Meritup

Privacy Policy

Last updated: 23 April 2026 — Version 1.0 — Versione italiana

This Privacy Policy describes how personal data of users of the Meritup mobile application ("the App") is processed, in compliance with Regulation (EU) 2016/679 ("GDPR"), the Italian Data Protection Code, the Apple App Store Review Guidelines, and the Google Play policies.

1. Data Controller

Controller: Nicholas Urru
Privacy contact: privacy@meritup.app

2. Categories of data collected

CategoryExamplesSource
IdentifiersName, surname, date of birthUser
Contact dataEmail, phone numberUser
CredentialsHashed password, Apple/Google Sign-In tokensUser / provider
Professional dataCV, profile photo, intro video, skillsUser
Usage dataUser ID, registration date, technical logsApp
Approximate locationGPS coordinates (when authorised)Device
Payment dataSubscription history, transaction IDs; never raw card dataApple/Google/Stripe
User contentPosts, messages, reviewsUser

3. Purposes and legal basis

PurposeLegal basis (GDPR)
Account creation and managementArt. 6(1)(b)
Job-search and matching servicesArt. 6(1)(b)
Premium subscription processingArt. 6(1)(b)
Tip processing via StripeArt. 6(1)(b)
Security, fraud prevention, legal complianceArt. 6(1)(c)(f)
Service communicationsArt. 6(1)(b)
Marketing communications (optional)Art. 6(1)(a) — consent
Aggregated analyticsArt. 6(1)(f) — legitimate interest

4. Mandatory vs optional data

Name, email and credentials are required. All other data (photo, CV, video, location, contacts) is optional.

5. How data is processed

Data is hosted on Google Firebase (europe-west1, Belgium), with TLS 1.2+ encryption, at-rest encryption, MFA on admin access, logging and access control.

6. Recipients and sub-processors

VendorServiceLocation
Google Ireland Ltd.Firebase Auth, Firestore, Cloud Functions, FCMEU
Apple Inc.Sign in with Apple, IAP, ASSNUSA (SCCs)
Google LLCPlay Billing, Google Sign-In, Google MapsUSA (SCCs)
Stripe Payments Europe Ltd.Tip and legacy subscription paymentsIreland

7. International data transfers

Transfers to the US rely on the Standard Contractual Clauses (EU Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework.

8. Retention periods

CategoryDuration
Active accountDuration of membership
Deleted account30 days, then permanent deletion
Financial records10 years (Italian Civil Code art. 2220)
Security logs12 months

9. Rights of the data subject

Under GDPR Art. 15-22 users may:

Requests: privacy@meritup.app — answered within 30 days.

9.1 In-app account deletion

Profile → Settings → Delete account.

10. Minors

The App is intended for users aged 16 or over.

11. Changes

Material changes are notified in-app at least 15 days in advance.

12. Contact

privacy@meritup.app