MyStor MyStor Back to home
Legal

Privacy Policy

Last updated: September 1, 2026

On this page

Information We Collect How We Use It Legal Bases Sharing Security Retention Your Rights Children Third Parties Changes Contact

BYTE CLUB, obrt za računalno programiranje i usluge, established in the Republic of Croatia ("BYTE CLUB", "we", "us", or "our"), operates MyStor and is the controller of the personal data described in this Privacy Policy unless a section says otherwise. This Policy applies to the MyStor mobile applications, website, support channels, and related marketplace services (together, the "Services"). Contact the controller at privacy@mystor.me.

Information We Collect

Personal Information

When you create an account or use the App, we may collect:

  • Account and identity data: name, email address, phone number, password hash, social-login provider and account identifier, roles, profile photo, and account status
  • Marketplace data: addresses and precise or approximate location you provide or choose to detect, job and project details, categories, offers, bookings, direct-payment method selections, ratings, reviews, messages, support requests, and dispute evidence
  • User content: profile images, job photos, work samples, chat attachments, identity images, and other files you choose to upload
  • Provider verification data: date of birth, business name and type, address, tax and trade-register details, licences, insurance information, payment-account details, government identification, selfie or liveness material, and the results and history of verification reviews
  • Payment and contract data: Stripe customer and payment-method identifiers, Platform Fee amount and status, receipts, refunds, fiscal records, consent wording and version, and booking-contract confirmations. Stripe receives card details directly; MyStor servers do not store full card numbers or security codes.

Automatically Collected Information

  • Device type, operating system, language, app version, IP address, device or installation identifiers, and push-notification tokens
  • Feature interactions, authentication and security events, timestamps, diagnostic logs, crash reports, and performance data
  • Approximate location inferred from IP and precise device location only when you enable a feature that requests it

Camera and Photos

The App requests camera or photo-library access only when you choose a feature such as taking a job photo, uploading work evidence, setting a profile picture, or completing identity verification. The App requests location access when you choose current-location features for address entry, matching, or job operations. You can deny or later revoke device permissions, although the related feature may then be unavailable. We do not use private photos, messages, or identity documents to train advertising or general-purpose artificial-intelligence models.

Sources

We obtain data from you, your device and App interactions, other Users involved in your bookings, Stripe and other service providers, social-login providers, and—where provider verification requires it—public registers or competent authorities.

How We Use Your Information

  • To create and manage your account
  • To connect customers with service providers
  • To process only MyStor Platform Fees through Stripe, preserve transaction and contract-confirmation records, and support refunds. The Provider's job or visit price is paid directly to the Provider and is not processed by MyStor.
  • To record direct-payment arrangements and support coordination between Customers and Providers without collecting the Provider's price
  • To verify Provider identity, trader status, registration, qualifications, and eligibility
  • To send push notifications about job updates, messages, and offers
  • To improve the App and our services
  • To detect and prevent fraud or abuse
  • To comply with legal obligations

Legal Bases for Processing

  • Contract: To create and administer accounts, publish requested content, match Users, create bookings, provide messaging, process Platform Fees, and provide transaction and support features
  • Legal obligation: To keep tax, accounting, fiscal, consumer-contract, provider-verification, and compliance records; respond to lawful requests; and meet applicable marketplace obligations
  • Legitimate interests: To secure the Services, prevent fraud and abuse, enforce rules, investigate disputes, maintain reliable systems, understand feature performance, and protect Users and BYTE CLUB, balanced against your rights
  • Consent: Where required for marketing, non-essential analytics, device permissions, and any other optional processing presented as consent-based. You may withdraw consent without affecting earlier lawful processing.

Information Sharing

We do not sell your personal information. We may share information with:

  • Other Users: Information needed to assess offers and fulfil bookings, such as names, profile information, trader status, ratings, job details, and contact or messaging information. We do not disclose a Provider's identity document to Customers.
  • Stripe: Payment identifiers, identity and contact data, Platform Fee transactions, refunds, and—where used—Provider identity or connected-account information. Stripe acts under its own terms for parts of this processing.
  • Google services: Google Sign-In, Firebase Cloud Messaging and Analytics, Maps/Places, and related mobile services receive the data needed for the feature you use, such as login identifiers, app-instance data, notification tokens, analytics events, or map queries.
  • Meta: If you choose Facebook Login, Meta and MyStor exchange the identifiers and profile information described in the login flow.
  • Infrastructure and operations providers: Hosting, database, object-storage, email-delivery, monitoring, error-reporting (including Sentry), backup, and security suppliers process data only as needed to provide those services.
  • Authorities and advisers: We may disclose data when legally required or reasonably necessary to establish, exercise, or defend legal claims, protect safety, investigate fraud, or obtain professional advice.
  • Business changes: Data may be disclosed under appropriate safeguards in a financing, reorganisation, sale, or transfer of all or part of the service.

Google Sign-In

If you choose Google Sign-In, MyStor receives an ID token and basic Google account data made available in the sign-in flow, which may include your Google account identifier, verified email address, name, and profile image. We use and store this data only to authenticate you, create or link your MyStor account, show the relevant account profile, maintain account security, and prevent fraud. MyStor does not request access to your Gmail, Google Drive, Google Contacts, or other Google account content; does not use Google Sign-In data for advertising; and does not sell it. We disclose it only to the service providers and authorities described in this Policy when needed for those stated purposes or required by law.

Data Storage and Security

We use measures appropriate to the risk, including encrypted network transport, access controls, credential protection, logging, backups, separation of environments, and restricted access to identity and payment records. Full card details are handled by Stripe. No system is completely secure, so we cannot promise absolute security.

We use suppliers that may process data in the European Economic Area and in other countries. Where personal data is transferred outside the EEA, we rely on an applicable adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where required.

Data Retention

We keep account and marketplace data while your account is active and as needed for open bookings, disputes, safety, and support. After a valid deletion request and resolution of any permitted blockers, data that is not required for another lawful purpose is deleted or irreversibly anonymised from active systems without undue delay, normally within 30 days. Residual encrypted backup copies expire under our backup schedule and are not restored for ordinary use.

Platform Fee, contract-confirmation, fiscal, tax, accounting, fraud-prevention, provider-verification, and legal-claim records are retained for the statutory or limitation period that applies to each record. We restrict retained data to the lawful purpose and delete or anonymise it when that period ends. See our Data Deletion page for request instructions.

Your Rights

Under the GDPR and applicable Croatian data protection law, you have the following rights:

  • Right of access: Obtain a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your data ("right to be forgotten")
  • Right to restrict processing: Limit how we use your data in certain circumstances
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to lodge a complaint: File a complaint with the Croatian Personal Data Protection Agency (AZOP) or your local supervisory authority

To exercise a right, use the in-app controls where available or contact privacy@mystor.me. We may request information needed to verify your identity. We normally respond within one month; GDPR permits an extension for complex or numerous requests, in which case we will explain the extension. You may complain to the Croatian Personal Data Protection Agency (AZOP) or the supervisory authority where you live or work.

Children's Privacy

The Services are intended only for people aged 18 or older. We do not knowingly permit minors to create accounts. If you believe a minor has provided personal data, contact us so we can investigate and delete it where appropriate.

Third-Party Services

Third-party services may act as our processors, independent controllers, or both, depending on the feature. Their own privacy notices apply to processing they determine independently. The App is not supported by behavioural advertising, and we do not sell personal data. If that model changes, we will update this Policy and obtain any consent required before the change applies.

Automated Processing

We may use rules or risk signals to detect fraud, abuse, security threats, or suspicious payments and to organise marketplace content. A User may request human review of a significant account restriction by contacting support. We do not use solely automated decision-making that produces legal or similarly significant effects unless we first provide the information and safeguards required by law.

Changes to This Policy

We may update this Policy when our processing, suppliers, or legal obligations change. We will publish the new effective date and provide additional notice of material changes where required. A Privacy Policy is a notice, not a substitute for consent; where new processing requires consent, we will request it separately.

Contact Us

Controller: BYTE CLUB, obrt za računalno programiranje i usluge, Republic of Croatia.

Privacy requests: privacy@mystor.me
General support: support@mystor.me

MyStor MyStor
Privacy Terms Data deletion Home

© 2026 BYTE CLUB. All rights reserved.