Privacy policy
What data the.in.ua sees about you, why, where it is kept, who receives it, and how to remove it.
1. Data controller
The controller of personal data is sole proprietor (FOP) Abyzov I. V., Lviv, Ukraine. Email: [email protected]. Portal phone: +380 96 526 8888 (also WhatsApp).
This policy covers all websites on *.the.in.ua, the portal's Telegram bot, the portal's WhatsApp and Viber number, and the addresses [email protected] and [email protected].
2. In short
- We do not sell data or share it for advertising. There are no ad trackers and no tracking cookies.
- Data is stored on the controller's own server in Ukraine.
- We collect what you enter yourself and what the service cannot work without.
- The content of your messages is not sent to any artificial-intelligence service.
3. What data, why, and for how long
General rule: data linked to an account is kept while the account is active or until you ask us to delete it. The controller has not set any other retention periods except those stated below.
Account and sign-in
- Sign in with Google: Google ID, name, email address and whether it is verified. We do not store your profile photo.
- Sign in with Telegram: Telegram ID, name or username. If you allow the bot to message you — the chat ID.
- Account creation and last sign-in dates, role. One record per day of which portal sections you visited — without what you did there.
- Purpose: to recognise you and protect the account. The sign-in session is a 7-day cookie; expired session files are removed from the server.
Phones and messengers
- Phone number, the channel used to verify it (Telegram, Viber, WhatsApp), verification date, technical chat ID.
- A verified number belongs to one account only. If the number is already verified on another account, the attempt is recorded for the administrator.
- You can delete a number yourself in the cabinet.
Email and mailings
- Email address, your settings (whether you agree to receive mail, topics, frequency) and a send log: what was sent and when, without the message text.
- Mail is sent only with your consent. Every mailing has one-click unsubscribe. An extra address is added only after you confirm it via a link (valid 24 h).
- Telegram bot messages — likewise only with consent, at most 12 per day;
/stopturns them off. An undelivered message waits in the queue for at most 2 days.
Places
- Only the code of a settlement or community from the Ukrainian KATOTTG codifier (up to 8 places). We do not store coordinates.
- The "detect my place" button works only when you click it: the browser sends coordinates rounded to about 1 km to our server, which returns a place code and does not record the coordinates.
- For guests, the calendar remembers the chosen city and view in a cookie for 1 year.
- Date, time and city of birth are stored only if you enter them yourself for the calendar; you can erase them in the cabinet.
Cabinet
- Storage rooms, vessels, batches, measurements and events, controllers, runs, saved calculations, calendar entries, scheme passports, work areas and their members.
- Only what you enter or what your controller sends. It is visible to you and to people you have given access to in a work area.
- The anonymous calculation counter (which calculator and with which numbers) is linked neither to an account nor to an IP address.
oCBot controllers
- Device ID (derived from the hardware address), name, last-seen time, API key hash, channel encryption key, licences.
- Telemetry — sensor readings and output states: raw data for 3 days; device logs and 5-minute summaries for 90 days; hourly summaries and run data — while the account is active.
- We do not store the controller's IP address. Device logs may contain your Wi-Fi network name and local IP address.
Requests, forms and pre-orders
- Name, phone, email, messenger, subject and text. For spam protection — an irreversible hash of the IP address; the address itself is not stored.
- Pre-orders: product, quantity, name, contact, comment.
- If a product is supplied by a portal partner, your pre-order (name, contact, comment) is forwarded to that partner via Telegram so they can contact you and quote a price.
Conversations with us
- Messages you send us via WhatsApp, Telegram, Viber, email or web forms are kept in a single thread: profile name, number, address or ID, text, date, media IDs.
- Emails and phone numbers written in the text are picked out as contacts automatically.
- Email attachments are not stored — only name, type and size. WhatsApp media is fetched from Meta on demand and not kept on our server.
- A new message may receive an automatic reply, and the team is notified via Telegram.
- Mail to [email protected] and [email protected] is also forwarded to the portal's Gmail mailbox.
Visit statistics
- The Umami counter runs on our own server and sets no cookies. It sees the page address, the referrer, device type, browser and country.
- Umami derives the country from the IP address but does not store the address. The counter is off in the administration area.
Telegram community
- The portal shows public posts and reactions from the community channel and chat: author name and ID, text. This is a copy of what is already published on Telegram.
Technical logs
- Servers keep service logs: errors, service events, sometimes IP addresses. They are needed for security and debugging. The controller has not yet set a separate retention period for them.
4. Cookies and browser storage
connect.sid— sign-in session, 7 days.lang— interface language, 1 year.cal_city,cal_grid— calendar city and view for guests, 1 year.- sessionStorage
loginHook— where you came from before signing in, to return you there; cleared when the tab closes.
Fonts are loaded from Google Fonts: when they load, Google receives your IP address and browser data. The sign-in page loads the Telegram widget.
5. Who receives data
- Cloudflare (USA) — DNS, protection and proxy: requests to the portal's sites pass through Cloudflare's network; also routing of mail to our addresses.
- Google — sign in with Google, Google Fonts, the Gmail mailbox that receives forwarded mail.
- Telegram — sign in with Telegram, the bot, conversations, team notifications, forwarding pre-orders to partners.
- Meta Platforms (WhatsApp) — conversations with the portal's number and phone verification via WhatsApp.
- Rakuten Viber — conversations and phone verification via Viber.
- SendPulse — sending email (SMTP): recipient address and message text.
- Partner suppliers — only your pre-order for their product.
Some of these services process data outside Ukraine, including in the USA. There are no other transfers except where required by law.
6. Legal bases
- Your consent — mailings, bot messages, place detection, date of birth.
- Performance of a contract — account, cabinet, controllers, replies to your requests and pre-orders.
- Legitimate interest — protection against spam and abuse, technical logs, de-identified statistics.
7. Your rights
You may find out what data we hold about you; correct it; delete it; restrict or object to processing; withdraw consent; receive a copy of your data. There is no built-in export in the cabinet yet — we will send a copy on request.
How to delete your data — see Data deletion. Requests go to [email protected].
You can complain to the Ukrainian Parliament Commissioner for Human Rights or, if you are in the EU, to the data protection authority of your country.
8. Security
Connections use HTTPS only. API keys and one-time codes are stored as hashes. Only the portal's administrators have access to data on the server.
9. Age
The portal is not intended for persons under 18.
10. Changes
When data flows change, this page and the edition date above change too.