NB! Pushwoosh does not collect sensitive or personally identifiable information (PII) about end users — no email address, phone number, name, credit card or financial information — unless that information is passed to us directly by the Pushwoosh customer. We do not collect cookies, IMEI or MAC addresses.
We do not share, distribute, market or advertise to any third parties, and Pushwoosh does not communicate with end users directly. These are your customers; Pushwoosh provides the platform so that our clients can communicate with their end users.
What we actually collect
Device data
- Geolocation information — city and country derived from the latest IP address a device was online from.
- Precise location data — only if the customer implemented location tracking in the app and the end user allowed location access (Geofencing).
- iOS IDFV (Identifier for Vendor) — used as the device HWID to route pushes between several iOS apps of the same vendor when sending to an Application Group.
We also collect and store:
- Device model;
- Device language;
- OS version;
- Application version;
- Device time zone;
- iOS bundle identifier and Android package name (to verify the push configuration);
- Browser — for platform recognition and as the Device Model default Tag value, for later targeting by the Controller;
- Any other data points collected by the SDK on behalf of the customer (custom Tags and events, and communication identifiers such as email address or phone number when the customer registers them for the Email, SMS or WhatsApp channels).
We use GeoIP for geo targeting (IP address), but the IP address itself is not stored on our side.
Where is the data originally received/created? (process and place)
Device data is generated on the user's device after the Pushwoosh SDK is initialized. It is then passed to Pushwoosh servers for further processing in accordance with the needs of the Pushwoosh customer (Controller).
Is explicit consent given by a customer? How aware is the customer of processing this data?
It depends on the implementation of your apps. Your developers may implement consent and data deletion mechanisms themselves. Our SDK also includes functionality that allows you to:
- unsubscribe/subscribe a device from all communication channels (pushes, in-app messages, etc.);
- remove all device-related data from Pushwoosh;
- once the data is removed, the Pushwoosh SDK is disabled completely, so no information is passed to our backend.
See also: Data collected by Pushwoosh.
Who is the owner (Controller) of the data?
A Pushwoosh customer is the Controller of the data.
Who is the Processor of the data?
Pushwoosh is the Processor of the data.
How do you process the data? Is the data needed on the individual level, or aggregated?
All the types of data described above are processed for:
- sending broadcast push notifications (aggregated level);
- segmenting users by sets of Tag conditions (defined by the Controller);
- sending transactional push notifications (individual level);
- sending timezone-sensitive notifications (based on the device time zone).
It is up to the Data Controller to decide whether the data is needed at the individual or aggregated level.
Where is the data stored?
Pushwoosh operates its own data center facilities in Nuremberg, Germany and in Washington DC, USA; secondary backup location is in Frankfurt, Germany. Customers who require their data to remain within the EU are hosted in the German facilities. If you have a data-residency requirement, please confirm your account's region with our support team.
Who has access to the data?
The Data Controller (data owner) has access to the data. The Processor performs only those operations with the data that are stated in the executed agreement.
Comments
0 comments
Please sign in to leave a comment.