Junction® App Privacy Policy
Last updated: 26 August 2026
This notice explains which personal data the Junction® mobile app for iOS and Android collects, why, and what you can do about it. It is drafted under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
The dojunction.online website is covered by a separate Privacy Policy and Cookie Policy.
1. Who processes your data
Marco Tribuzio — data controller, a natural person
Controller's email address: privacy@dojunction.online
The controller is a natural person, which the GDPR expressly allows (Art. 4(7)). No Data Protection Officer is appointed: the processing does not meet the conditions of Art. 37(1).
2. What the app does
Junction® authenticates physical products. You scan a QR code or tap an NFC tag; the app tells you whether the code is genuine, what the product is, who owns it, and which actions you can take — activate it, transfer ownership, report it lost, send feedback to the brand.
3. Personal data collected
- Account data — your name, email address and the account identifier returned by Google Sign-In or Sign in with Apple. Junction® never sees or stores your password.
- Scan data — the code read (QR or NFC), the state it resolves to (free, owned by you, owned by someone else, locked, activation required), the timestamp, and the product the code belongs to.
- Location, approximate or precise, non-continuous — captured only if you grant the permission, and only at the moment of a scan, of a product activation, of feedback or of a lost-item report. The app does not follow you in the background and cannot reconstruct your movements.
- Camera images — used only to read a QR code. Frames are processed on your device and are never saved, recorded or transmitted.
- NFC reads — the identifier of the contact-less tag you tap. No other tag content is retained.
- Ownership and transfer records — who owns an item, and every transfer of that ownership, appended to a signed history (see § 8 and § 11).
- Feedback you write — your message about a product (up to 500 characters) or about the app, with the language and, if permitted, the location it was written from.
- Lost-item reports — the message and location you attach when you flag one of your products as lost.
- Device identifier and notification token — a unique identifier of your installation, used to keep your preferences and to deliver push notifications.
- Usage and diagnostic data — app version, device model, operating system, screens opened, errors and crashes. Collected through Firebase Analytics only if you turn analytics on (see § 5 and § 7).
- Local scan history — every scan is stored in an encrypted database on your device (see § 12) so you can consult it offline.
Unless stated otherwise, the data above is necessary to provide the app. Refusing it may make the app partly or wholly unusable — refusing the camera or NFC permission, for instance, prevents scanning altogether.
4. Using the app without an account
You can scan without signing in. Guest scans are held on your device and are queued for synchronisation. If you later create an account, the queued scans are linked to it and stop being anonymous. Before signing in you can clear the local history from the app settings, which discards the queue.
5. Purposes and legal bases
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account, signing you in | Account data, device identifier | Performance of a contract — Art. 6(1)(b) |
| Authenticating products, showing the scan result, product passport and history | Scan data, product data | Performance of a contract — Art. 6(1)(b) |
| Activating a code and transferring ownership between users | Account data, ownership and transfer records | Performance of a contract — Art. 6(1)(b) |
| Location-based features: where a scan or a report happened, distance and origin | Location, non-continuous | Consent — Art. 6(1)(a), given through the device permission |
| Push notifications about your items | Notification token | Consent — Art. 6(1)(a), given through the OS permission |
| Sending your feedback or your lost-item report to the brand | Feedback text, location, language | Consent — Art. 6(1)(a); you choose whether to write and send it |
| Backing your history up to your own cloud account | Scan history | Consent — Art. 6(1)(a); off unless you enable it |
| Understanding how the app is used, to improve it | Usage and diagnostic data | Consent — Art. 6(1)(a); analytics is off until you turn it on |
| Anti-counterfeiting, detecting abusive or fraudulent use of codes, security logs | Scan data, device identifier, logs | Legitimate interest — Art. 6(1)(f): protecting brands and buyers from counterfeits |
| Warning you when a product is not authorised for sale in your region | Location, product data | Legitimate interest — Art. 6(1)(f): enforcing the brand's distribution rules |
| Accounting, tax, and answering lawful requests from public authorities | As required by law | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | The data strictly needed | Legitimate interest — Art. 6(1)(f) |
Where the basis is consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before.
6. Device permissions
The app asks for a permission before any related data can be processed:
- Camera — to read QR codes. Nothing is recorded.
- NFC — to read contact-less tags.
- Location, approximate or precise — captured only at the moment of an action, never continuously.
- Notifications — to deliver push messages about your items.
You can revoke any of these at any time in your device settings, and analytics can be turned off in the app settings. Revoking a permission does not affect processing already carried out lawfully. Revoking the camera or NFC permission stops the app from performing its main function.
7. Who else receives your data
| Recipient | Role | Place of processing |
|---|---|---|
| Google Ireland Ltd — Google Sign-In | Registration and authentication | Ireland / EU |
| Apple Distribution International Ltd — Sign in with Apple | Registration and authentication | Ireland / EU |
| Google Ireland Ltd — Google Cloud Platform | Hosting, database and backend infrastructure | EU regions |
| Google Ireland Ltd — Firebase Cloud Messaging | Delivery of push notifications | EU / US |
| Google Ireland Ltd — Firebase Analytics | Usage statistics, only if you enable analytics | EU / US |
| Google Ireland Ltd — Google Drive | Backup of your history, in your own Drive account, only if you enable it | EU / US |
| Apple Distribution International Ltd — iCloud / CloudKit | Backup of your history, in your own iCloud account, only if you enable it | EU / US |
| Apple App Store and Google Play Store | App distribution, aggregate download and usage statistics | Ireland / EU |
| Brands and authorised operators of the products you scan | Recipients of feedback, lost-item reports and, where applicable, supply-chain entries | EU and, depending on the brand, outside it |
The technical providers listed above act as processors under Art. 28 GDPR, except where they determine their own purposes as independent controllers.
Brands are not our processors. When you send feedback about a product, report it lost, or when an authorised operator records a supply-chain entry, that brand or operator receives the data as an independent controller and processes it under its own privacy notice, which we do not control. Only the data attached to that specific action is passed on — never your full scan history.
An up-to-date list of processors is available on request at privacy@dojunction.online.
8. What other users can see
Some features disclose data to people other than us and the brand. Before you use them, know that:
- A lost-item report is public to later scanners. Anyone who subsequently scans that product sees the alert and the message you wrote. Do not put anything in it you would not want a stranger to read.
- An ownership transfer identifies the two parties to each other. A transfer code is valid for 30 minutes; whoever holds it can accept ownership, so share it only with the person you intend to hand the item to.
- A transfer request reveals that you scanned an item owned by someone else, so that the owner can decide whether to accept.
- Feedback you write may be shown to the brand together with the language and the place it was written from.
9. Cloud backup
If you enable it, your scan history is copied to your own Google Drive (application data folder) or your own iCloud/CloudKit space. The copy lives in your personal cloud account, under your agreement with Google or Apple, not in ours. You can disable synchronisation at any time in the app settings and delete the copy from your Drive or iCloud account. Backup is off unless you turn it on.
10. Transfers outside the EU
Data is processed in the European Union wherever the provider allows it. Where a transfer to a third country takes place, it relies on an adequacy decision — including the EU-US Data Privacy Framework for certified US recipients — or on the Standard Contractual Clauses adopted by the European Commission, together with supplementary technical measures.
The EU-US Privacy Shield invoked by the previous version of this notice was invalidated by the Court of Justice in 2020 and is no longer relied upon.
11. How long data is kept
- Account data — while the account exists, then deleted within 30 days of a deletion request.
- Scan data — for the life of the product record, since it evidences authenticity.
- Ownership records — the ownership chain is signed and append-only, because it is the proof of authenticity and provenance that the product carries. If you erase your account, your identity is removed from the chain and replaced by a pseudonym; the chain itself is retained under Art. 17(3)(e) GDPR, for the establishment, exercise or defence of legal claims by the current and future owners of that product.
- Feedback and lost-item reports — until you withdraw them or the underlying product record is deleted; copies already received by the brand are governed by the brand's own notice.
- Notification token — until you disable notifications or uninstall the app.
- Security and server logs — up to 12 months.
- Analytics data — up to 14 months from collection, and deleted when you turn analytics off.
- Data kept for legal obligations — for the period imposed by law.
12. Security
Appropriate technical and organisational measures protect your data: encryption in transit (TLS), encryption at rest of the local database on your device (AES-256-GCM), a cryptographically signed (HMAC) ownership chain that makes tampering detectable, access on a need-to-know basis, and logging of administrative access.
13. Your rights
Under Articles 15 to 22 GDPR you may:
- access your data and obtain a copy of it;
- have inaccurate data rectified;
- have your data erased — you can delete your account yourself from the app settings, or use the Delete user data page;
- obtain restriction of processing;
- receive your data in a structured, machine-readable format, or have it transmitted to another controller;
- object to processing based on legitimate interest, for reasons relating to your particular situation;
- withdraw any consent at any time — through the device permissions, the analytics switch, or the backup switch.
Write to privacy@dojunction.online. Requests are free of charge and answered within one month. You also have the right to lodge a complaint with the Italian Data Protection Authority or with the supervisory authority of your country of residence.
14. Minors, changes, definitions
Minors. The app is not directed to children. Minors may use Junction® only with the assistance of a parent or guardian, and in no case may it be used by anyone under 14 — the age set in Italy for consent to information-society services under Art. 8 GDPR.
Push notifications. The app may send push notifications for the purposes described here. You can disable them at any time in your device notification settings; disabling them may mean you miss alerts about your own products.
Do Not Track. The app has no browsing interface and does not process "Do Not Track" signals.
Changes. This notice may be updated at any time. Changes are published on this page with a new date, and where they concern processing based on consent, consent is collected again.
Definitions.
- Personal data — any information relating to an identified or identifiable natural person.
- Usage data — information collected automatically by the app, such as app version, device model, operating system, screens opened, errors and crashes.
- User / data subject — the natural person using the app, to whom the data relates.
- Processor — a party processing data on behalf of the controller.
- Controller — the party determining the purposes and means of the processing.
This notice relates solely to the Junction® mobile app.