Privacy Policy

Version dated 2026-09-16

This policy covers Mooldo.com, Mooldo.ro, Mooldo.com.ua and Mooldo apps. Each activity has its own purpose and legal basis; this policy does not ask you to consent to all processing.

Moldova

The Moldovan version of Mooldo is subject to Moldova’s Law No. 195/2024 on personal data protection, effective from 23 August 2026.

This regional version corresponds to the site country. Language changes only the translation. Choosing a country or language does not limit rights under mandatory applicable law, including the GDPR where it applies.

Who is responsible

For questions and requests about personal data processing: [email protected]

Data, purposes, retention and providers

DataPurpose and legal basisRetention / deletion criterionProvider / recipient
Google, Apple or Facebook account identifier, chosen provider and available name/emailOptional social registration, sign-in, explicit linking and account protection — contract / legitimate security interest.Account data and the provider link are removed on account deletion; see the social sign-in section for revocation credentials.Mooldo and hosting; the provider you select; email provider for necessary account messages.
Provider sign-in proofs, temporary confirmation records and encrypted Apple/Facebook revocation credentials where availableValidate account ownership and revoke provider access on deletion — contract / legitimate security interest.Temporary confirmations expire after five minutes; revocation credentials remain until the retry succeeds or they are confirmed invalid.Mooldo and hosting; Google, Apple or Meta for the corresponding sign-in or revocation.
Name, email, password hash, language, country, optional avatar and usernameRegistration, sign-in and account features — contract.While the account exists; erased on confirmed deletion. File deletion is queued and retried.Mooldo; hosting and file storage; email provider for confirmations.
Favourites, loyalty cards, images, shopping lists and share linksSaving and syncing content you choose — contract.Until the content or account is deleted. Share links normally expire after 90 days.Mooldo; hosting and storage; people to whom you disclose a share link.
Login, password-reset and deletion-confirmation tokensAuthentication and account protection — contract and legitimate security interest.Until expiry or revocation; account-linked tokens are removed on deletion. Deletion links last 60 minutes.Mooldo; hosting; email provider.
Push tokens, browser endpoints and keys, language, shop preferences; subscription emailChosen notifications — consent; necessary service messages — contract.Until withdrawal or account deletion. Linked delivery addresses, delivery records and events are erased with the account.Expo; browser push services, Apple/Google; email provider; Mooldo.
Support messages, email, error reports and submitted contextAnswering requests and diagnosing problems — contract or legitimate interest in fixing errors.Until the request is resolved and its outcome no longer needs documenting. No automatic expiry is currently set; account-linked records are removed on deletion.Mooldo; hosting; email provider.
Search queries; IP, User-Agent, URLs and referrers in technical logsSearch, catalogue usage counts, diagnostics and abuse prevention — contract / legitimate interest, subject to the right to object.Some logs have no automatic expiry: deletion and retention are reviewed on request. Account searches are erased on deletion; linked views lose identifiers and URLs.Mooldo; hosting.
GA4: visit events, technical information and analytics cookies when consentedCookie-based analytics — consent. With consent denied, GA4 may send technical measurements without analytics cookies.Site-configured GA4 cookies: up to 180 days. Google event retention depends on the property settings; request the actual period by email.Google Analytics (Google).
AdSense: ad requests, technical information, consent choices and permitted identifiersAdvertising; personalisation and optional storage according to choices in the Google consent message.Google CMP retains choices under its retention rules; you may change them. After refusal, limited ads may use an IP for delivery and anti-fraud storage depending on AdSense settings.Google AdSense and partners listed in the consent message.
Session, CSRF protection, language settings, bot-protection signals and consent choicesSite operation, security and remembering choices — contract / legitimate interest; optional purposes are separate.Session lifetime follows server settings. Site choices, version and date: 180 days in this browser’s localStorage; separate Google choices follow Google CMP expiry. Security information is reviewed during incident investigations.Mooldo; Cloudflare/Turnstile; Google Privacy & messaging.

Restricted database access does not make data anonymous. Logs without automated expiry require manual deletion review; this policy does not claim that automated cleanup is already configured. Backups and data held separately by providers require separate handling of requests. Their actual retention cycle can be requested by email.

Signing in with Google, Apple or Facebook

Social sign-in is optional. Google and Facebook are available on the website and in the iOS and Android apps; Sign in with Apple is available in the iOS app. You choose the provider on the sign-in screen. Email and password sign-in remains available.

Google: we request openid, email and profile. We use the unique Google account identifier, name and verified email to create or recognise your Mooldo account. A Google sign-in response may include a profile photo URL; Mooldo does not copy that photo into your account. We do not request access to Gmail messages, contacts, Google Drive or calendars.

Apple: we use the identifier Apple assigns to this app and, when supplied, your name and verified email. If you choose Hide My Email, we store the relay address provided by Apple. Apple may supply your name only on the first authorisation.

Facebook: we request public_profile and use the app-specific user identifier and name. We do not request the email permission, friends list or permission to publish. The iOS app uses Limited Login. A missing name or email does not prevent creation of a social account.

These data are used for registration, sign-in, account security, linking a sign-in method you select, and confirming account deletion. Mooldo creates its own session after verifying the provider response. When Google confirms ownership of a Gmail or Google Workspace email matching an existing Mooldo account, we can connect Google and sign you into that account automatically. Other email matches require signing in to the existing account and confirming ownership before linking. Existing provider links are not transferred between accounts.

The selected provider receives the authentication request and the technical information needed to process it. Mooldo sends the provider the codes or tokens needed to validate sign-in or revoke access. Mooldo and its hosting process the account data; a stored email may be used by our email provider for necessary account messages. Google, Apple and Meta also process data under their own privacy policies and may process them internationally. Social sign-in data are not sold or passed to advertising platforms for ad targeting; advertising and analytics are described separately below.

Sign-in exchanges with Mooldo and the providers use HTTPS. Provider passwords are entered with the provider and are not received by Mooldo. The server checks signed identity proofs or validates access tokens with the provider. Credentials retained for Apple or Facebook revocation are encrypted in storage. Google access and refresh tokens are not retained for later access to Google services.

The provider identifier and its link to your Mooldo account are retained while that account exists. Account deletion removes this link and account data. If an Apple or Facebook credential has been retained for revocation, an encrypted copy stays in a retry queue until revocation succeeds or the credential is confirmed invalid; there is no fixed maximum retry retention period. Temporary sign-in and ownership confirmations expire after five minutes and are removed by scheduled maintenance. You can also manage Mooldo access in your provider account; withdrawing provider access does not itself delete your Mooldo account. Use the deletion procedure below.

Providers and international transfers

Hosting, email and S3-compatible storage process the information needed for their respective functions. S3 compatibility does not necessarily mean AWS is the provider. Google, Expo and Cloudflare may process information in other countries, including the US and EEA countries. You can request the actual providers, locations, transfer bases and copies of applicable safeguards by email. No unconfirmed adequacy decisions or contracts are asserted here.

Transfers from Moldova to countries outside the EEA are subject to Chapter V of Law No. 195/2024: an adequacy decision, appropriate safeguards or a statutory exception is required. Article 44(2) excludes transfers to EEA countries from this special regime. The particular basis depends on the recipient and transfer.

How Google uses information from partner sites

Cookie and advertising choices

The Mooldo panel lets you allow or decline GA4 analytics cookies and ad personalisation. This choice does not disable ad spaces or block catalogues. Settings are stored for 180 days in this browser and can be changed using the button below; closing is not consent. Without permission, GA4 runs in denied mode and may send measurements without analytics cookies. Without confirmed consent to personalisation, the site sends AdSense the non-personalised-ad request flag without pausing ad requests. Non-personalised ads are not necessarily cookieless. Advertising purposes, cookies and partners are additionally managed in the Google message; AdSense determines the eligible mode, including Limited ads, using its signals and settings. Limited ads may also use IP addresses and fraud-prevention storage. A new explicit choice in Google updates site settings; an older grant does not override a local refusal of personalisation. Third-party cookies can also be managed in your browser.

In this country the site enables Google Analytics cookies and ad personalisation by default and gives you a simple way to switch each of them off: use the panel that appears on your first visit or the button below. Switching them off removes the site-set analytics cookies and asks AdSense for non-personalised ads.

Exercising your rights

Email [email protected] and describe the action requested; for account-related requests, use the account email where possible. Do not send a password or an identity document copy without being asked. If necessary, we explain what information is needed to verify identity.

You may request access, correction, erasure and restriction where the law provides, object to legitimate-interest processing and stop direct marketing. Portability covers data you provided that is processed automatically on the basis of contract or consent. You may withdraw consent without affecting earlier lawful processing.

We normally respond free of charge without undue delay and within one month. Complexity and the number of requests may require up to two additional months; we explain any extension within the first month.

If your rights are infringed, you may complain to CNPDCP or seek a judicial remedy.

CNPDCP — Moldova’s data protection authority

Deleting your account

Request deletion in account settings. For an email/password account, confirm through the email. You can also confirm ownership with a linked social provider and then confirm deletion, including when the account has no email or password. If you cannot sign in or manage a shop account, write to [email protected] for manual review, including ownership of shop content. Deletion covers the profile, social account links, linked login tokens, cards and photos, lists, favourites, push addresses, linked searches, support records and delivery history. Revocation credentials are handled as described in the social sign-in section. Copies already saved by other people cannot be recalled automatically. Specific records may be retained for a legal obligation or legal claims; the basis, data and period are explained in the response.

Account deletion instructions, including when you cannot sign in

Required fields, children and automation

Email and a password are required for email registration. Social registration does not require a separate Mooldo password and can work without an email; the provider identifier is needed to recognise the account. Public catalogues remain available without an account. Avatars, cards and subscriptions are optional. Do not submit health details, identity documents or other sensitive information in searches or error reports. We do not make solely automated decisions with legal or similarly significant effects. Personalised ads may involve profiling according to consent choices.

Where an online service is offered directly to a child and processing relies on consent, a child under 14 requires consent or authorisation from their legal representative.

Policy updates

The current version and date appear here. Material changes are announced through the website or account. Continued use alone does not authorise a new purpose that requires consent.

© Mooldo 2021-2026

Mooldo

Get access to all discounts in the app!