Privacy Policy

Price ur Plastic (PuP)  ·  Mobile app for Android and iOS
Effective 1 August 2026  ·  Last updated 1 August 2026  ·  Version 2.0

01) Summary

The short version, in plain language. The detail is in the sections that follow, and the full policy is what governs.

  • We collect what the App needs to run: your account details, your scan history and points, and the photos taken when a bin or bottle scan is confirmed.
  • We never sell your data, never show ads, and never track you across other apps or websites.
  • Audio and live camera frames are analysed on your device and are never uploaded.
  • Location is used only to centre the map while you’re looking at it. It is not logged against your account.
  • Scan photos may be used to improve bin and bottle recognition. You can opt out of this at any time in Settings, without losing any App features.
  • You can delete your account and all associated data from inside the App, or by emailing us.

02) Who we are

Price ur Plastic (“the App”, “PuP”, “we”, “us”) helps people recycle plastic bottles by scanning recycling bins, scanning bottles, and confirming when a bottle is deposited, in exchange for reward points.

The App is published by V. S. Jerrom Sustainable Waste Management, which is the data controller (or “data fiduciary”) responsible for the personal information described here.

By creating an account or using the App, you agree to this policy. If you don’t agree, please don’t use the App. Where the law requires your consent for a specific activity, we ask for it separately — agreeing to this policy alone is not treated as consent for optional processing such as microphone use or training data.

03) Information we collect

Account information

When you register, we collect your nameemail address, and optionally your mobile number and a profile picture. Your password is handled by Firebase Authentication and is never visible to us in plain text.

Recycling activity

To calculate your points and rewards, we record which bin you scanned, which bottle barcode (if applicable) you scanned, the time of each scan, and your running point and bottle totals.

Photos captured during scans

See Camera & photos — this is a distinct category because some images may be used to improve the App’s detection accuracy, not just to record your activity.

Device & diagnostic information

Like most apps, we automatically receive basic technical data — device model, operating system version, app version, language, coarse region, and crash and error logs — to keep the App working reliably. This comes from Firebase and Google Play services and is used to fix bugs, not to build a profile of you.

Identifiers we use

We use a Firebase user ID (to link your data to your account), a Firebase installation ID, and — if you allow notifications — a Firebase Cloud Messaging token. We do not collect or use the Android Advertising ID or Apple’s IDFA.

What this looks like on the app store listing

This table mirrors our Google Play Data Safety declaration and Apple App Privacy labels, so you can check them against each other.

Data typeCollectedSharedPurpose
Name, email, phone numberYesNoAccount management
Photos (confirmed scans, profile picture)YesNoApp functionality, detection accuracy
In-app activity (scans, points, rewards)YesNoApp functionality
Crash logs and diagnosticsYesNoReliability and troubleshooting
Approximate locationNo — used on device onlyNoCentring the bin map
AudioNo — analysed on device, never storedNoConfirming an insertion
Live camera framesNo — analysed on device, never storedNoDetecting bins and bottles
Advertising ID / IDFANoNoNot used

04) Camera & photos

Camera access is required for the App’s core function. Before we first use it, the App shows an in-app explanation and asks for the system permission. It is used for three things:

  • Scanning a bin — the camera analyses the live video feed to recognise a recycling bin’s colour and shape. Once confirmed, a single photo is captured.
  • Scanning a bottle — similarly, the camera identifies a bottle before you insert it.
  • Confirming insertion — while you insert the bottle, the camera analyses motion in real time to confirm the action happened. This analysis runs on your device; no video of this step is recorded or uploaded.

Only the still photos captured at confirmed bin and bottle scans are uploaded. They are compressed, stored in Firebase Storage, and linked to your account and — for a bin scan — to that bin’s record.

Please don’t photograph other people. Point the camera at the bin and the bottle. If a scan photo does capture a bystander’s face or a vehicle number plate, tell us and we will delete it. We also remove such images from any training set during review.

The App does not read your photo library. If you set a profile picture, you choose that single image through your device’s system photo picker, and the App receives only the image you selected.

05) Microphone

Microphone access is optional and off until you allow it. If granted, the App listens for a brief, generic sound-level spike at the moment of bottle insertion, as a second confirmation signal alongside the camera. This audio is analysed instantly on your device — we do not record, store, or transmit any audio, and we do not perform speech recognition. If you deny microphone permission, the App works normally using camera detection alone.

06) Location & bin data

Location access is optional. Recycling bin locations (name, coordinates, address) are added by administrators and are not tied to individual users’ movements.

If you allow it, the App uses your device’s approximate location only while the map screen is open, to centre the map on you. We do not collect background location, and this position is not stored or logged against your account. Deny the permission and the map still works — it just opens on a default view.

Bin search uses OpenStreetMap’s Nominatim service. Only the text of your search is sent to it; no account information is attached.

07) How scans help improve detection

The App uses image analysis to recognise bins and bottles and to confirm insertions. To make this more accurate over time, some photos captured during confirmed scans may be kept as training data, reviewed by an administrator, and used to retrain the detection model.

  • This is optional. You can turn it off in Settings → Privacy → Help improve detection at any time. Every App feature keeps working if you do.
  • Before an image enters a training set, it is separated from your name and email and labelled with a random identifier.
  • Training images are never shared publicly, sold, or given to anyone outside the team operating the App.
  • They are used solely to improve bin and bottle recognition — never for advertising, profiling, facial recognition, or identifying people.
  • You can ask us to remove images you have already contributed. See Your choices & rights.

The model makes no decisions about you as a person. It only judges whether a bin, a bottle, or an insertion is present in the frame, and a failed detection simply means the scan doesn’t count — you can retry or contact us.

08) How we use information

We use it to…Which data
Create and manage your accountName, email, mobile, profile picture
Track your recycling activity and calculate points and rewardsScan records, bottle counts
Detect bins, bottles, and insertions accuratelyCamera frames (on device), confirmed scan photos
Improve detection accuracy over timeTraining photos, if you’ve opted in
Show you nearby binsApproximate device location, bin locations
Send you activity and reward notificationsAccount ID, notification token, preferences
Diagnose and fix technical problemsDevice and app diagnostics, crash logs
Prevent fraudulent or duplicated scansScan timestamps, bin ID, account ID
Meet legal obligations and respond to lawful requestsWhichever data the obligation covers

We do not use your data for automated decisions with legal or similarly significant effects, and we do not build advertising or behavioural profiles.

09) Legal bases for processing

If you are in the EEA, the UK, or another region with equivalent law, these are the legal grounds we rely on.

ActivityLegal basis
Creating your account, recording scans, awarding pointsPerformance of a contract with you
Camera use for scanning and confirmationPerformance of a contract (the App’s core function)
Microphone, location, notifications, training-data useYour consent, withdrawable at any time
Crash reporting, security, fraud preventionOur legitimate interest in a working, honest service
Keeping records the law requires us to keepLegal obligation

Withdrawing consent doesn’t affect processing that already happened before you withdrew it.

10) Sharing & third parties

We do not sell your personal data, we do not share it for advertising, and we do not trade it. It reaches only the service providers below, each acting on our instructions.

ServiceWhat it handlesPolicy
Firebase Authentication (Google)Sign-in, passwordsFirebase privacy
Cloud Firestore / Realtime Database (Google)Account, scan, and points recordsFirebase privacy
Firebase Storage (Google)Scan photos, profile picturesFirebase privacy
Firebase Crashlytics (Google)Crash and error reportsFirebase privacy
Firebase Cloud Messaging (Google)Push notificationsGoogle privacy
OpenStreetMap / NominatimMap tiles and place searchOSMF privacy

We may also disclose information where we must: to comply with a valid legal obligation or court order, to enforce our terms, to investigate fraud, or to protect the rights and safety of users and the public. Where the law allows, we’ll tell you first.

If the App is ever transferred to another organisation, your data may move with it. You’ll be notified in the App before that happens and this policy will continue to apply until you’re given a new one.

11) No ads, no cross-app tracking

The App contains no advertising SDKs and no third-party analytics beyond Firebase. We do not track you across other companies’ apps or websites, so the App does not present Apple’s App Tracking Transparency prompt and does not request the advertising identifier on either platform. There is nothing here to opt out of, because we never opt you in.

12) Security & international transfers

Your data is stored on Google Firebase infrastructure and protected by:

  • Encryption in transit (HTTPS/TLS) and at rest, applied by Google Cloud.
  • Firebase Security Rules, so a signed-in account can read and write only its own records.
  • Restricted admin access — only authorised administrators can view training data, manage bins, or open user records, and their accounts are protected by strong, unique credentials.
  • Least-privilege access, reviewed when anyone joins or leaves the project.

Our Firebase project stores data in name your Firebase region, e.g. asia-south1 (Mumbai). Google operates a global network, so your information may be processed in other countries whose privacy laws differ from your own. Where required, these transfers rely on Google’s Standard Contractual Clauses and equivalent safeguards under Google’s Data Processing Addendum.

No method of transmission or storage is completely secure, but we take reasonable, industry-standard steps to protect your information. Please use a strong, unique password and keep your device locked.

13) If there’s a data breach

If a security incident affects your personal data, we will investigate immediately, take steps to contain it, and notify the relevant supervisory authority within the time the law allows — 72 hours of becoming aware, under GDPR. Where the breach is likely to put you at risk, we will notify you directly by email and in the App, describing what happened, what data was involved, and what you can do.

14) Data retention

We keep data only as long as it serves the purpose it was collected for.

DataHow long we keep it
Account profile (name, email, mobile, picture)While your account is active; deleted within 14 days of account deletion
Scan records and points historyWhile your account is active; deleted or anonymised within 14 days of account deletion
Scan photos linked to your activity12 months, or until you delete your account — whichever comes first
Training images (if you opted in)Kept in de-identified form until the model is retired or you ask us to remove them
Crash logs and diagnosticsUp to 90 days
Anonymised, aggregated statistics (e.g. total bottles recycled)Indefinitely — this data can no longer identify you
Records we must keep by law, or for fraud investigationOnly for the period the law or the investigation requires

Inactive accounts are flagged after 24 months. We’ll email you before deleting anything.

15) Your choices & rights

Wherever you live, you can ask us to do the following. Depending on your region, some of these are legal rights.

  • Access the personal data we hold about you
  • Correct inaccurate information — name, email, mobile, and picture are editable directly in your Profile
  • Delete your account and associated data (see below)
  • Export a machine-readable copy of your data
  • Withdraw consent for camera, microphone, location, or notifications in your device settings, and for training-data use in Settings → Privacy
  • Object to or restrict processing based on our legitimate interests
  • Complain to your local data protection authority

Email app.swmisnow@gmail.com from the address on your account, or use Settings → Privacy → My data in the App. We respond within 30 days, and sooner where the law requires it. We will never charge you for a request or treat you differently for making one. If we can’t act on a request, we’ll explain why.

16) Delete your account and data

In the App: Profile → Settings → Account → Delete account. You’ll be asked to confirm, and the deletion begins immediately.

By email: if you can’t sign in, write to app.swmisnow@gmail.com with the subject “Delete my PuP account” from your registered email address. We’ll verify it’s you and confirm when it’s done.

What gets deleted: your profile, login credentials, scan history, points balance, uploaded scan photos, profile picture, and notification token.

What we keep: anonymised aggregate totals that can no longer identify you, and any record we’re legally required to retain — for example a fraud investigation or a tax record. Training images you contributed are already de-identified; tell us in your request if you want those removed too, and we will.

How long it takes: your account is disabled at once and all associated data is erased from live systems within 14 days. Encrypted backups roll off within 30 days.

Deleting your account forfeits any unredeemed reward points, and this cannot be undone.

17) App permissions

Every permission is requested at the moment it’s needed, with an in-app explanation first. Optional permissions can be denied or revoked later in your device settings without breaking the App.

PermissionRequired?Why
CameraRequiredScan bins and bottles, confirm insertions
MicrophoneOptionalSecond confirmation signal for insertions — processed on device, never recorded
Photos (system picker only)OptionalChoose a profile picture. We see only the image you pick, and we don’t request full library access
Approximate location (while in use)OptionalCentre the bin map. No background location
NotificationsOptionalAlerts about rewards and account activity
Internet / network stateRequiredSync your account, scans, and points

Revoking camera access will stop scanning from working, since that is the App’s core function. To turn permissions on or off: Android — Settings → Apps → Price ur Plastic → Permissions. iOS — Settings → Price ur Plastic.

18) Children’s privacy

The App is not directed at children and we do not knowingly collect personal information from them. You must be at least 13 years old to create an account — or older where your local law sets a higher age, which includes 16 in parts of the EEA and 18 in India, where a parent or legal guardian must give verifiable consent for anyone younger.

We do not serve behavioural advertising to anyone, and we never profile or track children. If you believe a child has given us personal information without the right consent, contact us and we’ll delete the account and its data promptly.

19) Regional notices

EEA and UK (GDPR / UK GDPR)

Our legal bases are listed in section 09. You have the rights in section 15, including data portability and the right to lodge a complaint with your national supervisory authority. Transfers outside your region are covered in section 12.

India (Digital Personal Data Protection Act, 2023)

We act as a Data Fiduciary. We process your data for the lawful purposes described here, with your consent where required, and you may withdraw that consent as easily as you gave it. You can nominate another person to exercise your rights if you die or become incapacitated. Contact our Grievance Officer in section 20; if unsatisfied, you may approach the Data Protection Board of India.

California (CCPA / CPRA)

In the past 12 months we have collected the categories described in section 03 and disclosed none of them for money or for cross-context behavioural advertising. We do not sell or share personal information, including that of anyone under 16, so no “Do Not Sell or Share My Personal Information” link is required. You have the right to know, delete, correct, and to limit use of sensitive information, and we will not discriminate against you for exercising any of them. An authorised agent may act for you with written proof.

Everywhere else

We apply the standards in this policy to all users, regardless of where you live. If your local law gives you more, we’ll honour that too.

20) Grievance officer

In line with India’s Information Technology Rules, 2021 and the DPDP Act, 2023, you can raise a complaint about how we handle your data with:

  • Name: V. S. Jerrom
  • Designation: Developer
  • Email: app.swmisnow@gmail.com
  • Address: Katpagapillaiyar Kovil Road, Urumpirai, Jaffna, Sri Lanka

We acknowledge complaints within 24 hours and resolve them within 15 days of receipt.

21) Changes to this policy

We may update this policy as the App changes. If we make material changes — new data types, new purposes, or new recipients — we’ll update the effective date, notify you in the App, and where the law requires it, ask for your consent again before the change takes effect. Continued use after that means you accept the update.

VersionDateWhat changed
2.01 August 2026Added legal bases, retention schedule, account deletion, breach notification, regional notices, and app-store data disclosures
1.031 July 2026First published

22) Contact us

Questions, requests, or concerns about this policy or your data:

  • Email: app.swmisnow@gmail.com
  • Developer and organisation: V. S. Jerrom Sustainable Waste Management
  • Postal address: Katpagapillaiyar Kovil Road, Urumpirai, Jaffna, Sri Lanka

We aim to reply within 30 days. If you’re not satisfied with our response, you can complain to your local data protection authority.Price ur Plastic — Privacy Policy · Version 2.0 · Last updated 1 August 2026