Privacy Policy | Libme
LibMe

Privacy Policy

Last updated: 4 July 2026

This Privacy Policy explains how Ibraint (EOOD, UIC/EIK: 204105221, registered address: Bulgaria, Ruse, Obzor 25) (“we”, “us”, “our”) processes personal data when you use the Libme platform and related services (“Libme”, “the Service”). We are established in the European Union, in Bulgaria, and process data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian law. By using Libme you acknowledge this Policy. For our contractual terms, see our Terms of Service.

Data controller and contact

The data controller is Ibraint, Bulgaria, Ruse, Obzor 25, UIC/EIK: 204105221. VAT number (if applicable): .

Privacy and data protection enquiries: [email protected]. General support: [email protected] or the contact form in the Help section.

Scope

This Policy applies to visitors, registered users, and anyone who interacts with Libme through our website, progressive web app, or related channels.

Libme is a technology platform. We do not act as a party to book sales, exchanges, loans, or auctions between users unless explicitly stated otherwise in a separate written agreement.

Categories of personal data

Account and profile: name, email address, hashed password, preferred language, country and city (if provided), notification preferences, subscription and billing status, team/library membership, and settings you choose.

Authentication: credentials for email/password login; passkey (WebAuthn) public key credentials and device labels (we do not receive or store biometric data from your device); Google account identifier, name, and email if you choose “Sign in with Google”.

User content: libraries, book records, photos, descriptions, availability status, messages, auction listings and bids, reading activity, sprint participation, reports, and other content you submit.

Communications: support requests, contact form messages, and email correspondence.

Payment-related data: subscription plan, payment history, and billing identifiers processed by Stripe. We do not store full payment card numbers on our servers.

Technical and security data: IP address, device and browser type, operating system, language, session identifiers, cookies and similar technologies, security logs, error logs, and abuse-prevention signals.

Push notifications: browser push subscription endpoints and related tokens if you enable web push notifications.

Analytics and marketing (only with consent): pseudonymous usage events via Google Analytics 4 and marketing/remarketing signals via Meta Pixel, managed through Cloudflare Zaraz according to your cookie choices.

Sources of data

Directly from you when you register, update your profile, publish content, send messages, participate in auctions or loans, subscribe to paid plans, contact support, or change your preferences.

Automatically when you use Libme, including through cookies, server logs, and security monitoring.

From third parties you connect: Google (if you use Google sign-in) and Stripe (payment and subscription status).

From other users when they interact with your public content, send you messages, bid in your auctions, or report content.

Purposes and legal bases

We process personal data only where a legal basis under GDPR Article 6 applies:

Performance of a contract (Art. 6(1)(b)): creating and managing your account; providing libraries, catalog, messaging, auctions, loans, reading features, and paid subscriptions; customer support related to the Service.

Legitimate interests (Art. 6(1)(f)): securing Libme, preventing fraud and abuse, maintaining logs, improving reliability, enforcing our Terms, defending legal claims, and communicating about important service changes — balanced against your rights.

Consent (Art. 6(1)(a)): marketing emails; non-essential cookies and similar technologies; Google Analytics 4 and Meta Pixel where required. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Legal obligation (Art. 6(1)(c)): accounting, tax, and regulatory records where applicable.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects within the meaning of GDPR Article 22.

Cookies and similar technologies

We use cookies (small text files), local storage, and similar technologies on Libme. They help the site work, remember preferences, keep you signed in, and — only with your consent — measure usage and show relevant marketing.

We group them as follows: (1) Strictly necessary — required for authentication, security, language, and consent storage; (2) Functional — UI preferences such as theme and sidebar layout; (3) Analytics — usage statistics via Google Analytics 4, loaded only with consent; (4) Marketing — Meta Pixel for marketing and remarketing, loaded only with consent.

First-party cookies are set by Libme. Third-party cookies or similar technologies may be set by Cloudflare (Zaraz, security), Google, and Meta when you consent or when strictly necessary for security.

We use Cloudflare Zaraz as our consent management platform. Non-essential analytics and marketing tools are not loaded until you consent, or they run in a limited mode according to your choices.

You can change or withdraw consent at any time using “Cookie settings” in the site footer or on our Cookie Policy page. You can also use your browser settings to block or delete cookies; some features may not work if you disable necessary cookies.

For a detailed list of cookies and similar technologies, legal bases, and durations, see our Cookie Policy (linked in the site footer).

Marketing communications

We send marketing emails only if you give separate opt-in consent at registration or in profile settings.

You may withdraw marketing consent at any time via the unsubscribe link in each email, in profile settings, or by contacting [email protected].

Transactional and service-related messages (security alerts, billing, legal notices) may still be sent as necessary to provide the Service.

Recipients and processors

We share personal data only as needed to operate Libme, with parties bound by data protection obligations:

Infrastructure and security: Cloudflare (hosting, CDN, Zaraz consent management, DDoS protection).

Payments: Stripe, Inc. (subscription billing and payment processing).

Authentication: Google LLC (if you use Google sign-in).

Analytics and advertising (with consent): Google (Analytics) and Meta Platforms (Pixel).

Email delivery: our email service provider(s) for transactional and, where consented, marketing email.

Other users: content you make public or share (public libraries, listings, messages, auction details) is visible according to your settings and platform features.

Authorities: where required by law, court order, or to protect rights, safety, and security.

We do not sell personal data. We do not share data with third parties for their own independent marketing without your consent.

International transfers

Some processors listed above may process data outside the European Economic Area (EEA), including in the United States.

Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms under GDPR Chapter V.

You may request more information about transfers and safeguards by contacting [email protected].

Retention

We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.

Account and profile data: for as long as your account is active and, after deletion, only for as long as needed to handle disputes, security, backups, and legal obligations.

User content: until you delete it or your account, subject to backup cycles and legal holds.

Billing and tax records: for as long as required by applicable accounting and tax law.

Security and technical logs: only for as long as needed for security, operation of the Service, and investigation of incidents.

Marketing consent records: for as long as needed to demonstrate compliance plus applicable limitation periods.

When data is no longer needed, we delete or anonymise it in accordance with our retention procedures.

Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, hashed passwords, and monitoring.

No method of transmission or storage is completely secure. You are responsible for keeping your credentials confidential and securing devices used to access Libme.

We take the protection of your personal data seriously. In the event of an incident affecting the security of your personal data, we will make all reasonable efforts to determine its scope and will notify you without undue delay if we determine that the incident poses a real risk to your rights and interests, in accordance with GDPR requirements.

If we become aware of a personal data breach likely to affect your rights, we will notify you and the competent supervisory authority where required by GDPR Articles 33 and 34.

Your rights

Under GDPR you may have the right to: access your data; rectify inaccurate data; erase data (“right to be forgotten”) in certain cases; restrict processing; data portability where applicable; object to processing based on legitimate interests or for direct marketing; and withdraw consent where processing is consent-based.

To exercise your rights, contact [email protected]. We may need to verify your identity. We respond within one month unless extension is permitted.

You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP / KZLD): https://cpdp.bg/, or with the supervisory authority in your EU/EEA country of residence or workplace.

Children

Libme is not directed at children under 16. We do not knowingly collect personal data from anyone under 16 without verifiable parental consent where required by law.

If you believe a child has provided us data without appropriate consent, contact [email protected] and we will take appropriate steps to delete it.

Changes to this Policy

We may update this Policy to reflect legal, technical, or business changes. The “Last updated” date will be revised and, where changes are material, we will provide additional notice (for example by email or in-app notice).

Continued use of Libme after the effective date of an update constitutes acknowledgment of the revised Policy, except where your consent is required by law.