Privacy Policy

Last updated: March 2026

Yooraa ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By using our platform, you agree to the practices described here.

01 Information We Collect

We collect only the information necessary to operate the platform:

badge

Account Data

Your full name and email address, collected when you create an account via Firebase Authentication.

storefront

Listing Content

Any content you voluntarily submit as a listing: title, description, price, photos, and contact details.

account_circle

Profile Data

Your profile photo (avatar), bio (optional short text), and WhatsApp number (optional, visible to all registered users if provided). Also your aggregated seller rating (average score and count).

chat

Chat & Conversations

All messages you send and receive, together with conversation metadata: participant IDs, last-message preview, unread status, and the list of participants who have hidden the conversation.

star

Ratings & Reports

Ratings you give or receive (score 1–5, from/to user IDs, timestamp). Reports you submit about listings (reason, count) or other users (reason, your UID, reported UID). Aggregated report counts on listings are visible to all users.

notifications

Push Notification Token

If you grant notification permission, we store a device push token (FCM token) linked to your account. This token is used exclusively to deliver message alerts to your device. It is stored in a private collection not accessible by other users.

favorite

Favorites

A list of listing IDs you have saved as favorites, stored privately and linked to your account. This data is not visible to other users or sellers.

block

User Blocking

If you block another user, we store the blocked user's ID in a private collection linked to your account (userBlocks/{yourUID}). This list is never visible to other users and is used solely to filter blocked users from your feed and prevent contact.

feedback

Feedback & Bug Reports

If you submit feedback or a bug report, we store the message, feedback type, your user ID, name, email, device information, and an optional screenshot. This data is accessible only to the platform administrator and is used exclusively to improve the service.

devices

Usage Data & Analytics

Basic technical information such as your device type and browser, used to improve performance. We use Firebase Analytics (Google) to collect anonymous usage events (e.g. page views, feature interactions). This data is aggregated and does not include your name or email. We do not use third-party advertising cookies.

01.1 Local Device Storage

We use localStorage (browser storage on your device) to provide a smooth experience. No third-party cookies are used. The following items are stored locally on your device only and are never sent to our servers independently:

stm_session

Login session (name, email, timestamp — expires after 30 days)

stm_user

Cached user profile (name, avatar URL) for fast page load

stm_avatar

Your avatar URL, cached locally to avoid repeated server requests

stm_lang

Your language preference (en / es)

darkMode

Your display mode preference (light / dark)

mkt-favs-{uid}

Your saved favourites (listing IDs), stored per user ID

my_listings

Temporary cache of your own listings for the profile page

stm_edit_listing

Temporarily holds listing data while you are editing a post (cleared after save)

All local storage is cleared when you delete your account or sign out. You can also clear it manually at any time via your browser settings.

02 How We Use Your Information

We use the information we collect to:

  • Create and manage your account
  • Display your listings to other users
  • Send you important account-related notifications (e.g., password reset emails)
  • Improve the platform's performance and user experience
  • Enforce our Terms of Service and prevent fraud or abuse

We do not sell, rent, or share your personal information with third parties for marketing purposes.

03 Firebase & Data Storage

Our platform is built on Google Firebase, which handles authentication and data storage. Your account data (name, email, and user ID) is stored securely in Firebase Authentication and Firestore, hosted on Google Cloud infrastructure.

Google Firebase operates under its own Privacy Policy and complies with applicable data protection regulations including GDPR. Data may be stored on servers located outside of Costa Rica. By using Yooraa, you consent to this transfer.

04 Public Listings & User Content

Any information you include in a public listing is visible to all users of the platform.

You are solely responsible for the content you choose to share in your listings, including any personal contact details such as phone numbers or WhatsApp numbers. We recommend sharing only the minimum information necessary and avoiding the inclusion of sensitive personal data in public listings.

05 Data Sharing

We do not sell your personal data. We may share data only in the following limited circumstances:

  • Service Providers: Firebase/Google Cloud for infrastructure, authentication, and anonymous analytics. GMX (1&1 Mail & Media GmbH) for transactional email delivery via SMTP (e.g. report notifications). These sub-processors are bound by their own data protection agreements.
  • Legal Requirements: If required by law, court order, or to protect the rights and safety of our users or the public.
  • Business Transfer: In the event of a merger or acquisition, your data may be transferred to the new owner, who will be bound by this Policy.

06 Your Rights

You have the following rights regarding your personal data:

Access & Correction

You can view and update your name and email at any time through your profile settings.

Data Portability

You may request a copy of the personal data we hold about you at any time by contacting us.

Right to Deletion

You have the right to request the deletion of your account and all associated personal data at any time. We will process your request within 30 days. See Section 07 for details.

Objection & Restriction

You may object to or request restriction of certain types of data processing by contacting us directly.

gavel Costa Rica Ley No. 8968 — ARCO Rights

Under Costa Rica's Law No. 8968 you have the right to Access, Rectification, Cancellation, and Opposition (ARCO) of your personal data. We will respond to all ARCO requests within 5 business days of receipt. Send your request to legal@yooraa.com with the subject line ARCO Request.

You may also file a complaint with the Agencia de Protección de Datos de los Habitantes (PRODHAB) at prodhab.go.cr if you believe your data rights have been violated.

07 Data Deletion Request

You can delete your account directly in the app: go to Profile → Settings → Delete Account. This will immediately and permanently delete your profile, all your listings, ratings, and messages.

Alternatively, you may send a deletion request to legal@yooraa.com with the subject line Delete My Account. We will process your request within 30 days.

07.1 Data Retention

We retain personal data only as long as necessary to provide the service or as required by law:

storefront

Listings

Active listings expire after 90 days (renewable up to 3 times). Sold listings are deleted after 30 days. All listing images in Storage are deleted together with the listing.

chat

Conversations & Messages

Retained until both participants hide the conversation, after which the entire conversation and all messages are automatically deleted. You can hide any conversation at any time via the chat menu.

account_circle

Profile & Account Data

Retained until you delete your account. Account deletion removes your profile, avatar, name, email, bio, WhatsApp number, all listings, and your Firebase Auth credential.

star

Ratings

Ratings you gave are deleted when you delete your account (GDPR Art. 17). Ratings you received from others remain associated with the seller's aggregate score unless the rater also deletes their account.

flag

Reports

User reports are retained until reviewed and deleted by an administrator. Listing report counts are cleared when the listing is deleted.

notifications

Push Notification Tokens

FCM tokens are deleted when you delete your account. You can also revoke push notification permission in your browser or device settings at any time, which will prevent new tokens from being generated.

07.2 Legal Basis for Processing (GDPR / DSGVO Art. 6)

We process your personal data only where we have a valid legal basis under GDPR Art. 6. The following table explains the basis for each type of processing:

Account & Listings

Art. 6(1)(b) — Performance of contract. We process your name, email, and listings to provide the marketplace service you signed up for.

Chat Messages

Art. 6(1)(b) — Performance of contract. Messages are stored to enable real-time communication between buyers and sellers, which is a core feature of the platform.

Push Notifications

Art. 6(1)(a) — Consent. We only send push notifications if you explicitly grant permission in your browser or device settings. You can withdraw consent at any time.

Automated Data Cleanup

Art. 6(1)(f) — Legitimate interest. We automatically delete sold listings after 30 days and expire inactive listings after 90 days to keep the platform clean and relevant for all users.

Ratings & Reviews

Art. 6(1)(f) — Legitimate interest. Ratings help build trust within the community. Processing is limited to verified transaction parties only.

08 Children's Privacy

Yooraa is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has created an account, we will delete it promptly.

08.1 Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify the Agencia de Protección de Datos de los Habitantes (PRODHAB) and all affected users within 5 business days of discovery, as required by Costa Rica Law No. 8968. The notification will include the nature of the breach, the data affected, corrective actions taken, and preventive measures implemented.

09 Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this page occasionally. Continued use of the platform after updates constitutes acceptance of the revised Policy.

10 Contact Us

For any questions, data requests, or privacy concerns, please contact us at:

Yooraa

Data Controller

Christian Regler

Santa Teresa, Cobano, Puntarenas, Costa Rica

legal@yooraa.com