WORKING PRIVACY DRAFT
Privacy Notice
What VareVenn handles, why it is needed, and the choices people should have.
1. Data controller and contact
Launch blocker: the data controller’s final legal identity must be inserted before public access. The person or entity deciding why and how VareVenn processes personal data is the controller. Closed-beta privacy questions and requests can be sent to kontakt@varevenn.no.
2. Information handled
- Account data: an immutable random VareVenn ID, an admin-friendly member number, current and prior private email/display-name changes, public display name, verification status, roles, settings, and whether profile/background images were changed or removed. The history records the event and limited metadata, not copies of old profile images.
- Identity and trust: durable account warnings, member responses, their resolution, and restricted account-change history so renaming or changing email does not detach moderation records. The Owner and designated senior admins may inspect prior identity values and relevant administrative changes; members can see their own account timeline and export. Ordinary reviewers do not receive the restricted history.
- Tester requests: email, requested display name, phone platform/model, optional municipality or area, optional testing note, review result, and invitation status.
- First-week feedback: a signed-in tester may answer whether VareVenn helped yet and optionally explain why. The answer is linked to that account, appears in the account export, and is removed with the account. The Owner and authorised admins may see the response, optional note, and display name in the Control Room so they can improve onboarding.
- Privacy-safe discovery totals: public pages may add one daily aggregate count on that browser for a small allowlist of steps such as opening VareVenn, trying the catalogue, adding a trial item, opening or sending the tester form, or opening a shared link. The aggregate table stores only the day, step, surface, and total count—not an IP address, visitor ID, email, account, or individual click history.
- Contributions: products, barcodes, prices, stores, comments, verification decisions, timestamps, and attribution choices.
- Area suggestions: the general area and municipality you propose, review outcome, and the account that submitted it. VareVenn asks for place names only—not an address or exact location. Pending suggestions are hidden from Store Bounties.
- Product evidence: photos attached to a barcode when you choose to capture or upload them.
- Store Bounties: your private chosen home/bounty area, claims, submitted store/price/note, evidence photo, review result, and separate test-credit history. The chosen area is not a GPS trail or background movement history.
- Recipe Marks: Mark Credit ledger entries, gifts sent and received, recipe identifiers, Creator Credits, queued Premium months, Owner approvals, limits, reversals, and audit events. Other members see aggregate recipe counts, not a biggest-spender ranking. Release 1 has no Mark purchases or cash redemption.
- Shopping data: lists and queued scans. The mobile beta may keep drafts locally until you submit them.
- Location: only when you actively allow location access for nearby areas/stores or submit a map pin. Continuous background tracking is not part of the current plan.
- Security and administration: session records, failed login counts, device/admin authorisations, moderation actions, and audit logs.
3. Purposes and proposed legal bases
The working assessment is: account and core feature processing is necessary to provide the requested service; security, moderation, duplicate prevention, and service improvement rely on legitimate interests where appropriate; optional permissions such as device location or camera access are requested at the moment they are needed; and records may be kept where a legal obligation applies. These bases must be confirmed against the final service and operator before launch.
4. Who receives data
Authorised VareVenn staff see only what their role requires. Ordinary admins should receive masked account identifiers unless sensitive access is necessary; only the Owner can change admin authority. Service providers may process data for hosting/database operations, email delivery, maps, and security. The final provider list, locations, and data-processing agreements are a launch requirement.
5. Public information
Your chosen display name, optional avatar, approved contributions, and leaderboard information may be visible to other users according to your settings. Your sign-in email is not intended to be public. Hiding or replacing public attribution does not necessarily erase the restricted pseudonymous audit link needed to prevent abuse.
6. Retention
Login sessions currently target a maximum of 14 days unless revoked sooner. Email confirmation links expire after 30 minutes. Tester requests are kept only for selecting, inviting, and administering the controlled field-test group, and should be removed when they are no longer needed; the final automatic retention period remains a launch requirement. When an account is deleted, its sign-in credentials, sessions, private profile settings, avatar, personal background image, unpublished recipe submissions with their images, chosen bounty area, and Store Bounty evidence photos are removed. Unfinished bounty claims are cancelled. Useful catalogue facts, published recipes, point-integrity records, completed bounty-integrity records, Marks ledgers, recipe-award totals, and restricted moderation or security records may remain with public attribution changed to Deleted User so the catalogue, balances, reversals, and abuse controls remain trustworthy. Some retained integrity records remain pseudonymous rather than fully anonymous. Exact retention periods for every record category still require final legal review before public launch.
7. Your choices and rights
You can edit your nickname and visibility settings, choose a private home area, securely change your sign-in email after password re-authentication and confirmation of the new address, and respond to an active warning when you believe the requested change has been completed. That response remains pending until authorized moderation verifies and resolves it. Completed email changes are logged, notify the old address, revoke other sessions, and have a seven-day safety cooldown. Home-area changes have a 30-day anti-abuse cooldown with an audited Owner correction path. Accounts created through the controlled tester programme may display a permanent Beta Tester badge; the underlying invitation provenance is retained with the account for integrity. From Account, you can review your account timeline, download a ZIP containing readable JSON, CSV summaries, identity/trust history, and available images uploaded by your account, or start permanent account deletion after re-entering your password. The export excludes password hashes, secret tokens, passkey material, staff actor identities, and other users’ information. A person who submitted a tester request without creating an account can ask for access, correction, or deletion through kontakt@varevenn.no. Read the account-deletion process or use the same contact fallback. Depending on the applicable law, you may also ask for restriction, portability, or object to certain processing, and may complain to Datatilsynet. The final manual identity-verification and response procedure remains a launch requirement.
8. Security
VareVenn uses one-use email confirmation links, slow salted password hashing, server-side role checks, secure session cookies, login lockouts, and admin audit trails. An Owner-only passkey pilot stores public credential material and limited device, backup, use, and security-event metadata; the private passkey stays with the device or passkey provider. Password sign-in and verified-email recovery remain available during the pilot. No system is perfectly secure; a tested incident and breach-response procedure is a launch requirement.
9. Children and international transfers
The closed beta is not designed for children. A final age approach and any required guardian consent must be decided before public launch. Any provider processing outside Norway/EEA must be identified together with its transfer safeguards.
10. Changes
This notice will change as VareVenn’s hosting, app, providers, and features become final. Material changes should be shown clearly, not hidden in a long document.
11. In-app notifications
VareVenn stores notification content, delivery/read/dismissal timestamps, and category preferences. Critical notices may temporarily override a disabled category only for security, safety, legal, compatibility, or required-account actions. Release 1 does not send operating-system push notifications.
12. Recovery, progress, achievements, and feedback
Password-reset links expire after 30 minutes, work once, and revoke existing sessions when used. VareVenn keeps limited delivery status without exposing secret tokens. The member activity area may store onboarding milestones, earned achievements, Home Area move requests and decisions, contribution-freshness prompts, and one optional first-week usefulness response. These records are account-linked, available in the member export where appropriate, and removed or de-identified through the documented account-deletion process.
13. Submission assistance / Registreringshjelp
When you request staff assistance, VareVenn saves your barcode, confirmed store/branch, private product and price-tag photos, messages, staff actions, and your acceptance of one fewer Contribution Point from the eventual approved reward. No existing points are debited. You and authorised staff can view the evidence; approved catalogue facts keep your contribution attribution. The optional nearby-store search compares your location with store pins on your device. It does not send or save your coordinates as part of the request. Assistance records and available photos are included in your account export. Account deletion removes the private requests, messages and evidence, while approved catalogue facts and point-integrity records follow the retention rules above.
Når du ber om registreringshjelp, lagrer VareVenn strekkode, bekreftet butikk, private vare- og prislappbilder, meldinger, behandlingshistorikk og samtykket til ett poeng mindre ved godkjenning. Ingen eksisterende poeng trekkes. Bare du og autoriserte medarbeidere kan se dokumentasjonen. Valgfritt søk etter butikker i nærheten bruker posisjonen på enheten din; koordinatene sendes eller lagres ikke i forespørselen. Private forespørsler og bilder følger med i kontoeksporten og slettes når kontoen slettes.
14. Monthly discovery estimate / Månedlig besøksanslag
From 12 September 2026, opening Home may also add one anonymous aggregate count per browser/app per calendar month in Europe/Oslo. A local marker stores only the last counted month, not an identifier. The monthly count is separate from the daily activity totals above. Guests and staff are included. Different browsers/devices, private browsing and cleared storage may count again; blocked storage is excluded, and network failures may miss visits. The server stores only day, event, surface and total, with no visitor ID, account link or individual click history. This is an estimate of browsers/apps, not people.
Fra 12. september 2026 kan åpning av forsiden også legge til én anonym telling per nettleser/app per kalendermåned i Europe/Oslo. En lokal markør lagrer bare sist talte måned, ikke en identifikator. Månedstallet holdes adskilt fra den daglige aktiviteten ovenfor. Gjester og medarbeidere er inkludert. Andre nettlesere/enheter, privat nettlesing og slettet lagring kan telle på nytt; blokkert lagring utelates, og nettverksfeil kan føre til manglende besøk. Serveren lagrer bare dag, hendelse, side og total, uten besøks-ID, kontokobling eller individuell klikkhistorikk. Dette er et anslag over nettlesere/apper, ikke personer.