Privacy Policy

Last updated: May 12, 2026

This Privacy Policy explains how personal data of users of the EndingSmoke service is processed pursuant to Regulation (EU) 2016/679 ("GDPR"). Processing is based on the principles of lawfulness, fairness, transparency, data minimization, and storage limitation.

1. Data Controller

The Data Controller is DGMA, with registered office at Unit 1603, 16th Floor, The L. Plaza, 367-375 Queen's Road Central, Sheung Wan, Hong Kong (HK). For any request relating to the processing of personal data, please write to [email protected].

2. Categories of data collected

As part of providing the EndingSmoke service, the following categories of data are collected:

  • Account data: name, email address, password (stored in hashed form), preferred language. If registration occurs via Google, also the associated Google identifier.
  • Onboarding data: quit date (or planned quit date), cigarettes per day, pack price, brand, reasons for quitting, prior attempts, motivation level.
  • In-app behavioral data: logged cravings (intensity, triggers, outcome), slip-ups, mood check-ins, milestones reached, savings goals created and achieved, push notification subscriptions.
  • Technical and navigation data: IP address (anonymized where possible), user agent, session identifiers, UTM/click ID parameters captured at first visit to measure acquisition campaign effectiveness (consent-based only).

3. Processing methods and purposes

Processing is carried out using automated computer and electronic tools with technical and organizational measures appropriate to prevent unauthorized access, loss, or alteration of data. Purposes: (i) delivering service features (counters, milestones, craving and goal management); (ii) user identity verification and account management; (iii) sending transactional communications (email verification, password recovery, subscription confirmations); (iv) product improvement through aggregate analysis; (v) compliance with accounting and tax obligations for paid subscriptions.

4. Legal basis for processing

  • Performance of a contract and pre-contractual measures — art. 6, par. 1, lett. b) GDPR
  • Explicit consent of the data subject (for analytics and marketing cookies) — art. 6, par. 1, lett. a) GDPR
  • Legitimate interest of the Controller in service improvement and security — art. 6, par. 1, lett. f) GDPR
  • Compliance with legal obligations (e.g. tax requirements for transactions) — art. 6, par. 1, lett. c) GDPR

5. Disclosure to third parties and data processors

Data may be disclosed to the following parties, who act as data processors under Article 28 GDPR pursuant to specific agreements:

  • Stripe Payments Europe Ltd (Irlanda) — payment processing for premium subscriptions. No card details are stored on our systems.
  • Postmark (ActiveCampaign Inc.) (USA) — sending of transactional emails (welcome, account verification, password reset, administrative communications). Transfer based on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
  • Google Ireland Ltd — authentication via Google account ("Sign in with Google"), activated only at the user's choice.
  • Google Ireland Ltd — aggregate and anonymous analysis of service usage via Google Analytics 4 and Google Tag Manager (consent-based only).
  • Meta Platforms Ireland Ltd — measurement of advertising campaigns on Facebook/Instagram via Meta Pixel and Conversion API (consent-based only).

6. Cookies and tracking tools

To improve the service and measure acquisition campaign effectiveness, we use the following third-party tools — all conditional on your prior consent:

  • Google Tag Manager (Google Ireland Ltd) — container that orchestrates the scripts below.
  • Google Analytics 4 (Google Ireland Ltd) — aggregate usage statistics: page views, events, retention. IP anonymized.
  • Meta Pixel and Conversion API (Meta Platforms Ireland Ltd) — advertising campaign measurement and remarketing.
  • Google Ads Conversion Tracking (Google Ireland Ltd) — measurement of advertising campaign conversions.

You can review or withdraw consent at any time here: .

7. Extra-EU data transfers

Personal data is hosted on servers located within the European Economic Area (EEA). Some external processors (in particular Postmark, Meta, and Google services) may process data outside the EEA; in such cases, transfers occur exclusively on the basis of Standard Contractual Clauses approved by the European Commission and/or within the framework of the EU-US Data Privacy Framework, in compliance with Articles 44-49 GDPR.

8. Retention period

Account and behavioral data are retained for the entire duration of the user account. Upon a deletion request, the account is immediately deactivated and data is retained for a further 30 days in read-only mode ("grace period") to allow reactivation; at the end of this period, data is permanently deleted. Invoice and payment data are retained for 10 years as required by Italian law. Aggregate marketing campaign data is retained in anonymous form.

9. Your rights

As a data subject, you have the right at any time to exercise the rights provided for by Articles 15-22 GDPR: access to personal data, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing, and withdrawal of consent. You may exercise these rights directly from the app's Profile section, or by writing to [email protected]. The Controller will respond within 30 days of receipt.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) pursuant to Article 77 GDPR, if you believe that the processing of your personal data violates the Regulation.

10. Changes to this policy

The Controller reserves the right to modify this policy at any time, notifying users through the service. Please review this page regularly. The date of last update is shown at the top.

11. Contact

For questions about this policy or to exercise your rights, write to [email protected].