PRIVACY POLICY

of the «Laffy Smart Wishlist» application

Version of 7 September 2026

This English version is a translation provided for convenience. In case of any discrepancy, the Russian version at https://laffy.store/privacy_policy.html prevails.

1. General provisions

1.1. This Privacy Policy of the «Laffy Smart Wishlist» application sets out how the personal data of users of the «Laffy Smart Wishlist» mobile application (the «Application») is processed and protected.

1.2. The personal data operator is INOLT Limited Liability Company (the «Operator»):

Full name: INOLT LIMITED LIABILITY COMPANY.

Short name: INOLT LLC.

INN (taxpayer ID): 2223639154.

KPP: 222301001.

Registered address: office N15, 99 Vlasikhinskaya St., Barnaul, Altai Krai, Russia.

E-mail for personal data matters: laffyconnect@bk.ru

1.3. The Application may be distributed through the App Store, Google Play and RuStore, and through other platforms officially designated by the Operator.

1.4. Apple, Google, RuStore and other distribution platform owners may independently process data related to the user's account on the respective platform, downloading and updating the Application, the device, in-app purchases and use of the app store. Such processing is carried out by those parties under their own documents and privacy rules.

1.5. The mere availability of the Application in the App Store, Google Play or RuStore does not mean that the Operator transfers the user's phone number, name, city, photo or wishlist contents to the platform. Such transfer is possible only where there is a corresponding technical integration and a lawful basis.

1.6. This Policy has been drawn up in accordance with the Constitution of the Russian Federation, the Civil Code of the Russian Federation, Federal Law No. 152-FZ of 27.07.2006 «On Personal Data», Federal Law No. 149-FZ of 27.07.2006 «On Information, Information Technologies and Information Protection» and other applicable regulations.

1.7. The Policy applies to all personal data the Operator receives during registration, sign-in and use of the Application, when users contact support, restore access, and use the features for creating and jointly viewing wishlists.

1.8. Use of the Application is also governed by the user agreement. The Policy informs the user about data processing and does not by itself replace the user's separate consent where such consent is required by law.

2. Definitions

2.1. Personal data means any information relating directly or indirectly to an identified or identifiable natural person.

2.2. User or data subject means a natural person who has registered in or uses the Application.

2.3. Processing of personal data means any action or set of actions performed on personal data, including collection, recording, systematisation, accumulation, storage, clarification, retrieval, use, provision, access, blocking, deletion and destruction.

2.4. Dissemination of personal data means actions aimed at disclosing personal data to an indefinite range of persons.

2.5. Provision of personal data means actions aimed at disclosing data to a specific person or a specific range of persons.

2.6. Depersonalisation means actions as a result of which it becomes impossible, without additional information, to attribute personal data to a particular user.

2.7. Wishlist means a list created by the user of wishes, goods, services, gifts, links, images, descriptions and other materials.

3. Principles of personal data processing

The Operator processes personal data:

4. What data the Operator processes

4.1. Data provided during registration

When registering or filling in the profile, the user may provide:

The phone number is used for registration, sign-in, confirming actions, restoring access, preventing abuse and contacting the user about the operation of the Application.

If the city and photo are not objectively necessary for the core operation of the Application, the user should be given the option not to fill in these fields or to delete them later.

4.2. Data created when using the Application

The Operator may process:

The user must not include in wishlists passport details, bank details, medical information, information about their intimate life, political or religious views, or other special or excessive categories of personal data.

4.3. Technical data

When the Application is used, the following may be processed automatically:

Advertising identifiers and cross-service tracking data may be processed only where the corresponding advertising technologies are actually used and where there is the necessary lawful basis or the user's permission.

4.4. Data received from distribution platforms

The Operator may receive from the App Store, Google Play or RuStore aggregated information about installations, uninstallations, Application versions, crashes, purchases and device specifications.

If the Application offers paid features, the user's payment details are, as a rule, processed by the respective platform or payment provider. The Operator may receive information about the payment status, transaction ID, plan, amount and subscription term, but does not receive the full bank card number unless the user is expressly told otherwise.

4.5. User photo

The profile photo is used as an element of the profile design and is not used by the Operator for automatic identification, face recognition or establishing identity based on physiological characteristics.

When used in this way, the photo is not processed by the Operator as biometric personal data. If face recognition or other biometric identification is introduced in the future, the Operator will first update its documents and obtain separate consent where required by law.

4.6. Data the Operator does not request during registration

For ordinary registration the Operator does not request:

If a particular feature requires access to contacts, the camera, photos or notifications, the corresponding system permission is requested immediately before the feature is used. Refusing an optional permission must not prevent the use of features that do not require it.

4.7. Sign-in with Yandex ID and Google

The user may sign in to the Application with a Yandex ID or Google account instead of a phone number. In this case the Operator neither receives nor stores the password of that account.

When the user signs in with Google, the Operator receives from Google a signed Google ID token, which may contain:

Of this data, the Operator stores only the Google account identifier (to recognise the user at the next sign-in), the name and the profile photo (the photo is used only if the user has not uploaded their own photo to the Application). The e-mail address is not stored by the Operator. The Operator does not request access to contacts, mail, files, calendar or any other data of the Google account.

When the user signs in with Yandex ID, the Operator receives from Yandex the account identifier, name, profile photo and phone number, if the user has allowed them to be shared, as well as the access token issued by Yandex for authorisation.

Data received from Google and Yandex is used solely to create the account, sign the user in to the Application and display the user's profile. The Operator's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data received through Google APIs:

The user may at any time revoke the Application's access to their Google account at https://myaccount.google.com/permissions, or to their Yandex ID account in its settings, and may delete their Laffy profile at https://laffy.store/del_a.html — in which case the stored data is deleted as described in section 11.

5. Purposes of data processing

5.1. Registration and account management

Processed: phone number, name, city, photo, technical account identifier and authorisation data.

Purposes: creating the account, identifying the user within the Application, confirming the phone number, signing in, restoring access and maintaining the profile.

5.2. Providing smart wishlist features

Processed: profile data, wishlists, links, images, categories, visibility settings, marks and user actions.

Purposes: creating, storing, editing, sorting, suggesting, jointly viewing and providing other wish management features.

5.3. Giving access to other users

Processed: name, photo, city, profile data selected by the user, wishlist contents and access settings.

Purpose: making a wishlist available to specific invited persons, registered users or an indefinite range of persons, depending on the settings chosen by the user.

Personal data is made public only with a separate consent to the processing of personal data permitted by the data subject for dissemination, where such consent is required.

5.4. Communication with the user

Processed: phone number, push token and account information.

Purposes: sending confirmation codes, security messages, notices of changes to the terms, support replies and service notifications.

Advertising and marketing messages are not covered by the mandatory consent to personal data processing. Sending them requires the user's separate prior consent.

5.5. Security

Processed: phone number, IP address, device information, technical logs, actions in the Application and information about violations.

Purposes: preventing fraud, unauthorised access, unsolicited messaging, attacks, abuse and violations of the user agreement.

5.6. Technical support and improvement of the Application

Processed: user requests, diagnostic information, Application version, error data and anonymised statistics.

Purposes: fixing bugs, handling requests, quality control, developing features and assessing the stability of the Application.

5.7. Compliance with the law

The Operator may process and store data in the cases and for the periods established by law, and provide information to authorised state bodies upon a lawful and duly executed request.

6. Legal grounds for processing

The Operator processes data on the following grounds:

Refusing to provide a phone number may make registration, sign-in, account protection and access recovery impossible.

Refusing to provide an optional photo or city must not restrict the core features of the Application, unless this data is required for a specific feature.

7. Procedure and methods of processing

7.1. Processing is carried out by automated means and, in certain cases, without the use of automation.

7.2. The Operator may perform the following actions:

7.3. Dissemination of data to an indefinite range of persons is not part of the mandatory processing necessary for registration. It is permitted only if the user chooses a public mode and there is a separate lawful basis.

7.4. The Operator does not make decisions that produce legal consequences for the user solely on the basis of automated processing of personal data.

7.5. Recommendation algorithms may use wishlist contents, categories and user actions to sort or suggest suitable wishes. Such recommendations are for information only and produce no legal consequences.

8. Visibility of the profile and wishlists

8.1. The Application may provide the following modes:

8.2. The user's phone number must not be shown to other users or included in a public profile.

8.3. Before a public mode is enabled, the user must be clearly shown exactly which data will be published.

8.4. The public mode must not be enabled by default.

8.5. Consent to the dissemination of personal data is given separately in accordance with Article 10.1 of Federal Law No. 152-FZ. The user must be able to determine the list of published data, the conditions of their dissemination and prohibitions on further processing.

8.6. Cancelling public access stops further dissemination of the data by means of the Application; however, the Operator cannot guarantee the deletion of copies previously lawfully saved by other users or posted by them outside the Application.

9. Transfer and entrustment of processing

9.1. The Operator may engage parties that provide:

9.2. An up-to-date list of the parties entrusted with processing personal data, stating the purpose of the entrustment and the data transferred, is provided to the user upon request sent to the Operator's e-mail laffyconnect@bk.ru.

9.3. Parties processing data on behalf of the Operator receive only the minimum necessary amount of data. They are obliged to maintain confidentiality, comply with security requirements and follow the Operator's instructions.

9.4. The Operator may provide information without the user's consent where this is provided for by law or is necessary to comply with a lawful request of an authorised body.

9.5. In the event of the Operator's reorganisation, rights and obligations regarding personal data may pass to the legal successor, subject to the law and this Policy.

9.6. The Operator does not sell personal databases and does not provide phone numbers to advertising companies for their own marketing without the user's separate consent.

10. Localisation and cross-border transfer

10.1. When collecting personal data of citizens of the Russian Federation, the Operator records, systematises, accumulates, stores, clarifies and retrieves such data using databases located in the Russian Federation, in accordance with Part 5 of Article 18 of Federal Law No. 152-FZ.

10.2. The main database of the Application's users must be located in the Russian Federation: Selectel (Selectel LLC), data centre in Moscow.

10.3. If the Operator uses foreign services, including foreign analytics, error monitoring, notification delivery or cloud storage systems, the Operator, before starting a cross-border transfer, complies with Article 12 of Federal Law No. 152-FZ, including assessing the foreign recipient and sending the required notification to Roskomnadzor.

10.4. If no cross-border transfer actually takes place, the Operator states: «No cross-border transfer of users' personal data is carried out».

10.5. The clause on cross-border transfer must not be left undetermined. Before the Policy is published, the actual operation of all SDKs, APIs, push services and analytics tools must be checked.

11. Retention periods and deletion of data

11.1. Account data is processed for as long as the Application is used.

11.2. After the account is deleted, the data is deleted or depersonalised within 30 calendar days, unless longer storage is required by law, the resolution of a dispute, the performance of a contract or the protection of the rights of the Operator and users.

11.3. Backups may be kept for no more than 30 days. Access to them is restricted, and restored data is again subject to deletion.

11.4. Technical security logs are kept for 14 days, unless a longer period is required to investigate an incident or comply with the law.

11.5. Support requests are received at the Operator's e-mail and kept as part of the e-mail correspondence for the time needed to handle the request and confirm its fulfilment; no separate ticketing system is used.

11.6. Data processed on the basis of consent is deleted after the consent is withdrawn, unless the Operator has other lawful grounds to continue processing.

11.7. The user may delete an individual photo, city, wishlist or other materials in the Application settings, where the corresponding feature is provided.

11.8. The Application must offer an account deletion feature or clear instructions on how to send a deletion request. Deleting the Application from the device does not automatically delete the account.

12. Protection of personal data

The Operator takes the necessary legal, organisational and technical measures, including:

At the same time, no method of transmitting or storing information can guarantee absolute security. The user is also obliged to keep confirmation codes safe and not to give third parties access to their phone.

13. User rights

The user has the right to:

To exercise these rights, the user sends a request:

The request must make it possible to identify the applicant and the corresponding account. The Operator may request reasonably necessary additional information to verify identity, but must not request excessive data.

A reply is sent within the time limits established by law.

14. Withdrawal of consent

14.1. The user may withdraw consent in the Application settings or by sending a request to the Operator.

14.2. Withdrawal of consent does not affect the lawfulness of processing carried out before the Operator received it.

14.3. After receiving the withdrawal, the Operator stops processing and destroys the data within the period established by law, unless keeping it is still required to perform a contract, comply with the law or protect the Operator's rights.

14.4. If the core features cannot be provided without the relevant data, withdrawal of consent may result in deletion of the account or termination of access to certain features.

15. Notifications and advertising messages

15.1. Service messages include SMS codes, security notifications, messages about changes to documents, support replies and information about the account. They are not advertising.

15.2. Notifications about wishlist events can be turned off in the Application or device settings, unless they are required for security.

15.3. Advertising and marketing messages are sent only on the basis of separate prior consent.

15.4. Consent to advertising must not be a condition of registration and must not be combined with consent to personal data processing.

16. Data of minors

16.1. The Operator does not aim to collect personal data of children who by law cannot independently accept the terms of use of the Application.

16.2. If minors are allowed to use the Application, the Operator must set age conditions in the user agreement and provide for obtaining the consent of a legal representative where necessary.

16.3. If an account created without the necessary consent of a legal representative is discovered, the Operator may restrict access and delete the corresponding data.

17. User obligations

The user must:

If the user creates a wishlist for another person or uploads their photo, the user is solely responsible for having a lawful basis for doing so.

18. Changes to the Policy

18.1. The Operator may amend the Policy when the law, the Application's features or the data processing procedure change.

18.2. The current version is published at https://laffy.store/privacy_policy.html (English translation: https://laffy.store/privacy_policy_en.html) and within the Application.

18.3. The date of the last update is shown at the top of the document.

18.4. The Operator notifies the user of material changes within the Application, by SMS, push notification or another available means.

18.5. If a change requires new consent, continued use does not by itself replace such consent. The Operator requests it by a separate action.

19. Operator details

INOLT LIMITED LIABILITY COMPANY.

INN (taxpayer ID): 2223639154.

KPP: 222301001.

Registered address: office N15, 99 Vlasikhinskaya St., Barnaul, Altai Krai, Russia.

Settlement account: 40702810023600000571.

Account currency: Russian rouble.

Bank: Novosibirsky branch of ALFA-BANK JSC.

BIC: 045004774.

Correspondent account: 30101810600000000774.

E-mail for personal data matters: laffyconnect@bk.ru