Where To?

Privacy Policy – Where To?

Effective Date: October 6, 2026 · Last updated: October 6, 2026

1. Introduction

This Privacy Policy explains how Where To? (“Where To?”, “App”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the iOS or Android App and related public pages and services.

We aim to collect only the data reasonably needed to provide, secure, troubleshoot, and improve the service. We do not sell personal data, share it with data brokers, or use it to track you across other companies’ apps or websites. Sponsored placements are contextual rather than behavioral.

2. Data Controller

The controller responsible for this service is:

Hidde van Hall

Netherlands

Email: hello@wheretoapp.nl

3. Scope

This Policy applies to the Where To? mobile apps, account and social features, invite and plan-sharing pages, and our related legal and support pages. It does not replace the privacy notices of Apple, Google, Supabase, Vercel, or other third-party services you choose to use.

4. Personal Data We Collect

4.1 Account and Profile Data

Depending on how you sign in and what you choose to add, we process:

We do not automatically use a provider profile picture as your in-app avatar. An avatar is uploaded only when you choose one.

4.2 Social Activity and User Content

We process information you create or share through the App, including:

Where communities are available, this also includes community memberships and owner roles, invitations, fixed event cards, your optional attendance answers, personal status-publication choices, and cancellation or replacement records. A cancellation is recorded as a member's report, including who marked it and when; it is not an independently verified statement from the event organiser. Accepted community members can see who chose to attend. Joining a community does not make its members your friends or give them access to your other plans or live status. Ghost Mode, friend audiences and hiding a plan from your status control personal publication; they do not remove your explicit attendance answer inside the community.

Reports are confidential. We do not tell the reported person or other users who submitted a report, although the reporter’s account identifier may be retained internally for moderation and abuse prevention.

Where To? does not access, upload, or import your device address book or an external contact list. Friendships and groups are created within the App.

4.3 Location and Venue Data

Location features are optional and depend on your settings and device permissions. We process:

On Android, active-plan monitoring may use geofences or a location foreground service with a visible notification. On iOS, it may use Core Location background updates, significant-location changes, visits, or region monitoring.

Raw live device fixes and distance calculations are used on the device for the location feature. They are not sent to our first-party backend as device coordinates and are not retained by us as a movement trail. Apple, Google, or their map and location services may process device location when providing their platform services under their own privacy notices. Our first-party diagnostic records do not store device coordinates, plan identifiers, or location trails; beta test builds may additionally record deliberately coarsened distance and accuracy values as described in Section 4.5.

We use the selected venue coordinates already stored with plans to create internal geographic planning analytics. The administrative activity map groups plans into geographic grid cells and does not expose individual plans, user identifiers, or exact venue coordinates. A grid cell is given a location on the map only when at least three distinct users have plans in that cell in either the selected reporting period or its comparison period. Quieter cells are not placed on the map, although their activity may be included in overall non-geographic totals. The map is generated from retained plan records when requested; it does not create a separate heat-map dataset or user movement history.

We do not build route histories or maintain a continuous movement log. Venue coordinates, status, and timestamps can remain part of a plan record for as long as that plan is retained.

You can deny or withdraw location permission. Background status updates will then stop, but information already shared or retained under this Policy is not automatically erased.

4.4 Search Data

When you search for venues, events, or other profiles, the search text is sent to the provider needed to return results. This may include Apple MapKit on iOS, Google Places on Android, or our Supabase-backed curated-event and profile search. We do not retain raw search text in our first-party database after servicing the search. Recent selected venues, but not a server-side search history, may be stored locally on your device.

We do not place raw search text in our own app-flow analytics or client diagnostic records. We may record only categorical search-flow events, such as starting a search or receiving no results. Search and map providers may process requests under their own terms and privacy notices.

4.5 Identifiers, Analytics, Advertising, and Diagnostic Data

We may automatically process limited technical and operational data, including:

Product-interaction and sponsored-placement records use an internal account identifier so we can count unique activity, limit duplicate events, detect invalid activity, and produce aggregate measurements. They do not contain names, email addresses, raw search text, advertising identifiers, or raw device location. We do not combine them with data from other companies’ apps or websites for advertising.

Except for the beta-build diagnostics described below, our first-party client diagnostics use a short-lived random session identifier and are not linked to your account. They do not contain crash reports, raw error messages, stack traces, device models, screen metrics, names, usernames, email addresses, raw search text, authentication or notification tokens, plan identifiers, or device coordinates. They are used only to investigate operational failures and maintain reliability, not for product analytics or advertising. Repeated copies of the same failure are limited, and these records are kept for no more than 30 days. The App may still produce operating-system crash and performance information made available to us through Apple App Store or Google Play developer tools according to your device and store settings; that information is governed by your device and store settings.

Beta test builds. If you use a pre-release version of the App installed through Apple TestFlight or a comparable beta program, the App also sends us account-linked troubleshooting diagnostics so we can investigate why an automatic arrival or departure update did or did not happen for a specific tester. These consist of an occasional snapshot of feature-relevant device settings (platform, operating-system version, App version and build, location-permission mode, and whether location services, background refresh, and notifications are enabled) and short categorical records of the App's arrival and departure decisions (the processing step, its outcome, the App's foreground or background state, and — for a plan you created — the selected venue's name, plan date, plan status, configured radii, and a deliberately coarsened distance and accuracy value). These records never contain device coordinates, routes, or movement trails, and they are limited and rate-limited on the device. Public App Store and Google Play releases do not send these records for ordinary accounts. On iOS, the App enables this reporting only when it detects at runtime that it was installed as a TestFlight beta build. On Android, where the store offers no equivalent install signal, this reporting stays disabled unless our backend confirms that the signed-in account has been individually enrolled as a tester, and the backend additionally refuses these reports for accounts that are not enrolled. Both checks fail closed, and unsent records are deleted when reporting is disabled. Beta decision records are kept for no more than 7 days and beta device-settings snapshots for no more than 30 days.

4.6 Photos, Camera, QR Codes, Notifications, and Local Storage

If you select an avatar, the App accesses only the image you select, prepares it on the device, and uploads the final image to Supabase Storage.

If you scan a Where To? QR code, the App uses the camera to process barcode frames on-device. Camera frames and scanned images are not uploaded or retained by us.

If you enable notifications, we process your preferences and an Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) device token, together with the limited platform and app information needed to deliver notifications.

The App stores limited information locally, which may include recent venue selections, active-plan monitoring details, cached avatar previews, authentication session data, push registration state, App preferences, and dated snapshots of your plans and the friend information shown in the App. Dated offline snapshots are deleted when their relevant App day has passed or 30 days after their last successful refresh, whichever happens first. Signing out clears offline snapshots, recent venue selections, queued status changes, and active-plan monitoring details so another account on the device cannot inherit them. Account deletion also clears account-specific App preferences, the saved calendar destination, and calendar-export bookkeeping. Past entries already written into your personal calendar remain under your control there; Where To? removes entries dated today or later when you sign out, delete your account, or turn calendar export off.

4.7 Calendar Export

Calendar export is optional and one-way. If you turn it on, Where To? adds your own plans to one calendar you choose and keeps those entries up to date when a plan moves or is cancelled. Calendar access is used only to create, identify, update, move, and remove entries created by Where To?. The App checks calendar entries for its own identifying marker; it does not import, analyse, store, or otherwise use unrelated events, and unrelated events are not uploaded to our backend. Editing or deleting a calendar entry does not change the original plan in Where To?.

An exported entry may contain its title and date, an optional time, the group name or plan state, the planned place, and a link back to the plan. On iPhone, the entry may also contain a structured location with the planned place's coordinates. Private plans and plans made while Ghost Mode is on can still be exported because those controls govern visibility inside Where To?, not copies in your personal calendar.

If you answer that you are going to a community event, that personal commitment can export while calendar sync is enabled, including when you hide it from your status. Browsing, joining a community or posting an event without choosing to attend does not export its events. A replacement event requires a fresh attendance answer.

The calendar provider you choose may synchronize exported entries to its servers and your other devices under its own terms and privacy notice. Providers can include Apple/iCloud, Google, Microsoft/Outlook/Exchange, or another calendar account configured on your device. Anyone who can access a shared, family, or work calendar you select may see exported plans and, for timed entries, the calendar's free/busy information. The destination picker warns about this before the first export.

Our backend receives only whether calendar export is enabled. It receives no calendar names, unrelated events, exported entries, entry counts, or calendar analytics. The selected calendar and the bookkeeping used to recognize entries created by Where To? stay on the device.

Turning calendar export off or deleting your account removes entries dated today or later when the App still has calendar access. Past entries remain. Upcoming entries may also remain if calendar permission was withdrawn before cleanup could run; you can delete any remaining entries in your calendar application. A Where To? calendar created locally on your device remains under your control and is not deleted automatically.

4.8 Illegal-Content Reports and Moderation Records

Anyone — including people without a Where To? account — can report content they believe is illegal through our public report form. For these reports we process the reporter's name and email address (both optional for reports of child sexual abuse material), the description of the reported content, the explanation given, and our correspondence about the report, in order to receive, review, and decide on the report and to inform the reporter, as required by the EU Digital Services Act.

When we take a moderation decision, we keep a record of that decision — what was decided, on what ground, and the statement of reasons sent to the affected person. Reports are kept for up to 12 months after they are closed, and decision records for as long as reasonably necessary for safety, enforcement, appeals, and legal obligations. Reporter identities are kept confidential from the reported person.

4.9 Public Pages and Shared Links

When you open a public invite, group, QR, calendar-plan, plan-sharing, or profile-sharing page, our web host may process the link identifier together with IP address, browser, device, timestamp, and standard request or security logs. Invite, group, QR, and plan pages may display limited profile, group, venue, date, or plan-preview information that a user chose to share. The public fallback for a shared profile is generic and does not display the profile owner’s name, username, avatar, friendship state, or plans.

An accepted friend may share another friend’s profile link. The target profile’s display name, username, and avatar are resolved only after the recipient opens the link inside Where To? while signed in. Plans remain subject to the normal friendship and visibility rules.

Any accepted member of a group can create and distribute a public link for one group-plan card. Anyone with the link may see the limited web or chat preview. Depending on the card, that preview may show the group name and avatar, date or date range, plan or poll name, response counts, leading date or place, venue and time, and up to four participant avatars indicating availability or attendance. Participant names, raw device location, live movement, and the rest of the group are not part of the public preview. Only accepted group members can open the full group plan inside the App. An invited person must join the group first, and a stranger cannot use the link to enter or inspect the group.

Public plan previews are designed not to expose raw device location or a live movement history. Links can be forwarded, so anyone who receives a working link may be able to view its limited preview.

Community invitation previews may show the community name, image and member count. Community event previews may show the community name or image, event name, date, planned venue and time, up to four attendance avatars, attendance count, cancellation or replacement state, and a replacement link. A terminal event labels prior attendance as historical. Participant names, personal publication settings and live status are excluded. Opening a link does not accept an invitation or answer attendance, and full community access requires accepted membership.

5. How We Use Personal Data

We use personal data to:

We do not make decisions that produce legal or similarly significant effects about you solely through automated processing.

6. Legal Bases for Processing

Where the General Data Protection Regulation or similar law applies, we rely on one or more of these legal bases:

You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal or processing based on another lawful basis.

7. When We Share Data

7.1 Other Users and Link Recipients

We share profile, status, plan, venue, and group information with friends, group members, or link recipients only as needed for the social and sharing choices you make. Another group member may create a public link whose limited preview includes information about your availability or attendance as described in Section 4.9. Visibility inside the App still depends on your settings, group participation, and Ghost Mode; possession of a group-plan link does not grant membership or full group access.

7.2 Service Providers

We use providers that process data to operate the service:

Depending on the feature, these providers may receive identifiers, IP address, device information, map or Places requests, venue search input, approximate or precise location supplied to their APIs, or push-delivery metadata. When an administrator uses our internal activity map, Apple MapKit receives map requests and aggregated grid-cell coordinates, but not the underlying user or plan identifiers. These providers process data under their own terms and privacy notices.

We require service providers to handle data for the services they provide and under applicable contractual and data-protection obligations. We assess and use appropriate safeguards where required.

7.3 Venue Partners

Sponsored or promoted venues may receive aggregated reporting such as impressions, taps, plans created, or verified arrivals. Sponsors do not receive names, emails, usernames, friend graphs, raw device location, movement history, device identifiers, or individual user records solely because of a sponsorship.

The internal event records are linked to an account identifier, but sponsors receive only aggregated campaign reporting. We retain the internal records as needed to calculate those aggregates, detect invalid activity, administer a campaign, resolve disputes, and meet applicable accounting obligations. Sponsored placements are identified in the App.

7.4 Legal, Safety, and Business Disclosures

We may disclose information when reasonably necessary to comply with law or a lawful request, enforce our Terms, investigate misuse, protect users or the public, establish or defend legal claims, or support a reorganization or transfer of the service subject to appropriate safeguards and notice where required.

8. Retention

We retain data only for as long as reasonably needed for the purposes described above:

When you delete your account, account-linked data is deleted or anonymized as described on our Account Deletion page, subject to shared records, moderation and safety needs, legal obligations, dispute resolution, fraud prevention, and backup cycles.

9. Your Choices and Rights

You can:

You can also review deletion instructions on our Account Deletion page.

An authentication identifier, username, and display name are required to create and operate an account. If you do not provide them, we cannot provide the account-based Service. Calendar export and permission, location permissions, background location, notifications, camera access, photo uploads, friend aliases, group-plan names, and custom report text are optional, although declining a permission prevents the related feature from working. Withdrawing calendar permission stops synchronization and can prevent the App from removing entries it previously created.

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy of certain data; withdraw consent; and lodge a complaint with a supervisory authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.

Send privacy and rights requests to hello@wheretoapp.nl. We may need to verify your identity before completing a request.

10. International Transfers

Our primary database and backend infrastructure is hosted by Supabase in the United Kingdom (London). The United Kingdom is covered by a European Commission adequacy decision, which means the European Commission has formally determined that it provides an adequate level of data protection.

Other providers may process data outside your country, including in the United States. Where required, we use or rely on lawful transfer safeguards such as adequacy decisions, the European Commission’s Standard Contractual Clauses, the EU-US Data Privacy Framework, or another valid transfer mechanism. You may contact us for more information about the safeguards relevant to your data.

11. Security

We use reasonable technical and organizational measures designed to protect personal data, including encrypted transmission, authentication controls, access restrictions, row-level database controls, restricted administrative access, and data minimization. No service can guarantee absolute security.

12. Children

You must be at least 16 years old to create or use a Where To? account. The service is not directed to children under 16, and we do not knowingly collect personal data from them.

If we learn that someone under 16 has provided personal data, we will take reasonable steps to remove the account and data. A parent or guardian who believes this has happened can contact us. More information about our safety standards is available on our Child Safety Standards page.

13. Changes to This Policy

We may update this Policy as the service, law, or our providers change. We will post the revised Policy with a new effective date and provide additional in-App or other notice when a change is material and notice is required.

14. Contact

For privacy questions, requests, or complaints:

hello@wheretoapp.nl

© Where To? — Hidde van Hall, Netherlands