Gott Technologies LATAM ("Company," "we," "us," or
"our") is committed to protecting the privacy and personal data of users of the Gott SafeCall
mobile application ("the App"). This Privacy Policy explains what information we collect, how we
use it, how we protect it, and your rights regarding your personal data. This policy applies to
all users of Gott SafeCall and complies with Mexico's Federal Law on Protection of Personal Data
Held by Private Parties (LFPDPPP) and the General Data Protection Regulation (GDPR) where
applicable.
1. Data Controller
The data controller responsible for your personal data
is:
2. Information We Collect
We collect the following categories of information to
provide and improve the Gott SafeCall service:
2.1 Information You Provide
- Account information: first name, last name, and phone number (collected
during registration via phone number verification with OTP). Your phone number
identifies your account: the data described in this policy is associated with it. If you
sign in with a different number, that is a separate account with its own data. If you
verify a number that has no account and choose not to continue, the authentication
record created at that moment is deleted immediately.
- Year of birth: requested during registration. We use it for two purposes:
to confirm that you meet the minimum age required to use the App (18 years), and to
understand the age profile of our users so we can improve the service. We store the year
of birth in your account record; for analytics we only ever use a broad
age range (for example "60-69"), never your exact age or year of birth.
- Emergency contacts: names and phone numbers of up to 3 emergency contacts
you designate within the App. You must obtain their consent before adding them.
- Cancellation feedback: if you cancel your subscription, the reasons you
select (and any free-text comment you choose to write) are stored together with your user
ID, your plan and the date. Providing this feedback is part of the cancellation screen; the
comment field is optional.
2.2 Information Collected Automatically
- Call event data: phone state changes (ringing, off-hook, idle), timestamps,
and whether the number is saved in your contact list. This applies to incoming calls only. We
do not record call content or audio.
- Registration date: a server-generated timestamp recording when your account
was created.
- Subscription state: your plan, trial/subscription status, and related
billing metadata (e.g., expiration and auto-renewal), verified against Google Play. When you purchase, the App sends Google Play an encrypted identifier of your Gott SafeCall
account (not your name or phone number) so the subscription is linked to your account and
cannot be used on another one.
- Free trial control: to grant the no-card trial only once per number, we
keep a fingerprint of your phone number (SHA-256 hash) together with the trial dates and
whether that number has already subscribed. We do not store the number itself, your name,
or your contacts there. This fingerprint is kept even if you delete your account, for the
period stated in section 7, only to prevent the trial from being repeated.
- Contact change limit: the date of your last voluntary change of trusted
contacts, so the one-change-per-month limit applies even if you reinstall the App.
- Contact list access: the App reads your device's contact list locally to
determine the whitelist of known callers. Contact names and numbers are not uploaded
to our servers — this comparison is performed entirely on-device.
- Call log analysis (on your phone only): to identify who is
calling you, the App reads the device call log and counts how many times that same
number has called in the last 14 days and whether any of those calls was answered.
It uses this to warn you when a number keeps calling and you have never spoken to
it — the pattern of an automated fraud dialler. The App also shows the number's
approximate region, derived from its area code using a table bundled inside the
App itself: no external service is queried to find out who a number
belongs to. All of this analysis happens entirely on your
device and its result is never uploaded to our servers.
- Alert history: records of alerts sent (timestamps, notification tier, and
call duration) stored in Firebase Cloud Firestore.
- Device and usage data: device model, operating system version, app version,
crash logs, and analytics data collected through Firebase Crashlytics and Firebase Analytics.
- In-app activity: which screens of the App you open, and your interaction
with the educational videos (when a video starts, how much of it you watch, and whether you
finish it, together with the episode title and season). This tells us which content and
sections are actually useful so we can improve them. We also measure the steps of
subscribing: whether you reach the plans screen, which plan you choose, and whether you open,
close, or complete the Google Play payment, so we know at which step people stop. It is usage
measurement only — we do not record audio, video, or anything you type, and we never receive
your card or payment details.
- Reminder data (kept on your phone only): the App stores the date you last
opened it and which reminders it has already shown you, so it does not repeat them. This
lets it tell you about a new episode, the end of your free trial, call blocking still
being switched off, the App having lost permissions it needs to protect you, trusted
contacts still not chosen, or a stretch of time without opening the App. This information
never leaves your device: it is not uploaded to our servers and is not
shared with anyone. You can turn these reminders off at any time from your phone's
notification settings, without affecting call alerts.
- Blocked numbers (kept on your phone only): the list of numbers you block
and how many times each one tried to call you. It is stored only on your device, is not
uploaded to our servers, and is erased if you uninstall the App.
2.3 Information from Third-Party Services
- Firebase services: authentication tokens, anonymized analytics identifiers,
and push notification tokens (FCM).
2.4 Promotions and Referrals
If you come to Gott SafeCall through a promoter's recommendation, either
in person or on social media, we may collect, always with your consent:
- The code of the promoter who referred you.
- Your name.
- The phone number of the device where the App will be installed, and who it is for
(yourself or a family member).
- Your email address, only if you choose to provide it.
When the promoter uses a form, this information is filled in by you or
by the promoter with you present. We never ask for passwords, verification codes, payment
details, or the contacts in your address book.
When you install the App from a promotion link, Google Play tells us the
label of that link (for example, the promoter's or the campaign's name). We store only that
label, alongside your account and in the App's usage statistics, so we know how many people
arrived through each promoter or campaign. It does not identify who referred you to the App,
and it is not shared with third parties.
2.5 Advertising and Measurement
To learn which ads bring new installs we use the Meta (Facebook) SDK. When
you install and when you open the App, Meta receives those two events along with the
advertising identifier Android assigns to your phone (which you can delete or reset under
Settings › Google › Ads) and technical device data: model, system version,
language, time zone, carrier and IP address. Meta processes that data under its own
policies.
We do not send Meta your name, your phone number, your
trusted contacts, your call log, or your subscriptions or payments.
You can turn this measurement off at any time, without leaving the App, in
Settings › Advanced › "Help improve our ads". Turning it off
does not limit any App feature.
3. How We Use Your Information
We use the collected information for the following
purposes:
- Core functionality: detecting incoming calls from unknown numbers, sending
escalating alert notifications via WhatsApp to your designated emergency contacts, and
letting you block or unblock suspicious numbers.
- Account management: creating, authenticating, and maintaining your user
account.
- Service improvement: analyzing usage patterns, screen and video activity,
age ranges, crash reports and cancellation feedback to improve the App's performance,
reliability, and user experience. All of this is reviewed in aggregate and is never used to
contact you or to make automated decisions about you.
- Age verification: confirming that you meet the minimum age of 18 required
by our Terms of Service.
- Communication: sending you important service-related notices, such as
security alerts, updates, and changes to these policies.
- Subscription management: processing payments, verifying your purchase
server-side, keeping your subscription status up to date, and — when you request it from
within the App — submitting the cancellation to Google Play on your behalf.
- Legal compliance: fulfilling legal obligations and responding to lawful
requests from authorities.
- Promotion tracking: matching the number you provided against the accounts
registered in the App to find out whether the referral led to a registration and a
subscription, and to calculate the promoter's payment. If you gave us your email, we may
contact you to help you set up the App. We do not use this data for advertising or to send
you offers.
4. Legal Basis for Processing
We process your personal data based on the following
legal grounds:
- Consent: you provide explicit consent when you accept these terms and grant
device permissions during the onboarding process.
- Contractual necessity: processing is necessary to deliver the service you
subscribed to.
- Legitimate interest: we have a legitimate interest in improving our services
and ensuring application stability.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We
share information only with the following third-party service providers that are necessary to
deliver our service:
- Google / Firebase: authentication (phone OTP), cloud database (Firestore),
push notifications (FCM), analytics, and crash reporting (Crashlytics).
- WhatsApp Business API (Meta): to send alert notifications to your emergency
contacts via WhatsApp. Phone numbers of your emergency contacts are transmitted to Meta's
servers solely for message delivery. No call content or audio is shared.
- Google Play Billing & Google Play Developer API: to process
subscription payments, to verify your purchase from our servers, and to cancel your
subscription when you request it inside the App. For these operations we send your purchase
token and product identifier to Google; we never receive or store your card or payment
details.
- Bunny CDN: to deliver educational video content within the App.
- Google Forms and Google Sheets: responses to promotion forms are stored
by Google.
- Meta (advertising measurement): the event that you installed or opened the
App, along with your phone's advertising identifier and technical data, to measure our
ads. You can turn it
off under Settings › Advanced (see 2.5).
- Promoters: a promoter only receives the number of verified referrals
credited to them for payment. They do not receive your subscription status, your payments,
or any data about your use of the App.
Each third-party provider operates under their own privacy policies. We
recommend reviewing the privacy policies of Google and WhatsApp (Meta).
6. Data Storage & Security
Your data is stored in Google Firebase Cloud Firestore
servers. We implement industry-standard security measures to protect your personal data,
including:
- Encryption in transit (TLS/SSL) and at rest on Firebase servers.
- On-device encryption: sensitive personal data (name, phone number, and
emergency contact information) is encrypted on your device using AES-256-GCM backed by the
Android Keystore before being written to local storage.
- Firebase Security Rules to restrict unauthorized database access.
- Firebase Authentication to verify user identity.
- Firebase App Check to verify the integrity of requests from the App.
- Minimal data collection principle — we only collect what is strictly necessary.
Despite our efforts, no method of electronic storage or transmission is
100% secure. We cannot guarantee absolute security of your data.
7. Data Retention
We retain your personal data for as long as your
account is active or as needed to provide you with the service. Specifically:
- Account data: retained until you delete your account.
- Phone fingerprint for the free trial: kept for up to 24 months from the
start of the trial, even if you delete your account, and then deleted automatically.
- Alert history: retained for up to 12 months for service improvement and
user reference, then automatically deleted.
- Analytics and crash data: retained according to Firebase's default retention
policies (up to 14 months for analytics).
- Cancellation feedback: retained for up to 24 months for product analysis,
then deleted or anonymized.
- Year of birth: retained with your account record until you delete your
account. The derived age range held in analytics follows Firebase's retention policy.
- Promotion data: retained for up to 12 months after the related promotion
ends, for payment inquiries, and then deleted. You may ask us to delete it sooner under your
ARCO rights.
When you delete your account, we will delete or anonymize your personal
data within 30 days, unless retention is required by law, except for the phone fingerprint for the free trial described above.
8. Your Rights (ARCO Rights)
Under Mexican data protection law (LFPDPPP) and, where
applicable, the GDPR, you have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Cancellation (Deletion): request deletion of your personal data.
- Opposition: object to the processing of your data for specific purposes.
- Portability: request your data in a structured, machine-readable format
(where applicable under GDPR).
- Withdrawal of consent: withdraw your consent at any time without affecting
the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at emiliano.aguilar@gottlatam.com. We will respond to your request
within 20 business days as required by Mexican law.
9. Children's Privacy
Gott SafeCall is not intended for use by children under
the age of 18. We do not knowingly collect personal data from minors. If we become aware that a
child under 18 has provided us with personal information, we will take steps to delete such
data promptly. If you believe a minor has provided us with personal data, please contact us at
emiliano.aguilar@gottlatam.com.
10. International Data Transfers
Your data may be processed and stored on servers
located outside of Mexico (including Google Cloud servers in the United States). When data is
transferred internationally, we ensure that appropriate safeguards are in place, including
compliance with applicable data protection regulations and the use of service providers that
adhere to recognized privacy frameworks.
11. Cookies & Tracking
The Gott SafeCall mobile application does not use
browser cookies. However, Firebase Analytics and Crashlytics may use device identifiers and
anonymous tracking technologies to collect usage and performance data — including which screens
you open, your activity with the educational videos, and your age range. This data is used to
measure and improve the App; it is not used for advertising and is not sold or shared with
advertisers. You can opt out of Firebase Analytics data collection through your device
settings.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We
will notify you of significant changes through the App or via email. The "Last updated" date at
the top of this page indicates when the policy was last revised. Your continued use of Gott
SafeCall after changes are posted constitutes your acceptance of the updated Privacy Policy.
13. Governing Language
This Privacy Policy is published in English and in
Spanish. The English version is the governing version. The Spanish text is
provided as a courtesy translation for our users in Mexico; in the event of any discrepancy,
ambiguity or conflict between the two versions, this English text prevails.
14. Contact
If you have any questions, concerns, or requests
related to this Privacy Policy or the handling of your personal data, please contact us at: