🛒 Arduino, ESP32 & modules
Home/Privacy Policy
Legal Document

Privacy Policy

This policy explains what information the Embedded.az website and the Embedded.az mobile app collect about users, why we use it, who we share it with and how we protect it.

Last updated: 11 September 2026

Your Data Is Safe

This policy explains what information the Embedded.az website (embedded.az and its subdomains — auth, shop, lms, kabinet, status, rewards, notify) and the Embedded.az mobile app (Android) collect about users, why we use it, who we share it with and how we protect it. The website and the app use the same account and the same servers, so this document applies to both. By using the website or the app you accept this policy.

1. Data controller and contact

  • The controller of your data is Embedded.az (Baku, Azerbaijan). For any privacy question or request: [email protected] or the contact form on the website / in the app.

2. Information we collect

  • Account data: name, e-mail address, username, profile picture and language. When you sign in with Google we receive your name, e-mail and profile picture from your Google account; your password is never shared with us.
  • Order and delivery data: delivery addresses (recipient name, phone, city, address), an optional map pin (the precise coordinates of the address), order history, cart, wishlist and price quotes sent to you.
  • User content: product reviews and the photos you attach to them, comments and reports on posts, contact-form and feedback messages.
  • Kabinet (repair and service jobs): job entries, amounts, confirmations by both parties, files, photos, videos and voice messages you attach to a job (only when you send them).
  • Learning: course enrolments, lesson progress and quiz results.
  • Rewards: points balance, points history and your referral code.
  • Notifications: push token (FCM), platform (Android/iOS/web), OS and app version, notification preferences and notification history.
  • Session and security data: the IP address of each sign-in, device or browser information (app version, Android version, device model) and the sign-in time. You can see and end your active sessions on the "Active sessions" screen in the app.
  • Location: only while placing a delivery-address pin — when the pin screen opens (if the address has no pin yet) or when you tap "Use my location" — the device GPS is read and, if you confirm the pin, the precise coordinates are stored with that address. The app never tracks location in the background. If you decline, you can type the address instead and use the app fully.
  • Crash reports: when the app stops unexpectedly, the device model, operating system, app version and error trace are collected through Firebase Crashlytics.
  • We do not collect advertising identifiers, behavioural analytics or ad-tracking data.

3. How we use it

  • Providing the service: taking and delivering orders, managing your account, course access, keeping kabinet job records, delivering notifications.
  • Support: answering your requests and solving problems.
  • Security: protecting your account, notifying you of sign-ins from a new device, preventing fraud, abuse and unauthorised access.
  • Improvement: fixing app errors based on crash reports.
  • Legal obligations: accounting and where the law requires it.

4. Legal basis

  • Order, account, course and kabinet data are processed to perform our contract with you. Device permissions for location, microphone and notifications are used only with your consent, which you can withdraw at any time in the device settings. Session and IP data are kept on the basis of our legitimate interest in security; accounting records on the basis of legal obligation.

5. Mobile app device permissions

  • Notifications (Android 13+): to show push notifications; if declined, the app works without them.
  • Location (precise/approximate): only on the delivery-address pin screen; never in the background.
  • Microphone: only while you record a voice message in the kabinet.
  • Internet: to reach our servers.
  • We do not request access to your photo or media library — when you pick a photo or video the system picker opens and only the file you choose is sent to us. Every permission is optional and can be revoked at any time in the device settings.

6. Third-party services

  • We do not sell your personal data and do not share it with third parties for advertising. To run the service we use the following technical partners, which receive only what is necessary:
  • Cloudflare — network security and bot protection (IP address, request data);
  • Cloudinary — image storage and processing (profile picture, review photos, product images);
  • Google Firebase — Cloud Messaging (push notifications) and Crashlytics (crash reports);
  • Google — "Sign in with Google" (only if you choose that method);
  • MapTiler / OpenStreetMap — map imagery; when a map is shown in the app, your device's IP address and the coordinates of the area you view are sent to MapTiler's servers;
  • Courier / taxi services — at delivery time your name, phone number, address and (if set) the map pin are given to the driver so the order can be delivered.
  • These partners' servers may be located outside Azerbaijan. No personal data is passed to the AI models used to prepare website content.

7. Push notifications

  • To send notifications we store your device's notification token (FCM) on our server, tied to the session you signed in with. When you sign out, end the session or delete the account, the token is removed from the server; invalid tokens are cleaned up automatically. You can turn off notification types in the app settings and all notifications in the device's system settings.

8. Crash reports

  • When the app stops unexpectedly, technical crash data (device model, OS version, app version, error trace) is collected through Firebase Crashlytics so we can fix the cause. It is not used to identify you or for marketing.

9. Data stored on your device

  • The mobile app stores only the following on your device: a session token so you stay signed in (in encrypted storage); language and theme choice; an anonymous cart identifier so you can build a cart before signing in; a cache of contact details, categories and site content for offline use; an image cache; flags so one-time dialogs are not shown again. This data is excluded from the device's cloud backup and is not shared with other apps. Uninstalling the app removes all of it.

10. Retention

  • Account data is kept while your account is active. Sign-in sessions expire automatically after 30 days. When you delete your account, your personal data is deleted or anonymised immediately (see section 11). Kabinet financial entries confirmed by both parties are kept because they are records both sides agreed to, but personal data such as name, phone and IP is removed from them. Order and invoice documents may be retained for as long as accounting law requires.

11. Deleting your account

  • You can delete your account yourself at any time: in the mobile app under Account → Settings → "Delete account", or on the web at https://auth.embedded.az/en/danger. Accounts with a password must confirm it; accounts that sign in only with Google must have signed in within the last 24 hours.
  • Deletion is immediate and cannot be undone: the account, linked sign-in methods and sessions on all devices are deleted; the profile picture is deleted; notification devices, preferences and history are deleted; your data in the shop, learning, rewards, posts and kabinet services is deleted or anonymised — your reviews and comments no longer show who wrote them.

12. Your rights

  • You have the right to: access your data and obtain a copy; correct inaccurate data (name, username, picture and addresses can be changed in the app's profile section); delete your account and data; opt out of notifications; revoke device permissions; end sessions on other devices. We answer requests within 30 days.

13. Security

  • All traffic is encrypted with TLS. Passwords are stored in a non-reversible form (hash). In the app the session token is kept in the device's encrypted storage. You are notified when your account is signed in from a new device and can end a suspicious session with one tap. Access to data is limited to staff who need it.

14. Children's privacy

  • The service is not intended for persons under 16. If we learn that a user under 16 has given us personal data, we delete it.

15. Changes

  • We may update this policy from time to time. Significant changes will be announced on the website, in the app or by e-mail. The date of the last update is shown at the top of this page.

16. Contact

Have a question?

If you have any questions regarding our privacy policy, please get in touch with us.

Contact us