Privacy Policy
This policy explains what personal data the BuD app (“BuD”, “we”) collects, why, who receives it, and the rights you have under the EU/UK General Data Protection Regulation (GDPR). BuD is for people aged 18 and over.
Tanishq Ahire
Schadowstrasse 31, 3 OG Links
45147 Essen
Germany
Email: tahire29@gmail.com
1. Data we collect
- Account: your phone number, used to sign you in with a one-time SMS code.
- Profile: your first name, age, gender, an optional short bio and optional photos (up to three).
- Location: your device's approximate location at the moment you open the venue list, only to show venues within about 5 km. It is sent to our server to calculate distances and is not saved in our database. We do not track you in the background and we do not store your precise coordinates. Short-lived technical logs of our hosting provider may contain the request.
- Tonight's activity: the venue you check in at, the interest tags you choose, winks and matches, any photo/video/text “story” you post, and the optional note you write for a match (for example “red hat, by the bar”). This is cleared when the night ends.
- Venues you add: the venue's name, type and address. Venues are visible to all users. If you add a venue as an owner or staff member, we also keep the work email you give us.
- Safety data: people you block, and reports you make or that are made about you.
- Technical data: your IP address and basic request data are processed by our hosting and SMS providers when you use the app.
We do not use advertising, analytics or tracking tools, and the app contains no third-party tracking code. Fonts are bundled in the app, so nothing is loaded from Google or other font services.
2. Why we use it, and the legal basis
- To provide the service you asked for: sign-in, nearby venues, check-ins, winks and matches (Art. 6(1)(b) GDPR, performance of a contract).
- To use your location to show nearby venues, when you allow it on your device (Art. 6(1)(a), consent; you can withdraw it in your device settings at any time).
- To keep the community safe, handle reports and block abuse (Art. 6(1)(f), our legitimate interest in a safe service).
- To meet legal obligations, such as answering lawful requests (Art. 6(1)(c)).
We never use your phone number for marketing.
3. Who sees your data
Other users. People checked in at the same venue can see your check-in card (first name, age if you allow it, bio, tags). Photos and videos are never shown to other people unless you both wink at each other. They are then visible to the two of you only while the one-hour match window is open. Our server withholds them from everyone else. Turning on “Invisible” hides you from the venue list.
Service providers (processors), who handle data only on our instructions:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database and server hosting | All app data | EU (Frankfurt, Germany); provider is a US company |
| Twilio | Sending the sign-in SMS | Your phone number | Provider is a US company |
| Photon (komoot) | Turning a venue address into map coordinates | Only the venue address, never personal data | Germany |
We do not sell your personal data and do not share it for advertising.
4. Transfers outside the EU
Where a provider is based in the United States (Supabase, Twilio), transfers rely on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses. Your app data is stored in Frankfurt.
5. How long we keep it
- Tonight's check-ins, winks, matches, match notes and stories are deleted when the night rolls over.
- Your profile and account are kept until you delete your account. Sign-in sessions expire after 90 days.
- When you delete your account, your data is erased straight away from our database, including your profile, activity and venue applications. Copies in our provider's technical backups are overwritten on a short rolling schedule. Venues you added stay on the map, but without a link to you.
- Safety reports may be kept longer when needed to protect people or to meet a legal obligation.
6. Your rights
You can ask for access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interests. In the app you can download everything we hold about you (Profile → Settings → Download my data) and delete your account (Profile → Settings → Delete account). You can also write to tahire29@gmail.com; we answer within one month. See also how to delete your account.
You may complain to a data protection authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (www.ldi.nrw.de); you can also contact the authority in your own country.
There is no automated decision-making or profiling that has legal or similarly significant effects on you.
7. Children
BuD is only for people aged 18 and over. We do not knowingly collect data from anyone under 18 and will delete it if we learn we have.
8. Security
Data is encrypted in transit, stored in an EU hosting region, and other users cannot see more than the rules above allow. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.
9. Changes
If we make material changes to this policy we will tell you in the app before they take effect. The date at the top shows the latest version.
10. Contact
Questions or requests: tahire29@gmail.com or by post to the address above.