Version 2026.6 of this document takes effect on 13 October 2026, and until then the version in force applies. See the version in force
Privacy Policy
Effective 13 October 2026
Contents
1. Who we are and how to write to us
2. What data we collect and where it comes from
3. Identity check through Evrotrust
4. Payments
5. Technical data
6. Analytics and advertising
7. What others see
8. Why we process data and on what legal basis
9. Who we share data with
10. Transfers outside the EEA
11. How long we keep data
12. Deleting your account and getting a copy of your data
13. Your rights
14. Automated decisions and profiling
15. How we protect data
16. Only for people aged 18 or over
17. Changes to this policy
18. Contact
Here we explain what personal data we process when you use Strehana, why, who sees it, who we share it with, how long we keep it and what rights you have. This policy covers the website strehana.com and the Strehana apps for Android and iOS.
1. Who we are and how to write to us
The controller of your personal data is Vizium OOD (Визиум ООД), the company that runs Strehana. When this policy says "we", it means Vizium OOD.
- Company number (ЕИК) 208647543
- Registered office and address of management: 1113 Sofia, Izgrev district, Iztok, 2 Nikolay Haytov St, entrance G, floor 14, apartment 47, Bulgaria
- Manager: Vladimir Krasimirov Yanakiev
- Email: legal@strehana.com
- Phone: 0897898180
We have not appointed a data protection officer. For any question about your personal data, write to legal@strehana.com.
2. What data we collect and where it comes from
We collect the data you give us, the data created while you use Strehana, and the data we receive from the partners described here.
Sign-in account with Google or Apple
You sign in only with Google or with Apple. We have no passwords.
From Google we receive your Google account id, your email address, your name and your picture. From Apple we receive your Apple id, your email address (or the hidden address Apple creates for you) and, on the first sign-in only, your name.
We keep the email, the provider (Google or Apple), your id with that provider and when the account was created. If you change your email with Google or Apple, we update it the next time you sign in.
On your first sign-in with Google we copy the picture from your Google account as a photo on your Strehana profile. We do this once per account.
When you sign in with Apple through the app, we keep the token Apple gives us, so that we can end our access at Apple when you delete your account.
We also keep whether the account is suspended or banned, until when and for what reason.
Profile
The name on your profile is the one Google or Apple gave us, or the one you type in. You can change it. We also keep what you fill in:
- photos
- date of birth and gender, optional (after the identity check they come from your ЕГН, see section 3)
- whether you study, work or both
- languages
- a text about you and about the flatmate you are looking for
- habits: smoking, pets, how social you are, daily routine, working from home and working hours, how often guests come over, whether you are part of a couple
- up to 5 personality traits and up to 3 interest groups
While you use Strehana we create and keep: whether you are online and when you were last active, how quickly you reply to messages (average time and a score), how complete your profile is (a score from 0 to 100), what you are looking for on Strehana, and internal dates for your first steps, for example since when you have been looking for a room.
We keep when you accepted the Terms of Service and this policy, and which version.
Card
Your card says what you are looking for. In it we keep:
- your maximum monthly budget
- your move-in date and for how long you are looking
- your text (up to 500 characters)
- the places you chose: a neighbourhood, a city or a point on the map (for example a place or an address), with a radius
- whether you accept buddy-ups
- whether your photo is shown on the card
- the card's status and dates, and whether it is featured and until when
Alongside the card we also keep how many different signed-in people have seen it, a snapshot of your profile completeness score, a copy of your gender and whether you smoke (for the deck's filters), and the reason if our team restricted it.
The name, age, photo and habits others see on the card are not stored in it. We take them from your profile when the card is shown.
Room listings
When you publish a room, we keep everything in the listing:
- title, description and photos
- the exact location of the home: the point on the map and the address or place name you chose
- the rooms: name, description, size, rent, deposit, available from, bed, photos, for how long they are let
- the home: floor and number of floors, parking, accessibility, bills, rules on smoking and pets
- who lives there: number of people, ages, whether the host lives in the home, type, gender mix and atmosphere of the household, children and how many, pets, languages
- your role: owner, current tenant or subletter, and whether you live in the home
- how viewings work and whether you accept applications only from people with a checked identity
- the listing's status and dates, whether it is featured and until when, and the reason if our team restricted it
The data on who lives in the home is also data about other people. Everyone can see it (see section 7).
We count each listing's views and impressions per day, without keeping in that counter who looked at it.
We also keep your saved rooms and, in the app, your saved searches: a name, the filters (price, place, habits) and whether you want a notification about a new matching listing.
Likes, invites, applications and matches
We keep who likes whom, and when:
- an invite from a host to a card: which room, status, dates and the message, if there is one
- a buddy-up, from a person to a card, with the same data
- an application to a room: who applied, to which listing and which rooms, status and dates. With it we keep a copy of the applicant's habits at the time of applying (smoking, pets, how social, routine, languages). If the application contains a note or details of a group, we keep those too: the number of people and each person's age, gender and occupation.
- a match: when two people like each other, an invite or an application becomes accepted and a conversation opens
For the contact ladder we count how many likes you sent in the last 24 hours. The counter is kept for up to 48 hours.
If you like someone without an account, the likes (up to 3) stay only on your device. We send them when you sign in.
Conversations and messages
We keep your conversations: between which people, about which listing, when they started, whether they are closed and by whom. We keep the text of every message, when it was sent and whether it was read.
When you hide a conversation, it disappears only for you. The messages stay.
Notifications and emails
We keep the notifications we show you in Strehana. Some contain a person's name, a listing title or the first 100 characters of a message.
In the app we keep your phone's notification token so that we can send you notifications. On the website, notifications are shown only in the open browser tab and do not go through any outside service.
We send you emails about a new application for your room, an accepted application, a received or accepted invite or buddy-up, unread messages, new rooms and people in your areas (a daily summary), confirmation of a card payment, and our team's decisions on your content or account, and on reports, appeals and notices you sent.
The unread-message email names nobody and quotes no messages. You can unsubscribe from it and from the daily summary through the link in the email itself. We keep these settings.
The deck
When you browse the deck while signed in, we record every card we showed you: when, in which position, whether you saw it and for how long, whether you passed or liked it, on the website or in the app, and the reasons for the order.
This is how we avoid showing you the same cards again. Without an account we do not record this on the server. Passed cards are remembered only on your device, for 30 days.
Reports, notices, appeals and decisions
When you report a card, a listing, a message or a person, we keep who reported, what, the reason, your text, the legal provision if you name one, the status and our team's notes. The reported person is not told who reported them. When we decide, we tell you what we decided, in the app and by email, with a way to appeal.
Anyone can send a notice of illegal content, also without an account, from the page strehana.com/en/report. We keep the link to the content, the reason, the provision, the explanation, the name and email if you give them, the decision and our team's notes. We also keep a salted hash of your IP address, to limit notices to 5 per hour from one address.
When you appeal a decision from the page strehana.com/en/appeal, we keep which decision the appeal is about, your text, your account or, if you are not signed in, your email, the outcome of the appeal and our reply.
When we restrict a listing, a card or an account, we keep the decision: what we decided, the facts, the ground and the provision, if any. We send them to you as a statement of reasons by email and, for listings and cards, also as a notification.
Blocks and feedback
We keep whom you blocked and when.
When you write to us through «Помощ и обратна връзка» (Help and feedback), we keep the category, the subject, the text, the page you wrote from, your browser and the screenshot, if you attach one.
Data other people give about you
Sometimes we receive data about you from other people: a host describes who lives in the home, an applicant describes their group, someone writes to you or reports you or your content.
3. Identity check through Evrotrust
The check is optional. After it, your profile gets the «Потвърден» (Verified) badge.
You enter your ЕГН (Bulgarian personal number). We check that it is valid and work out your date of birth and sex from it. If the ЕГН says you are under 18, we refuse the check without contacting Evrotrust and alert our team with your account id only. A person on the team decides about the account.
Otherwise we send the ЕГН to Evrotrust. Evrotrust checks whether you have a verified account with them and sends a request to the Evrotrust app on your phone. You confirm there. Evrotrust returns only the result to us. We receive no name, photo or data from your document.
We do not keep the ЕГН. We keep:
- a keyed hash (HMAC) of the ЕГН, so that one ЕГН cannot verify two accounts
- the date of birth and sex from the ЕГН
- the Evrotrust transaction number
- when the identity was verified and by which route
While we wait for your confirmation, we hold this data, without the ЕГН, in temporary memory for up to 5 minutes.
After the confirmation we write the date of birth and sex from the ЕГН to your profile. After that they cannot be changed from the profile.
When you delete your account, we delete the check record. We keep separately, with no link to the account, only the hash of the ЕГН and the deletion date, for 12 months. While we keep them, the same ЕГН cannot verify another account. Then we delete them.
The old phone check by SMS is no longer offered, and we do not keep the phone numbers from it.
4. Payments
The paid services are a featured listing, a featured card and a boosted application. We do not keep bank card data.
By card on the website (Stripe)
Card payments on the website go through Stripe. You type your card or wallet details (Apple Pay, Google Pay) into a Stripe field. They go straight to Stripe and do not pass through our servers.
We send Stripe the amount, the currency, our payment number, your account id, the type of service and which listing, card or application it is for.
Stripe's code loads only on the payment pages. It collects data about your device and sets cookies to prevent fraud.
After a card payment we email you a confirmation: the service, the amount, when it starts and ends, the payment number and the consent you gave at checkout for the service to start at once and to lose the 14-day right of withdrawal, with the time and the Terms version. Without such consent, the email describes your 14-day right of withdrawal.
In the app (App Store and Google Play)
In the app you pay through Apple's App Store or through Google Play. The payment and its details stay with Apple or Google. They also send you the receipt.
The app sends us the store's receipt. We check it and keep only the transaction number and the product. We do not keep the receipt itself. We check Google Play receipts through Google.
When Apple or Google refund a payment, we learn about it and stop the paid service.
What we keep for each payment
- type, amount, duration, status, dates and which listing, card or application it is for
- the Stripe payment number or the store transaction number
- the consent to start at once, with the time and the Terms version
- the promo code, if you use one, or who on our team gave the service for free and why
- whether the payment came from the website, Android or iOS and whether there was advertising consent
- if there was advertising consent: Meta's identifiers (_fbp, _fbc), the IP address and the browser the payment came from
We also keep until when each paid service runs.
5. Technical data
Record of your cookie and analytics choice
When you answer the cookie banner on the website or the analytics question in the app, we keep your choice (analytics yes or no, advertising yes or no), the policy version and when. With the record we keep a random id from the browser, your account if you are signed in, a salted hash of your IP address and your browser (up to 512 characters).
This lets us show what choice you made and when.
Server logs
Every request to our servers is written to a log: its address and parameters (for example the text of a place search), the IP address, the browser or app, the result and the time.
The logs stay on the servers our services run on. We do not collect them in a separate system.
To limit excessive requests, we hold your IP address or your account id in a counter for up to one minute, and for place searches also until the end of the day (UTC).
Device location
In the Android app, when you tap the location button on the map for a listing's address, your phone asks for permission. We use the location only to move the map. We do not send it to our servers. Google's map sees it to show your dot. As the room's location we store only the point you choose.
The iOS app does not ask for access to your location.
On the website, the location button on the map for a listing's address asks your browser and only moves the Google map. We do not send the location to our servers.
Crash and error reports
The app sends crash and error reports to Sentry and to Google's Firebase Crashlytics. A report contains the error, the steps before it (for example which screens and which addresses of our server were open, with ids removed), the language, the device, the system and the app version. Sentry also receives speed data for some sessions.
The reports are not linked to your account. We do not send your id.
You can stop them at any time: in Settings, section «Поверителност» (Privacy), the «Споделяй диагностика» (Share diagnostics) switch, and without an account from the «Спри отчетите» (Stop the reports) line on the sign-in screen. Stopping applies from then on.
The website sends Sentry reports of errors in the browser: the error message, the page address without sign-in data, the browser and system, and speed data for 10% of page loads. Sentry sees your IP address when it receives the report.
Data on your device
The website keeps some data in your browser, for example your cookie choice, the cards you passed and drafts of a listing or a card. The list is in the «Политика за бисквитки» (Cookie Policy) (strehana.com/en/cookie-policy).
On the sign-in pages and forms, Apple's sign-in library loads. Sign-in with Google opens in a separate Google window only when you press the button.
The app keeps your sign-in data in the phone's protected storage (the Keychain on iOS, encrypted with the Android Keystore on Android). It also keeps a cache of your profile, listings, conversations, notifications and payments, drafts, passed cards and pictures. When you sign out it deletes them, except a few device settings, such as your analytics and diagnostics choices.
On an iPhone, the app's settings and drafts may end up in the phone's backups.
Each time the app starts, Google's Firebase creates an installation id and a notification token. We send the token to our server only while you are signed in, and delete it when you sign out.
Each time it opens, the app asks PostHog whether its version is still supported. The request carries a new random id each time and no data about your account. PostHog sees your device's IP address.
When you download a copy of your data in the app, the file is saved in the phone's temporary folder so that you can share it.
6. Analytics and advertising
Analytics and advertising are optional. On the website you choose in the cookie banner, separately for analytics and for advertising. Both are off by default and none of it runs before you answer. The app has one joint choice for analytics and sharing with Meta. We ask only people with an account. Without an account the app collects no analytics.
With analytics consent
- Google Analytics (website): which pages you open and what you do on them, _ga cookies and, when you are signed in, your account id and three measures of it: how complete it is, whether it is verified and how many days old it is. Google sees your IP address.
- PostHog (website): the same actions and pages, the full page address, the device type, system and language, the source of your first visit and, after sign-in, your account id. PostHog sees your browser's IP address and can derive an approximate location from it.
- PostHog (app): which screens you open and your actions in the deck and elsewhere, the app version, the device type, system, language and your account id. On Android also the install source from Google Play.
- PostHog (from our server): events for your actions, for example a new listing, a like, a message without its text, a payment, with your account id and data such as city, budget, amount, gender, occupation, age group, your email domain (not the address), ids of listings and of the other people in the action, and the listing's location rounded to about 1 km. These events do not carry your IP address.
- Source of the visit to the website: where you came from and the link parameters (utm, gclid, fbclid), in a cookie for 90 days. The channel and campaign are sent to our server with your actions.
When another person has given analytics consent, the events for their actions can contain your account id, for example when they write to you or apply to your room.
With advertising consent
We share key actions with Meta (Facebook, Instagram) to measure our advertising:
- Meta Pixel (website): pages opened, listings viewed, searches by city, applications, saved listings, messages, new listings and cards, starting a payment and payments, with amounts and ids of listings and payments. The Pixel sets the _fbp and _fbc cookies and sends your name, gender and account id, hashed.
- From our server (Meta Conversions API), for actions on the website and in the app: registration, application, first message, saved listing, payment, new listing and new card. We send your email, name and account id hashed, on registration and a new listing or card also your gender, and unhashed the IP address, browser, _fbp and _fbc, plus the city, listing type, amount and ids.
- If you give advertising consent within 7 days of registering, we also send Meta the registration event.
- In the Android app: the id of the click on a Meta ad, if the install came from such an ad.
- If you also have analytics consent, Google Analytics also receives Google's advertising signals.
We send Meta a server event only if consent was given at the moment of the action. We do not send Meta a phone number, date of birth or precise location.
Without consent
Even without consent, our server sends PostHog counts of actions, so that we know how much Strehana is used. They all go under one shared id, the same for everyone, without your account id and without your IP address, and with the hour but not the minutes. They carry only general fields, for example the kind of listing, the number of results, the position in the deck and whether a sign-in attempt worked, with Google or with Apple. They carry no city, budget, number of places or payment amount.
In the same way we count the cards shown in the deck to people without an account, answers to the cookie banner and failed sign-in attempts (provider and type of error).
How to change your choice
On the website, the «Настройки за бисквитки» (Cookie settings) link at the bottom of the page opens the banner again. If you are signed in, you can also use Settings, section «Поверителност и данни» (Privacy and data), row «Бисквитки» (Cookies).
In the app: Settings, section «Поверителност» (Privacy), the «Продуктова аналитика» (Product analytics) switch.
When you withdraw consent, we stop collecting and sending this data. Our server picks up the change within 5 minutes. Withdrawing does not affect what was already sent.
When you sign out in the app, analytics is switched off. If you sign in again with the same account, we apply your choice again.
7. What others see
The deck, listings and cards are visible without an account. So part of your data is public.
Everyone, even without an account
- Room listings in full: text, photos, prices, rooms, floor, who lives in the home and its rules.
- The room's location is approximate: the point is moved by 100 to 125 metres, and instead of the address it shows «neighbourhood, city, country». Only the listing's owner sees the exact location. We do not show it after a match either. The address can be shared in the conversation.
- For the host of every listing: first name, age, gender, the first profile photo, the «Потвърден» (Verified) badge and the host's number of listings. That photo cannot be hidden from the listings.
- The card: first name, age (if there is a date of birth), gender (if given), budget, move-in date, duration, text, the places with their points on the map, languages, the «Потвърден» (Verified) badge, whether you accept buddy-ups, when it was published and whether it is featured. If you choose a point (for example a place or an address), it is shown exactly.
- The first photo from your profile is shown on the card, unless you hide it in the card form.
- Every listing's page contains the host's account id. With it, anyone can open the same person's other active listings and active card.
- The address of every uploaded photo contains the id of the account it was uploaded from.
- The pages of active listings and cards can appear in search engines. The preview when a card is shared contains the first name, the places and the start of the text or the budget, but never your photo. The preview of a listing contains a room photo, the title, the price and the city, with no data about the host.
People with an account also see
- the habits on the card: smoking, pets, occupation, daily routine, guests, working from home and whether you are part of a couple
- your profile: the name as entered, all photos, the text about you and about the flatmate you are looking for, your age (not the date of birth), gender, occupation, languages, habits, traits and interests, the badge, the scores for profile completeness and reply speed, whether you are online and when you were last active, and since when you have been on Strehana
- your account id, including on your card and your listings
A person you block does not see your profile, card and listings while they are signed in, and you do not see theirs. Without an account, public content stays visible to everyone.
Other people do not see
- your email
- your date of birth (we show only your age)
- your ЕГН, which we do not keep
- the exact location of your room
- your messages, except the person in the conversation
- your payment records
8. Why we process data and on what legal basis
To provide Strehana to you (contract, Art. 6(1)(b) GDPR)
- the account and sign-in with Google or Apple
- your card and listings and showing them in the deck
- the deck and its order for people with an account
- likes, invites, buddy-ups, applications, matches and conversations, with the contact ladder
- notifications and emails about things that concern you
- the identity check, when you ask for it
- the paid services
Legitimate interest (Art. 6(1)(f) GDPR)
- security and protection from abuse: server logs, limiting excessive requests, blocks and reports of breaches of the Terms
- Stripe's fraud protection for card payments
- crash and error reports from the website and the app, so that we can fix errors. In the app you can stop them.
- the counts without consent that our server sends PostHog under a shared id, so that we know how much Strehana is used
- showing and ordering the deck for people without an account
- the daily summary and the unread-message emails, which you can unsubscribe from
- Google's maps on listing pages and when choosing an address
- checking whether the app version is still supported
- keeping the ЕГН hash for 12 months after an account is deleted, so that nobody can avoid a restriction with a new account
- keeping reports about content and records of listing reviews after the content is deleted
You can object to this processing (see section 13).
Consent (Art. 6(1)(a) GDPR)
- analytics: Google Analytics, PostHog and the source of the visit
- sharing with Meta and the advertising signals to Google
You can withdraw your consent at any time (see section 6). Withdrawing does not affect processing before it.
Legal obligation (Art. 6(1)(c) GDPR)
- the accounting and tax records of payments
- notices of illegal content, statements of reasons and appeals under the Digital Services Act
- the records with which we prove your consent
- our answers to requests under this policy
9. Who we share data with
We share data only with these recipients and only for what is described:
- Other people on Strehana: they see the data in section 7. The person in a conversation sees the messages, and the host sees the application.
- Hébergement OVH Inc. (Canada): hosting, as a processor. Our servers and databases run in OVH's cloud in Warsaw, Poland, where the photos are kept too.
- Google, as an independent controller: sign-in with Google; maps on listing pages and in the app; place and address search, where our server sends only the text typed or the point on the map, without your IP address; payments and receipt checks in Google Play. Google, as a processor: app notifications through Firebase Cloud Messaging (the token and the notification text, sometimes with a person's name or a listing title, without the text of messages), crash reports through Firebase Crashlytics, and Google Analytics with consent.
- Apple: sign-in with Apple, payments in the App Store and delivery of notifications to iPhones. For App Store purchases the seller is Apple Distribution International Ltd., which processes the purchase data as an independent controller.
- Stripe: card payments on the website (section 4). For the payment itself Stripe is a processor; for its fraud checks and its legal duties it is an independent controller.
- Evrotrust: the identity check. It receives your ЕГН (section 3). Evrotrust is an independent controller and processes the data in the EU.
- Meta: only with advertising consent (section 6). For collecting the data with the pixel and sending it from our server we are joint controllers with Meta Platforms Ireland Ltd.; for what Meta does with it afterwards, Meta is an independent controller. The essence of our arrangement with Meta is in Meta's controller addendum (www.facebook.com/legal/controller_addendum). If advertising consent was ever given, when the account is deleted we also send Meta an erasure signal with a hashed account id.
- PostHog: analytics (section 6) and the app version check, in PostHog's EU cloud (Germany). PostHog is a processor.
- Sentry: error reports from the website and crash reports from the app, in Sentry's EU region (Germany). Sentry is a processor.
- Proton AG (Switzerland): sends our emails from no-reply@strehana.com. It receives your address and the email's text. Proton is a processor.
- OpenStreetMap Foundation (United Kingdom), the Nominatim service: for neighbourhood boundaries in the app, our server sends a point on the map, with no data about you.
We do not sell personal data. We give data to public authorities only when the law requires us to.
10. Transfers outside the EEA
Some recipients are companies outside the European Economic Area (EEA) or belong to groups based outside it. So data may also be processed outside the EEA:
- Google, Meta and Stripe: to the US on the basis of the EU-US Data Privacy Framework (European Commission decision of 10 July 2023) and, where it does not apply, the European Commission's standard contractual clauses.
- PostHog and Sentry: the data is kept in the EU (Germany), but both companies may also process it in the US, on the basis of the EU-US Data Privacy Framework, or otherwise standard contractual clauses.
- Apple: on the basis of the European Commission's standard contractual clauses.
- Proton, in Switzerland: on the basis of the European Commission's decision that Switzerland ensures adequate protection.
- OpenStreetMap Foundation, in the United Kingdom: on the basis of the European Commission's adequacy decision.
- Hébergement OVH Inc., in Canada: the data is kept in Warsaw, Poland; OVH's access from Canada rests on the European Commission's adequacy decision for Canada.
You can ask for a copy of the standard contractual clauses at legal@strehana.com. Whether a company is in the Data Privacy Framework can be checked at www.dataprivacyframework.gov.
11. How long we keep data
When you delete your account, we delete most data at once (section 12). Otherwise the periods are:
- Profile, photos, habits and the records of accepting the Terms and this policy: while the account exists.
- The card is active for 30 days and you can renew it. After that it is hidden, and the record stays until the account is deleted. A card you delete is removed completely 30 days later; until then the record stays so that we can look into reports.
- A listing is active for 30 days and you can renew it. An expired listing is archived and deleted 7 days later. A listing you delete is deleted at once. A paused listing, or one our team restricted, does not expire.
- When we delete a listing, we delete the photos in it too. A photo you remove from a listing or profile stays in our storage until you delete your account, and anyone who has its address can open it.
- Likes, invites and buddy-ups: until the sender or the recipient deletes their account. An invite you withdraw before an answer is deleted at once.
- Applications: while the listing exists and while the applicant and the host have accounts.
- Deck history: 12 months after the last action on the card or listing, or until the account is deleted if that comes first. If you take back a pass, the record for that card is deleted.
- Conversations and messages: until one of the two people in the conversation deletes their account. When a listing is deleted, its conversations are closed but stay.
- Notifications: read ones 90 days, unread ones 180 days.
- Email settings and the records of daily summaries sent: until the account is deleted. The record of an unread-message email is deleted as soon as the conversation is read.
- Notification token: until you sign out in the app or delete the account.
- Saved rooms and searches: until you remove them or delete the account.
- Blocks: until you unblock or one of the two accounts is deleted.
- Feedback: until the account is deleted.
- Identity check record: until the account is deleted. After that only the ЕГН hash and the deletion date, for 12 months.
- Payments: when the account is deleted, the records lose the link to your account and the advertising data. We delete them 10 years after the end of the year of payment.
- Reports: those you filed and those against your account are deleted with your account. The rest are deleted 12 months after the decision on them.
- Notices of illegal content: until we decide and 12 months after the decision.
- Appeals: until we decide and 12 months after the decision. An appeal filed from an account is also deleted with the account.
- Records of the cookie and analytics choice: 3 years, as proof of consent; your latest choice is kept while it stands. When an account is deleted, we remove the account, the IP address hash and the browser from them. Records made without an account keep the IP address hash and the browser.
- Records of listing edit reviews (old and new text, photos, whose listing it is), when such review is switched on: 12 months after the review decision, also after the listing is deleted. Reviews not yet decided are kept until the decision.
- Server logs: until the servers replace them.
- Counters against excessive requests: up to one minute or until the end of the day. Likes counter: up to 48 hours.
- Internal delivery records of events between our services: 7 days after sending. Copies in our event system are kept for 7 or 30 days depending on their type.
- Cache of place searches, not linked to any person: from 1 hour to 30 days.
- Database backups: OVH makes them automatically. Deleted data can remain in them until the backups are replaced.
- How long PostHog, Google Analytics, Meta, Sentry and Firebase Crashlytics keep data is set in their settings.
12. Deleting your account and getting a copy of your data
Deleting your account
You delete your account from Settings: on the website in «Опасна зона» (Danger zone), row «Изтрий профила завинаги» (Delete account permanently), and in the app in section «Поверителност» (Privacy), row «Изтриване на акаунт» (Delete account).
Deletion is immediate and final. There is no cooling-off period and it cannot be undone.
Your account disappears at once. Our other services delete their data, usually within seconds. If one fails, we try again automatically over the following hours.
We delete the account, the photos you uploaded, the card, your listings and the applications to them, the likes, invites and buddy-ups sent and received, your applications, the deck history and the records of who saw your card or listings, the conversations, your notifications and other people's notifications that mention you, the reports filed by you and against your account, the blocks, the feedback, the saved rooms and searches, the notification tokens, the email settings and the identity check record.
Conversations are deleted in full, also for the other person in them. They also lose their own messages in the conversation.
If your account is linked to Apple through the app, we also end our access at Apple.
We send PostHog a request to delete the data about your account and the events linked to it. If advertising consent was ever given, we send Meta an erasure signal with a hashed account id.
What remains after deletion
- the payment records, with no link to you, until 10 years after the end of the year of payment; Stripe keeps its own record of the payment with your account id
- the records of the cookie and analytics choice, with no link to the account
- the ЕГН hash and the deletion date, for 12 months
- reports and notices from other people about a specific listing, card or message, until 12 months after the decision on them
- records of listing edit reviews
- the id of the deleted account and the date of deletion, for 30 days, so that we can finish the deletion in all our services
- technical records of revoked sessions, for up to about an hour
- data in the backups, until the backups are replaced
- the data Google Analytics, Meta and Stripe already received, under their rules, and the counts without an id in PostHog
A copy of your data
From Settings you download one JSON file with your data: on the website in section «Поверителност и данни» (Privacy and data), row «Изтегли данните си» (Download your data), and in the app in section «Поверителност» (Privacy), row «Изтегли моите данни» (Download my data). You need to be signed in.
The file contains:
- the sign-in account: email, provider and when it was created
- the profile and the records of accepting the Terms and this policy
- the records of your cookie choice
- the card
- the invites and buddy-ups received and sent
- your listings
- the applications sent and received
- the deck history
- the conversations and every message in them
- the notifications
- the email settings
- the saved searches and rooms
- the people you blocked
- the reports you filed and your feedback
- the payments
- the identity check record: whether verified, when, by which route, the date of birth, the sex, the Evrotrust transaction number and whether we keep an ЕГН hash (never the hash itself or the ЕГН)
Photos are in the file as links. For a copy of anything that is not in the file, write to legal@strehana.com.
13. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- Access: to learn what data we process and to get a copy. The quickest way is from Settings (section 12).
- Rectification: you correct most data in your profile, card and listings. Your email comes from Google or Apple: change it there and we will update it the next time you sign in. After the identity check, the date of birth and gender come from the ЕГН and cannot be changed from the profile. If they are wrong, write to us.
- Erasure: from Settings (section 12) or by a request to us.
- Restriction: to ask us to stop processing data, for example while we check whether it is accurate or whether your objection is justified.
- Objection: to processing based on legitimate interest. For crash reports in the app, use the «Споделяй диагностика» (Share diagnostics) switch. For everything else, write to us.
- Portability: the copy in Settings is in a machine-readable format (JSON).
- Withdrawing consent: at any time, as described in section 6.
- Complaint: to the Commission for Personal Data Protection, www.cpdp.bg. You can also go to court.
For any request, write to legal@strehana.com. We answer within one month. For complex or numerous requests the period can be extended by two more months, and we will tell you why.
14. Automated decisions and profiling
The deck orders cards automatically. This is profiling: we use data about you to decide what to show you first. The order has no legal effects on you and does not affect you in a similarly significant way.
When you are signed in, the order takes into account who has already liked your card, your filters, the budget and date from your card or the rent and date from your listing, the distance to the place you are looking in, how many people have already seen the card, how complete the person's profile is and how new the card is. A person's age, habits and languages do not affect the order by their values. Only whether they are filled in counts, as part of profile completeness. Gender and smoking come in only as filters. Featured cards take set places in the deck.
A detailed description is on the page «Как подреждаме картите» (How we order the cards) (strehana.com/en/how-ranking-works).
We also work out the contact ladder automatically. How many likes you can send in 24 hours depends on whether you have an account, an active card or listing, how complete your profile is and whether your identity is checked.
We automatically choose whom to notify about a new room or card, based on the places and budget in the cards.
The identity check automatically refuses an ЕГН that says you are under 18. A person decides about the account.
Decisions on reports, notices, restricting content or accounts, and on appeals are made by a person on our team. We do not use automated means for them.
15. How we protect data
- Connections to the website, the app and our servers are encrypted (HTTPS).
- We have no passwords: you sign in only with Google or Apple.
- On the website the session is in cookies that JavaScript cannot read. The access token is valid for 15 minutes and the refresh token for 30 days. We keep refresh tokens only as a hash.
- In the app, sign-in data is in the Keychain on iOS or encrypted with the Android Keystore.
- We do not keep the ЕГН, only a keyed hash of it.
- Your bank card details go straight to Stripe.
- We re-process every uploaded photo and remove its hidden data (EXIF), including GPS coordinates.
- Messages are not end-to-end encrypted. We keep them as text in our database.
- Our databases have automatic backups at OVH.
- Only the members of our team who need the data to run Strehana, handle reports and answer requests under this policy can access it.
16. Only for people aged 18 or over
Strehana is only for people aged 18 or over. The sign-in page, the sign-in card in the deck, the sign-in in the listing and card forms and the sign-in in the app say that by signing in you confirm you are 18 or over.
If you enter a date of birth, we check that you are 18 or over.
The identity check refuses an ЕГН that says you are under 18, and alerts our team.
17. Changes to this policy
When we change the policy, we publish the new version at least 15 days before it takes effect. Until then, a note at the top of this page gives the date and links to the new version. The page shows the version number and the date from which it applies, and earlier versions are on the «Earlier versions» page.
When the new version takes effect, the website and the app ask everyone who is signed in to accept it before continuing. If you do not accept it, you can sign out.
On the website the cookie banner is shown again when a new version of the policy takes effect.
18. Contact
Write to us at legal@strehana.com or call 0897898180. Our address is 1113 Sofia, Izgrev district, Iztok, 2 Nikolay Haytov St, entrance G, floor 14, apartment 47, Bulgaria.
If you think we are infringing your rights, you can complain to the Commission for Personal Data Protection, www.cpdp.bg.