Privacy Policy
Effective Date: May 26, 2026 Last Updated: May 26, 2026
Data Controller
The controller of your personal data is:
EBARION D.O.O.E.L. North Macedonia Email: info@buketi.mk Website: https://buketi.mk
Introduction
We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how Buketi ("we", "our", "the app") collects, uses, shares, and protects your information when you use our mobile application and website (https://buketi.mk).
We process your data in accordance with the Law on Personal Data Protection of the Republic of North Macedonia (Official Gazette No. 42/2020) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Information We Collect
Information you provide
- Account information: name, email address, phone number, password
- Delivery information: delivery address, recipient name and contact
- Order information: order history, items purchased, payment confirmation
- Communications: messages to our customer support, reviews, feedback
Information collected automatically
- Device information: device model, operating system, app version, language, time zone
- Device identifiers: Advertising Identifier (IDFA on iOS / GAID on Android), used for advertising attribution and analytics
- Usage data: screens viewed, features used, interactions with products, time spent in the app, crash and performance data
- Approximate location: derived from your IP address for delivery zone matching
- Network information: IP address, mobile network type
Information from payment processors
We do not store full payment card data. Payment information is processed directly by our payment providers — Halkbank Macedonia (NestPay/Asseco) — which are PCI-DSS compliant.
2. How We Use Your Information
We process your data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Processing and delivering your orders | Performance of contract |
| Providing customer support | Performance of contract |
| Sending order updates and transactional notifications | Performance of contract |
| Measuring app performance and fixing bugs | Legitimate interest |
| Marketing and advertising (including via Meta) | Consent / Legitimate interest |
| Personalizing your in-app experience | Consent |
| Complying with legal obligations (tax, accounting) | Legal obligation |
| Preventing fraud and abuse | Legitimate interest |
3. Sharing Your Information with Third Parties
We do not sell or rent your personal data. We share data only with:
Service providers
- Couriers and delivery partners — to deliver your order (name, address, phone number)
- Florists in our marketplace — to fulfill your order (delivery details and order contents)
- Payment processors — to process transactions
- Cloud hosting providers — to store and serve app data
Advertising and analytics partners
-
Meta Platforms, Inc. (Facebook/Instagram) — we use the Meta SDK to measure the effectiveness of our advertising campaigns. The following data may be shared with Meta:
- Device advertising identifier (IDFA/GAID)
- App install and activity events
- Purchase events (amount and currency, no card details)
- Custom events such as product views and add-to-cart
Meta processes this data as a separate data controller. Learn more in Meta's Privacy Policy and Meta's Business Tools Terms.
-
PostHog, Inc. — product analytics, funnel tracking, and session replay. We share usage events (page views, clicks, purchases) and a pseudonymous user ID. PostHog acts as our data processor.
Legal disclosures
We may share data when required by law, court order, or to protect our rights and the safety of our users.
4. International Data Transfers
Some of our service providers (including Meta Platforms, Inc.) are located outside North Macedonia, including in the United States. When we transfer your data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
5. Mobile Identifiers and Tracking
iOS (App Tracking Transparency)
On iOS devices, we will ask for your permission before tracking your activity across other companies' apps and websites. You can change this at any time in iOS Settings → Privacy & Security → Tracking → Buketi.
Android (Advertising ID)
On Android, you can reset or opt out of personalized advertising in Settings → Google → Ads.
If you opt out, you will still see ads, but they will be less relevant to you, and we will not be able to measure ad effectiveness for your device.
6. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described in this policy:
- Account data: retained while your account is active, and for 12 months after deletion or last activity
- Order data: retained for 10 years to comply with Macedonian tax and accounting laws
- Analytics and advertising data: retained for up to 24 months
- Customer support messages: retained for 24 months
7. Your Rights
Under Macedonian and EU data protection law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data ("right to be forgotten")
- Restrict how we process your data
- Object to processing based on legitimate interest
- Data portability — receive your data in a structured format
- Withdraw consent at any time
- Lodge a complaint with the Agency for Personal Data Protection of North Macedonia (AZLP) at https://azlp.mk
How to request data deletion
To request deletion of your account and all associated personal data:
- Open the Buketi app → Profile → Settings → Delete Account, or
- Email info@buketi.mk with the subject "Data Deletion Request" from the email address associated with your account
We will process your request within 30 days and confirm completion by email. Some data may be retained where required by law (e.g. order records for tax purposes).
8. Children's Privacy
Buketi is not intended for children under 16. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us at info@buketi.mk and we will delete it.
9. Security
We use industry-standard security measures including encryption in transit (HTTPS/TLS), secure authentication, and access controls to protect your data. However, no system is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent changes. Material changes will be communicated via the app or by email.
11. Contact Us
For questions about this Privacy Policy or to exercise your data protection rights:
EBARION D.O.O.E.L. Email: info@buketi.mk Website: https://buketi.mk
Data Protection Authority (for complaints): Agency for Personal Data Protection of North Macedonia (AZLP) https://azlp.mk