Skip to content
Stanar +
HomeFor managersSupportSrpski

← Back to home

Privacy Policy

Effective date: 6 August 2026

This is a translation provided for convenience. In case of any discrepancy, the Serbian version prevails.

This privacy policy describes how the Stanar + app, developed and maintained by PETAR CENIĆ PR HECO DEVELOPMENT, Jovana Apela 16, 18000 Niš, Serbia, company number 68533970, tax number (PIB) 115659746 ("we", "us"), collects, uses and protects user data ("you", "the user"). By using Stanar + you accept the practices described in this document.

1. What data we collect

Account data

  • Email address and password (the password is stored and processed solely by Firebase Authentication; we neither see it nor store it in readable form)
  • First and last name
  • Apartment number
  • Role in the app (resident or manager)
  • Identifiers of the buildings you belong to

Content you create yourself

  • Polls and votes within your building
  • Posts on the building's bulletin board
  • Issue reports (description, location, optional phone number)
  • Photographs you attach to posts or issue reports

The record of how members declared themselves in a poll

  • When you vote in the app we record how you voted, an identifier of your account, the time from your device and the time from the server. Once written, that record cannot be changed — not by you, not by the manager, not by us.
  • The manager can enter a declaration collected outside the app — on paper, in person or by phone. Such an entry holds the apartment number, the first and last name as the manager typed them, how the declaration was collected, an identifier of the manager who entered it, and the time of entry. This is data about you entered by someone else, so where the apartment number matches exactly one account in the building, we immediately notify that person that the entry was made; that notification cannot be switched off. If you disagree with the entry, vote in the app — your own vote replaces the manager's entry, and the entry is deleted.

Push notifications and devices

  • For each device you are signed in on we record the Firebase Cloud Messaging (FCM) device token, the platform (Android or iOS), the notification permission status the device reports to us, and the time it was last updated. The token is a device identifier linked to your account and we use it solely to send notifications from your building — about new polls, posts and report status changes.
  • Your choice of which notifications you want to receive (new polls, a reminder before the deadline, results), stored with your profile

Diagnostic data

  • Crash reports and basic technical device information, collected through Sentry (servers in the EU, .de ingest domain)

Camera and photo library

  • With your prior permission, the app accesses the camera (scanning a building QR code, taking photos) and the photo library (choosing photos for posts and issue reports). You can enable or disable camera and photo library access at any time in your device settings; the app accesses them only when you initiate it.

There are no ads in the app. We do not use behavioural analytics, we do not track users for marketing purposes, and we do not sell data to third parties. If your building has Stanar+ TV, ads appear only on that screen in the entrance hall — never in the app, and never based on data about you. Section 4 explains how it works.

2. Who processes your data and where it is stored

The following service providers process data on our behalf and on our instructions:

  • Google Firebase — Authentication, Firestore (database), Storage (photos) and Cloud Messaging (push notifications)
  • Sentry — crash reporting and diagnostics (servers in the EU)

Data is stored in the United States. The database (Firestore) and the photos (Storage) sit in Google's nam5 multi-region, on servers in the USA. The server-side code that sends notifications and prevents a vote from being counted twice runs there as well (the us-central1 region), because database triggers can only be bound to the region the database itself is in. What stays in Europe is the enquiry form on this site (europe-west1) and the crash reports at Sentry. This means the data described here — including your name, apartment number and how you declared yourself — leaves Serbia and the European Economic Area. The transfer takes place under Google's data processing terms for Firebase, which incorporate the European Commission's standard contractual clauses.

3. Visibility of data within the building

Please note that Stanar + is designed for communication within a building. Your name, apartment number and the content you create (polls, posts, and votes where applicable) are visible to other members of your building and to the building manager.

Other residents do not see how you voted. They see the aggregate result only, and everyone sees their own vote. The named record of how members declared themselves — who voted, how and when, together with the declarations the manager entered from outside the app — is visible to your building's manager alone, because that is what the law puts into the minutes (see section 5).

4. Stanar+ TV — the screen in the entrance hall

If your building association opts for Stanar+ TV, a screen is installed in the building's common area showing building content and ads. The screen stands where non-residents also see it — couriers, guests, tradespeople — so stricter rules apply to it than to the app:

  • The screen never shows personal data. No name, no apartment number, no contact details, no record of how anyone voted, and no content of issue reports.
  • Financial figures and votes can only appear in aggregate, and only if the manager turns that on — for example the building's total balance or how many apartments have voted so far, never individual entries or anything per apartment.
  • What appears is decided by the building manager: notices they marked for the entrance hall, and public notices about planned power and water outages.
  • The screen has no camera, microphone or sensors and does not recognise who is in the entrance hall. It collects no data about residents or passers-by.
  • Ads are not targeted. They are not selected using any data about residents — everyone in the same entrance hall sees the same rotation at the same time. No profiling, no tracking, no cookies, no audience measurement.

Stanar+ TV is a separate app meant solely for that screen; residents neither install it nor sign in to it.

5. How long we keep data, and what remains after account deletion

We keep account data for as long as your account exists in the app. When you delete your account, your profile — first and last name, apartment number, email address, role, link to the building, notification settings and the device token of the device you delete from — is deleted immediately. The full procedure is on the Account deletion page.

The record of how members declared themselves is not deleted with the account. Until 6 August 2026 this section said that only anonymised records of votes remain after account deletion. For part of that record this is not true, so we are changing the promise rather than quietly breaking it. After account deletion the following remains:

  • Your vote cast in the app remains as a record of that poll, but without your name and apartment number — those were in the profile that was deleted. What stays alongside the vote is an internal identifier of the account that cast it and the time of voting.
  • A declaration the manager entered on your behalf holds the first and last name as the manager typed them. That record did not originate from your account and is not deleted with it.
  • Minutes or an extract already drawn up hold the names as they stood on the day of the vote and remain unchanged.

The basis for this. The minutes of an assembly of a building association must contain a record of how each member declared themselves — Article 46, paragraph 3, item 4 of the Law on Housing and Building Maintenance ("Official Gazette of the RS" nos. 104/2016 and 9/2020). That statutory duty rests on the manager and the building association, and we hold the data in the app so that the manager can discharge it. A record that disappears the moment someone deletes their account would not be a record.

For how long. We keep the named record of declarations and the minutes drawn up from it for five years from the end of the year in which the vote closed, and then delete them. The period is deliberately longer than the six months the law leaves for bringing an action to annul a decision (Article 12, paragraph 1, item 5 of the same law), because that deadline does not start on the same day for everyone, and the consequences of a decision — works, contracts and payments — last considerably longer than it.

Other building-related content you created yourself, for example bulletin board posts and issue reports, may remain stored as part of the building's record, but without personal identifiers that would link it directly to you.

6. Your rights

You have the right to:

  • request access to the data we hold about you
  • request correction of inaccurate data
  • request deletion of your account and personal data

You can delete your account directly in the app (Profile → Delete account) or by sending a request to stanar@hecotech.dev. A detailed explanation of the account and data deletion procedure is on the Account deletion page.

The right to erasure does not cover data we have to retain by law or as part of the building association's record. What exactly remains, on what basis and for how long, is set out in section 5.

7. Data security

All data is transmitted encrypted (HTTPS/TLS), and access is restricted by database security rules. Your personal details — name, email address and apartment number — are visible only to you and your building's manager. How you voted is visible only to you and your building's manager; other residents see the aggregate result alone. Basic building details such as the name and address are readable without signing in, because registration needs them. Please note that no method of transmission or storage on the internet is completely secure, so we cannot guarantee absolute security, but we protect data in line with good industry practice.

8. Disclosure required by law

We may disclose your data to third parties only where we are required to do so by law or by a valid request from a competent authority (for example a court or another state body), and where it is necessary to protect the rights and safety of the app's users.

9. Children

Stanar + is not intended for people under 16 years of age. We do not knowingly collect data from children under 16.

10. Changes to this policy

We may update this privacy policy from time to time. We will notify you of material changes through the app or by the email address associated with your account.

Change of 6 August 2026. Section 5 was rewritten. It used to say that only anonymised records of votes remain after account deletion; that is not true of the declarations a manager enters on a resident's behalf, nor of minutes already drawn up, so it now states what remains under a name, on what basis (Article 46, paragraph 3, item 4 of the Law on Housing and Building Maintenance) and for how long (five years). Section 1 was extended with the record of declarations and with device and notification-settings data, section 2 with the fact that the database and photos are stored on servers in the United States, and section 3 with who can see the named record of declarations.

Change of 30 July 2026. Section 4, on the screen in the entrance hall (Stanar+ TV), was added, and it was clarified that there are no ads in the app — the earlier wording said only that we use no advertising, without distinguishing the app from the screen in the common area.

11. Contact

For any privacy-related questions, contact us at stanar@hecotech.dev.

Stanar +HomeFor managersAdvertisingSupport
LegalPrivacy PolicyTerms of ServiceService Terms (SaaS)Account deletion

Stanar + is built and maintained by Heco Development.
Contact: stanar@hecotech.dev
Impressum — official company registration details