π
Last Updated: June 12, 2026 Β· Effective Date: June 12, 2026
Privacy Policy
This Privacy Policy describes how LNR Consulting Services LLC ("LNR," "we," "our," or "us") collects, uses, shares, and protects your personal information when you access or use RenewAll (the "App"), available at lucianarepetto.com/tracker and on Google Play. RenewAll is a personal renewal and expiration tracking tool that helps you manage documents, subscriptions, insurance policies, and important deadlines. By using the App, you agree to the collection and use of information in accordance with this policy.
01 Information We Collect
A. Information You Provide
- Google Account Information: When you sign in using Google OAuth, we receive your full name, email address, profile photo URL, and a unique Google user ID for authentication purposes only.
- Tracking Data You Enter: RenewAll stores the renewal items, expiration dates, categories, notes, and reminders that you manually input into the App. This data is stored in your personal Firestore account and is never shared with third parties or used for advertising.
- Payment Information: When you subscribe, you are directed to Stripe's secure checkout. LNR never receives, processes, or stores your credit card number, CVV, or banking credentials.
- Family Sharing Data: If you use the family sharing feature, you may invite other users by email. Their acceptance of your invitation is required before any shared access is granted.
B. Information Collected Automatically
- Subscription Status: We store whether your RenewAll subscription is active or inactive in Google Firestore, associated with your user ID and email address.
- Device & Technical Data: Standard web server logs may record your IP address, browser type, operating system, and pages visited for security and operational purposes only.
- Google Calendar Data: If you enable Google Calendar sync, RenewAll requests permission to create calendar events on your behalf. We only create events β we do not read, modify, or delete your existing calendar events.
C. Information We Do NOT Collect
We do not collect, sell, or share: your tracking item contents for advertising, your behavioral data within the App, your location, your contacts, your camera or microphone access, or any sensitive personal information beyond what is strictly necessary to provide the service.
02 How We Use Your Information
| Purpose | Data Used | Legal Basis |
| Authenticate your identity and maintain your session | Google email, user ID | Contract performance |
| Store and display your renewal tracking items | Items you enter in the App | Contract performance |
| Verify and grant access to premium features | Subscription status in Firestore | Contract performance |
| Process subscription payments | Email (passed to Stripe) | Contract performance |
| Send renewal reminder notifications | Email address, item due dates | Contract performance |
| Sync renewal events to Google Calendar | Item name and date (if enabled) | Consent |
| Prevent fraud and ensure security | IP address, login timestamps | Legitimate interests |
| Respond to support inquiries | Email address | Legitimate interests |
| Comply with legal obligations | As required by law | Legal obligation |
We do not use your personal information for advertising, behavioral profiling, or sale to data brokers under any circumstances.
03 Legal Basis for Processing
For users in the European Economic Area (EEA) and United Kingdom, we process personal data under the following lawful bases as defined by the GDPR:
- Contractual Necessity: Processing your login credentials, tracking data, and subscription status is necessary to provide the service you subscribed to.
- Consent: Google Calendar sync is only activated with your explicit permission, which you may revoke at any time through your Google account settings.
- Legitimate Interests: We have a legitimate interest in maintaining the security of our systems and preventing fraudulent access.
- Legal Obligation: We may retain certain records to comply with applicable tax, accounting, and legal requirements.
04 Data Sharing & Third Parties
We do not sell, rent, trade, or otherwise disclose your personal information to any third party for commercial purposes. We share data only with the following service providers, strictly to operate the App:
| Service Provider | Purpose | Data Shared | Privacy Policy |
| Google Firebase | Authentication & database | Email, user ID, tracking items, subscription status | View |
| Stripe, Inc. | Payment processing | Email address, payment confirmation | View |
| Netlify, Inc. | Web hosting | IP address (server logs) | View |
| Google Calendar API | Calendar event creation (optional) | Item name and date only (if enabled) | View |
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights or the safety of others.
05 Data Retention
- Tracking Items & Account Data: Your tracking items and account data are retained for as long as your account is active. If you delete your account or request data deletion, all tracking items will be permanently deleted within 30 days.
- Subscription Records: Retained for the duration of your active subscription, plus up to 3 years after cancellation for legal and accounting purposes.
- Payment Records: Stripe retains payment records per their own retention policies and applicable financial regulations.
- Server Logs: Automatically deleted after 90 days.
You may request early deletion of your data at any time by contacting us at info@lnr-consultingservices.com.
06 Data Security
We implement multiple layers of security to protect your personal information:
- Google OAuth 2.0: Industry-standard authentication β no passwords stored by us.
- Google Firestore Security Rules: Each user can only read and write their own data. Family sharing access is permission-based and requires explicit invitation acceptance.
- Stripe PCI DSS Level 1: The highest level of payment security certification available.
- HTTPS/TLS Encryption: All data is transmitted over encrypted connections.
- Access Controls: Only authorized LNR personnel have access to production systems.
While we implement industry-standard safeguards, no method of transmission over the Internet is 100% secure. In the event of a breach, we commit to notifying affected users promptly (see Section 12).
07 Your Rights
ποΈ
Right to Access
Request a copy of the personal data we hold about you.
βοΈ
Right to Rectification
Request correction of inaccurate or incomplete data.
ποΈ
Right to Erasure
Request deletion of your personal data and all tracking items.
π¦
Right to Portability
Request your data in a structured, machine-readable format.
βΈοΈ
Right to Restrict Processing
Request that we limit how we use your data in certain circumstances.
π«
Right to Object
Object to processing based on legitimate interests.
To exercise any of these rights, contact us at info@lnr-consultingservices.com. We will respond within 30 days.
08 California Residents β CCPA Rights CCPA
If you are a California resident, the CCPA grants you specific rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information. You may submit a "Do Not Sell My Personal Information" request and we will confirm our non-sale policy.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To submit a CCPA request, email info@lnr-consultingservices.com with the subject line "CCPA Request."
09 Children's Privacy COPPA
RenewAll is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at info@lnr-consultingservices.com and we will promptly delete such information.
10 International Data Transfers
LNR Consulting Services LLC is based in the United States. If you access the App from outside the United States, your information will be transferred to and processed in the United States. For users in the EEA or United Kingdom, we rely on Standard Contractual Clauses (SCCs) and the data processing agreements of our service providers (Google and Stripe) to ensure adequate protection of your data.
11 Cookies & Tracking Technologies
- Firebase Authentication Cookies: Strictly necessary to maintain your login session. Cannot be disabled without losing access to the App.
- Local Storage: Used to temporarily store your App session state. No personal data is stored in local storage beyond what is needed for the current session.
- Google Calendar OAuth Tokens: If you enable calendar sync, Google OAuth tokens are stored securely to maintain the connection. You can revoke this access at any time through your Google account settings at myaccount.google.com/permissions.
We do not use advertising cookies, third-party tracking pixels, Google Analytics, Facebook Pixel, or any behavioral advertising technology. We do not serve advertisements.
12 Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, LNR Consulting Services LLC will:
- Notify affected users via email within 72 hours of becoming aware of the breach (where feasible).
- Notify relevant supervisory authorities as required by applicable law.
- Provide a description of the nature of the breach, the data affected, and the steps we are taking to remediate it.
- Recommend steps you can take to protect yourself, such as changing passwords or monitoring your accounts.
13 Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date, post a notice within the App, and for significant changes, send an email notification to your registered address. Your continued use of the App after the effective date constitutes acceptance of the updated policy.