Weenjoy

PRIVACY NOTICE

Weenjoy Users by Administradora Weenjoy, Sociedad Civil

Last Updated: June 20, 2025

Privacy Notice - Quick Summary

This summary provides key highlights. Please read the complete privacy notice below for full details.

Data We Collect

  • Account info (name, email, country)
  • Location data (GPS coordinates, country)
  • Usage data (transactions, preferences)
  • Firebase analytics (crashes, performance)

Why We Collect It

  • Manage your loyalty account
  • Show businesses near you
  • Process rewards and transactions
  • Send personalized offers

Location Data

  • Used to find businesses near you
  • Detect your current country
  • Cached for 24 hours, then refreshed
  • You can disable anytime in settings

Your Rights

  • Access your data anytime
  • Correct inaccurate information
  • Request deletion of your account
  • Opt out of marketing communications

Contact for Privacy Questions: corporation@weenjoy.com

COMPREHENSIVE PRIVACY NOTICE

Administradora Weenjoy, Sociedad Civil, with address at Paseo de las Flores No. 51, Col La Floresta Michoacana, C.P. 58088, Morelia, Michoacán, is responsible for collecting your personal data, the use given to it, and its protection, and hereby informs you of the following:

Use of Your Personal Data

The personal data we collect from you will be used for the following necessary purposes to provide you with our services:

  • Account Creation and Management: Create and maintain your user account for the Weenjoy Loyalty Program
  • Authentication and Security: Verify your identity when you log in and secure your account
  • Location-Based Services: Show you participating businesses and offers near your current location or in your country/region
  • Loyalty Program Operations: Track your transactions, calculate rewards, and manage your loyalty points and benefits
  • Personalization: Display content in your preferred language, show prices in your local currency, and adjust timezone settings
  • Communication: Send you important notifications about your account, transactions, and program updates
  • QR Code Validation: Process QR code scans at participating businesses to register your transactions and award loyalty points
  • Customer Support: Respond to your inquiries and provide technical assistance

Additional Uses (Optional - Require Your Consent)

Additionally, we will use your personal information for the following secondary purposes that are not necessary for the core service, but allow us to provide you with better attention and personalized experiences:

  • Marketing Communications: Send you promotional offers, special deals, and commercial information about the Loyalty Program and participating partner businesses through email, push notifications, and in-app messages
  • Location-Based Marketing: Use your location data to send you personalized offers from businesses near you
  • Analytics and Statistics: Analyze usage patterns, user behavior, and preferences to improve our services and understand market trends
  • Personalized Recommendations: Suggest businesses, products, and services based on your location, preferences, and transaction history
  • Market Research: Conduct surveys and research to improve the Loyalty Program and develop new features
  • Partner Marketing: Share aggregated and anonymized data with participating businesses to help them understand customer preferences (individual identifying information is never shared without explicit consent)

You Have Control: You can opt out of these secondary uses at any time. Opting out will not affect your ability to use the core loyalty program features.

How to Opt-Out:

  • Marketing Emails: Click the "unsubscribe" link in any promotional email
  • Push Notifications: Disable notifications in your device settings or app settings
  • Location-Based Marketing: Disable location access in your device settings
  • All Secondary Uses: Send an email to corporation@weenjoy.com stating which purposes you wish to opt out of

Device Permissions We Request

The Weenjoy app requests the following permissions from your device. You can grant or deny each permission. Some features may not work if permissions are denied.

Location (GPS)

Why we need it: To show businesses near you, calculate distances, detect your country, and provide location-based offers

When we access it: When you open the app or use location-based features. Background location (optional) allows country detection when traveling

Required: No - app works without it, but you'll only see businesses from your registered country

Notifications

Why we need it: To send you alerts about rewards earned, special offers, and important account updates

When we access it: Continuous (you can disable in device settings)

Required: No - you can use the app without notifications

Internet

Why we need it: To communicate with our servers, sync your data, and provide all app features

When we access it: Continuous when app is running

Required: Yes - app requires internet connection to function

Note: You can review and modify these permissions at any time in your device's Settings app under "Weenjoy" (iOS) or App Permissions (Android).

Permissions We DON'T Request: We do NOT request access to your camera, photo library, microphone, contacts, calendar, or biometric authentication (Face ID/Touch ID).

Personal Data We Collect

To carry out the purposes described in this privacy notice, we collect and process the following categories of personal data:

1. Account Information (Collected During Registration)

When you create an account, we collect the following information:

Required Information:

  • Email Address - For login and verification
  • Password - Encrypted with bcrypt
  • First Name - For personalization
  • Last Name - For account identification
  • Country - Auto-detected from device

What We DON'T Collect: We do NOT collect profile photos, date of birth, physical address, phone number, or any biometric data. The country is automatically detected from your device's system settings (locale).

2. Location Data

How we access location: We access your device's GPS location services when you grant permission through your device settings.

What location data we collect:

  • Precise Location: GPS coordinates (latitude and longitude) when you use location-based features
  • Approximate Location: Country and region derived from your GPS coordinates or device settings
  • Home Country: The country you register in or set as your primary country
  • Current Country: Your current location country (refreshed every 24 hours when location is enabled)

How we use location data:

  • Show you businesses and offers near your current location
  • Calculate distance from your location to participating businesses
  • Detect when you're traveling to automatically show businesses from your current country
  • Filter and personalize content based on your geographic region
  • Determine your default currency based on your country
  • Provide navigation directions to business locations via integrated maps (Google Maps, Waze)

Location permission types:

  • While Using the App: Location is accessed only when you actively use the app
  • Background Location (optional): Allows the app to detect country changes when traveling, even when not actively using the app

You can disable location access at any time through your device settings. If you disable location, the app will use your registered home country for displaying businesses and offers.

3. Usage and Activity Data

  • Loyalty program transactions and rewards earned
  • Businesses you visit and interact with
  • Search history within the app
  • Preferences and settings you configure
  • App usage patterns and features accessed

4. Notification Data

If you grant notification permissions, we collect device notification tokens to send you push notifications about your loyalty rewards, special offers, and program updates. You can disable notifications at any time in your device settings.

Data We Do NOT Collect: We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health information, or sexual orientation.

Data Transfer and Sharing

Who We Share Your Data With:

1. Participating Partner Businesses

What we share: When you make a transaction at a participating business by scanning a QR code, we share your user ID and transaction details with that specific business to register your loyalty points.

Why: To process your loyalty rewards and enable the business to track program participation.

2. Service Providers and Technology Partners

What we share: Technical data (device tokens, usage analytics) with trusted service providers who help us operate the app.

Examples: Cloud hosting providers, push notification services, analytics platforms, authentication services.

Protection: These providers are contractually obligated to protect your data and use it only for the services they provide to us.

3. Aggregated Statistical Data

What we share: Anonymized and aggregated statistics (e.g., "500 users in Mexico City visited restaurants this month") that cannot identify individual users.

Purpose: Market analysis and program improvement.

4. Legal Requirements

We may disclose your personal data if required by law, court order, or government regulation, or to protect our legal rights and prevent fraud.

Your Express Consent:

By creating your user account and accepting the Terms and Conditions, you expressly authorize Administradora Weenjoy, S.C. to:

  • Share your country, region, language, timezone, and currency preferences with our systems
  • Process your location data to provide location-based services
  • Share transaction data with participating businesses where you earn loyalty rewards
  • Use aggregated statistical data for marketing and analytics purposes

International Data Transfers:

Your data may be stored and processed on servers located in different countries where we or our service providers operate. We ensure that any international transfer complies with applicable data protection laws and that your data receives adequate protection.

How Long We Keep Your Data

Active Account Data:

We retain your personal data for as long as your account is active and you continue to use our services.

After Account Deletion:

  • Your personal identifying information is deleted within 30 days of account deletion
  • Transaction history may be retained in anonymized form for accounting and legal compliance (up to 7 years as required by law)
  • Some data may be retained longer if required by legal obligations or to resolve disputes

Location Data:

Current location data is cached for 24 hours and then automatically refreshed. Historical precise location data is not stored; we only retain the country/region information associated with your transactions.

Your Right to Deletion: You can request deletion of your data at any time by contacting us at corporation@weenjoy.com or by deleting your account through the app settings.

How We Protect Your Data

We implement industry-standard security measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction:

Encryption

  • All data transmitted between your device and our servers is encrypted using HTTPS/TLS
  • Passwords are encrypted using industry-standard hashing algorithms
  • Sensitive data is encrypted at rest in our databases

Access Controls

  • Strict access controls limit who can view your data
  • Multi-factor authentication for our staff
  • Regular security audits and monitoring

Device-Level Security

  • Secure token-based authentication
  • Automatic session timeout for inactive users

Security Practices

  • Regular security updates and patches
  • Penetration testing and vulnerability assessments
  • Incident response and breach notification procedures

Important: While we implement robust security measures, no system is 100% secure. You are responsible for keeping your password confidential and logging out of shared devices. If you suspect unauthorized access to your account, contact us immediately at corporation@weenjoy.com.

Your ARCO Rights

You have the right to know what personal data we have about you, what we use it for, and the conditions of use we give it. Likewise, it is your right to request:

  • Access: Know what personal data we have about you
  • Rectification: Correction of your personal information if it is outdated, inaccurate, or incomplete
  • Cancellation: Deletion from our records or databases when you consider it is not being used in accordance with regulations
  • Opposition: Object to the use of your personal data for specific purposes

How to Exercise Your ARCO Rights

To exercise any of the rights of access, rectification, cancellation, and opposition, you must send an email to corporation@weenjoy.com indicating the following:

  1. The name of the holder and address or other means to communicate the response to your request
  2. Documents that prove the identity or, where appropriate, the legal representation of the holder
  3. A clear and precise description of the personal data regarding which you seek to exercise any of the aforementioned rights
  4. Any other element or document that facilitates the location of personal data

Response Timeline:

  • Initial Review: If the information provided is insufficient, within 5 business days we may require additional elements or documents
  • Your Response Time: You will have 10 business days to address the requirement. Failure to respond will result in the request being considered not submitted
  • Final Response: We will communicate our determination within a maximum of 20 business days from receipt of the complete request
  • Implementation: If appropriate, changes will be effective within 15 business days following the response communication

The response will be sent electronically to the email address from which the request was sent.

Limit Use or Disclosure

You may limit the use or disclosure of your personal data by sending your request to the email address corporation@weenjoy.com. The procedure to address your request will be governed by the same criteria indicated in the previous section.

Changes to This Privacy Notice

This privacy notice may undergo modifications, changes, or updates derived from new legal requirements; our own needs for the services we offer; our privacy practices; changes in our business model; or other causes.

We commit to keeping you informed about changes that this privacy notice may undergo, keeping it updated on our website weenjoy.com

SECONDARY PRIVACY NOTICE

Administradora Weenjoy, Sociedad Civil is responsible for collecting your personal contact and information data, the use given to it, and its protection.

If you do not wish for your data to be used for secondary purposes such as advertising, statistical marketing purposes, you can submit your request at this time.

For more information about the mechanisms to submit your request, as well as the terms and conditions under which your personal data will be processed, you can consult the comprehensive privacy notice on our website: https://weenjoy.com

Third-Party Services and SDKs

Our app uses third-party services that may collect, process, and store data independently. These services have their own privacy policies:

Google Firebase

Services Used:

  • Firebase Cloud Messaging (FCM): For push notifications
  • Firebase Core: Base infrastructure

Data Collected by Firebase:

  • Device Information: Device model, OS version, unique device identifiers
  • App Instance ID: Unique identifier for your app installation
  • FCM Token: Token used to send push notifications to your device
  • Analytics Data: App usage patterns, crashes, and performance data (if analytics enabled)
  • IP Address: For fraud prevention and approximate location

Purpose:

  • Deliver push notifications about rewards and offers
  • Monitor app performance and crashes
  • Provide analytics to improve our services

Firebase Privacy Policy: firebase.google.com/support/privacy

Google Play Services

Our Android app uses Google Play Services for core functionality:

  • Location Services: Provides GPS and network-based location
  • Google Fonts: Renders text using Google Fonts
  • SafetyNet/Play Integrity: Verifies device authenticity

Google Privacy Policy: policies.google.com/privacy

Map and Navigation Services

When you use navigation features, we may open external map applications:

  • Google Maps: Your location and destination are shared with Google Maps when you use navigation. Privacy Policy
  • Waze: Your location and destination are shared with Waze when you use their navigation. Privacy Policy

Our Backend Services

The app communicates with our GraphQL API servers to provide services:

  • Data Transmission: All data is encrypted in transit using HTTPS/TLS
  • Server Location: Data may be processed on servers in different countries
  • Retention: Data is retained as described in the "Data Retention" section above

Important: Third-party services operate independently and have their own privacy policies. We encourage you to review their privacy policies to understand how they handle your data.

Account Deletion and Data Removal

Delete Your Account and Data

You have the right to delete your account and request removal of your personal data at any time. We provide two methods:

Method 1: Delete Account In-App

  1. Open the Weenjoy app and log in to your account
  2. Go to Settings or Profile
  3. Scroll down and tap "Account Settings"
  4. Tap "Delete My Account"
  5. Confirm deletion by entering your password
  6. Your account and personal data will be deleted within 30 days

Note: Some transaction history may be retained in anonymized form for legal compliance (up to 7 years).

Method 2: Email Deletion Request

If you cannot access the app, send an email to corporation@weenjoy.com with:

  • Subject: "Account Deletion Request"
  • Your registered email address
  • Your full name
  • A brief statement requesting account deletion

Response Time: We will respond within 5 business days and complete deletion within 30 days.

What Happens When You Delete Your Account?

  • Immediate: Your account is deactivated and you can no longer log in
  • Within 30 days: Your personal identifying information (name, email, country) is permanently deleted
  • Location Data: All cached location data is immediately deleted
  • Loyalty Points: All unredeemed loyalty points and rewards are forfeited
  • Transaction History: Anonymized transaction records may be retained for legal/accounting compliance (7 years)
  • Firebase/Analytics: Device tokens and analytics data are removed from our systems
  • Third-Party Services: We delete data from our systems, but third-party services (Firebase, Google) may retain data according to their own policies

Can't Access Your Account? If you've forgotten your password or can't log in, email us at corporation@weenjoy.com with proof of identity, and we'll help you delete your account.

Google Play Store - Data Safety Information

This section provides information required by Google Play's Data Safety form, explaining how we handle your data:

Location Data

Collected: Yes

Types: Approximate location (country/region) and Precise location (GPS coordinates)

Required or Optional: Optional (app works without location, but with limited features)

Purpose: App functionality (find nearby businesses), Personalization

Shared with third parties: No (stays within our systems)

Encrypted in transit: Yes (HTTPS/TLS)

Can request deletion: Yes (delete account or clear cache)

Personal Information

Collected: Yes

Types: Name, Email address, Country

Required or Optional: Required for account creation

Purpose: App functionality, Account management, Communication

Shared with third parties: No (except participating businesses for transactions)

Encrypted in transit: Yes

Encrypted at rest: Yes (passwords are hashed)

Can request deletion: Yes

Financial Information

Collected: Limited

Types: Loyalty points balance, Transaction history (no credit card data)

Required or Optional: Automatically collected when you earn rewards

Purpose: App functionality (manage loyalty program)

Shared with third parties: Yes (with participating businesses for transaction verification)

Can request deletion: Yes (but may be retained anonymized for 7 years for legal compliance)

Device and App Data

Collected: Yes

Types: Device ID, App version, OS version, Crash logs, Performance data

Purpose: Analytics, App functionality, Bug fixes

Shared with third parties: Yes (Firebase for crash reporting and analytics)

Encrypted in transit: Yes

Can request deletion: Yes

Photos and Videos

Collected: NO

Note: We do NOT collect photos or videos. Profile photos and camera features are not implemented in the current version of the app.

Security Practices:

  • Data is encrypted in transit using HTTPS/TLS
  • Data is encrypted at rest in our databases
  • Users can request data deletion through the app or via email
  • We comply with Google Play's Data Safety requirements
  • We follow industry-standard security practices

Children's Privacy

Our app is not directed to children under the age of 13 (or the applicable age of digital consent in your country).

We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at corporation@weenjoy.com.

If we discover that we have collected personal information from a child under 13 without parental consent, we will delete that information immediately.

Contact Information

For Privacy Questions: corporation@weenjoy.com

For Account Deletion: corporation@weenjoy.com

General Inquiries: corporation@weenjoy.com

Address: Paseo de las Flores No. 51, Col La Floresta Michoacana, C.P. 58088, Morelia, Michoacán, Mexico

Last Updated: June 20, 2025

This privacy policy applies to Weenjoy Users mobile application (iOS and Android) by Administradora Weenjoy, Sociedad Civil

Version 2.0 - Comprehensive update with detailed location data disclosure and device permissions

© Copyright 2025 Weenjoy México SAPI de CV. All rights reserved.