Can we use analytics cookies to see which pages are useful? We only set them if you say yes, and never use them for ads.

Skip to main content
OMG! Translate!

Privacy Policy

Last updated: 14 September 2026, pending legal review.

Awaiting legal review

This page describes how the service actually works, but a qualified lawyer has not yet reviewed the wording. It will be updated once that review is done.

This policy explains what personal data OMG! Translate! collects, why it is collected, how long it is kept, and what rights you have over it. It applies to the website, the customer and translator dashboards, the mobile app, and the calls made through them.

Who is responsible for your data

The data controller is:

Craig Darren Robert Malton
Avenida Doctor Meca 44, P04-7, 30860 Puerto de Mazarrón, Murcia, SPAIN
craig@omgtranslate.com

Data we collect

  • Account data. Email address, display name and a password hash — never the password itself. If you enable them, a verified phone number and two-factor authentication settings, whose secrets are stored encrypted.
  • Profile data. For translators, a public name, photo, languages, proficiency levels and areas of expertise, which anyone can see. For customers, the languages you speak, visible only to you.
  • Call data. The languages and area of expertise you asked for, what you said you need help with — which the translator sees before they accept — who took part, and when the call was requested, connected and ended.
  • Billing data. Charges, the prices that applied, payments you make, balance movements, refunds and payout requests. Card details are entered with our payment processor and never reach our servers.
  • Device data. If you allow notifications in the app, a token that lets us send them to that device. It is retired when you sign out.
  • Technical data. IP address and browser or app details, recorded against sign-ins and security-relevant actions so that misuse of an account can be investigated.

We do not record calls

Call audio travels between the two people on the call, encrypted in transit. Where a direct connection is not possible it passes through a network relay, which forwards it without storing it. We never record a call and never make a transcript, and we will not begin doing either without first changing this policy and our terms and asking for your agreement.

Setting up a call involves exchanging technical connection messages between the two devices. Those are deleted by routine maintenance once the call has been over for an hour.

Cookies and analytics

Signing in sets one cookie that keeps you signed in. It is strictly necessary for the service to work, cannot be read by scripts on the page, and needs no consent.

The sign-up, sign-in and password reset pages, and the same steps in the app, use Google reCAPTCHA to tell people from automated programs. It sends Google information about your device and how the page is being used, and may set a cookie of its own. We rely on our legitimate interest in keeping accounts secure and stopping fake sign-ups, so it does not wait for the analytics choice below.

The website uses Google Analytics to understand which pages people find useful, and only with your permission. Until you choose Allow on the banner, no analytics cookie is set and no identifier is sent; Google may receive cookieless measurement signals that carry no identifier. If you allow it, Google Analytics sets cookies to count visits, and we ask Google to shorten your IP address. Advertising features are switched off whatever you choose.

Your choice is kept in your browser’s local storage rather than in a cookie. You can change it at any time with the Cookie choices link at the bottom of every page. The mobile app has no analytics.

How we use it

To run your account, connect calls, work out and collect charges, pay translators, send the emails, text messages and notifications the service depends on, meet tax and accounting obligations, and protect the service against fraud and abuse.

Legal basis

Performance of our contract with you for account, call and billing data; legitimate interests for security and fraud prevention; legal obligation for financial records; and consent for analytics, for notifications on your device, and for any optional information you choose to give.

How long we keep it

  • Financial and audit records — charges, payments, refunds and payouts — for at least six years, as Spanish commercial and tax law requires.
  • Sign-in records are deleted 30 days after they expire. Call connection messages are deleted an hour after the call ends.
  • When an account is closed it stops being usable, but it is not erased while financial records tied to it must be kept. You can ask us to erase anything the law does not require us to keep.

Who we share it with

Translators see a customer’s display name and what they need help with when a call is offered to them. Translator profiles are public. Beyond that, we share data only with the providers that run parts of the service on our behalf, each bound by a data processing agreement:

  • Stripe, for card payments and refunds.
  • Twilio, for text messages and for relaying call audio when a direct path fails.
  • SendGrid, for email.
  • Expo, for delivering notifications to the mobile app.
  • Amazon Web Services, for storing uploaded files.
  • Google, for reCAPTCHA, which protects sign-up, sign-in and password reset.
  • Google, for analytics, and only with your consent.
  • Our hosting provider, which runs the servers and database.

Some of these providers process data outside the European Economic Area. Where they do, the transfer relies on an adequacy decision or on standard contractual clauses. We do not sell personal data.

Changes to this policy

We update this policy from time to time. The date at the top shows when it last changed, and it is your responsibility to check it. The updated policy applies from that date.

Your rights

You can ask for access to, correction, erasure, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent at any time without affecting what was done before. Write to the address above. You can also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority where you live.