Privacy Policy
What data we collect, why, who processes it, and your rights.
Who we are
The data controller is offline (the "Operator"). Contact: in the app under Settings → Help → "Message us". Further contact details for the Operator will be added before launch.
What data we collect
• Identification: name, email, date of birth, age, and whether the user is under 18 (`isUnder18`) for adult-content filtering.
• Gender: female/male/other. Not publicly shown on your profile — used solely to gate access to the "Women only" safety feature for private events. Processed on the basis of legitimate interest (Art. 6(1)(f) GDPR) and in accordance with Slovak Anti-Discrimination Act 365/2004, which permits differential treatment based on gender if it pursues a legitimate aim (here: women's safety at offline meetups). The value cannot be changed in the app after first setting — corrections are handled via support.
• Profile: photos, bio, interests, preferred search radius, home location (if you set one).
• Activity: created events, attendance (with GPS verification), swipes (Yes/No after event — kept only to enable the post-event match window; auto-deleted 90 days after the event), bookmarks, reviews, messages.
• Interaction and usage data: which events you are shown, which you open, how long you view them, which you dismiss as "not interested", and that a search occurred (we store the search's length and whether it led to a tap, never the raw search text). We use this to improve the service and for personalized event recommendations. We process it on the basis of legitimate interest (Art. 6(1)(f) GDPR), retain it for a maximum of 12 months, and you can object at any time — see "Your rights" below.
• Matching is purely mechanical (mutual Yes) and involves no automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR. The event feed is personalized: its order is driven by your own interaction history (which events you open and which you dismiss), your declared interests, the distance from your home location and how soon the event starts; an organizer can also pay to promote an event so that it ranks higher. This ranking likewise produces no legal or similarly significant effects on you within the meaning of Art. 22 GDPR. You may object to this processing at any time in Settings → "Personalized recommendations" (Art. 21 GDPR); once personalized recommendations are switched off we stop collecting your interaction data and do not use it to order the feed; the remaining parameters — your chosen interests, distance from your home location and how soon the event takes place — still apply, and paid promotion remains the strongest factor: an event with paid promotion outweighs all the other parameters combined.
• Affiliate: unique code and the inviter's code (`affiliateReferredBy`) — stored permanently for the affiliate program. The code is invisible to third parties except the operator.
• Communication behavior: list of muted chats, pinned chats, notification preferences. Processed for app functionality (Art. 6(1)(b) GDPR).
• Notification token (Expo Push) — used solely to deliver notifications. Explicitly nulled before cascade on account deletion.
• Technical: device model, logs, anonymized errors.
• Payment: via Stripe. The Operator does not see card numbers — they are processed only by Stripe.
Why we process data (legal basis)
• Performance of contract (Art. 6(1)(b) GDPR) — without this the App cannot function.
• Consent (Art. 6(1)(a) GDPR) — for marketing notifications and optional extensions.
• Legitimate interest (Art. 6(1)(f) GDPR) — security, fraud prevention, analytics.
• Legal obligation (Art. 6(1)(c) GDPR) — accounting and tax obligations.
Retention period
• Account and profile: during account lifetime.
• Group chats: kept 1 month after event end, then automatically deleted. After account deletion, your messages in group chats remain with an anonymized signature "Deleted account" — based on the legitimate interest of other participants (Art. 6(1)(f) GDPR).
• Direct chats: until deleted by one of the participants or until account deletion.
• Payment records: 10 years (statutory accounting obligation — Slovak Act 431/2002). This data is also retained by our processor Stripe.
• Application error logs: 30 days (TTL set in database; legitimate interest — diagnostics and service stability). We do not collect IP addresses.
• Swipes (Yes/No after event): auto-deleted 90 days after event end (legitimate interest — match window functionality; not usable beyond that window).
• Firebase backup window (Point-in-Time Recovery): 7 days.
Processors (third parties)
Selected personal data is processed by our processors, contractually bound under Art. 28 GDPR (DPA). Transfer of data outside the EEA is covered by Standard Contractual Clauses (SCC) per EC Decision 2021/914 or by an adequacy decision.
• Google Ireland Ltd. (Firebase) — authentication, Firestore database, Storage, Cloud Functions, hosting. Data held in europe-west1 region (Belgium, EEA). Safeguard: DPA + standard GDPR clauses.
• Stripe Payments Europe Ltd. (Ireland) — payment processing, KYC for business accounts (Stripe Connect), refunds, dispute management. Some technical data may be processed by Stripe Inc. (USA) — covered by SCC. Safeguard: Stripe DPA, PCI-DSS Level 1.
• Expo (Pollux Labs Inc., USA) — push notification infrastructure (Expo Push API). Push token + notification body (title + message preview) pass through US infrastructure. Safeguard: SCC.
• Apple Inc. (USA) and Google LLC (USA) — APNs and FCM delivery infrastructure for push (via Expo). Safeguard: SCC.
The following parties are not our processors — we have no Art. 28 GDPR contract with them, they do not act on our instructions, and they are responsible for their own processing. They are public map services, and without them the map cannot be displayed. When the map loads they receive your IP address and the map area you are viewing; when you search for an address, the text you type as well. Your account, your name and anything you create in the app are not sent to them.
• OpenStreetMap Foundation (United Kingdom) — map tiles and address search (Nominatim) on the website, and venue lookup in the app (Overpass).
• Google (on Android) and Apple (on iPhone) — the map component inside the app itself. The map is drawn by the operating system's map service, which receives the area being displayed.
Fonts and the map library on the website are served from our own servers, so loading a page sends nothing to any other party.
Retention in backups: Firebase Firestore has system backups (Point-in-Time Recovery) with max 7-day retention. After account deletion, personal data may persist in backups for max 7 days, during which they are not actively used.
The current list of processors may change — we will update this policy and version-tag the change when a new processor is added.
Your rights
• Right to access your data.
• Right to rectification of inaccurate data. Some data (date of birth, gender, affiliate code) is immutable after setting in the app to preserve integrity of safety features and the program; corrections go through in-app support (Settings → Help → "Message us").
• Right to erasure ("right to be forgotten"). On account deletion the following is retained: (a) your group chat messages with an anonymized "Deleted account" signature (legitimate interest of other participants, Art. 6(1)(f)), (b) payment records for 10 years in accounting archives (statutory obligation — Slovak Act 431/2002), (c) Firebase backups max 7 days.
• Right to restriction of processing.
• Right to data portability (JSON export via the app, max 1× per 24h per Art. 12(5) — proportionate to cost).
• Right to object to processing carried out on the basis of legitimate interest (Art. 21 GDPR) — including the processing of interaction and usage data for personalized recommendations. You can object at any time in Settings → "Personalized recommendations"; the feed will then stop using your interaction data for personalization.
• Right to lodge a complaint with the Slovak Office for Personal Data Protection.
To exercise your rights, contact us through in-app support (Settings → Help → "Message us").
Geolocation
The App uses device location to show nearby events and verify attendance. You may disable location anytime in OS settings — the App will then use your set home location or the default (Bratislava).
Push notifications and cookies
We send push notifications only if you allow them. Disable anytime in App or OS settings.
The mobile App does not use classic HTTP cookies — it runs as a native app.
The website beoffline.app uses minimal client-side storage (sessionStorage) to temporarily store an invite code from the `?ref=...` URL parameter — this storage is automatically cleared when the browser tab/window is closed. We do not use third-party tracking or analytics cookies. When signing into the business portal (`/ucet/*`), Firebase Auth stores its authentication token locally (IndexedDB), which is "strictly necessary" within the meaning of the ePrivacy Directive (Art. 5(3) exception) — without it you couldn't sign in.
Children
The App is not intended for persons under 16. If we learn of such an account, we will remove it.
Changes to the policy
For material changes we will notify you in the App. We retain older versions.