HungrySpots is operated by Airus Energy LLC, a company registered in Mongolia. This policy explains how we handle personal information when you visit HungrySpots, create or manage a restaurant website, use a QR menu, contact us, or use an enabled HungrySpots feature. It explains the information we collect, why we use it, who receives it, how long we keep it, and how you can exercise your rights.
1 Who is responsible for your information
Our registered business address is Apartment 17, Entrance 3, Building 15, Baga Toiruu, 4th Khoroo, Chingeltei District, Ulaanbaatar, Mongolia. You can contact us about privacy at airusenergymn@gmail.com or write to our registered address. Our website is https://hungryspots.com.
For account administration, platform security, our own billing, support, and our own business communications, Airus Energy LLC determines why and how personal information is processed. We act as a data controller for those activities.
A restaurant generally controls information that it collects from its own customers through its website. Where we host or process that information only on the restaurant's instructions, we act as its processor or service provider. The restaurant must provide its own privacy notice. A separately accepted Data Processing Agreement governs that processing and is available at https://hungryspots.com/data-processing. This policy still applies to processing that we independently control, including platform security and our own account administration. A restaurant cannot use this policy as a substitute for explaining its own customer data practices.
If we are required to appoint a representative or data protection officer for your region, we will identify them in this contact section before undertaking processing that requires their appointment. Airus Energy LLC is the current published privacy contact; it is not described as an EU representative or statutory data protection officer. You can always contact our privacy team using the address above.
2 Services covered by this policy
Our core service lets restaurant owners and authorised staff create, edit, publish, and manage restaurant websites and QR menus. It includes restaurant information, menu content, photographs, opening hours, events, website settings, and account administration.
Some services, such as paid plans, customer enquiry forms, restaurant discovery, or visitor analytics, are available only where the corresponding feature is enabled. We do not collect a category of information simply because a future feature is discussed in this policy. Enabled on-platform reservations are described in section 3.7. We provide additional notices before a new feature introduces materially different processing.
External reservation, food ordering, delivery, messaging, and payment websites have their own policies. Following a link to those services does not mean HungrySpots receives the information you give them.
3 Information we collect
3.1 Account and identity information
We collect the information you provide to create and manage an account. This can include your name, email address, account identifier, profile image and basic provider profile metadata where supplied, and restaurant ownership or access role. If you register with a password, the authentication service stores a protected password verifier. We do not need your Google or Facebook password and never ask you to provide it to us.
We keep account status, verification events, login and logout events, and authentication or session records needed to provide secure access. Our social-login information is described in section 5.
3.2 Restaurant information and uploaded content
We collect restaurant names, addresses, business contact details, location coordinates, menus, pricing, opening hours, media, social links, events, and website configuration that an authorised user enters. Business information can also be personal information, for example a sole trader's name, personal telephone number, or an identifiable person in a photograph.
Information you deliberately publish becomes available to visitors and may be indexed by search engines. Drafts and unpublished changes are intended for authorised restaurant users and staff who need access to operate the service. Publishing is a separate action from saving a draft.
Please upload only information and media you are entitled to use. Do not include private customer records, identity documents, payment card details, or sensitive personal information in public restaurant content.
3.3 Support and communications
When you contact us, we collect your contact details, messages, attachments, and the information needed to resolve your request. If we ask for evidence of restaurant ownership or authority, we request only what is proportionate to the dispute and provide a secure way to send it. We do not routinely require identity documents for ordinary privacy requests.
3.4 Billing information when paid services are enabled
For our paid services, we collect plan details, billing contact information, invoice details, transaction references, payment status, and relevant tax information. HungrySpots currently records plan and invoice information; this policy does not represent that an automatic card checkout or recurring card collection is already available. If a payment integration is offered, the named payment provider handles payment credentials through its own secure interface. We do not store complete payment card numbers or card security codes. The checkout identifies the payment provider and any separate seller or merchant of record before you pay.
3.5 Technical information
Our servers and infrastructure providers receive information needed to deliver and secure the service. This can include IP addresses, request times, requested pages, browser and operating system details, error reports, and security events. An IP address may be used to estimate a broad country or region. We do not use it to track your precise movements.
Where visitor analytics are enabled, we may record page or QR menu visits and interactions with menu, directions, telephone, reservation, delivery, or social links. Optional analytics operate according to the choices and notices described in section 7. Restaurant reports must not expose a visitor's account credentials or a history of their activity across unrelated restaurant websites.
3.6 Information from others
We receive permitted account information from an identity provider when you choose social login. Where staff membership is offered, an authorised restaurant owner may provide a staff member's email address to invite that person to the restaurant account. A payment provider may send us payment confirmations. We may receive relevant information from a person reporting fraud, unlawful content, or an ownership dispute.
Where we receive personal information indirectly and the law requires a separate notice, we give the required information within the applicable period, usually by the first communication or disclosure and no later than one month, unless a lawful exception applies.
3.7 Reservation requests and reports
When a restaurant enables table requests, we receive your name, email address or telephone number, party size, requested date and time, optional notes, and the request reference and status. These details are made available to the restaurant to handle and confirm your request. A request is not a confirmed booking until the restaurant confirms it. HungrySpots hosts this information on the restaurant's instructions; the restaurant determines its booking purposes and customer retention requirements. Contact the restaurant about its use of these details or contact us for help routing a privacy request. Do not enter medical histories, identity documents, card details, or other sensitive information in reservation notes.
Website problem reports contain the restaurant page identifier, the message you supply, and technical information needed to prevent abuse and investigate the report. They are reviewed by authorized HungrySpots administrators. Do not include another person's private details unnecessarily.
3.8 Information we do not seek
Our core service does not request government identification numbers, biometric identifiers, precise device location, private social messages, social friend lists, or health records. Restaurant menu labels about allergens or dietary options describe food, rather than a visitor's health. Do not send personal medical or allergy histories through general support or public content fields.
If an optional feature needs sensitive information, we assess it separately and provide the required notice, lawful basis, consent where required, and safeguards before collection. Information supplied accidentally is restricted and assessed for prompt deletion.
4 Why we use information
Where EU or UK data protection law applies, we use the following legal bases. For restaurant-controlled reservations, we process under the restaurant's documented instructions; the restaurant is responsible for identifying its own lawful basis. A legal basis for processing and a permission for international transfer are separate questions. We also meet any additional consent or other requirements under Mongolian or applicable US law.
| Purpose | Information involved | EU or UK legal basis |
|---|---|---|
| Create an account and provide the requested builder and hosting services | Account, restaurant, content, session, and configuration data | Performance of a contract with you; legitimate interests where you act for a business rather than contract personally |
| Manage staff access and restaurant ownership | Membership, invitation, role, and proportionate ownership evidence | Legitimate interests in authorised account administration and prevention of unauthorised changes |
| Process our subscription charges and invoices when enabled | Billing, transaction, invoice, and tax data | Contract performance and applicable legal obligations |
| Respond to support requests | Contact details, messages, and relevant service records | Contract performance or legitimate interests in responding to requests |
| Protect accounts and prevent fraud or abuse | Limited technical logs, session records, and security events | Legitimate interests in service security; applicable legal obligations where relevant |
| Send essential account, security, and service notices | Contact information and relevant account status | Contract performance, legitimate interests, or legal obligations depending on the notice |
| Send optional promotional emails or use optional tracking | Contact preferences, consent records, and selected analytics data | Consent where required; another basis only where the law permits and an opt-out is available |
| Meet legal duties and handle legal claims | Only information relevant to the obligation or claim | Applicable legal obligations or legitimate interests in establishing, exercising, or defending claims |
Our legitimate interests include maintaining a functioning service, protecting users, and managing business accounts. We assess whether those interests are outweighed by your rights. You can object to processing based on legitimate interests. We stop unless we establish a lawful reason to continue. We always honour an objection to direct marketing.
Information required to create an account or perform a requested service is identified in the relevant form. If you do not provide it, we may be unable to provide that service. Optional information and optional marketing consent are not required for ordinary access.
We do not use personal information for decisions that have legal or similarly significant effects solely through automated processing. If that changes, we will explain the decision, its effects, and the available rights before the processing begins.
5 Google and Facebook sign-in
5.1 Google
When you choose Google sign-in, we request only basic sign-in permissions, normally openid, email, and profile. Depending on the information Google makes available, we receive a Google account identifier, email address and verification status, name, profile image, and basic profile information such as language.
We use that information to create or recognise your HungrySpots account, authenticate you, and display the account details you choose to use. Authentication services process the identity response and the tokens needed for the sign-in flow. We do not request Gmail, Drive, Calendar, Contacts, or other additional Google account access for basic sign-in. We retain provider tokens only where they are needed for an enabled feature and do not request ongoing API access simply to prepare for a future feature.
HungrySpots follows the Google API Services User Data Policy, including the Limited Use requirements, for information received from Google APIs. We do not sell that information or use it for advertising, credit decisions, surveillance, or training general artificial intelligence models. Transfers and staff access are restricted to permitted, disclosed purposes under that policy. Any proposed new Google data use requires the appropriate notice and authorisation before it begins.
5.2 Facebook
When you choose Facebook sign-in, we request the permissions needed for basic account creation and authentication, normally public_profile and email. Depending on permission, availability, and your settings, we receive your app-specific Facebook identifier, name, profile image, and email address. Facebook may not provide an email address. If the provider does not supply the required email address, social sign-in may be unavailable; email registration remains an alternative.
We use this information for account creation, login, and the account profile you choose to use. Basic sign-in does not give us access to your private messages, friends, posts, Pages, or advertising account. We do not use Facebook information to create advertising audiences, sell it, or give it to data brokers. Any additional Facebook integration must have its own notice and appropriate permissions.
5.3 Your controls
You can withdraw HungrySpots access through your Google account connections or Facebook Apps and Websites settings. Where account settings offer a disconnect option, you can also disconnect the provider there. Establish another permitted login method before disconnecting your only method of access.
Revoking provider access stops future authorised access through that connection. It does not by itself cancel a paid subscription or necessarily erase an existing HungrySpots account. To request deletion, use the process in section 12. We also act on valid deletion requests received through a supported provider deletion mechanism.
Provider account information is not automatically published on your restaurant website. Google and Meta independently process your use of their services under their own privacy policies.
6 When information is disclosed
We disclose information only for the purposes explained in this policy and only to recipients that need it.
- Service providers support authentication, database and file storage, hosting, content delivery, email delivery, support, security, and payment processing. Where they act as our processors, they work under appropriate contracts and processing restrictions.
- Authorised members of your restaurant account can access information allowed by their role. Restaurant visitors can see the content you deliberately publish.
- A restaurant receives information you submit directly to it through an enabled enquiry feature. Its privacy notice explains its further use. We do not give restaurants your HungrySpots login credentials or your social-login profile merely because you visit their menu.
- Professional advisers receive information necessary to provide legal, accounting, or similar services under appropriate confidentiality duties.
- Authorities or other parties may receive information where required by a valid legal obligation or where lawfully necessary to protect people, investigate abuse, or handle claims. We assess the request and restrict the disclosure to what is necessary.
- A buyer or successor may receive information in a lawful business transaction, subject to appropriate safeguards and notice. Google and Meta data remain subject to their platform restrictions. Where a provider rule requires prior consent, we obtain it before the transfer.
- We disclose information to another recipient when you specifically direct us to do so or give the required consent.
Our current service provider register at https://hungryspots.com/data-protection#providers identifies active providers, their roles, and relevant processing locations. Public hosting and private account records must be distinguished in that register. Identity and payment providers may act as independent controllers for parts of their own services.
We do not sell personal information. We do not share it for cross-context behavioural advertising or use it for targeted advertising across unrelated services. These statements apply to the broad legal meanings of sale and sharing, including exchanges for non-monetary value. We do not treat the mere absence of a cash payment as proof that a disclosure is permitted.
If advertising or another materially different use is introduced, we will update notices and implement the required choices before it starts. Google and Meta data will not be used in a way prohibited by their rules, even if another law would permit the use.
7 Cookies analytics and embedded services
We use cookies or similar storage necessary for authentication, security, and choices you ask the service to remember. Optional analytics, marketing tools, and nonessential embedded services are handled separately. We do not interpret visiting a page, scrolling, or accepting the Terms as consent to optional tracking.
Where consent is required, optional storage and tracking remain off until you choose to enable them. You can allow or reject the optional analytics category through the privacy controls. Refusing optional categories does not prevent use of the core builder or viewing ordinary public menus. You can change your decision using Privacy preferences in the footer of every page.
The cookie notice at https://hungryspots.com/privacy#cookies lists the actual cookies and similar technologies, their providers, purposes, and durations. We do not describe all analytics as strictly necessary. A narrow legal exemption is used only after a documented assessment of the particular technology and jurisdiction.
The current restaurant directions and social links open external services when you follow them; we do not treat those links as permission to access your social account. A future embedded map, video, or social widget may send your IP address and other browser information to its provider. Before introducing an optional embed, we assess its data flows and provide prior permission controls where required.
We honour legally recognised universal opt-out signals, including Global Privacy Control, for processing to which those signals apply. We do not currently sell information, share it for cross-context behavioural advertising, or conduct targeted advertising. We apply your signal to any covered processing rather than using it to disable essential security functions. We also honor Do Not Track by keeping optional analytics off. A browser signal does not disable essential account security or prevent you from making a separate privacy request.
7.1 Current cookies and browser storage
| Technology and provider | Purpose and choice | Duration or expiry criterion |
|---|---|---|
| Supabase authentication cookies, beginning with sb- and including auth-token or code-verifier entries | Essential sign-in, session renewal, and authorization-code verification; only used for requested account access | Authentication cookies can have a browser maximum of 400 days and are renewed or cleared by the authentication service; actual access-token and session validity is controlled separately. Sign-out clears the applicable account cookies. Code-verifier entries are cleared when used or when the authentication flow is reset |
| HungrySpots hs_analytics cookie | Stores yes or no for optional analytics; rejection is as available as acceptance | 180 days from the choice, unless cleared earlier |
| HungrySpots hungryspots-analytics-v1 local storage entry | Remembers the privacy preference on this device | Until you change the choice or clear browser storage; an accepted choice is not effective after its consent cookie expires |
| Supabase browser user-profile cache, when created by the authentication client | Supports the account session and user interface | Until removed by sign-out, authentication cleanup, or your clearing browser storage |
| Optional Vercel Web Analytics | Measures permitted public-page visits after your choice; no advertising cookies | Vercel describes a visitor hash that is discarded after 24 hours. Aggregate reports follow the provider's service retention and reporting rules |
| Optional HungrySpots restaurant analytics | Records enabled menu and QR events after your choice, using a random page token and restaurant-scoped hash | The page token exists only in application memory for that page session; event records and aggregate reports follow the criteria in section 10 |
Optional analytics exclude account, dashboard, administrator, API, and authentication routes. Query strings and URL fragments are removed before Vercel analytics events are sent. No optional advertising category is enabled. The preference is device and browser specific. Clearing cookies or using another device may require a new choice. You can also disable cookies through your browser, although blocking essential authentication storage may prevent account access.
8 Marketing and service messages
Optional promotional communications use the permissions required for your location. Consent is separate from registration and can be withdrawn. Promotional email includes an unsubscribe option. We act promptly on requests to stop marketing and within any applicable legal deadline, including the US requirement to honour email opt-outs within ten business days.
We may still send necessary account, billing, security, legal, or service messages. We keep these messages focused on their necessary purpose. We retain a limited suppression record so that we do not add you back to marketing without a lawful basis.
9 International processing
Airus Energy LLC is based in Mongolia. Access by our authorised staff in Mongolia and processing by infrastructure providers can involve international transfers. The current provider register identifies actual hosting regions and other countries from which personal information may be accessed. Public restaurant content is available globally by design.
Where EU or UK transfer restrictions apply, we use an applicable legal mechanism before the transfer. This may involve an adequacy decision or appropriate contractual safeguards, supported by a transfer assessment and additional measures where necessary. Where contractual safeguards are required, the applicable instrument and annexes must be completed before restricted processing. This policy is not evidence of a signed transfer agreement. We use Standard Contractual Clauses only where the selected instrument and module are legally appropriate for the actual parties and processing. A vendor's contract does not automatically cover every separate transfer to us in Mongolia.
For transfers governed by Mongolian law, we meet its separate requirements, including obtaining informed consent where required and no other permitted legal ground applies. Accepting the Terms does not by itself provide every consent needed for a foreign transfer. We identify the relevant recipients, destinations, purpose, and consequences in the applicable notice.
You can ask our privacy contact about the safeguards relevant to your information and request an appropriate copy, with confidential information and security-sensitive details removed where permitted. We do not claim that HungrySpots is certified under a data transfer framework merely because a supplier participates in one.
10 How long we keep information
We retain personal information only for a defined purpose and for no longer than necessary. The following schedule governs ordinary processing. A shorter legal requirement or valid deletion right takes priority. Any longer legal hold must be limited to the relevant records, recorded, access restricted, and reviewed.
| Information | Ordinary retention |
|---|---|
| Active account and private restaurant management data | While the service is active and the information remains needed. Inactive, unpublished, or archived records are reviewed for continuing service, legal, or claim needs; unpublishing alone does not trigger automatic erasure |
| Verified account or restaurant erasure requests | Without undue delay after necessary identity and legal checks, within applicable rights deadlines. We normally respond within one calendar month and explain any lawful extension or exception |
| Residual protected backups and provider logs | Until expiry under the applicable provider's backup or log schedule. These copies are restricted, are not used to restart ordinary processing, and relevant erasures must be reapplied after restoration. We do not promise an unverified universal 90-day backup limit |
| Routine request, error, and security records | Only while needed to operate the service, investigate a specific incident, or meet a defined legal requirement; provider-controlled log windows depend on the selected service |
| Support correspondence and account administration records | While a request or account relationship remains active, then only for documented complaint, legal, or accountability needs. Records no longer needed must be deleted or de-identified |
| Restaurant-controlled reservation records | For the restaurant's documented booking and lawful retention purposes, followed by its deletion instruction or a valid applicable erasure request. We assist the restaurant with deletion; it cannot lawfully retain booking details indefinitely simply because storage is available |
| Invoices, tax, and accounting records | For the statutory period applicable to the transaction and the particular record; only information necessary for that obligation is retained |
| Consent, privacy request, and deletion evidence | For the proportionate period needed to demonstrate the action and meet an applicable legal or claim requirement. Erasure completion removes account identifiers and request content that is no longer necessary, while retaining limited accountability evidence |
| Marketing suppression records, if marketing is introduced | Minimum contact identifier and preference for as long as necessary to honor the opt-out |
| Optional visitor analytics | Restaurant events are kept only while needed for the disclosed reporting and security purpose, with removal or de-identification when no longer needed. Vercel visitor hashes expire after 24 hours; aggregate-report retention depends on its service rules and is not an asserted fixed deletion deadline |
Disconnecting social login removes unneeded provider tokens and connection data promptly. Basic account information may remain for the separate HungrySpots account until deletion is requested or its lawful retention purpose ends. Provider deletion instructions and shorter provider requirements take priority for information obtained from that provider.
Unpublishing a website removes it from ordinary public display but is not the same as requesting erasure. Hiding content or setting a soft-deletion flag is not treated as completed erasure. A verified erasure request also covers appropriate copies in database records, file storage, versions, search indexes, and caches under our control. Search engines and other parties may retain their own copies of information you previously published. We take steps required by applicable law to notify relevant recipients or seek removal.
11 How we protect information
We use safeguards appropriate to the service and the risk, including secure transmission, access restrictions, protection of stored records, separation of restaurant access, and processes for responding to security incidents. Staff and contractors access personal information only when authorised and necessary for their work.
No service can guarantee complete security. If a personal data breach occurs, we assess it, take steps to contain it, and provide notices to affected people, restaurant customers, providers, or authorities where required. We do not claim a security certification or independent audit unless it has actually been completed and applies to the service described.
Our public data protection overview is available at https://hungryspots.com/data-protection. Detailed internal security procedures are restricted to people who need them.
12 Your rights and deletion requests
You can contact airusenergymn@gmail.com to request access, correction, deletion, a portable copy, restriction, or an objection to processing. You can withdraw a consent at any time without affecting processing that was lawful before withdrawal. We provide the rights required by your applicable law and consider reasonable privacy requests from other users as well.
You do not need to create an account to make a privacy request. Give us enough information to identify the relevant account or information and explain your request. We verify identity only to the extent necessary to protect you. We do not ask for your Google or Facebook password. We do not require unnecessary identity documents or sensitive information. An authorised representative can act for you where permitted, subject to proportionate verification of their authority.
12.1 How to request account deletion
- Use Delete Account in account settings where the control is available, or email airusenergymn@gmail.com with the subject HungrySpots Data Deletion.
- Identify the email address used for HungrySpots and say whether the request concerns your account, a restaurant website, or information received from Google or Facebook. Do not send your password or payment card number.
- We confirm receipt, complete necessary identity or authority checks, and explain any relevant impact on a restaurant account or paid service.
- We delete the covered information, instruct relevant processors, revoke or remove applicable credentials and connections, and tell you when the request is complete or explain a lawful exception.
You can request deletion of provider information without supplying a reason. Deletion does not authorise us to erase another person's information or an organisation's records where you have no authority. If you are leaving a restaurant that has other authorised users, we can remove your personal access and assess your personal information separately from the restaurant's business records. We identify any required retention instead of keeping the entire account indefinitely.
Submitting a deletion request stops further renewals for subscriptions you are authorised to cancel, subject to proportionate verification. We explain any final payment legally owed for an already supplied service. Revoking Google or Facebook access alone does not cancel the subscription. Cancel Subscription remains available separately from deletion.
Public deletion instructions are also available at https://hungryspots.com/data-deletion. The current public route provides deletion instructions and a contact method. If a Facebook deletion callback is separately configured, valid requests through it must receive the processing and acknowledgement required by that mechanism; publication of these instructions does not represent that a callback is installed. We do not require you to log in after you have already removed the app simply to make the request.
12.2 Response periods and exceptions
For requests governed by the GDPR, we respond without undue delay and normally within one calendar month. If the law permits an extension of up to two further months for complexity or the number of requests, we explain the extension and reasons within the first month. For applicable US state requests, we respond within the required period, commonly 45 days, and provide any permitted extension notice. Shorter deadlines for particular rights or laws take priority.
Requests are generally free. Any refusal, limitation, or fee must be permitted by applicable law and explained. We do not charge merely because you exercise a right. We may retain limited records required by law or needed for a specific legal claim, with restricted access and a defined retention basis.
12.3 Complaints and appeals
You can ask us to review a decision by emailing airusenergymn@gmail.com with the subject Privacy Appeal. Please identify the request and the issue you want reviewed. We accept an appeal within at least 60 days of our decision, or longer where the law requires. We explain the result within the applicable deadline, generally within 45 days where that is sufficient under local law.
You can also complain directly to your competent data protection authority or state attorney general. In the EEA, this can be the authority where you live, work, or believe a breach occurred. In the UK, it is the Information Commissioner's Office. In Mongolia, privacy complaints may be made to the competent authority or the National Human Rights Commission as applicable. You do not have to complete our complaint process before using a legal remedy.
13 Additional information for United States residents
US privacy laws differ by state and by the type and size of business. Where a state law applies to our processing, we provide its required rights. These can include access, confirmation of processing, correction, deletion, portability, information about recipients, and an appeal. Where applicable, you may opt out of sale, sharing, targeted advertising, and profiling used for legally or similarly significant decisions, and control specified sensitive information processing. We do not retaliate against you for exercising a privacy right.
The categories we collect are described in section 3. The sources, purposes, recipient categories, and retention periods are described in sections 3, 4, 6, and 10. That disclosure covers identifiers and contact details, commercial and service records, internet or network activity, voluntarily uploaded images, broad location information, and relevant business or professional information. Authentication credentials may be sensitive personal information under applicable law. We use them only for permitted service and security purposes. We do not build sensitive personal profiles.
For California residents, the category and retention disclosures also serve as our notice of relevant practices for the preceding 12 months, to the extent those categories were actually collected. We do not sell or share personal information as those terms are defined in the CCPA. We do not knowingly sell or share the information of people under 16. We do not use sensitive personal information beyond permitted purposes such as providing the service, authentication, and security. No financial incentive programme involving personal information is offered under this policy.
Where the CCPA applies, you can request the categories and specific pieces of personal information, required source and purpose information, and categories of recipients. Applicable rights to limit sensitive information use and to use an authorised agent are preserved. Requests can be made through our privacy contact or the available privacy request form at https://hungryspots.com/account. Where another US state law requires disclosure of specific recipients or additional information about profiling, we provide that information as required.
Some laws exclude particular employment or business-to-business information while others, including the CCPA where applicable, cover it. We assess the correct rule rather than treating all restaurant-owner information as exempt.
14 Children and younger visitors
Restaurant-owner and paid management accounts are for adults aged 18 or older who are legally able to enter the relevant contract. The service is not directed to children under 13, and we do not knowingly collect their personal information through account registration or optional tracking. An age statement alone does not remove our duties if we learn that a child has provided information.
If you believe a child has supplied personal information, contact airusenergymn@gmail.com. We restrict the information and take the steps required by law, including deletion or any properly authorised parental process where applicable. We do not knowingly use targeted advertising for minors. If we introduce features intended for younger users, we will complete a separate legal and design assessment before launch.
15 Changes and contact
We update the date at the top when this policy changes. For material changes, we provide notice through the service, email, or another appropriate channel. We obtain renewed consent or authorisation where needed before a new processing purpose or broader Google or Facebook access begins. Continued use does not replace a consent that the law or provider requires.
Privacy contacts are in section 1. Support: airusenergymn@gmail.com.
