Nimbzo

Privacy Policy

Last Updated: January 24, 2026

Introduction

This Privacy Policy explains what personal data Nimbzo ('we', 'us') collects from users of the Nimbzo mobile application ('App'), how and why we use it, who we share it with, your rights under applicable data protection laws including Bangladesh data protection legislation, and how to contact us. Effective date: January 24, 2026.

1. Data Controller & Contact

Nimbzo is the data controller. We are located in Bangladesh. For privacy inquiries, contact us at: [email protected]. This policy covers the Nimbzo App on iOS and Android platforms. Visit our website at https://www.nimbzo.com/

2. Data We Collect

We collect: (a) Account data: name, email, password (hashed), phone number (if provided). (b) Profile data: profile picture, bio, education, location (city/country). (c) Device identifiers: device type, OS version, IP address, advertising ID (IDFA/AAID). (d) Location data: precise (GPS) and coarse location (if you grant permission). (e) User Content: posts, photos, videos, messages, comments. (f) Usage data: pages visited, features used, interactions, crashes (via analytics). (g) Contacts: if you grant permission to find friends. Data is collected directly from you, automatically via analytics SDKs, and from third parties (e.g., social login providers).

3. Legal Basis & Purposes

We process your data for: (a) Providing and maintaining the App (contractual necessity). (b) Authentication and account security (contractual necessity). (c) Personalizing content and recommendations (legitimate interest). (d) Analytics, crash reporting, app improvement (legitimate interest). (e) Marketing and promotions (consent, which you can withdraw). (f) Fraud prevention and legal compliance (legal obligation and legitimate interest). (g) Responding to lawful government requests (legal obligation). Under Bangladesh data protection ordinances, we obtain consent where required and honor your data subject rights.

4. Data Sharing & Cross-Border Transfers

We share data with: (a) Service providers: cloud hosting (e.g., Firebase, AWS), analytics (Google Analytics, Firebase Analytics), payment processors, customer support tools. (b) Legal authorities: when required by Bangladesh law, court order, or to prevent harm. (c) Business transfers: in case of merger or acquisition. We do not sell your personal data. Some data may be stored or processed outside Bangladesh (e.g., cloud servers in the US/EU). We use standard contractual clauses and encryption to safeguard cross-border transfers in compliance with Bangladesh regulations.

5. Data Retention & Security

We retain account data for the duration of your account plus 90 days after deletion (to honor legal/audit requirements). Analytics and logs are retained for 24 months. User content is deleted when you delete it or your account. We use encryption in transit (TLS/SSL) and at rest, access controls, and regular security audits. However, no system is 100% secure; you are responsible for keeping your password confidential.

6. Your Rights & Choices

You have the right to: (a) Access your data (download a copy). (b) Correct inaccurate data. (c) Delete your account and data (right to be forgotten). (d) Object to processing for direct marketing. (e) Withdraw consent (e.g., location, contacts). (f) Data portability. To exercise these rights, go to Settings > Delete Account or contact [email protected]. We will respond within 30 days. You may also file a complaint with the relevant Bangladesh data protection authority.

7. Children & Minors

The App is intended for users aged 13 and above. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us immediately and we will delete it. Parents of users under 18 should supervise their child's use.

8. Third-Party SDKs & Advertising

We use third-party SDKs for analytics (Firebase, Google Analytics), ads (AdMob), and crash reporting. These may collect device identifiers and usage data. You can opt out of personalized ads via device settings (iOS: Limit Ad Tracking; Android: Opt out of Ads Personalization). See our website for a full list of third-party processors.

9. Changes to This Policy

We may update this policy to reflect legal requirements or feature changes. We will notify you via in-app notice or email at least 7 days before material changes take effect. Continued use after notice constitutes acceptance. Check the 'Last Updated' date at the top.

10. Bangladesh-Specific Compliance

We are committed to following Bangladesh's Digital Security Act and protecting your data rights. We do not collect or share sensitive personal data (like religion or political views) without your explicit permission. We work with local authorities when required by law and have steps in place to handle any data security issues.