Yumo Yumo Privacy Notice

Last Updated: April 20, 2026

This legal document is provided in English only.

This Privacy Notice explains which personal data Yumo Yumo collects, why we process it, who we share it with, and how anonymized or aggregated insight products may be created from eligible datasets.

Data Controller

Yumo Yumo Inc. is the company responsible for Yumo Yumo. Registered mailing address: 8 The Green Suite B, Dover, DE 19901, United States. Phone: +1 302-719-1468. Email: info@yumoyumo.com.

1. Data We Collect

Depending on how you use the Services, we may collect your email address, username, password hash, country, birth date, receipt data, wallet address, support messages, session logs, IP address, device or browser information, captcha verification results, and email verification or password reset records.

2. Why We Process Data

We process personal data to create and secure your account, verify your email, reset your password, provide receipt and spending analysis, support rewards features, respond to support requests, prevent abuse and fraud, keep the platform secure, and comply with legal obligations.

3. Anonymized and Aggregated Insight Products

We may transform eligible datasets into anonymized or aggregated outputs by removing or reducing data points that directly identify a person. These outputs may be used to generate statistics, benchmarks, market insights, analytics, reports, and product intelligence. Where those outputs no longer identify a specific person, they may be shared, licensed, commercialized, or offered to partners or customers.

4. Legal Basis

Where applicable, we process personal data because it is necessary to perform our contract with you, to protect legitimate interests such as security and fraud prevention, to comply with legal obligations, or because you have given consent for optional processing. Not every processing activity depends on consent.

5. Service Providers and Recipients

We may use infrastructure, hosting, database, email, security, analytics, AI, fraud prevention, wallet, blockchain, and support vendors to operate the Services. Current or planned vendors may include Vercel, Neon, Vercel Blob, Cloudflare Turnstile, Resend, Google APIs including Gemini, Vision, Maps and Places, OpenAI, Axiom, Solana infrastructure, wallet providers, and similar service providers. We may also disclose data to regulators, courts, or public authorities where legally required.

6. International Transfers

Because some of our vendors or servers may operate internationally, your data may be processed in countries outside your own jurisdiction. Where required, we aim to use appropriate safeguards such as data processing agreements, standard contractual clauses, transfer impact assessments, access controls, encryption, and data minimization.

7. Retention

We keep personal data only for as long as needed for the purposes described in this Notice, for account security, for service continuity, or to meet legal, tax, audit, and dispute-resolution obligations. Receipt image files are designed to be deleted from blob storage after approximately 48 hours, while receipt metadata, reward ledgers, fraud records, consent logs, and account records may be retained longer where needed for product integrity, legal compliance, dispute handling, and abuse prevention.

8. Your Rights

Depending on where you live, you may have rights to request access to your data, ask for correction or deletion, object to certain processing, request restriction, ask for portability, withdraw consent for optional processing where consent was used, appeal or complain to a privacy authority, or opt out of sale, sharing, or targeted advertising where those rights apply. To make a request, email info@yumoyumo.com. We may need to verify your identity before fulfilling the request. In-app automated account deletion and export are not available in this first version; requests are handled through the email workflow.

9. Security

We use reasonable technical and organizational measures to protect data, including access controls, hashed passwords, and operational security practices. No system can guarantee absolute security.

10. Age Restriction

The Services are intended for adults. You must be at least 18 years old, or the age of legal majority in your jurisdiction, to create an account.

11. Cookies and Similar Technologies

We use strictly necessary cookies and similar local storage technologies for security, authentication, abuse prevention, language preferences, and core site functionality. Where optional cookies or similar technologies are used for functional preferences or analytics, we ask for your choice before enabling them. You may reject optional cookies and continue using the Services. You can reopen Cookie Preferences from the site footer or app settings. If your browser sends a Global Privacy Control signal, we treat it as a request to keep analytics and targeted tracking off where applicable.

12. Sale, Sharing, and Targeted Advertising

We do not sell personal information. We do not intentionally share personal information for cross-context behavioral advertising or targeted advertising in the current product setup. If this changes, we will update this Notice, provide the legally required opt-out controls, and honor applicable Global Privacy Control signals.

13. Privacy Request Process

Send privacy requests to info@yumoyumo.com from the email address attached to your account when possible. Include the request type, your username, and enough information for us to verify the account. We will record the request, verify identity, review legal exceptions, respond within the timeline required by applicable law, and explain if we cannot complete a request in full.

14. Updates

We may update this Privacy Notice from time to time. Material updates may be announced through the website, app, or another appropriate digital channel.

15. Contact

For privacy or data protection questions, contact us at info@yumoyumo.com. You may also contact Yumo Yumo Inc. by phone at +1 302-719-1468 or by mail at 8 The Green Suite B, Dover, DE 19901, United States.

Data categories and purposes

Category
Account data
Purpose / legal basis
Create accounts, authenticate users, provide service, security, legal compliance
Typical recipients
Hosting, database, email, security providers
Category
Receipt data and metadata
Purpose / legal basis
Analyze receipts, generate insights, detect fraud, calculate rewards
Typical recipients
Hosting, blob storage, AI/OCR providers, database providers
Category
Wallet and reward data
Purpose / legal basis
Support utility rewards, eligibility, blockchain-related features when enabled
Typical recipients
Wallet providers, blockchain infrastructure, analytics and fraud systems
Category
Support and request data
Purpose / legal basis
Respond to support, privacy, legal, and security requests
Typical recipients
Email, support, hosting, database providers
Category
Cookie and device data
Purpose / legal basis
Security, language, preferences, optional analytics where allowed
Typical recipients
Hosting, analytics, security providers

Retention schedule

Data type
Receipt images
Default retention approach
Approximately 48 hours after upload
Notes
May be kept longer only if required for abuse, legal, or dispute handling
Data type
Receipt metadata and analysis outputs
Default retention approach
For account life plus legal/audit needs
Notes
Used for insights, reward records, fraud prevention, and account history
Data type
Account and consent records
Default retention approach
For account life plus legal limitation periods
Notes
Includes Terms, Privacy, cookie, and marketing consent records
Data type
Security, fraud, and abuse logs
Default retention approach
As needed for platform integrity
Notes
May be retained after account closure where legally permitted
Data type
Waitlist and marketing records
Default retention approach
Until unsubscribe, deletion request, or business need ends
Notes
Suppression records may be retained to honor unsubscribe requests

Subprocessors and transfers

Vendor / category
Vercel / Vercel Blob
Role
Hosting, deployment, blob storage
Transfer safeguard
Vendor DPA, technical safeguards, transfer safeguards where required
Vendor / category
Neon
Role
PostgreSQL database
Transfer safeguard
Vendor DPA, access controls, transfer safeguards where required
Vendor / category
Cloudflare Turnstile
Role
Captcha and abuse prevention
Transfer safeguard
Vendor terms/DPA, security purpose limitation
Vendor / category
Resend
Role
Transactional email
Transfer safeguard
Vendor DPA, email delivery controls
Vendor / category
Google APIs, Gemini, Vision, Maps, Places
Role
OCR, AI analysis, maps and place enrichment
Transfer safeguard
Vendor terms/DPA, data minimization, transfer safeguards where required
Vendor / category
OpenAI
Role
AI-assisted analysis where configured
Transfer safeguard
Vendor terms/DPA, data minimization, transfer safeguards where required
Vendor / category
Axiom
Role
Operational logging when enabled
Transfer safeguard
Vendor DPA, log minimization
Vendor / category
Wallet and Solana providers
Role
Wallet connection and blockchain infrastructure
Transfer safeguard
Public-chain constraints, user-controlled wallet interactions

This Notice should be read together with the Terms & Conditions and the disclosures shown during signup.

Last Updated: April 20, 2026