Privacy Policy

Privacy Policy

This privacy policy is intended to provide all the information on the processing of personal data carried out by Iumob S.r.l. when the User browses, registers, and uses the services offered on www.yooppe.com or on the Yooppe App.

Please note that, for Users residing in the United States, the use of Yooppe’s Services is available exclusively through the App.

If you are a California resident, please review our California Privacy Policy, which supplements this Privacy Policy.
 
If you reside in Washington State or Nevada, you may review our Consumer Health Data Privacy Policy, which supplements this Privacy Policy.
 
If you reside in Colorado, you may review our Colorado Safety Policy Information, which supplements this Privacy Policy.
 
If you reside in Indiana, Maryland, Nebraska, New Jersey, Texas, Tennessee, Virginia, Florida, or North Carolina you can consult our Privacy Policy for Users Residing in Other U.S. States, which supplements this Privacy Policy.

1. INTRODUCTION - WHO ARE WE?
Iumob Srl, with registered office in Milan - Via Comelico, 3, 20135, Tax Code/VAT No. 07048770965, registered within the Company Register of Milan under No. MI-1931950 (hereinafter, the “Controller”), owner of the website www.yooppe.com (hereinafter, the “Website”) and the Yooppe application (hereinafter, the “App”), as Controller of the personal data of the users who browse the Website and the App (hereinafter, the “Users”) provides the following privacy policy pursuant to Article 13 of EU Regulation 2016/679 dated 27 April 2016 (hereinafter, “GDPR”) and, for Users in the United Kingdom, pursuant to Article 13 of the UK General Data Protection Regulation (hereinafter, “UK GDPR” and together with the GDPR the “Regulations”), and in accordance with the Data Protection Act 2018 (hereinafter, together with the Regulations the “Applicable Law”) as well as any further provisions that apply if the User resides outside the European Union and the United Kingdom (hereinafter, the “Further Provisions”).

2. HOW TO CONTACT US?
The Controller takes the right to privacy and the protection of its Users' personal data into utmost consideration.
For any information regarding this privacy policy, Users may contact the Controller at any time using the following methods:
  1. Directly Online
    1. By contacting customer service by clicking directly here
  2. Through the postal letter
    1. By sending a registered letter with return receipt to the registered office of the Controller (Via Comelico, 3, 20135, Milan)
For specific requests to be sent to the Data Protection Officer (DPO) if the User who uses the Website/App resides in an EU or non-EU country (with the exception of the United Kingdom), the User can contact the Controller's DPO, whose contact details are provided below: the company Shibumi S.r.l., e-mail: dpo@iumob.it.

If the User using the Website/App resides in the UK, for requests relating to the processing of personal data, the User may contact GDPRLocal Ltd., as the Controller's designated Representative in the United Kingdom pursuant to Article 27 of the UK GDPR, whose contact details are:
  1. Telephone number: +441 772 217 800
  2. Address: GDPRLocal Ltd. 1st Floor Front Suite 27-29 North Street, Brighton England BN1 1EB


3. WHAT DO WE DO? - PROCESSING PURPOSES
By browsing the Website and the App, the User can register for the service, deciding whether to carry out the Standard Registration and thus activate a Free Profile, or use the Compete Subscription, which allows for the possession of a paid Premium Profile (hereinafter, the “Service”).
In relation to the activities that may be carried out through the Website or the App, the Controller collects personal data relating to Users.
 
This Website and App, as well as any services offered through them, are reserved for individuals who are 18 years and over. Therefore, the Data Controller does not collect personal data relating to individuals under 18 years of age. Upon request of the Users, the Data Controller will promptly delete all personal data that has been involuntarily collected and related to subjects under the age of 18. 
 
To download the App, the Controller will verify the User's age through the stores (Google Play Store or Apple App Store), if such verification is required by the applicable law in the User's country or state of residence. All information regarding the age verification process through the stores can be found at the following links:

 
In particular, Users' personal data will be processed by the Controller in compliance with the Applicable Law and the Further Provisions, for the purposes and on the legal bases indicated below.

Processing purpose

Personal data processed

Data source

Legal basis for processing

Allow the User to register and use the Services offered by the Controller via the Website or App.

 

 

The personal data required for registration are username, email address, password, date of birth, gender, city, and information revealing the User's sexual orientation.

 

Furthermore, through the provision of the Service, all personal information of the User that may be voluntarily provided through the publication of content (including photos and videos) or within the User’s profile is processed.

All data are provided by the User during registration and during use of the Service.

 

If the User logs in to the Controller's Website or App via Facebook log-in, the User’s data will be communicated to the Controller by Facebook.

For more information about the service and to change the privacy settings related to that service, please consult the following links: www.facebook.com/help/, www.facebook.com/about/privacy/your-info-on-other

Processing is necessary for the execution of the General Terms and Conditions of Service accepted by the User (art. 6, par. 1, letter b) of the Regulations).

 

The processing of data belonging to special categories occurs upon the User's specific consent (Article 9, paragraph 2, letter a) of the Regulations).

Process payments made by the User to purchase the Services offered by the Controller (not applicable to Users who make purchases through the Stores).

Details of the card used for payments.

This information is provided by the User.

Processing is necessary for the execution of the General Terms and Conditions of Service accepted by the User (art. 6, par. 1, letter b) of the Regulations).

 

Sending of promotional and commercial communications (advertising, direct sales, newsletters) by the Controller relating to products and/or services offered by the Controller and/or by third-party companies belonging to certain product categories.

Name, surname and email address.

This information is provided by the User.

Processing occurs upon the User's free and optional consent to the processing of their data for this specific purpose (Article 6, paragraph 1, letter a) of the Regulations).

Disclosure of data to the Controller's Partners, i.e., the following categories of third-party companies:

(i) clothing,

(ii) automotive,

(iii) retail,

(iv) credit and insurance,

(v) electronics,

(vi) IT and technology,

(vii) information,

(iix) health and wellness,

(ix) sports,

(x) entertainment, (xi) tourism,

(xii) online digital services, and

(xiii) personnel search and selection.

Following disclosure of data, the Partners will process the User's data as independent data controllers, based on the specific information that will be provided by the Controller's Partners to the Users.

Name, surname, gender, date of birth, city, email address.

This information is provided by the User.

Processing occurs upon the User's free and optional consent to the processing of their data for this specific purpose (Article 6, paragraph 1, letter a) of the Regulations).

Carrying out analysis and monitoring activities, as well as developing, testing and trialing new features, technologies and processes, aimed at improving and optimizing the Website/App and the related user experience.

Login data and usage data, including IP addresses, browser type, referring domain, pages viewed on the App/Site, search terms, photographs, registration information, profile information. It is specified that, in any case, the processing of information revealing the User's sexual orientation for this purpose is excluded.

Photographs are provided by the User during registration.

Usage and storage data are collected automatically from the device and/or system used to access the Website/App (e.g., online identifiers and technical logs).

 

 

Processing is necessary for the pursuit of the legitimate interests pursued by the Controller (Article 6, paragraph 1, letter f) of the Regulations).

Conduct investigations following reports of alleged violations or the publication of content that violates the General Terms and Conditions of Service and, where necessary, adopt enforcement measures (e.g. suspension or blocking of the account) to protect the security and integrity of the Service.

Information relating to the User's profile, information related to reports received by the Controller (e.g., messages and/or contents), usage and/or device data (e.g., IP address, technical logs).

Information regarding the profile or published content is provided by the User.

 

The information contained in the report is provided by the reporting person.

 

Usage and/or device data are collected automatically from the device and/or system used to access the Website/App.

 

Processing is necessary for the execution of the General Terms and Conditions of Service accepted by the User (art. 6, par. 1, letter b) of the Regulations).

 

Suspend or block transactions and/or payment accounts that appear to be anomalous or fraudulent.

Username, email address, IP address, payment information.

The data are provided by the User, except for the IP address, which is automatically collected from the device and system used to access the Website and/or the App.

Processing is necessary for the pursuit of the legitimate interest of the Controller (Article 6, paragraph 1, letter f) of the Regulations).


4. PROCESSING MEANS AND DATA RETENTION PERIOD
The Data Controller will process Users' personal data using manual and IT tools, with logic strictly related to the purposes themselves and, in any case, in order to guarantee the security and confidentiality of the data.
 
With regard to the data that the User makes available to the public on the Website and the App, as specified in the General Conditions of Service, the Controller is granted, among other things, any and all rights of publication, communication and making available to the public and other Users of the Website and/or the App.
 
The Services provided by the Controller through the Website and the App also include the Controller's use of a matching algorithm between User profiles, also based on machine learning, aimed at showing each User only profiles that match their profile and the search criteria they have entered. This algorithm processes Users' personal data, such as age, gender, location, and data relating to their use of the Website and/or the App.
 
The personal data of the Users of the Website/App will be retained for the periods indicated in the following table in relation to each processing purpose referred to in paragraph 3: 

 

Processing purpose

Data retention periods

Allow the User to register and use the Services offered by the Controller via the Website or App.

 

 

Users' personal data will be stored for a maximum period of 6 months from the end of the contractual relationship with the Controller.

Process payments made by the User to purchase the Services offered by the Controller (not applicable to Users who make purchases through the Stores).

Users' personal data will be stored for a period of 12 months from the processing of the payment and, in any case, in accordance with the period required for compliance with legal obligations in tax/accounting matters.

Sending of promotional and commercial communications (advertising, direct sales, newsletters) by the Controller relating to products and/or services offered by the Controller and/or by third-party companies belonging to certain product categories.

Users' personal data will be stored for a period of 12 months from the date of consent or, if earlier, until the User withdraws the consent.

Disclosure of data to the Controller's Partners, i.e., the following categories of third-party companies: (i) clothing, (ii) automotive, (iii) retail, (iv) credit and insurance, (v) electronics, (vi) IT and technology, (vii) information, (iix) health and wellness, (ix) sports, (x) entertainment, (xi) tourism, (xii) online digital services, and (xiii) personnel recruitment and selection. Following disclosure of data, the Partners will process the User's data as independent data controllers, based on the specific information that will be provided by the Controller's Partners to the Users.

Users' personal data will be stored for a period of 12 months from the date of consent or, if earlier, until the User withdraws the consent.

Carrying out analysis and monitoring activities, as well as developing, testing and trialing new features, technologies and processes, aimed at improving and optimizing the Website/App and the related user experience.

Users' personal data will be stored for a period of 6 months from their registration.

Conduct investigations following reports of alleged violations or the publication of content that violates the General Terms and Conditions of Service and, where necessary, adopt enforcement measures (e.g. suspension or blocking of the account) to protect the security and integrity of the Service.

Users' personal data will be stored for a period of 6 months from the reporting or detection of content that violates the General Terms of Service

Suspend or block transactions and/or payment accounts that appear to be anomalous or fraudulent.

Users' personal data will be stored for a period of 6 months from the suspension or blocking of the transaction or payment account.


In any case, any retention periods established by law or regulations or as necessary for the civil protection of the interests of both the Users and the Controller are reserved.
 
If the User decides to block and/or delete the User’s profile, all stored data relating to the User will be deleted. If the complete deletion of the User's data is not permitted or required by law, the data will be restricted from further processing.
 
For any further information or clarification regarding data retention periods and the Data Retention Policy adopted by the Controller, User can contact the customer service by clicking directly here.



5. TRANSMISSION AND DISSEMINATION OF DATA
The User's personal data may be transferred outside the European Union and the UK and, in such circumstances, the Data Controller will ensure that the transfer takes place in accordance with the Applicable Law and, in particular, in compliance with Articles 45 (Transfer on the basis of an adequacy decision) and 46 (Transfer subject to adequate safeguards) of the Regulations as well as the Further Provisions.
 
The employees and/or collaborators of the Data Controller who are in charge of carrying out Website and App maintenance may become aware of the personal data of the Users. These subjects, who are formally appointed by the Data Controller as in charge of processing, will process the User's data exclusively for the purposes indicated in this policy and in compliance with the provisions of the Applicable Law, as well as the Further Provisions. 
 
The personal data of the Users may also be disclosed to third parties who may process such data as independent “Data Controllers” or on behalf of the Controller as “Data Processors”, such as, by way of example:
  1. IT and logistics service providers functional to the operation of the Website and the App and/or anti-spam and anti-fraud activities to block any or suspected fraudulent registrations or transactions as required by the Controller’s anti-spam and anti-fraud procedures;
  2. outsourcing or cloud computing service providers, such as moderators for monitoring content uploaded to the App/Site; marketing service providers, for proposing marketing and advertising initiatives on various web channels and/or third-party applications and monitoring the performance of advertising campaigns; payment service providers, to facilitate the User’s purchase of premium services;
  3. professionals and consultants (e.g. legal advisors and/or lawyers, experts, accountants, etc.);
  4. the Authorities.
Users have the right to obtain a list of any data processors appointed by the Data Controller by making a request to the Data Controller using the methods indicated in the following paragraph 6 below.
In addition, other Users who use the Website and/or the App may also become aware of the User's personal data, in light of the nature of the Service described above and as specified in the General Terms and Conditions in this regard.
 
6. RIGHTS OF THE DATA SUBJECTS
Users may exercise the rights granted to them by the Applicable Regulations and/or from the Further Provisions that apply to the specific case, by contacting the Data Controller using the following methods.

  1. Directly Online
    1. By contacting customer service by clicking directly here
  2. Through the postal letter
    1. By sending a registered letter with return receipt to the registered office of the Controller (Via Comelico, 3, 20135, Milan)
For specific requests to be sent to the Data Protection Officer (DPO) if the User who uses the Website/App resides in an EU or non-EU country (with the exception of the United Kingdom), the User can contact the Controller's DPO, whose contact details are provided below: the company Shibumi S.r.l., e-mail: dpo@iumob.it.

If the User using the Website/App resides in the UK, for requests relating to the processing of personal data, the User may contact GDPRLocal Ltd., as the Controller's designated Representative in the United Kingdom pursuant to Article 27 of the UK GDPR, whose contact details are:
  1. Telephone number: +441 772 217 800
  2. Address: GDPRLocal Ltd. 1st Floor Front Suite 27-29 North Street, Brighton England BN1 1EB

Pursuant to the Applicable Law and/or the Further Provisions that apply to the specific case, the Users have the right to obtain information on (i) the origin of personal data; (ii) the purposes and methods of the processing; (iii) the logic applied in the event of processing carried out with the aid of electronic instruments; (iv) the identification details of the data controller and processors; (v) the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them in their capacity as processors or authorized persons. 

Furthermore, Users have the right to obtain: 
a) access, updating, rectification, or, when interested, completion of data; 
b) the erasure, anonymisation or blocking of data processed in breach of the law, including data that does not need to be stored in relation to the purposes for which the data was collected or subsequently processed; 
c) confirmation that the operations under letters a) and b) will be communicated, including with respect to the content thereof, to those to whom the data were communicated or disclosed, except where such task proves to be impossible or involves a use of means that is manifestly disproportionate to the right being protected.

Additionally, the Users have: 
a) the right to withdraw consent at any time, when processing is based on their consent, without such withdrawal affecting the lawfulness of the processing carried out prior to the withdrawal; 
b) the right to data portability (the right to receive all personal data concerning them in a structured format, commonly used and readable by automatic device); 
c) the right to object to: 
i) in whole or part, for legitimate reasons, the processing of personal data relating to User for legitimate reasons even pertinent to the purpose of collection; 
ii) in whole or part, the handling of personal data for the purpose of sending advertising or sales materials or for the carrying out of market research or for commercial communication purposes; 
iii) if personal data is processed for direct marketing purposes, at any time, to the processing of data for this purpose, including profiling in so far as it is related to such direct marketing. 

Furthermore, if the User resides in a country outside the European Union, the User may be granted different and/or additional rights, based on the Further Provisions. For further information on the list of these rights and how to exercise them, the User may contact the Controller by following the methods indicated at the beginning of this paragraph.
 
If the User believes that the processing of personal data concerning the User violates the Regulations and/or the Further Provisions, the User also has the right to lodge a complaint with the Supervisory Authority (in the member state in which the User habitually resides, in the member state in which the User works, or in the member state in which the alleged violation occurred). The Italian Supervisory Authority is the Garante per la protezione dei dati personali, with registered office in Piazza Venezia n. 11, 00187 - Rome (https://www.garanteprivacy.it/en). For the United Kingdom, the Supervisory Authority is the Information Commissioner's Officer, with registered office in Wycliffe House, Water Lane, SK9 5AF – Wilmslow (Cheshire) (https://ico.org.uk/). For further information on the Supervisory Authority of the User’s state of residence and on the possibility of lodging a complaint with that Authority, the User may contact the Controller using the methods indicated at the beginning of this paragraph.





The Data Controller is not responsible for updating all the links viewed in this Privacy Policy, therefore, whenever a link is not functioning and/or is not updated, the Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by that link.

Version updated on: July 07, 2026
Should the Controller make substantial changes to this policy, the Users will be promptly notified.

    • Related Articles

    • Privacy Policy Contacts

      This privacy policy aims to provide all the information regarding the processing of personal data carried out by Iumob S.r.l. when the user contacts Yooppe.com (as better specified below). Please note that, for Users residing in the United States, ...
    • Addendum to the CCPA Privacy Policy

      For consumers in California This section, which relates to the State of California, supplements the Privacy Policy and applies exclusively to consumers residing in California, excluding the personnel of Iumob S.r.l. (“Data Controller” or ...
    • Privacy Policy for Users Residing in Other U.S. States

      This Privacy Policy supplements the general Privacy Policy and is provided by Iumob S.r.l. (“Data Controller” or “Controller”) and applies solely to Users residing in the states of Indiana, Maryland, Nebraska, New Jersey, Texas, Tennessee, Virginia, ...
    • Colorado Safety Policy Information

      This section contains relevant information regarding the safety policies and reporting procedures adopted by Iumob S.r.l. (“Data Controller” or “Controller”), in accordance with the applicable law of the State of Colorado. Please also refer to the ...
    • Cookies Policy and other tracking tools

      Dear Visitor (hereinafter, "You" or the '"User"), This Internet website www.yooppe.com (hereinafter, the "Website") and the application Yooppe (hereinafter, the “App”) are owned by the company Iumob S.r.l., having its registered office in Via ...