✦ Legal documents

Privacy Policy

Last updated: August 21, 2026

By using around.md, you agree to this Privacy Policy. Please read it carefully.

1. Who we are

around.md is an online catalog of places and venues in Moldova, available at around.md. The owner and operator of the platform is Serghei Drici (info@dricomm.com), registered in the Republic of Moldova. We collect data entered in the site's forms, as well as the visitor's IP address and browser user-agent data for security and spam prevention purposes. We do not guarantee the accuracy of information added by users or third parties.

2. What data we collect

We collect the following categories of personal data: • Registration data: name, email, password (stored in encrypted form) • Profile data: phone number, avatar (optional) • Venue data: name, address, phone, description, photos (when adding a venue) • Reviews: review text, rating, photos • Technical data: IP address (when submitting reports, for spam protection), device data for push notifications • Usage data: saved places, viewing history, clicks (to improve recommendations) We do not sell or share your personal data with third parties for advertising purposes.

3. Purposes and legal bases for processing

We process your personal data for the following purposes and on the following legal bases: • Providing access to the service — contract performance • Ensuring security and protection against abuse — legitimate interest • Sending notifications you have subscribed to — consent • Improving recommendations and the service — legitimate interest • Internal administration and registration monitoring — legitimate interest

Media files

If you upload photos to the site, we recommend ensuring that images do not contain EXIF metadata with GPS coordinates. Visitors can extract this data by downloading the image. We automatically convert photos to WebP format, which may remove some metadata, but we do not guarantee complete removal.

4. How we use data

Collected data is used for: • Providing platform services (catalog, search, recommendations) • Personalizing recommendations based on your views • Improving site performance and traffic analysis • Sending push notifications (only with your explicit subscription) • Communicating with you about your account or requests • Ensuring security and preventing fraud

5. Data storage and protection

Your data is stored on Supabase servers (PostgreSQL), which ensures encryption of data at rest (AES-256) and in transit (TLS 1.2+). Photos are stored in secure cloud storage. We may transfer data to the following third-party services solely for platform operation: • Supabase Inc. (USA) — database and authentication • Vercel Inc. (USA) — hosting and CDN • Cloudflare Inc. (USA) — DDoS protection, Turnstile CAPTCHA • Resend Inc. (USA) — email delivery • Open-Meteo (Switzerland) — weather data • Esri Inc. (USA) — map tiles (displaying the map on the site) • OpenStreetMap / Nominatim — address geocoding when adding a venue Data may be processed on servers outside Moldova (EU, USA). For data transfers to the USA, Standard Contractual Clauses (SCCs) or other mechanisms are applied in accordance with applicable law.

6. Who we share data with

To operate the platform, we use the following service providers, who act as processors handling data on our behalf: • Supabase — database storage • Resend — email delivery • Telegram — service notifications (including notifications to the administrator about new registrations, reports, and venues being added) • Cloudflare — spam and bot protection • Google — sign-in via Google account, if you choose this option when registering or signing in • Groq and Anthropic — processing the text of your messages and preferences in AI features (smart recommendations, chat assistant, AI visit plan), only if you use them Separately: if you click the "Order taxi" button on a place page, your browser is redirected through a Yandex AppMetrica link — Yandex receives the place's coordinates, the fact of the click, and your IP address. This only happens when you explicitly click this button. A detailed list of server infrastructure (hosting, weather data) is provided in the "5. Data storage and protection" section above.

7. Cookies

We use cookies and browser local storage (localStorage) for: • Storing the authentication session — cookie, required • Remembering interface theme and language — localStorage, required • Caching weather data — localStorage, functional (can be disabled in cookie settings; weather will then be fetched again on every visit) Your cookie settings choice is kept for 6 months, after which we will ask again. You can disable cookies in your browser settings, however this may affect site functionality. By using the site, you agree to the use of required cookies. Additional information on the Cookies page.

Data retention periods

• Account data: retained until account deletion • Session cookies: deleted when browser is closed • Persistent cookies: stored for up to 1 year • Weather cache: 30 minutes in localStorage • Security logs (IP, user-agent): up to 90 days • History of place clicks and views (for recommendations): up to 12 months, then automatically deleted • Dashboard notifications: up to 6 months, then automatically deleted • Technical app session data (PWA): up to 12 months, then automatically deleted • Push subscriptions: retained until unsubscribed or until notification delivery becomes technically impossible (device unavailable) Automatic cleanup of expired data runs monthly.

8. User rights (GDPR and applicable law)

Under the laws of Moldova (Law No. 133/2011, Law No. 195/2024) and GDPR principles, you have the right to: • Access your data (Art. 15 GDPR) • Rectify inaccurate data (Art. 16 GDPR) • Request deletion of your data (Art. 17 GDPR) • Restrict processing of your data (Art. 18 GDPR) • Receive a copy of your data in a machine-readable format (Art. 20 GDPR) • Object to data processing (Art. 21 GDPR) • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal • Lodge a complaint with Moldova's National Center for Personal Data Protection (CNPDCP, www.datepersonale.md) To exercise your rights: info@dricomm.com EU users may contact their national data protection authority. California residents (CCPA): you have the right to know what personal information we collect, to delete it, and to opt out of its sale (we do not sell personal data). Contact us at info@dricomm.com.

9. Children's data

Our service is not intended for persons under 16 years of age. We do not intentionally collect data about children. If you believe a child has registered on the platform, contact us at info@dricomm.com to delete the account.

10. Policy changes

We may update this policy. For significant changes, we will notify users via the site or email. The date of the last update is shown at the top of this page. Continued use of the platform after changes are published constitutes acceptance of the new version.

11. Contact

For all questions related to personal data: Email: info@dricomm.com Telegram: @dricomm Response time: up to 30 days (in accordance with GDPR requirements)
Questions: info@dricomm.com