Skip to content

Trust

Privacy

How Oriolo handles personal data, in plain language.

On this page · 11 sections

Controller and contact

MIMIRS NEXUS DEVELOPMENT SRL, trading as Oriolo, is the controller of personal data processed through oriolo.app. Registered office: Intrarea Gheorghe Simionescu nr. 19, ap. B26, Sector 1, Bucharest 014155, Romania. Company registration J40/16116/2021; CUI 44922622; VAT number RO47560829.

Privacy requests: contact@oriolo.app or +40 750 463 661. See the legal notice for complete provider information.

Personal data we process

  • Account and sign-in data: email, display name, profile image, password hash, account role and status, and session data. We never store the password itself.
  • Social sign-in data: if you choose Google, the provider account ID, verified email, name, and profile image; if you choose Apple, the provider account ID, verified email or private-relay email, and any name shared on first sign-in.
  • Private account activity: collection records, watch nicknames, acquisition dates, prices, notes, wear history, notification preferences, and private share links you create.
  • Watch-recognition data: wrist photos you submit for recognition, the closest catalog candidates, the agent’s confidence and explanation, and the match returned to your account. Recognition photos are private inputs, not community posts. For unresolved watches, normalized copies may be securely processed by specialized image-analysis and public-web research services.
  • Community content: ratings, reviews, comments, discussions, votes, reports, encyclopedia contributions, wrist shots, captions, and other uploads. Profile and community content is public where the feature says so.
  • Contact and feedback data: your name, reply email, message category, subject, message, optional page or watch link, account association when signed in, and our private handling notes.
  • Billing data: Stripe customer and subscription identifiers, subscription status, selected price, renewal or end date, and whether cancellation is scheduled.
  • Partner-program data: partner account, display name, referral code, Stripe promotion-code identifier, attributed subscription counts, commission terms, earnings adjustments, and settlement method/reference records. Partners do not receive subscriber identities.
  • Notification data: push subscription endpoint and encryption keys, installation identifier, device category, browser user-agent, delivery status, and notification choices.
  • Security and support data: report reasons and notes, moderation records, messages you send us, and IP addresses processed transiently in server memory for sign-in rate limiting.

We receive data directly from you, from your browser or device, and—only when you choose them—from Google, Apple, or Stripe. We do not buy personal profiles or collect sensitive personal data intentionally. Please do not put sensitive personal information in public posts.

Purposes and legal bases

PurposeLegal basis
Create and operate your account; provide collection, wear tracking, sharing, community, and Premium features.Performance of our contract with you (GDPR Article 6(1)(b)).
Protect accounts, rate-limit abuse, prevent fraud, moderate content, enforce our terms, and defend legal claims.Our legitimate interests in operating a safe and trustworthy service (Article 6(1)(f)).
Receive, route, and respond to questions, feedback, bug reports, account or privacy requests, and business enquiries.Performance of our contract, steps at your request before a contract, compliance with legal obligations, or our legitimate interest in responding and improving the service, depending on the message (Articles 6(1)(b), 6(1)(c), and 6(1)(f)).
Send browser or native push notifications you enable.Your consent (Article 6(1)(a)); you can withdraw it in account and device settings.
Keep records required by tax, accounting, consumer-protection, or authority requests.Compliance with legal obligations (Article 6(1)(c)).
Process Premium checkout, subscription status, and access.Performance of the subscription contract and applicable legal obligations (Articles 6(1)(b) and 6(1)(c)).
Operate an agreed influencer program, attribute promotion-code subscriptions, calculate commissions, and document payouts.Performance of the partner agreement and applicable tax and accounting obligations (Articles 6(1)(b) and 6(1)(c)).

When we rely on legitimate interests, we consider the service need, the impact on you, and reasonable safeguards. You may object to this processing as explained below.

Cookies and browser storage

Necessary cookies support authentication, security, and features you explicitly request. The recently viewed list is optional and remains off until you allow it. We do not use advertising cookies, cross-site tracking, or third-party analytics. The cookie policy and settings list every cookie and browser-storage item, its purpose, and its lifetime.

Payments

If you subscribe to Oriolo Premium, Stripe Managed Payments acts as merchant of record and processes identity and contact details, payment method, billing address, transaction, fraud-prevention, and applicable tax information. We store only the identifiers and status needed to provide Premium. We do not receive or store your full card number or security code. Stripe processes transaction data under its own privacy terms and legal duties.

If you join the influencer program, we use Stripe promotion-code events to attribute eligible subscriptions and maintain a commission ledger. Approved earnings are paid separately under the partner agreement; Oriolo stores the payment method category and confirmed settlement reference, but not bank-account credentials. Commission dashboards expose aggregate counts and amounts, not subscriber identities.

Recipients and service providers

We disclose only the data needed to these recipients or categories:

  • hosting, database, backup, object-storage, content-delivery, and technical-support providers acting for us;
  • Google or Apple when you choose that sign-in method;
  • specialized image-analysis and public-web research providers when an unresolved watch needs optional identification research;
  • Stripe for Premium checkout, billing, fraud prevention, tax, invoices, transaction support, and promotion-code processing;
  • Firebase Cloud Messaging, Expo, and the push-delivery service operated by your browser or device platform when you enable notifications;
  • professional advisers, courts, regulators, law enforcement, or other authorities where legally required or necessary to establish, exercise, or defend legal claims;
  • another operator in a merger, acquisition, or reorganisation, subject to confidentiality and applicable notice requirements.

We do not sell personal data, provide it to data brokers, or share it for behavioural advertising. External marketplace or affiliate sites receive information from your browser only after you choose to follow their labelled link.

International transfers

Some providers may process data outside Romania or the European Economic Area. Where we control such a transfer, we use an applicable adequacy decision, the European Commission’s standard contractual clauses, or another lawful safeguard, and add technical or contractual protections where required. Contact us to request information about the safeguard relevant to your data.

Retention

  • Account, private collection, and wear data is kept while the account exists, then removed or anonymised after a valid deletion request unless a legal exception applies.
  • Public contributions remain until you delete them or request removal. If an account is deleted, content may be anonymised where keeping the community conversation is justified; you may request removal as well.
  • Moderation, report, support, fraud, and security records are kept only as long as needed to resolve the matter, enforce the terms, meet legal duties, or defend claims, then deleted or anonymised.
  • Push subscription data is kept until you disable notifications, remove the installation, delete the account, or the endpoint is found to be invalid.
  • Subscription identifiers and status are kept for the subscription and any legally necessary accounting, consumer, dispute, or claims period. Stripe applies its own statutory retention periods to transaction records.
  • Influencer attribution, commission, adjustment, and payout records are kept for the partner relationship and the legally required tax, accounting, contract, dispute, and claims period. Stripe applies its own retention rules to recipient and payout records.
  • Original watch-recognition photos are deleted when recognition reaches a terminal result. The structured result and catalog reference identifiers remain in your account so you can revisit the match.
  • Session and sign-in cookies expire as listed in the cookie policy. IP rate-limit entries exist only in server memory for the active limiter window or until the process restarts.
  • Residual copies may remain temporarily in restricted backups until they rotate out; they are not restored except for disaster recovery.

Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, or portability of your data; object to processing based on legitimate interests; and withdraw consent at any time without affecting earlier lawful processing. You may also provide instructions and ask questions about how your data is used.

Email contact@oriolo.app. Describe the account or data involved and the right you want to exercise. We may request proportionate information to verify identity. We normally respond within one month; GDPR permits an extension for complex or numerous requests, in which case we will explain it within the first month.

You may complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), including through its online complaint form, or to the supervisory authority where you live or work.

Automated decisions, security, and children

Oriolo does not make decisions producing legal or similarly significant effects solely by automated means. Automated technical signals may assist spam prevention, trust checks, ranking, moderation triage, or optional watch recognition, but reported-content decisions can be reviewed by a person. A recognition result is an informational visual opinion, not authentication.

We use access controls, password hashing, signed secure sessions, upload validation and metadata removal, rate limiting, least-privilege administration, and backups appropriate to the service. No online service is risk-free; please use a unique password and report suspected compromise promptly.

Oriolo is for people aged 16 and over. We do not knowingly create accounts for children under 16. Contact us if you believe a child provided personal data contrary to this rule.

Changes

We will update the date below when this notice changes. If a change materially affects how we use existing data or relies on new consent, we will provide an appropriate additional notice or request.

Last updated: July 20, 2026.

Back to top ↑

Your cookie choice

Necessary storage keeps Oriolo working. You can also allow recently viewed watches.

What this means

Necessary storage supports sign-in, security, and features you request. We do not use analytics or advertising cookies. Cookie details