Privacy Policy
Last updated: 29 June 2026
This Privacy Policy explains how Amin Huseynov, an individual entrepreneur (fərdi sahibkar) registered in the Republic of Azerbaijan (VÖEN: [1805136482]) ("Bronio", "we", "us", or "our"), collects, uses, shares, and protects your personal data when you use the Bronio mobile applications, the website bronio.az, and related services (together, the "Service").
We process personal data in accordance with the Law of the Republic of Azerbaijan on Personal Data (No. 998-IIIQ) and other applicable laws. For the purposes of that law, Bronio acts as the owner of personal data (controller) for the personal data described in this Policy, except where stated otherwise.
If you do not agree with this Policy, please do not use the Service.
1. Who This Policy Applies To
This Policy applies to:
- Customers – individuals who use the Service to discover Businesses and make
Reservations; and
- Business users – individuals who use the Service on behalf of a Business
that holds a Bronio account.
Where a Business receives your personal data through the Service (for example, your name and contact details when you make a Reservation), that Business acts as an independent owner/operator of your data for its own purposes, and its own privacy practices apply.
2. Personal Data We Collect
2.1 Data you provide to us:
- Account data: name, email address, phone number, and (for Business
accounts) business name, address, and role. You sign in with Google or Apple, so we never receive or store a password.
- Reservation data: the Businesses you book with, dates and times, party
size, notes, and similar details you submit when making a Reservation.
- Support data: information you give us when you contact support, including
the content of your messages.
- Optional profile data: anything you choose to add, such as a profile photo.
2.2 Payment and subscription data: When a Business purchases a paid Subscription, how payment data is handled depends on where the purchase is made:
- Web purchases (bronio.az): payment is handled by **Paddle.com Market
Limited ("Paddle")** as our Merchant of Record. Paddle collects and processes payment card and billing details directly.
- In-app purchases (Apple App Store / Google Play): payment is handled by the
relevant app store. We use RevenueCat, Inc. ("RevenueCat") to manage and track in-app Subscriptions; RevenueCat and the app stores may process purchase events, receipts, subscription status, and device identifiers.
In all cases we do not store full payment card numbers. We receive only limited information such as a transaction or subscription reference, subscription status, and partial card details.
2.3 Data we collect automatically:
- Device and technical data: device type, operating system, app version,
language, and similar technical identifiers.
- Push notification token: an identifier used to deliver push notifications
to your device.
- Usage and analytics data: how you interact with the Service, used to
operate, secure, and improve it.
- Location data (only if you grant permission). We use location for two
purposes depending on how you use the Service: to help Businesses set up and pin their workplace location quickly when creating a listing; and to show Customers nearby Businesses and services (for example, barbers or salons close to them). You can grant or withdraw location permission at any time in your device settings; without it, you can still use the Service but may need to enter or search locations manually. When you search or browse nearby Businesses, we may keep a record of the search together with an approximate location (rounded to about 1 km) to understand demand for services in different areas; these records are not linked to your account and never contain your precise location.
We will tell you at the point of collection which information is mandatory and which is optional, and the consequences of not providing mandatory information.
3. How We Use Personal Data and Our Legal Basis
We use personal data to:
- create and manage your account and authenticate you;
- enable you to make and manage Reservations and connect Customers with
Businesses;
- use location, where you permit it, to help Businesses set up their workplace
and to show Customers nearby Businesses and services;
- send push notifications, confirmations, reminders, and service messages;
- process and administer Subscriptions (via Paddle);
- provide customer support;
- secure the Service, prevent fraud and abuse, and debug problems;
- analyse and improve the Service; and
- comply with legal obligations.
Depending on the activity, our legal basis for processing is one or more of: your consent; the performance of a contract with you (these Terms); compliance with a legal obligation; or our legitimate interests in operating, securing, and improving the Service. Where we rely on consent (for example, for optional location data or marketing), you may withdraw it at any time.
4. Push Notifications
We use your push notification token to deliver Reservation-related notifications and reminders. You can turn off push notifications in your device settings at any time, though this may limit core functionality.
5. How We Share Personal Data
We share personal data only as needed to operate the Service:
- With Businesses: when you make a Reservation, we share the details
necessary to fulfil it (such as your name, contact details, and Reservation details) with the relevant Business.
- With Paddle: to process payments for Business Subscriptions purchased on
the web, as Merchant of Record.
- With RevenueCat and the app stores: to manage and process in-app
Subscriptions purchased through the Apple App Store or Google Play (subscription status, receipts, and related device identifiers).
- With service providers: hosting, push notification, analytics, and support
providers that process data on our behalf under appropriate safeguards.
- With app platforms: Apple and Google, to the extent necessary to distribute
and operate the app.
- For legal reasons: where required by law, court order, or a competent
authority, or to protect our rights, users, or the public.
- In a business transfer: in connection with a merger, acquisition, or sale
of assets, subject to this Policy.
We do not sell your personal data.
6. International Data Transfers
Bronio is based in the Republic of Azerbaijan, and the Service is available to users in Azerbaijan, the European Economic Area (EEA), the United Kingdom, the United States, and other regions. Your personal data may therefore be processed in, and transferred to, countries other than the one you live in, including Azerbaijan and the countries where our service providers operate.
- For transfers from Azerbaijan, we comply with the Law on Personal Data,
including its requirements for cross-border transfer.
- For transfers from the EEA or the United Kingdom, where the destination
country is not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.
In all cases we take reasonable steps to ensure your personal data receives an adequate level of protection.
7. Data Retention
We keep personal data only for as long as necessary for the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymise it. Subscription and transaction records may be retained for the period required by tax and accounting law.
8. Data Security
We apply appropriate organisational and technical measures to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction, including encryption in transit, access controls, and the use of reputable, secure payment providers. No method of transmission or storage is completely secure, but we work to protect your data using current good practice.
9. Your Rights
Subject to the Law on Personal Data, you have the right to:
- be informed about how your personal data is collected and used;
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure ("deletion") of your data;
- object to or restrict certain processing; and
- withdraw consent where processing is based on consent.
You can exercise these rights, including deleting your account and associated personal data, from within the app or by contacting us at turhan.huseynov@gmail.com. We will respond within the timeframe required by law. You also have the right to contact the competent state authority responsible for personal data protection in the Republic of Azerbaijan.
9.1 Additional rights for users in the EEA and the United Kingdom (GDPR). If you are in the EEA or the UK, you also have the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local data protection supervisory authority. Where we rely on consent, you may withdraw it at any time without affecting prior processing. Our legal bases for processing are described in Section 3.
9.2 Additional rights for users in the United States (e.g. California). If you are a US resident, depending on your state you may have the right to know the categories and specific pieces of personal data we collect, to access and delete it, to correct it, and to opt out of the "sale" or "sharing" of personal data or targeted advertising. We do not sell your personal data, and we will not discriminate against you for exercising your rights. You can exercise these rights using the contact details above.
10. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at turhan.huseynov@gmail.com and we will take steps to delete it.
11. Cookies and the Website
Our website bronio.az may use cookies and similar technologies for essential functionality, security, and analytics. You can control cookies through your browser settings. Where required, we will request your consent for non-essential cookies.
12. Third-Party Links and Services
The Service may link to or rely on third-party services (such as Apple, Google, and Paddle). This Policy does not cover those third parties, and we encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the Service or by other reasonable means and update the "Last updated" date above.
14. Contact Us
Amin Huseynov Bakı şəhəri, Sabunçu rayonu, Səməd bəy Mehmandarov 7, Poçt Şöbəsi No: 40 Email: turhan.huseynov@gmail.com Website: https://www.bronio.az