Privacy Policy
This policy explains what data we process about you, why, for how long, and what rights you have. Last updated: 2026-05-23
1. Data Controller
Imperial Market SRL (“we”, “the company”) Registered address: Strada Exemplu nr. 1, Timișoara, Timiș County, Romania VAT ID: RO00000000 Trade Registry No.: J35/000/0000 Privacy / DPO email: privacy@imperialmarket.ro
This policy applies to:
- The imperialmarket.ro website
- The Imperial Fidelity mobile app (also known as Imperial - Fidelizare)
2. The data we process
2.1 In the Imperial Fidelity app
| Category | Specific data | Purpose | Legal basis | Retention period |
|---|---|---|---|---|
| Account identification | Email, phone number, name, password (encrypted) | Creating and managing your account | Contract (Art. 6(1)(b) GDPR) | Until account deletion |
| Virtual loyalty card | Unique virtual card number | Identification at the till, applying discounts | Contract | Until account deletion |
| Fiscal receipts | Receipt number, store, date, total amount, products | Displaying your history and calculating savings | Legal obligation (Romanian fiscal legislation) + Contract | 10 years per the Romanian Fiscal Code |
| Viewed promotions | Clicks and views on promotions | Personalizing recommended promotions | Consent (Art. 6(1)(a)) | 12 months |
| Notification token | Firebase / APNS token | Sending push notifications about promotions | Consent | Until notifications are disabled or the account is deleted |
| Technical data | App version, operating system, anonymous device identifier | Diagnostics, technical statistics | Legitimate interest (Art. 6(1)(f)) | 12 months |
2.2 On the website
The website does not use non-essential cookies, does not run third-party analytics, and does not collect personal information. Our CDN server keeps anonymous technical logs (truncated IP, user-agent) for 30 days for protection against attacks.
3. Who we share data with
We use the following data subprocessors:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting + DDoS protection | Anonymous technical logs | EU / US (standard contractual clauses) |
| Google LLC (Firebase Cloud Messaging) | Push notifications to Android devices | Device tokens | EU / US |
| Apple Inc. (APNS) | Push notifications to iOS devices | Device tokens | EU / US |
| {{POS Provider}} | Syncing fiscal receipts with the virtual card | Virtual card numbers, transaction amounts | EU |
We do NOT sell your data to any third party. Data is shared only for the purposes described.
4. International transfers
Some subprocessors (Google, Apple, Cloudflare) are based in the United States. Transfers are made under the European Commission’s Standard Contractual Clauses (Decision 2021/914) and additional technical measures (encryption in transit, encryption at rest).
5. Your rights (GDPR Art. 15–22)
You have the following rights:
- Right of access (Art. 15) — to find out what data we process about you
- Right to rectification (Art. 16) — to correct inaccurate data
- Right to erasure (Art. 17) — to request deletion of your account and data (see the Account Deletion page)
- Right to restriction (Art. 18) — to request the temporary halt of processing
- Right to portability (Art. 20) — to receive your data in a structured format (GDPR export)
- Right to object (Art. 21) — to object to processing based on legitimate interest
- Rights regarding automated decisions (Art. 22) — we do not make decisions with legal effects on you based solely on automated processing
To exercise any right, write to privacy@imperialmarket.ro. We reply within a maximum of 30 days. See also the Your GDPR Rights page for practical details.
6. Complaints
If you believe your rights have been violated, you may file a complaint with the Romanian Data Protection Authority (ANSPDCP) — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București Tel: +40 318 059 211 / +40 318 059 212 Web: www.dataprotection.ro
7. Minors
The Imperial Fidelity app is not intended for persons under 16 years of age. We do not intentionally collect data about minors. If you become aware that a minor under 16 has an account, write to us at privacy@imperialmarket.ro and we will delete the account without delay.
8. Security
We use TLS encryption for all communications, passwords stored with hashing (bcrypt), and restricted database access for authorized personnel.
9. Changes to the policy
We may update this policy. The most recent version will always be available at imperialmarket.ro/en/privacy. Significant changes will be announced by email or by in-app notification.