Log in Create a free account

Privacy Policy

Last updated: August 8, 2026

This policy describes how Gudfy ("we") handles the personal data of people who use the platform. It applies to the gudfy.com website, the native Gudfy Android app, and any official communication through the channels listed here.

1. Responsable del tratamiento

Gudfy operates as a marketplace and SaaS facilitating platform. Any questions about your data can be directed to the official support channel at Telegram or through the public forum.

2. What data we collect

  • Account details: name, email, country, WhatsApp number, password (stored with bcrypt hash).
  • Acceso con Google: if you choose this option, we receive your account's stable identifier, name, and verified Gmail address from Google. We do not store the Google token or access your password, Drive, contacts, or email.
  • Activity data: history of published and purchased listings, internal chat messages, reviews, reports and disputes.
  • Seller's commercial details: configured payment methods (alias, bank, type), local currency, public store slug.
  • Technical data: IP address, user agent, timestamp of each session and, on Android, a random installation identifier, device model or name, app version, operating system version, language, and time zone.
  • Android notifications: if you enable alerts, Gudfy and Firebase Cloud Messaging process the token or installation identifier needed to deliver messages to the device. Notification permission can be withdrawn from Android, and marketing remains disabled unless you explicitly opt in.
  • Android diagnostics: the production version uses Firebase Crashlytics to receive crashes, traces, relevant app state, version, model, architecture, available memory or storage, and random Crashlytics/Firebase identifiers. Gudfy does not add passwords, messages, receipts, or delivered credentials to those reports.
  • Canales vinculados: identificador de chat y preferencias cuando conectas el bot oficial de Telegram.
  • Optional KYC: identification documents when a seller requests voluntary verification. They are stored encrypted and retained only as long as necessary to validate identity.

3. What do we use them for?

  • Operar el marketplace y el SaaS, autenticarte y entregar los servicios contratados.
  • Moderate the platform, prevent fraud, resolve disputes and apply the guarantees declared by each seller.
  • Send transactional notifications by email, push, or Telegram about your account, orders, messages, and disputes.
  • If Telegram is linked and promotions are enabled, select recommendations based on your role, latest activity, and recent interests on Gudfy. We limit this channel to one promotion every 72 hours, and you can disable it from the message by typing notificaciones marketing off or in Settings.
  • Improve the product based on aggregated and anonymous metrics.
  • Detectar, priorizar y corregir cierres inesperados de la app Android mediante Crashlytics.

4. Who we share data with

We do not sell your information. We share only what is necessary with:

  • The counterparty of your transaction: In a purchase, seller and buyer see the public name, nickname and payment method chosen to coordinate the exchange.
  • Technical providers: services that help us operate (transactional email, Firebase Cloud Messaging and Crashlytics for Android, Sentry monitoring in web services, and public-navigation analytics with Google Analytics and Microsoft Clarity — see section 8). Each receives only the minimum data required.
  • Google Identity Services: processes your account selection and confirmation when you choose to continue with Google. Gudfy receives only the basic data needed to authenticate you and link your Gmail.
  • Official gift card provider: Practisistemas receives the product reference, a transaction identifier and the minimum technical data needed to issue or check the code. Gudfy does not send the buyer’s name, email, phone number or payment receipt.
  • Autoridades competentes: only when there is a valid order issued by legal authority.

5. How long do we keep the data

We retain data while your account is active. You may request deletion at any time (see the next section). Non-transactional analytics events sent directly by the app are aggregated and deleted within 120 days. Firebase retains crash traces and associated Crashlytics identifiers for 90 days before beginning deletion. Installation identifiers used by FCM are retained until Gudfy asks Firebase to delete them; after that call, the provider begins removing them from active and backup systems, a process that may take up to 180 days. Details of Telegram campaign decisions, clicks, and attribution are retained for 180 days; afterward, only the daily aggregate remains. Some transaction records (orders, resolved disputes, reviews) are retained in anonymized form for up to 5 years as necessary for auditing and fraud prevention.

6. Your rights

In accordance with the applicable LATAM regulations (Habeas Data in Colombia, LFPDPPP in Mexico, LGPD in Brazil, etc.) you have the right to:

  • Know what data we store about you.
  • Correct, update or rectify incorrect information.
  • Request deletion of your account and associated data.
  • Oppose the use of your data for purposes other than operating the platform.
  • Receive an exportable copy of your personal data.

To exercise any of these rights, contact us through the official Telegram channel or at [email protected]. To delete an account, use Profile → Delete my account en Android o consulta el web deletion procedure. We respond within 15 business days of the request.

7. Cookies y almacenamiento local

We use strictly necessary cookies to keep your web session signed in (an HttpOnly cookie with SameSite Lax) and for CSRF protection. In addition, the analytics tools described in the next section place first-party measurement cookies (not advertising cookies). We do not track behavior across sites other than Gudfy. The browser may use localStorage for UI preferences (column order, theme), information that never leaves your device.

The Android app stores session and push tokens encrypted with Android Keystore, language preferences, and a cache limited to the public catalog. Orders, chat, profile, receipts, and credentials are not kept in the local database. Temporary attachments or receipts remain in private storage only while being processed and are deleted when finished, upon signing out, or on the next start after an interruption. You can erase all local storage by uninstalling Gudfy or using Storage → Clear data in Android; this does not delete the account from the server.

8. Analytics and session recording

To understand which pages are useful and where people get stuck, we use two tools that They are only activated in public areas of the site (home, marketplace, forum, toolkit, blog, information pages and registration/login forms). They are not activated in your authenticated area (Saas panel, settings, wallet, orders, profile) or in the administrative panel:

  • Google Analytics 4 — provider: Google Ireland Ltd. Records page views, time on page, device, approximate country (at city level) and automatic events (scroll, downloads, clicks to external links). It does not store personal identifiers.
  • Microsoft Clarity — supplier: Microsoft Corporation. Generate heat maps of clicks and scrolls, and record anonymous sessions as video to detect usability friction (broken buttons, frustrated clicks). Sensitive inputs (passwords, emails, card numbers) are automatically masked before leaving your device, as is any text within elements marked with the convention data-clarity-mask.

How to deactivate this tracking: enable the "Do Not Track" signal in your browser (both providers honor it), install an ad blocker like uBlock Origin, or use incognito mode. We do not place an additional cookie banner because the entire authenticated area of ​​the site is left out of the analytics.

App Android: the app does not integrate Google Analytics, Microsoft Clarity, advertising, or screen recording. It sends Gudfy only first-party events with allowed and bounded properties, such as app version, action type, and internal operation identifiers. Crashlytics is enabled only in production builds for technical diagnostics.

9. Seguridad

Traffic is encrypted over HTTPS with a Let's Encrypt certificate. Android requires TLS, enables Certificate Transparency on compatible versions, and does not allow HTTP traffic outside local hosts in laboratory builds. Passwords are stored as bcrypt hashes; we cannot see them in plain text. The database is backed up daily. If we detect a security incident affecting your data, we will notify you by email within 72 hours.

10. Menores de edad

Gudfy is not directed to children under 18 years of age. If we detect a minor's account, we suspend it and delete the associated data.

11. Changes to this policy

If we update this policy, we change the header date and notify those with active accounts by email. Continued use of the platform after a change implies acceptance of the new version.