FarmSolDirect is developed and maintained by an independent developer operating under Australian law.
com.farmsoldirect.appFor the purposes of the EU General Data Protection Regulation (GDPR) and UK General Data Protection Regulation (UK GDPR), the data controller is the developer identified above. If you are located in the European Economic Area (EEA) or United Kingdom and have questions about data protection, please contact us at the email address above.
FarmSolDirect is designed with a privacy-first, local-only architecture. All data remains exclusively on your device in app-private storage (Android SharedPreferences, EncryptedSharedPreferences, and local JSON files). No data is transmitted to any server we operate, because we do not operate any servers.
| Data type | Purpose | Legal basis (GDPR) |
|---|---|---|
| User profile (role, display name, region, currency & unit preferences) | Personalise the app experience for buyers and sellers | Contract (Art. 6(1)(b)) |
| Wallet public address & wallet name | Display wallet identity and SOL balance (opt-in) | Consent (Art. 6(1)(a)) |
| SGT status & member number | Display Seeker Genesis Token verification | Consent (Art. 6(1)(a)) |
| Buy requests (produce, quantity, specs, delivery address, pricing) | Store buyer-created purchase requests locally | Contract (Art. 6(1)(b)) |
| Sell listings (produce, pricing, availability, location) | Store seller-created listing information locally | Contract (Art. 6(1)(b)) |
| Counter-offers | Store negotiation responses locally | Contract (Art. 6(1)(b)) |
| Favourite produce items | Quick access to frequently used produce types | Contract (Art. 6(1)(b)) |
| Notification preferences (reminder frequency, market day) | Schedule local WorkManager reminders | Contract (Art. 6(1)(b)) |
| Disclaimer & onboarding acceptance state | Record that the user has acknowledged informational-only nature | Contract (Art. 6(1)(b)) |
FarmSolDirect requests Android coarse location permission solely for regulatory compliance — specifically to detect whether the device is located in a jurisdiction subject to international sanctions. This permission:
Legal basis (GDPR): Legitimate interest (Art. 6(1)(f)) — compliance with international sanctions law. We have conducted a balancing test and determined that the compelling legal obligation to screen for sanctioned regions outweighs the minimal privacy intrusion of a single on-device coarse location check that is never stored or transmitted.
FarmSolDirect requests the POST_NOTIFICATIONS permission to deliver local reminders scheduled via Android WorkManager (e.g., market day reminders, listing expiry reminders). These notifications are generated entirely on your device — no push notification service, no server, and no external messaging infrastructure is involved. You can disable notifications at any time in Android Settings.
FarmSolDirect does not operate any backend servers, databases, cloud storage, or analytics infrastructure. We have no server-side systems capable of receiving, storing, or processing user data. All data exists exclusively in your device's app-private storage and is inaccessible to other applications. Buy requests, sell listings, counter-offers, and user profiles never leave your device unless you explicitly share them using the Android Share Intent.
FarmSolDirect makes read-only API requests to the following third-party services to retrieve publicly available data. These requests are HTTPS-encrypted and no user-specific data is included in the requests except where noted:
| Service | Endpoint | Data retrieved | User data sent |
|---|---|---|---|
| Frankfurter API | api.frankfurter.dev | Currency exchange rates for price conversion | None |
| ipwho.is | ipwho.is | IP-based geolocation for country detection (sanctions screening) | Device IP address* |
| Solana RPC | api.mainnet-beta.solana.com | Wallet SOL balance; SGT token account check | Wallet public address** |
* Your device's IP address is inherently sent to ipwho.is as part of the geolocation request. This is used solely for sanctions region screening as a fallback when on-device location detection is unavailable. We do not control how ipwho.is handles IP addresses — please refer to their privacy policy.
** Your Solana wallet public address is sent to the Solana RPC endpoint only when you have opted in by signing in with your wallet. Wallet public addresses are publicly visible on the Solana blockchain and are not generally considered personal information, though GDPR may classify pseudonymous identifiers as personal data. The legal basis for this processing is your explicit consent (Art. 6(1)(a) GDPR).
Wallet sign-in uses Solana's Mobile Wallet Adapter protocol with Sign In With Solana (SIWS), which operates entirely locally between FarmSolDirect and your wallet app on the same device via Android inter-process communication. During the MWA sign-in process:
If you choose to verify your Seeker Genesis Token, FarmSolDirect queries the Solana blockchain via RPC to check for the presence of an SGT in your wallet. This process:
We implement the following security measures to protect locally stored data:
EncryptedSharedPreferences with AES-256-SIV encryption (via Google Tink)All data is stored locally on your device and is retained until you explicitly delete it. You can delete all FarmSolDirect data at any time by:
Since no data is stored on our servers, deletion from your device constitutes complete deletion. Note that any data you have previously shared via the Android Share Intent (e.g., to WhatsApp, email) is governed by those third-party services and is outside our control.
FarmSolDirect does not transfer personal data to our servers (we have none). However, when FarmSolDirect makes API calls to third-party services (see Section 4), network requests may be routed through servers located outside your country of residence, including servers in the United States and Europe.
For users in the EEA or UK: these API calls are limited to fetching publicly available currency exchange rates, geolocation data for sanctions compliance, and, where you have consented, querying your wallet's public balance. We rely on the derogation under Article 49(1)(a) GDPR (explicit consent for wallet balance queries), Article 49(1)(c) (necessary for the performance of the contract for currency data retrieval), and Article 49(1)(d) (necessary for important reasons of public interest for sanctions screening).
If you are located in the EEA or UK, you have the following rights under the GDPR:
Under the Australian Privacy Principles (APPs), you have the right to:
If you are a California resident, you have the right to:
If you are located in Japan, you have the right to request disclosure, correction, cessation of use, and deletion of your personal information. All data is stored locally on your device and can be deleted by clearing app data or uninstalling. For inquiries, please contact us at the email address in Section 1.
If you are located in South Korea, you have the right to:
All data is stored locally on your device. The personal information protection officer for this application can be contacted at aardappvark@proton.me.
If you are located in Singapore, you have the right to access and correct your personal data. We have designated the developer as the Data Protection Officer. For PDPA inquiries, contact aardappvark@proton.me.
FarmSolDirect is not directed at, marketed to, or intended for use by children under the age of 16 (or 13 in jurisdictions where that threshold applies, including the United States under COPPA). We do not knowingly collect any information from children. If you believe a child has provided data to the app, the data exists only on that child's device and can be removed by clearing app data or uninstalling the app.
FarmSolDirect performs one automated decision: sanctions region screening at app startup. If your device is detected in a sanctioned jurisdiction, the app displays an informational screen explaining the restriction. This automated decision is based on legitimate interest in regulatory compliance (GDPR Art. 22(2)(b)) and does not produce legal effects beyond restricting access to the app's informational features. You may contact us to contest this decision.
We have conducted an internal assessment of our data processing activities and determined that a formal Data Protection Impact Assessment (DPIA) under GDPR Art. 35 is not required because:
FarmSolDirect does not track users in any way and therefore inherently honours Do Not Track (DNT) signals. There is no tracking to disable.
For the purposes of the EU ePrivacy Directive (2002/58/EC) and its national implementations: FarmSolDirect stores configuration data, user profiles, buy requests, sell listings, counter-offers, and favourites on your device using Android SharedPreferences, EncryptedSharedPreferences, and local JSON files. This storage is strictly necessary for the functioning of the application (exempted from consent requirements under Art. 5(3)) and does not involve any tracking, profiling, or advertising functionality.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of FarmSolDirect after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
For any privacy-related questions, concerns, or to exercise your data subject rights, please contact:
We aim to respond to all privacy inquiries within 30 days.
This Privacy Policy is governed by the laws of Australia, without regard to conflict of law principles. This does not affect your statutory rights under the laws of your country of residence, including rights under GDPR (for EEA/UK residents), CCPA/CPRA (for California residents), or other applicable local privacy laws.