Privacy Policy
Version dated 2026-09-16
This policy covers Mooldo.com, Mooldo.ro, Mooldo.com.ua and Mooldo apps. Each activity has its own purpose and legal basis; this policy does not ask you to consent to all processing.
Moldova
The Moldovan version of Mooldo is subject to Moldova’s Law No. 195/2024 on personal data protection, effective from 23 August 2026.
This regional version corresponds to the site country. Language changes only the translation. Choosing a country or language does not limit rights under mandatory applicable law, including the GDPR where it applies.
Who is responsible
For questions and requests about personal data processing: [email protected]
Data, purposes, retention and providers
| Data | Purpose and legal basis | Retention / deletion criterion | Provider / recipient |
|---|---|---|---|
| Google, Apple or Facebook account identifier, chosen provider and available name/email | Optional social registration, sign-in, explicit linking and account protection — contract / legitimate security interest. | Account data and the provider link are removed on account deletion; see the social sign-in section for revocation credentials. | Mooldo and hosting; the provider you select; email provider for necessary account messages. |
| Provider sign-in proofs, temporary confirmation records and encrypted Apple/Facebook revocation credentials where available | Validate account ownership and revoke provider access on deletion — contract / legitimate security interest. | Temporary confirmations expire after five minutes; revocation credentials remain until the retry succeeds or they are confirmed invalid. | Mooldo and hosting; Google, Apple or Meta for the corresponding sign-in or revocation. |
| Name, email, password hash, language, country, optional avatar and username | Registration, sign-in and account features — contract. | While the account exists; erased on confirmed deletion. File deletion is queued and retried. | Mooldo; hosting and file storage; email provider for confirmations. |
| Favourites, loyalty cards, images, shopping lists and share links | Saving and syncing content you choose — contract. | Until the content or account is deleted. Share links normally expire after 90 days. | Mooldo; hosting and storage; people to whom you disclose a share link. |
| Login, password-reset and deletion-confirmation tokens | Authentication and account protection — contract and legitimate security interest. | Until expiry or revocation; account-linked tokens are removed on deletion. Deletion links last 60 minutes. | Mooldo; hosting; email provider. |
| Push tokens, browser endpoints and keys, language, shop preferences; subscription email | Chosen notifications — consent; necessary service messages — contract. | Until withdrawal or account deletion. Linked delivery addresses, delivery records and events are erased with the account. | Expo; browser push services, Apple/Google; email provider; Mooldo. |
| Support messages, email, error reports and submitted context | Answering requests and diagnosing problems — contract or legitimate interest in fixing errors. | Until the request is resolved and its outcome no longer needs documenting. No automatic expiry is currently set; account-linked records are removed on deletion. | Mooldo; hosting; email provider. |
| Search queries; IP, User-Agent, URLs and referrers in technical logs | Search, catalogue usage counts, diagnostics and abuse prevention — contract / legitimate interest, subject to the right to object. | Some logs have no automatic expiry: deletion and retention are reviewed on request. Account searches are erased on deletion; linked views lose identifiers and URLs. | Mooldo; hosting. |
| GA4: visit events, technical information and analytics cookies when consented | Cookie-based analytics — consent. With consent denied, GA4 may send technical measurements without analytics cookies. | Site-configured GA4 cookies: up to 180 days. Google event retention depends on the property settings; request the actual period by email. | Google Analytics (Google). |
| AdSense: ad requests, technical information, consent choices and permitted identifiers | Advertising; personalisation and optional storage according to choices in the Google consent message. | Google CMP retains choices under its retention rules; you may change them. After refusal, limited ads may use an IP for delivery and anti-fraud storage depending on AdSense settings. | Google AdSense and partners listed in the consent message. |
| Session, CSRF protection, language settings, bot-protection signals and consent choices | Site operation, security and remembering choices — contract / legitimate interest; optional purposes are separate. | Session lifetime follows server settings. Site choices, version and date: 180 days in this browser’s localStorage; separate Google choices follow Google CMP expiry. Security information is reviewed during incident investigations. | Mooldo; Cloudflare/Turnstile; Google Privacy & messaging. |
Restricted database access does not make data anonymous. Logs without automated expiry require manual deletion review; this policy does not claim that automated cleanup is already configured. Backups and data held separately by providers require separate handling of requests. Their actual retention cycle can be requested by email.
Providers and international transfers
Hosting, email and S3-compatible storage process the information needed for their respective functions. S3 compatibility does not necessarily mean AWS is the provider. Google, Expo and Cloudflare may process information in other countries, including the US and EEA countries. You can request the actual providers, locations, transfer bases and copies of applicable safeguards by email. No unconfirmed adequacy decisions or contracts are asserted here.
Transfers from Moldova to countries outside the EEA are subject to Chapter V of Law No. 195/2024: an adequacy decision, appropriate safeguards or a statutory exception is required. Article 44(2) excludes transfers to EEA countries from this special regime. The particular basis depends on the recipient and transfer.
Exercising your rights
Email [email protected] and describe the action requested; for account-related requests, use the account email where possible. Do not send a password or an identity document copy without being asked. If necessary, we explain what information is needed to verify identity.
You may request access, correction, erasure and restriction where the law provides, object to legitimate-interest processing and stop direct marketing. Portability covers data you provided that is processed automatically on the basis of contract or consent. You may withdraw consent without affecting earlier lawful processing.
We normally respond free of charge without undue delay and within one month. Complexity and the number of requests may require up to two additional months; we explain any extension within the first month.
If your rights are infringed, you may complain to CNPDCP or seek a judicial remedy.
Deleting your account
Request deletion in account settings. For an email/password account, confirm through the email. You can also confirm ownership with a linked social provider and then confirm deletion, including when the account has no email or password. If you cannot sign in or manage a shop account, write to [email protected] for manual review, including ownership of shop content. Deletion covers the profile, social account links, linked login tokens, cards and photos, lists, favourites, push addresses, linked searches, support records and delivery history. Revocation credentials are handled as described in the social sign-in section. Copies already saved by other people cannot be recalled automatically. Specific records may be retained for a legal obligation or legal claims; the basis, data and period are explained in the response.
Account deletion instructions, including when you cannot sign in
Required fields, children and automation
Email and a password are required for email registration. Social registration does not require a separate Mooldo password and can work without an email; the provider identifier is needed to recognise the account. Public catalogues remain available without an account. Avatars, cards and subscriptions are optional. Do not submit health details, identity documents or other sensitive information in searches or error reports. We do not make solely automated decisions with legal or similarly significant effects. Personalised ads may involve profiling according to consent choices.
Where an online service is offered directly to a child and processing relies on consent, a child under 14 requires consent or authorisation from their legal representative.
Policy updates
The current version and date appear here. Material changes are announced through the website or account. Continued use alone does not authorise a new purpose that requires consent.
Signing in with Google, Apple or Facebook
Social sign-in is optional. Google and Facebook are available on the website and in the iOS and Android apps; Sign in with Apple is available in the iOS app. You choose the provider on the sign-in screen. Email and password sign-in remains available.
Google: we request openid, email and profile. We use the unique Google account identifier, name and verified email to create or recognise your Mooldo account. A Google sign-in response may include a profile photo URL; Mooldo does not copy that photo into your account. We do not request access to Gmail messages, contacts, Google Drive or calendars.
Apple: we use the identifier Apple assigns to this app and, when supplied, your name and verified email. If you choose Hide My Email, we store the relay address provided by Apple. Apple may supply your name only on the first authorisation.
Facebook: we request public_profile and use the app-specific user identifier and name. We do not request the email permission, friends list or permission to publish. The iOS app uses Limited Login. A missing name or email does not prevent creation of a social account.
These data are used for registration, sign-in, account security, linking a sign-in method you select, and confirming account deletion. Mooldo creates its own session after verifying the provider response. When Google confirms ownership of a Gmail or Google Workspace email matching an existing Mooldo account, we can connect Google and sign you into that account automatically. Other email matches require signing in to the existing account and confirming ownership before linking. Existing provider links are not transferred between accounts.
The selected provider receives the authentication request and the technical information needed to process it. Mooldo sends the provider the codes or tokens needed to validate sign-in or revoke access. Mooldo and its hosting process the account data; a stored email may be used by our email provider for necessary account messages. Google, Apple and Meta also process data under their own privacy policies and may process them internationally. Social sign-in data are not sold or passed to advertising platforms for ad targeting; advertising and analytics are described separately below.
Sign-in exchanges with Mooldo and the providers use HTTPS. Provider passwords are entered with the provider and are not received by Mooldo. The server checks signed identity proofs or validates access tokens with the provider. Credentials retained for Apple or Facebook revocation are encrypted in storage. Google access and refresh tokens are not retained for later access to Google services.
The provider identifier and its link to your Mooldo account are retained while that account exists. Account deletion removes this link and account data. If an Apple or Facebook credential has been retained for revocation, an encrypted copy stays in a retry queue until revocation succeeds or the credential is confirmed invalid; there is no fixed maximum retry retention period. Temporary sign-in and ownership confirmations expire after five minutes and are removed by scheduled maintenance. You can also manage Mooldo access in your provider account; withdrawing provider access does not itself delete your Mooldo account. Use the deletion procedure below.