Privacy Policy

This Privacy Policy for Neverin, describes how and why we might collect, store, use, and/or share your information when you use our services.

Privacy Policy is available in Croatian and English.

Last updated:
Effective:

This Privacy Policy for Neverin, vl. Alen Šterpin ("Neverin", "we", "us", or "our"), describes how and why we collect, store, use, and/or share ("process") your personal data when you use our services ("Services"), including when you:

  • visit our website at https://www.neverin.hr or any of our pages that link to this Policy;
  • download and use our mobile application (Neverin);
  • use Neverin — a web and mobile application that provides weather forecasts, real-time meteorological data, and related visualisations, with free and subscription features;
  • engage with us in other related ways, such as marketing.

The Services include a free tier (available to everyone without registration) and a Premium tier (available to registered users with an active paid subscription). This Policy applies to both tiers and forms an integral part of our Terms of Use.

The controller of your personal data is Neverin, vl. Alen Šterpin. We are not required to appoint a data protection officer; for any privacy questions contact us at [email protected]. If you do not agree with this Policy, please do not use the Services.

1. Information we collect

Information you provide to us

We collect personal data that you voluntarily provide when you register, contact us, or use certain features. Depending on how you use the Services, this may include:

  • email address;
  • account credentials (e.g., password hash);
  • contact and authentication data.

Sensitive data. We do not process special categories of personal data (so-called sensitive data).

Payment data. Subscription payments are processed and stored solely by Paddle (our Merchant of Record). Neverin does not collect or store your card details (card number or security code). Paddle's privacy notice is available at paddle.com/legal/privacy.

Application data. If you use the App, with your permission we may process:

  • Location. With your consent, we may use your device location to provide location-based features (e.g., local forecasts). You can disable this permission at any time in your device settings.
  • Push notifications. With your permission, we may send you push notifications related to your account or features. You can turn them off in your device settings.
  • In-app analytics and diagnostics. In the mobile App we use Google Firebase (analytics, crash reporting, and push notifications). Firebase may collect device identifiers and app usage data for usage measurement, troubleshooting, and notifications. You can limit some of this in your device settings.

Information collected automatically

When you visit or use the Services, we automatically collect certain technical data that on its own does not usually reveal your identity. This includes:

  • Log and usage data. IP address, browser type and settings, date and time of access, pages viewed and features used, and diagnostic data (e.g., error reports).
  • Device data. Device and browser type, operating system, and basic configuration data.
  • Location. Approximate location based on IP address; precise location only if you have enabled it in the App.

We use this data primarily for the security and proper operation of the Services, troubleshooting, and internal analytics. Some of it is collected through cookies and similar technologies — see our Cookie Policy.

2. How we process your information

We process your personal data for the following purposes:

  • Account management. So you can create an account, log in, and use it.
  • Providing the Services. To deliver the free and Premium features you request.
  • Subscriptions and payments. To manage subscriptions and process billing via Paddle and to provide access to Premium features.
  • Support. To respond to your inquiries and resolve any issues.
  • Administrative notices. To inform you about changes to the Services, terms, and policies.
  • Security and abuse prevention. To protect the Services, users, and infrastructure, detect technical issues, and prevent fraud and unauthorised access.
  • Improving the Services. To analyse how the Services are used so we can improve them.

3. Legal bases for processing

Under the General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:

  • Consent. Where you have given us consent for a specific purpose (e.g., access to device location or push notifications). You can withdraw consent at any time.
  • Performance of a contract. Where processing is necessary to provide the Services you have requested (e.g., managing your account and subscription).
  • Legitimate interests. Where reasonably necessary for our legitimate interests that do not override your rights and freedoms — for example, the security and reliable operation of the Services, fraud prevention, and analysing and improving quality.
  • Legal obligations. Where we must comply with the law (e.g., accounting and tax obligations or requests from competent authorities).

4. Sharing your information with third parties

We may share your data with service providers (processors) that perform certain tasks for us and need access to the data for that purpose. We have contracts with them requiring that they process the data only on our instructions, protect it, and not use it for their own purposes.

The categories of recipients with whom we may share data are:

  • hosting and infrastructure providers (Hetzner, servers in Germany);
  • payment processing and billing (Paddle as Merchant of Record);
  • email delivery and customer support (Amazon Web Services – AWS, servers in the EU);
  • in-app analytics, diagnostics, and push notifications (Google Firebase);
  • performance analytics (Cloudflare Web Analytics, cookieless).

We may also transfer your data as part of a business transaction (e.g., a merger, acquisition, or sale of part of the business), with appropriate protection and in accordance with this Policy.

5. Cookies and tracking technologies

We use only cookies and similar technologies necessary for the basic functionality and security of the Services (for example, for login, sessions, and saving your settings). Such cookies do not require your consent, so we do not display a separate cookie consent pop-up. Details are in our Cookie Policy.

For audience measurement we use Cloudflare Web Analytics, which works without cookies, does not track you across other websites, and does not create an individual profile of you. We do not use third-party advertising or marketing cookies.

6. International data transfers

Our primary servers are located in the European Union (Croatia and Germany), and we aim to process data within the European Economic Area (EEA). If any of our service providers (for example, Google Firebase for the mobile App) processes data outside the EEA, we rely on appropriate safeguards provided for under the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs). Details of these measures are available on request.

7. Data retention period

We keep personal data only for as long as necessary for the purposes described in this Policy or as required by law. Indicative periods:

  • Account data: while the account is active; after deletion or termination it is deleted without delay, unless retention is required by law.
  • Payment and billing records: as required by tax and accounting law (typically up to 7 years).
  • Logs and analytics: typically up to 1 year.
  • Cookies: as stated in our Cookie Policy.

We do not keep data in backups longer than is technically necessary for system recovery and security. When data is no longer needed, we delete or anonymise it.

8. Data security

We implement reasonable technical and organisational measures to protect the personal data we process. However, no transmission over the internet or method of storage is 100% secure, so we cannot guarantee absolute security. Please access the Services within a secure environment.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the supervisory authority (AZOP) within 72 hours and, where the risk is high, inform affected users without undue delay.

9. Children's information

The Services are not intended for persons under 16, and we do not knowingly collect their data. By using the Services, you confirm that you are at least 16 years old or that you are a parent or guardian giving consent for such use. If we learn that we have collected data from a person under 16 without appropriate consent, we will terminate the account and delete the data without delay. If you suspect such a case, contact us at [email protected].

10. Your data protection rights

Under the GDPR, you have the following rights regarding your personal data:

  • access to your data and a copy of it;
  • rectification of inaccurate and completion of incomplete data;
  • erasure of data (the "right to be forgotten");
  • restriction of processing;
  • data portability;
  • objection to processing based on legitimate interests or for direct marketing.

To exercise any right, contact us at [email protected]. We will consider and act on your request in accordance with the law, normally within one month. We may extend this period by a further two months for complex or numerous requests, in which case we will inform you. If you use the Services from outside the EU, you may have additional rights under your local law; in any case, we will handle your request in accordance with applicable law.

Withdrawing consent. Where processing is based on your consent, you may withdraw it at any time; this does not affect the lawfulness of processing before withdrawal.

Direct marketing. You can opt out of marketing messages at any time via the unsubscribe link in the email or by contacting us at [email protected]. We will still send messages necessary for the operation of the Services (e.g., about your account or subscription).

Automated decision-making. We do not carry out automated decision-making that produces legal or similarly significant effects on you. Automatic subscription renewal and billing via Paddle constitute performance of the contract, not such decision-making.

Right to lodge a complaint. If you believe we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Croatia this is the Personal Data Protection Agency (AZOP), azop.hr; if you reside in another EU country, you may contact the supervisory authority there.

You can review and update your account information in your account settings, and request account deletion by contacting us at [email protected]. We may retain certain data where required by law or for legitimate purposes (e.g., fraud prevention or compliance with legal obligations).

11. Third-party websites

The Services may contain links to third-party websites, services, or advertisements that we do not control. We are not responsible for their content or privacy practices, and a link does not mean we endorse them. Data you share with third parties is not covered by this Policy — we recommend reviewing their privacy notices.

12. Changes to this Policy

We may update this Policy from time to time. The latest version is marked with the "Last updated" date at the top. We will notify you of significant changes on the Services or directly. We recommend reviewing it periodically.

13. Contact us

For questions or requests regarding this Policy, contact us by email at [email protected] or by mail at:

  • Neverin, vl. Alen Šterpin
  • Mošćenička ulica 2
  • 10000 Zagreb
  • Croatia