01Data controller
The data controller is Brel Nosse, creator of the PrintSpot service — a personal and independent project, with no company structure. For any question about your data: contact@printspot.app.
02Data we collect
Account and profile
- Phone number (the account identifier), verified with an OTP code.
- Optional profile information: first name, last name, email address, date and place of birth, city, neighbourhood, institution, profile photo.
- For Shop owners: identity document (national ID) and shop information, provided for approval.
Documents and orders
- The documents you upload for printing, along with the order details (format, finishing, copies, handover method).
Location
- Your GPS position, when you allow it, in order to show the nearest shops and sort them by distance. You can decline it in your device settings.
Camera
- The app may access the camera in two cases, and only when you act: scanning a shop's QR code to open its order page directly, and taking or choosing a photo (shop, profile, identity document).
- During a scan, the image is analysed on your device to read the code: no photo is stored or transmitted. Only the shop identifier contained in the code is sent to us, in order to redirect you.
- The permission can be denied or withdrawn at any time in your device settings; only the features concerned then become unavailable.
Payment
- Mobile Money number and amount when making a payment. Transactions are carried out by our payment provider; we do not store any Mobile Money secret code.
Technical data and notifications
- Notification identifier (push token) and messages exchanged with shops.
- Technical logs necessary for operation and security (for example, for abuse rate limiting).
03Purposes and legal bases
- Providing the Service (account creation, orders, payments, tracking, delivery) — performance of the contract.
- Shop approval and security (verifying shop owners' identity, fraud prevention, trust indicator) — legitimate interest and applicable obligations.
- Notifications relating to your orders — performance of the contract; non-essential messages on the basis of consent.
- Improvement and support — legitimate interest.
04Recipients and processors
Your data is only accessible to the people who need it to fulfil your order. We rely on technical providers, in particular:
- Mobile Money payment provider — processing payments and payouts.
- Infrastructure hosting — application server on an OVH VPS managed through Coolify, and file storage — hosting of data and documents.
- Expo Push Service (Expo, United States) — delivery of push notifications to your device. It receives the notification identifier and the content of the message displayed.
- WhatsApp Business (Meta) — sending verification codes (OTP), the channel used by default. Depending on how the service is configured, these codes may be delivered by SMS through the Orange operator instead.
- Host of this showcase website.
- Google Analytics — audience measurement for the showcase website only (see §08). The mobile app does not use it.
The Shop you choose receives the documents and information strictly necessary to fulfil your order. We do not sell your data.
05Security of your documents
- Your documents are never reachable through a guessable address: they are served through short-lived signed links and authenticated access.
- A shop's computer can only retrieve the documents of its own orders.
- Mobile Money payments are protected by an escrow mechanism, and access to resources is controlled server-side.
- A shop's public pages only expose the information needed to identify it. Its owner's personal contact details (phone, email address, identity document) are not disclosed to visitors: exchanges go through the internal messaging.
- The Service undergoes regular security reviews, and fixes come with automated tests intended to prevent any recurrence.
06Retention periods
We keep your data for as long as necessary for the purposes described, then delete or anonymise it. As an indication: order documents are kept only for as long as useful for fulfilment and follow-up; account data for as long as the account is active; some transaction data may be kept longer to meet legal or accounting obligations. Exact periods depend on the nature of the data and the purpose concerned.
07Your rights
You have a right of access, rectification, erasure, restriction and objection, as well as a right to data portability. To exercise it, write to contact@printspot.app. You may also refer the matter to the competent data protection authority.
09Print agent (shop computer)
Subscribed shops can install the PrintSpot print agent on their Windows computer. This section describes what it keeps locally, on the shop's machine.
- Configuration — the paired shops and their pairing token, the chosen printer, the interface language.
- Local copy of orders and queue of pending actions — so the shop keeps working without a connection. Pending actions are replayed when the network returns.
- Technical log — operational and error traces, useful for troubleshooting. The shop owner can export or delete it.
- Documents to print — downloaded into a temporary system folder, then deleted automatically once printing is finished. They are not archived on the machine.
These items stay on the shop's computer. Uninstalling the agent or deleting its data folder erases them. A machine can only download the documents of orders belonging to its own shops.
10Transfers outside Cameroon
Some technical providers (hosting, storage, notifications, messaging) may process data outside Cameroon. Where that is the case, we make sure appropriate safeguards cover those transfers.
11Minors
The Service is not intended for minors without their legal guardian's consent. If you believe a minor has given us data without authorisation, contact us so it can be deleted.
12Changes
This policy may be updated to reflect changes in the Service or in applicable regulations. The date of the last update appears at the top of the page.
13Contact
For any question regarding your personal data: contact@printspot.app.