Privacy Policy

Last Updated On: 15-July-2026
Effective Date: 30-Oct-2025

Chapter 1. Definitions and Scope

This Privacy Policy governs the processing of personal data carried out through the TimeOffApp application. The application is available to users worldwide. Where applicable, the processing of personal data complies with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), and any other applicable data protection legislation based on the user’s country of residence.

For the purposes of this Policy:

  • User means any natural person using the application.
  • Personal Data means any information relating to an identified or identifiable natural person.
  • Wallet means the public Polygon blockchain address provided by the user to receive OFF tokens.

Chapter 2. Data Controller

Until a legal entity is incorporated, the Data Controller is:

Nicolás Martin Laverdet Barlotti
Email: nicomlb@hotmail.com
Address: Ángeles Navas Atencia, 19, 2º Ático-B, 29730 Rincón de la Victoria, Spain

The application has been developed jointly by three individual developers. Once a company is incorporated, users will be informed accordingly and this Privacy Policy will be updated to identify the new Data Controller.

Chapter 3. Personal Data Collected

Registration
  • Full name
  • Email address
  • Password
  • Authentication through Google Sign-In
User Profile
  • Full name
  • Email address
  • Country
  • Type of identification document
  • Identification document number
  • Public Polygon wallet address
  • Optional profile picture
Technical Data

The application also collects technical identifiers, usage events, and performance metrics through Firebase Analytics.

Identity documents are stored using Firebase services and are reviewed manually by the developers exclusively for identity verification and fraud prevention purposes.

Chapter 4. Purposes of Processing and Legal Bases

Personal data are processed for the following purposes:

  • Creating and managing user accounts.
  • Authenticating users.
  • Manually verifying user identity.
  • Preventing fraudulent activities.
  • Allocating and distributing OFF tokens.
  • Providing customer support.
  • Improving the application through Firebase Analytics.
  • Complying with legal obligations.
  • Protecting the security and integrity of the service.

The legal bases for processing are:

  • Performance of a contract.
  • User consent, where required.
  • Legitimate interest in preventing fraud and securing the platform.
  • Compliance with legal obligations.

At present, the OFF Token has no monetary or market value.

The OFF Token does not constitute a financial product, investment instrument, security, or any guarantee of financial return.

The following chapters provide additional information regarding authentication, security, Know Your Customer (KYC) procedures, blockchain technology, service providers (Firebase/Google), international data transfers, data retention, user rights, security measures, and technical annexes.

Chapter 5. Registration, Authentication and Security

Users may register using an email address and password or by signing in with their Google account.

Authentication is managed through Firebase Authentication.

TIMEOFFAPP implements reasonable technical and organizational measures to protect user accounts, including encrypted communications, access controls, and the principle of least privilege.

Users are responsible for maintaining the confidentiality of their credentials and for immediately notifying TIMEOFFAPP of any unauthorized access or suspected security breach.

Chapter 6. Identity Verification (KYC)

To claim OFF tokens, users are required to provide:

  • Full name
  • Identification document type
  • Identification document number
  • Country
  • Public Polygon wallet address
  • Optional profile picture

Identity documents are stored using Firebase services and are reviewed exclusively through manual verification by the developers.

The purposes of this verification include:

  • Preventing fraud.
  • Preventing duplicate claims.
  • Ensuring compliance with the requirements of the rewards program.

TIMEOFFAPP does not use automated decision-making or profiling to approve or reject identity verification requests.

Chapter 7. Blockchain, Polygon and the OFF Token

The application uses the Polygon blockchain network to distribute OFF tokens to the wallet address provided by the user.

Blockchain addresses and confirmed transactions are public, permanent, and immutable.

TIMEOFFAPP:

  • Does not provide cryptocurrency custody services.
  • Does not control users’ private keys.
  • Cannot recover tokens sent to an incorrect wallet address provided by the user.

The OFF Token currently has no economic value and does not constitute:

  • a financial instrument;
  • a security;
  • a deposit;
  • an investment product; or
  • a promise of future profits or returns.

Should the OFF Token acquire economic value or its functionality change in the future, this Privacy Policy and the Terms of Use may be updated accordingly.

Chapter 8. Technology Providers and Data Recipients

TIMEOFFAPP uses Google Firebase services, including:

  • Firebase Authentication
  • Firebase Analytics
  • Firebase Storage
  • Related cloud infrastructure services where necessary

These providers act as data processors or technology service providers under their own contractual terms.

Personal data are not sold to third parties and are not used for personalized advertising.

Personal data may only be disclosed:

  • where required by law;
  • when necessary to provide the service;
  • or with the user’s explicit consent.

Notes for the Final Version

The consolidated version of this Privacy Policy will include cross-references to the chapters relating to international data transfers, data retention, user rights, security measures, incident management, and technical annexes.

Chapter 9. International Data Transfers

TIMEOFFAPP is available to users worldwide.

To provide the service, the application uses Google Firebase, whose infrastructure may involve processing personal data in different countries.

Google implements contractual and organizational safeguards designed to protect personal data in accordance with applicable legislation.

By using the application, users acknowledge that certain processing activities may take place outside their country of residence where necessary for the provision of the service.

Chapter 10. Data Retention

Account information will be retained while the user’s account remains active.

If a user requests deletion of their account, personal data will be deleted or anonymized whenever possible, except where retention is required:

  • by law;
  • for fraud prevention;
  • or to resolve disputes.

Identity verification documents will only be retained for as long as necessary to:

  • verify identity;
  • investigate incidents;
  • prevent fraud; and
  • comply with applicable legal obligations.

Chapter 11. Users’ Rights

Users may exercise their rights to:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Objection
  • Data portability
  • Withdraw consent where applicable

Requests may be submitted by email to:

nicomlb@hotmail.com

If users believe their rights have not been respected, they may lodge a complaint with the competent data protection authority.

For users located in Spain, the competent authority is the Spanish Data Protection Agency (AEPD).

Chapter 12. Security, Incidents and Policy Updates

TIMEOFFAPP implements reasonable technical and organizational measures to protect personal information, including:

  • Access controls
  • Authentication mechanisms
  • Secure Firebase services
  • Backups where appropriate
  • Periodic review of permissions

If a security incident is detected, TIMEOFFAPP will take appropriate measures to contain and mitigate the incident.

Where required by applicable law, the relevant supervisory authority and affected users will be notified.

This Privacy Policy may be updated to reflect technical, legal, or operational changes.

The latest version will always be available within the application or on the official website.

End of the Main Policy

The following section contains the technical annexes, including data categories, processing activities, retention periods, service providers, security measures, and definitions.

Annex I. Categories of Personal Data

Identification Data

  • Full name
  • Email address
  • Country
  • Identification document type
  • Identification document number
  • Optional profile picture

Technical Data

  • Device identifiers
  • Usage events
  • Firebase Analytics metrics

Blockchain Data

  • Public Polygon wallet address

Annex II. Record of Processing Activities

Processing activities include:

  • Account management
  • User authentication
  • Manual identity verification
  • Fraud prevention
  • Distribution of OFF tokens
  • Customer support
  • Analytics

Categories of data subjects:

  • Registered users

Data processors include Google Firebase and any other service providers necessary to deliver the application.

Annex III. Data Retention

  • Account information: retained while the account remains active.
  • Identity verification data: retained only as long as necessary for identity verification, fraud prevention, and legal compliance.
  • Analytics data: retained according to Firebase configuration and applicable legislation.

Annex IV. Data Processors

TIMEOFFAPP relies on:

  • Firebase Authentication
  • Firebase Analytics
  • Google cloud storage and infrastructure services required to provide the application

These providers process personal data in accordance with their contractual commitments and applicable legal safeguards.

Annex V. Security Measures

Security measures include:

  • Access control
  • Authentication mechanisms
  • Secure communications
  • Least-privilege access
  • Manual identity document review
  • Backups where appropriate
  • Regular updates of technological components

Annex VI. Blockchain

Transactions carried out on the Polygon blockchain are public and immutable.

TIMEOFFAPP uses only the public wallet address provided by the user to distribute rewards.

TIMEOFFAPP does not control users’ private keys and cannot reverse confirmed blockchain transactions.

Annex VII. Glossary

GDPR – General Data Protection Regulation.

Wallet – A public blockchain address used to receive digital assets.

KYC (Know Your Customer) – Identity verification procedure.

Firebase – Google’s cloud platform used by the application for authentication, analytics, storage, and related services.

ADVERTISING (ADMOB)

Our mobile application uses Google AdMob to display ads. AdMob may collect certain data automatically (such as device identifiers, IP address, and usage information) to serve personalized or non-personalized ads.

For more details on how AdMob and Google handle your data, please refer to Google’s Privacy & Terms.

YOUR RIGHTS

Depending on applicable laws (such as GDPR), you have the right to:

  • Access, rectify, or delete your personal data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact us at help@timeoff-app.com.
We will respond in accordance with applicable data protection regulations.

Please note that withdrawing consent or refusing to provide required information may prevent us from providing certain services, including cryptocurrency-related features.

COOKIES AND TRACKING TECHNOLOGIES

Our website uses cookies and similar technologies to enhance your browsing experience, operate the site, analyze performance, and show relevant content or advertisements.

What are cookies?

Cookies are small text files that websites place on your device to store information about your preferences, improve navigation, and recognize returning visitors. Some cookies are essential for the site to function correctly, while others require your consent.

Types of cookies we use

Category Purpose Consent Required
Necessary Essential for basic functionality, such as remembering consent settings or maintaining session data. ❌ No
Functional Enable site personalization (language, preferences, display options). ✅ Yes
Analytics / Performance Help us understand how users interact with our website (traffic, behavior, etc.). ✅ Yes
Advertising / Marketing Used by third parties (e.g., Google AdMob) to deliver personalized ads and measure campaign performance. ✅ Yes

Cookies we may use

Below are examples of cookies used by our site and plugins. The specific cookies may vary as the site is updated:

  • cookieyes-consent (Provider: CookieYes) – Stores your consent preferences. Category: Necessary.
  • Cookies from Contact Form 7 – Used for managing form submissions and preventing spam.
  • Cookies from Slider Revolution – Used for functionality and animation performance.
  • Cookies from WPBakery Page Builder – Used to enhance visual rendering and layout functionality.
  • AdMob / Google cookies (e.g. _ga, _gcl_au, _gid, _fbp) – Used for analytics and advertising when consent is given.

(A complete and automatically updated list of cookies can be reviewed through the CookieYes consent banner on our site.)

How we collect and manage consent

When you visit our website, a cookie banner powered by CookieYes | GDPR Cookie Consent will appear, allowing you to:

  • Accept all cookies
  • Reject non-essential cookies
  • Customize cookie preferences

You can change or withdraw your consent at any time using the “Manage Cookies” link or banner available on every page. Essential cookies will remain active as they are necessary for the site to function.

How to delete or block cookies

You can delete existing cookies or block new ones through your browser settings. However, blocking essential cookies may affect the functionality of the website or app.

SECURITY

The security of your information is important to us. We use reasonable technical and organizational measures to protect your personal data from loss, misuse, or unauthorized access.

However, given the inherent risks of the internet, we cannot guarantee absolute security, and any information you transmit to us is at your own risk.

GRIEVANCE / DATA PROTECTION OFFICER

If you have any questions or concerns about how your data is processed, you may contact our Data Protection Officer at:

Time Off App
C/ Bergantín 9, Madrid 28042, Spain
Email: help@timeoff-app.com

We will address your concerns in accordance with applicable data protection laws.