Privacy Policy

Last updated: August 17, 2026

Who is responsible for this data

The operator of UA Near (uanear.com) and the data controller is TODO-SET-BEFORE-LAUNCH. For privacy questions, write to TODO-SET-BEFORE-LAUNCH.

What we collect

Browsing the directory does not require an account. To serve pages and keep them secure, we process only what is technically necessary: standard server request logs, and the request data Cloudflare — our hosting and content-delivery provider — collects while handling each request (IP address, request time, User-Agent).

While browsing the directory without signing in, the site sets only one cookie — it stores your chosen interface language; no account cookie appears on these pages (see "Accounts" below). This data is used only for security, diagnostics and running the site, and is not shared with anyone except Cloudflare as a technical service provider. In addition, when a search of the directory returns nothing, we count the query itself: we store only the normalised search text, the city and how many times it happened. No name, no account, no IP address — it is a measure of unmet demand, not a record of who searched for what. These queries are shown publicly on the Community requests page. Searches containing an email address, or anything shaped like a phone number, are not stored at all.

Accounts

If you create an account — with email and password, or by signing in with Google — we store your email address, name, chosen interface language, role (user, moderator or admin) and whether your address is verified. For password sign-in we store not the password itself but its cryptographic hash with a unique salt per password — it cannot be decrypted. If you sign in only with Google, we hold no password for you at all: we store only which provider you use and a technical identifier for that link. We never receive or see your Google password, and we deliberately do not store your Google profile picture.

We process this data to provide the service you asked for — creating and running your account — and to protect it from abuse. It is kept for as long as the account exists. You can delete it, and this data with it, at any time on the Account page — see "Your rights" below.

After signing in or registering, the site sets one encrypted session cookie in your browser, valid for 30 days, inaccessible to JavaScript and sent only over a secure connection. It carries your id, name, role, language and email-verified flag — for rendering the interface only; the right to any action is re-checked against the database every time, never from the cookie's contents. While browsing the directory without signing in, this cookie does not appear: an anonymous visit to the homepage, a city page or search receives no session cookie at all. It only shows up when your own browser calls the internal sign-in check — right after you sign in or register, or during client-side navigation between pages; in that second case, even without signing in, the cookie can carry no more than an anonymous technical id, with no personal data in it.

The email-verification link is valid for 24 hours, the password-reset link for 1 hour; both are single-use and stop working the moment they are used. Only a cryptographic fingerprint of the token is stored in the database, never the token itself — the token exists only in the email you received.

To protect accounts against password guessing, we keep a technical log of failed sign-in and registration attempts. What is keyed there is not the address or IP itself but a cryptographic fingerprint of it, salted with a secret value only the server knows — it cannot be reversed back to an address or IP, and cannot be tied to a specific person or account.

Verification and password-reset email is sent through Resend — it receives the address, subject and body of the exact email being sent to you, and nothing else of ours. If you sign in with Google, your browser talks to Google directly during that step, so Google sees your IP address the same way it would on any other site with a "Sign in with Google" button — that happens under Google's own privacy terms, not UA Near's.

What we publish about businesses

The directory contains public information about businesses — name, address, category and contact details — gathered from public sources. This is not personal data about site visitors; it is data about business entities. If you own a business and believe it was listed by mistake or should be removed, use the Contact page.

Your rights

If you have an account, the Account page lets you, at any time and on your own: change your name and interface language, set or change your password, download a copy of your data as JSON (profile, sign-in method, your reviews, ownership claims and businesses you own) and permanently delete your account. Deletion immediately and irreversibly erases your email, password, Google link, verification and reset tokens, and your reviews and ownership claims; business listings you added or own stay in the directory — only the link to your account is removed — and public ratings are recomputed right after your reviews are deleted.

For any other data we hold about you, or a business listing in the directory, you have the right to find out exactly what we hold, have inaccuracies corrected, or request removal. Write to TODO-SET-BEFORE-LAUNCH — we respond within TODO-SET-BEFORE-LAUNCH.

Changes to this policy

We update this page whenever what data we process, or why, changes. The date of the last update is shown at the top.

What you publish yourself

Reviews, community requests and replies to them are published under the name on your account and are visible to everyone. An ownership claim is NOT public: it is seen only by moderators, together with the contact details and evidence you provide, and is kept as an internal record with its decision. With a review we also store a hashed fingerprint of your IP address (never the address itself), solely to resist abuse. Deleting your account deletes your reviews, claims, requests and replies along with it.