Privacy Policy
Last updated: 16 September 2026
Rateory is operated by Northbird, a business registered in the Netherlands (KvK 42164736). Privacy questions and data-rights requests can be sent to info@northbird.nl.
1. What Rateory processes
Rateory does not require a user account and does not ask you to provide your name, email address, payment details, or precise location to use the currency converter.
- Local website data: favorites, recent conversions and web alert settings can be stored in your browser's local storage. They are not sent to Rateory's push service.
- Local mobile data: favorites, recent conversions, language choice and alert settings can be stored on your device.
- Optional push data: only after you choose to enable mobile notifications, Rateory sends a random device identifier, a Firebase Cloud Messaging token, platform information, and your alert settings (currency pair, target, direction and timestamps) to the Rateory push service.
The mobile app creates a device secret locally. The push service stores only a hash of that secret for authentication, rather than the secret itself.
When you access Rateory, hosting and network providers may process ordinary technical data needed to deliver and secure the service, such as IP address, request metadata, timestamps and security signals.
2. Why we process data
- To provide currency conversion, history and the features you request.
- To register an opted-in mobile device and deliver target-rate notifications.
- To secure, troubleshoot and maintain the service.
- To prevent abuse and protect Rateory's infrastructure.
Depending on the processing activity, the legal basis is performance of the service you request, our legitimate interests in secure and reliable operation, and your choice or consent for optional notifications where applicable.
3. Service providers
Rateory uses Cloudflare for hosting, network delivery, security and push-service storage, and Google Firebase Cloud Messaging to issue and deliver mobile notification tokens and messages. Exchange-rate requests are served through Rateory and may use third-party reference-rate sources.
These providers may process data outside the European Economic Area. Where required, international transfers are covered by applicable provider terms and transfer safeguards, such as standard contractual clauses or other recognized mechanisms.
4. Retention and deletion
Local browser or app data remains until you remove it, clear application/browser storage, or uninstall the app. Server-side push registration and alert data is configured to expire no later than 180 days after its last relevant update.
You can delete mobile notification data earlier from the Rateory app by choosing Disable & delete notification data. This removes the device registration and alert records stored by the Rateory push service and disables the app's FCM token.
5. Cookies and analytics
At the date of this policy, Rateory does not use advertising or analytics SDKs in the mobile app and does not use advertising or analytics cookies on the website. Browser local storage is used for functional preferences and locally saved Rateory features.
6. Your rights
Where the GDPR or another applicable data-protection law applies, you may have rights to access, correct, delete, restrict or object to processing, and to data portability where relevant. You may withdraw consent where processing relies on consent without affecting earlier lawful processing.
To exercise a right, contact info@northbird.nl. You may also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or another competent authority.
7. Sharing and sale
Rateory does not sell personal data. Data is shared with service providers only as needed to operate, secure and deliver the service, or where required by law.
8. Changes
We may update this policy when Rateory's features or legal obligations change. The current version and update date will remain available on this page.
9. Contact
Northbird · KvK 42164736 · Netherlands
Email: info@northbird.nl