
• Plant entries, care notes, and observations
• Photos you upload to document your plants or garden
• Custom plant entries you add when a plant is not in our library (see Sections 3 and 7 for how these may be used)
The photos you upload are your content. For details on how we may use User-Added Plant photos in the shared plant library, see our Terms and Conditions, Section 5.
1.7 Communications Data
When you contact us or interact with our messages:
• Your name, email address, and message content when you write to support
• Email engagement data: open rates, link clicks (tracked by Customer.io for transactional and product emails)
• In-app message interactions
1.8 Data We Do Not Collect
We Do Not Collect:
• Full payment card numbers, CVV, or bank account details
• Social Security numbers or government-issued ID numbers
• Health or medical information
• Content of messages in other apps or outside our Service
• Contact lists or address books
• Background location (GPS is accessed only while the app is in active use)
• Personal data from children under 13 (see Section 13)
2. How We Use Your Information
We use the information we collect for the following purposes:
Purpose | Data Used | Legal Basis (GDPR) |
Providing the Service: account management, garden plans, care plans, plant database | Account data, garden content, location | Contract Performance |
Personalizing your experience: localized weather, seasonal schedules, care plan timing based on your ZIP code and frost dates | ZIP code, GPS location (if granted), plant selections | Contract Performance / Legitimate Interest |
AI-Assisted Content: generating plant descriptions, care tips, seasonal advice, and visual assets (sprites) displayed in the app. AI is used for content only — we do not use AI to profile individual users or make automated decisions about users. | Plant type, ZIP code / region, garden data (non-identifiable for AI processing) | Legitimate Interest |
Push notifications: task reminders, weather alerts, seasonal tips | Push token, usage data, location | Consent |
Email communications: transactional (receipts, password reset), onboarding, product updates | Email address, account data | Contract Performance / Legitimate Interest |
Marketing emails and campaigns: promotions, re-engagement | Email address, usage data | Consent |
Analytics & product improvement: understanding feature usage, fixing bugs | Usage data, device data, crash logs | Legitimate Interest |
UX research: Session Replay analysis to improve app flows (see Section 5) | Masked screen interaction data | Legitimate Interest |
Mobile attribution: attributing app installs to advertising campaigns (when ads are active) | Device ID (IDFA/GAID) | Consent (ATT on iOS) / Legitimate Interest |
Payment processing and subscription management | Transaction data, subscription status | Contract Performance / Legal Obligation |
Fraud prevention, security, and legal compliance | Account data, device data, IP address | Legal Obligation / Legitimate Interest |
Aggregated research: anonymized, non-identifiable insights about gardening patterns | Anonymized data | Legitimate Interest |
3. Third-Party Services & Data ProcessorsWe work with trusted third-party service providers to operate the Service. Each provider acts as a data processor under a Data Processing Agreement (DPA) and may only use your data for the specific purposes listed below.
The following table lists all third-party services currently integrated or planned for integration into the Service:
Service | Provider | Purpose | Data Received |
Firebase Analytics | Google LLC | App event analytics and funnel tracking | Device ID, events, session metadata |
Firebase Crashlytics | Google LLC | Crash and error reporting | Device info, OS version, crash stack traces |
Firebase Cloud Messaging (FCM) | Google LLC | Delivery of push notifications | Push notification token |
Firebase Remote Config | Google LLC | A/B testing and feature flags | Device ID, app version |
Firebase Authentication | Google LLC | User account authentication | Email address, auth tokens |
Sign in with Apple | Apple Inc. | Account authentication (sign-in) | Name (optional), email or Apple relay email, Apple user identifier |
Google Sign-In | Google LLC | Account authentication (sign-in) | Name, email, Google account identifier, profile photo |
Facebook Login | Meta Platforms, Inc. | Account authentication (sign-in) | Facebook user identifier, name, profile photo, email (only if you grant permission) |
Google Analytics | Google LLC | Web analytics (website visitors) | IP address (anonymized), browser, behavior |
Amplitude Analytics | Amplitude Inc. | Behavioral analytics: events, funnels, retention | User ID, device ID, events, session data |
Amplitude Session Replay | Amplitude Inc. | UX research: masked screen recordings (see Section 5) | Masked interaction sequences, screen flow data |
AppsFlyer | AppsFlyer Ltd. | Mobile attribution: attributing installs to ad campaigns (when paid ads are active) | Device ID (IDFA/GAID), install event data |
Customer.io | Peaberry Software Inc. | Email & in-app messaging: transactional, onboarding, product, marketing, weather alerts | Email address, user ID, behavioral events |
OpenWeatherMap | OpenWeather Ltd. (UK) | Real-time weather data, forecasts, and frost/freeze alerts for your garden location | ZIP code (always); GPS coordinates (only when location permission is granted). No personal identifiers are transmitted. |
Stripe | Stripe Inc. | Payment processing (web / direct purchases) | Payment card data (handled entirely by Stripe; easyDacha does not receive card details) |
Apple In-App Purchase | Apple Inc. | Payment processing (iOS subscriptions) | Transaction data (handled by Apple) |
Google Play Billing | Google LLC | Payment processing (Android subscriptions) | Transaction data (handled by Google) |
We may add new service providers over time. When we do, we will update this Privacy Policy and, where required by law, notify you before the new provider begins processing your data.
All third-party providers are required to: process your data only for the specified purposes; maintain appropriate security measures; comply with applicable data protection laws, including GDPR and CCPA; and enter into a Data Processing Agreement with us.
Third-Party Links: Our app and website may contain links to third-party websites or services not listed in the table above. This Privacy Policy does not govern those third-party services or websites. We encourage you to review the privacy policies of any third-party service before providing personal information.
**** Sign-in through Apple, Google, and Facebook is brokered through Firebase Authentication. Your use of a third-party sign-in provider is also subject to that provider’s own privacy policy.
4. Advertising, Attribution & Apple App Tracking Transparency 4.1 Mobile AttributionWe use AppsFlyer to understand which marketing channels (e.g., social media ads, search ads) lead users to download and install the easyDacha app. This is called “mobile attribution.” When we run paid advertising campaigns, AppsFlyer may receive your device advertising identifier (IDFA on iOS or GAID on Android) to match your install to a campaign.
We do not run personalized advertising within the easyDacha app itself. We do not sell your data to advertising networks or data brokers.
4.2 Apple App Tracking Transparency (ATT) — iOSOn iOS devices, Apple’s App Tracking Transparency framework requires us to ask your permission before accessing your IDFA for cross-app tracking purposes. When you first open the app, you may see a system prompt asking whether to allow tracking.
• If you allow tracking: your IDFA may be shared with AppsFlyer for attribution when we run ad campaigns.
•If you deny tracking: we will not access your IDFA. Analytics will be based on anonymized, aggregate data only. You can change this permission at any time in iOS Settings → Privacy & Security → Tracking.
4.3 Android Advertising ID (GAID)On Android devices, you can opt out of ad personalization in Google Settings → Ads → Delete advertising ID or opt out of ads personalization. If you opt out, we will not use your GAID for attribution.
4.4 California — Right to Opt Out of “Sharing” (CPRA)Under the California Privacy Rights Act (CPRA, effective January 2023), sharing personal data with third parties for cross-context behavioral advertising — even without payment — is treated similarly to selling. When we run advertising campaigns using AppsFlyer, this may constitute “sharing” under CPRA.
California residents have the right to opt out of the sharing of their personal information. To exercise this right, email us at
[email protected] with the subject line “Do Not Share My Personal Information — [Your Name].” You may also opt out through your device settings (ATT on iOS; GAID opt-out on Android).
Global Privacy Control (GPC): We also honor Global Privacy Control signals. If your web browser transmits a GPC signal when you visit easydacha.com, we will treat it as a request to opt out of the sharing of your personal information for cross-context behavioral advertising. Note: GPC operates at the browser level and applies to website visits only; it does not automatically apply to in-app data. To opt out of app-level sharing, use the device settings described in Sections 4.2 and 4.3 above.
5. Session Replay & UX Research (Amplitude)We use Amplitude’s Session Replay feature to analyze how users navigate the easyDacha app. This helps our product and UX team identify usability issues, understand where users encounter difficulties, and improve the app experience.
How Session Replay Works Session Replay records the sequence of screens and interactions (taps, scrolls, navigation) a user takes during an app session. It does NOT capture:
• The actual text you type (all input fields are masked / replaced with ■■■)
• Your email address, username, passwords, or any credentials
• Content from other apps or outside our Service
The following screens are excluded from Session Replay recording entirely:
• Payment and subscription screens
• Account settings and profile screens
• Any screen containing personal data fields
What IS recorded:
• Which screens you visit and in what click
• Tap locations (shown as dots, no content captured)
• Scroll depth and navigation patterns
Additional safeguards we apply:
•High masking level enabled in the Amplitude SDK: all visible text and input fields are replaced with placeholder blocks before any data leaves your device.
• Access to Session Replay recordings is restricted to a limited number of product and UX team members.
• Recordings are automatically deleted from Amplitude’s servers after 90 days.
• Session Replay data is processed by Amplitude as our data processor under a signed DPA, which includes Standard Contractual Clauses (SCCs) for international transfers.
Legal basis for Session Replay: Legitimate Interest. We have conducted a Legitimate Interest Assessment (LIA) and determined that UX improvement through masked, privacy-preserving session recording is proportionate and does not override users’ privacy rights, given the strong masking measures applied.
Opt-out: If you wish to opt out of Session Replay, email
[email protected] with the subject “Session Replay Opt-Out — [Your Name].” We will configure your account to exclude it from recording.
6. Email & In-App Communications (Customer.io)We use Customer.io to manage and send several types of communications:
Type | Examples | Consent Required? | How to Opt Out |
Transactional | Registration confirmation, password reset, subscription receipts | No — required for Service | Cannot opt out (required for account function) |
Product / Onboarding | Getting started tips, feature announcements, care plan reminders | No — Legitimate Interest | Unsubscribe link in email or contact support |
Weather Alerts | Frost warnings, extreme heat alerts affecting your plants | No — Legitimate Interest | Unsubscribe link in email or contact support |
Marketing | Product news, feature highlights, seasonal campaigns, offers, re-engagement | Yes — for US users, presented as opt-out (on by default); opt-in elsewhere | Unsubscribe link in email, or in-app notification settings |
In-App Messages | Feature tips, announcements, survey prompts within the app | No — Legitimate Interest | Contact support to disable in-app messaging |
Customer.io receives your email address, user ID, and behavioral events (e.g., “user has not opened the app in 7 days”) to power automated messaging. Customer.io does not use your data for their own advertising purposes.
You can manage your email preferences at any time by clicking “Unsubscribe” in any email or by contacting
[email protected]. Opting out of marketing emails does not affect transactional communications.
(The consent screen described in this section is present in app version 1.0.8 and later. If you are using an earlier version, you have not yet been shown this screen. In the meantime, marketing email is sent on an opt-out basis with an unsubscribe link in every message, and you will be shown the screen when you update.)
How We Obtain and Record Marketing Consent. We send marketing communications (product news, feature highlights, offers, seasonal campaigns, and re-engagement messages) only with your consent. For users located in the United States, marketing email consent is presented on an opt-out basis: the toggle is on by default the first time you see the notifications screen, and you can turn it off at that time or unsubscribe at any later point, consistent with the CAN-SPAM Act. If we expand outside the United States, this choice will be presented as opt-in (toggle off by default) wherever local law requires it. Marketing push notifications are never pre-selected, in any country: they require your separate, explicit action, consistent with Apple’s platform requirements and independent of your email marketing choice. You can withdraw marketing consent at any time using the unsubscribe link in any marketing email, or in your in-app notification settings. Withdrawing marketing consent does not affect service-related communications (transactional messages and messages we send on the basis of legitimate interest). We keep a record of each marketing consent action. That record includes a pseudonymized identifier for your account, the exact consent text shown to you, the version of that text, the channel (email or push), the state of the toggle at that moment, whether consent was given or withdrawn, the date and time of the action in UTC, and the IP address from which the action was taken. The record is generated automatically at the moment you act and is not edited afterwards. We keep it in a restricted archive, held separately from your active profile, for up to 24 months after you withdraw consent or delete your account, so that we can respond to a complaint or a regulatory inquiry about whether consent was given. Section 9 describes this retention.
7. Data Sharing & Disclosure 7.1 What We Do Not DoWe Do Not Sell Your Personal Data. easyDacha does not sell your personal information to third parties for money. We do not sell data to data brokers, advertising exchanges, or lead generation companies.
We do not share personal information with third parties for their own direct marketing purposes. (California residents: this is our disclosure under Cal. Civ. Code §1798.83 — the “Shine the Light” law.)
When we run advertising campaigns, we may “share” limited device identifiers with AppsFlyer (see Section 4). California residents have the right to opt out of this sharing (see Section 11.2).
Nevada residents: we do not sell your covered information. To submit a Nevada opt-out request (NRS 603A), contact
[email protected] — Subject: “Nevada Privacy Request.”
7.2 When We Do Share DataWe share data only in the following circumstances:
• Service Providers: with the third-party processors listed in Section 3, under written DPAs, solely for the purposes described.
• Legal Requirements: when required by law, court order, subpoena, or government regulation, or when necessary to protect the rights, property, or safety of easyDacha, our users, or the public.
• Business Transfers: in the event of a merger, acquisition, sale of assets, or reorganization, your data may be transferred to the successor entity. We will notify you before your data is subject to a different privacy policy.
• With Your Consent: for any other purpose, only with your explicit prior consent.
7.3 Aggregated & Anonymized DataWe may share aggregated, anonymized data (data that cannot reasonably identify any individual) for research, industry analysis, or product improvement purposes. This data does not constitute personal information under applicable law.
8. Cookies & Tracking TechnologiesCookies and similar technologies are primarily used on our website (easydacha.com). Our mobile app does not use browser cookies but uses equivalent technologies such as device identifiers and local storage.
Technology | Used In | Purpose | Can You Opt Out? |
Session cookies | Website | Maintain your login session | Yes — browser settings |
Analytics cookies (Google Analytics) | Website | Understand visitor behavior on the website | Yes — browser settings / Google opt-out |
Device identifiers (IDFA, GAID, IDFV) | Mobile App | Analytics, attribution, personalization | Yes — device settings (see Section 4) |
Firebase Installation ID | Mobile App | App instance identification for analytics and FCM | Limited — tied to app installation |
Local storage | Mobile App | Store app preferences and cached data locally on device | No — cleared by uninstalling app |
Global Privacy Control (GPC): Our website responds to GPC signals as described in Section 4.4. We also honor browser-based “Do Not Track” (DNT) signals for our website where technically feasible. Our mobile app does not respond to DNT or GPC signals, as no standardized mobile protocol currently exists; however, you can manage tracking through your device’s operating system settings as described in Section 4.