1Controller and contact
The controller within the meaning of Article 4(7) GDPR is Room4 Solutions, German sole proprietorship (Einzelunternehmen), Elisenstr. 3, 45888 Gelsenkirchen, Germany, represented by Seyd Njoya. The business is not entered in the German commercial register (Handelsregister). As a small business within the meaning of § 19 UStG (Kleinunternehmer), no VAT is charged; the business has no VAT identification number.
For any data protection question and to exercise your rights, write to contact@meetdo.fun.
Data protection officer: none appointed. Where the conditions of Article 37 GDPR are not met and no officer has been appointed, the contact address above is the point of entry.
2Principles and scope
This policy covers the meetDo mobile app on iOS and Android and the associated servers. It does not cover third-party services reachable from the app, which have privacy notices of their own.
We collect only the data a feature actually needs, and only for as long as it is used. No personal data is sold and no advertising network is embedded.
What is optional
Without an account the app cannot be used — that is the contract. Location and push notifications, by contrast, are genuine choices: you can decline them and withdraw them at any time, and the rest of the app remains open to you.
3Overview of processing activities
Purpose, categories of data, legal basis and retention — activity by activity.
3.1 Account and authentication
- Data: email address, password hash, display name, registration date, session and refresh tokens.
- Legal basis: Article 6(1)(b) GDPR — performance of the user contract.
- Retention: for the life of the account, then 30 days before final erasure.
3.2 Public profile
- Data: display name, profile picture, level, activities practised, optional details.
- Legal basis: Article 6(1)(b) — without a visible profile no match can be made.
- Retention: for the life of the account; changes take effect immediately.
3.3 Slots and programmes
- Data: title, description, activity, date and time, meeting point and coordinates, participant list, rhythm and duration of a programme.
- Legal basis: Article 6(1)(b).
- Retention: for the life of the account; past sessions for up to 24 months for your practice statistics.
3.4 Messaging between members
- Data: content, sender, recipient, timestamp, read status.
- Legal basis: Article 6(1)(b).
- Retention: until deleted by those involved, at the latest when the account is closed.
3.5 Location and proximity search
- Data: precise device coordinates, search radius, addresses you type.
- Legal basis: Article 6(1)(a) — your consent, given through the operating system dialog.
- Retention: a position is processed for the duration of the search and is not kept as a history; the coordinates of a meeting point stay with the slot.
3.6 Push notifications
- Data: device token, device type, language, notification preferences.
- Legal basis: Article 6(1)(a) — your consent.
- Retention: until consent is withdrawn, until uninstall, or after 90 days of an invalid token.
3.7 Online status and attendance
- Data: last activity time, attendance confirmations for slots.
- Legal basis: Article 6(1)(b), under the control of the "online status visible" setting.
- Retention: the status is continuously overwritten and never historised.
3.8 Badges and progress
- Data: number of participations, badges earned, derived statistics.
- Legal basis: Article 6(1)(b).
- Retention: for the life of the account.
3.9 Safety and abuse prevention
- Data: reports and their content, suspension decisions, technical characteristics of abusive access.
- Legal basis: Article 6(1)(f) — our legitimate interest in protecting users and the service; the balance tips in your favour as soon as the data is no longer necessary for that purpose.
- Retention: up to three years, matching the limitation period for possible claims.
3.10 Technical logs
- Data: IP address, timestamp, endpoint called, status code, app version, operating system, error reports.
- Legal basis: Article 6(1)(f) — operational security, diagnostics, defence against attacks.
- Retention: 30 days, up to 12 months in the event of a documented security incident.
3.11 Support requests
- Data: the content of your message, contact address, account concerned.
- Legal basis: Article 6(1)(b) and (f).
- Retention: three years after the request is closed.
4Location data in detail
Proximity search and the map only work with your device's precise position. We ask for it only when you actually open one of those features — not at installation, and never in the background.
Withdrawable at any time
Consent to location processing is given through the iOS or Android system dialog and withdrawn the same way: in your device settings, without giving reasons, with immediate effect for the future. The app remains usable afterwards, simply without proximity search.
We keep no location history. A position is used to compute distances and then discarded. The only coordinates stored durably are those of meeting points you have yourself attached to a slot or a programme — they are content, not a movement profile.
The "public location" setting on your profile decides whether other members see a location for you. It is independent of the system permission: one allows us to process, the other governs visibility.
5Messaging
Messages are transmitted encrypted and stored on our servers so that you find them again on a new device. We do not use end-to-end encryption at present: we are technically able to access content, but do so only to handle a report or on the basis of a legal obligation.
Messages are not analysed for profiling, advertising or model training.
The "receive messages" setting determines who may write to you. Deleting a conversation removes it from your view; the copy held by the other person remains, as it forms part of their own data.
6Push notifications and device token
To send notifications, your operating system generates a device token — an identifier that designates your device to the delivery service. We store it with your account and pass it to Firebase Cloud Messaging (Android) or to the Apple Push Notification service (iOS).
The content of a notification necessarily passes through those services. We therefore keep it to the minimum and avoid including sensitive information.
You can turn notifications off entirely in your device settings, or tune them type by type in the app. The token is deleted as soon as you withdraw consent, uninstall the app, or the delivery service reports it as permanently invalid.
7Recipients and processors
Inside the app, other members see what you publish: your profile, your slots and programmes, the messages you send them. Beyond that, we pass data only to the following providers, each bound by a processing agreement under Article 28 GDPR and limited to what they need to deliver their service.
- Railway — hosting of the servers, the database and uploaded files.
- Google Maps Platform and Places API — map display and address autocompletion; requests contain the coordinates needed for display.
- Firebase Cloud Messaging (Google) — delivery of notifications to Android devices.
- Apple Push Notification service — delivery of notifications to iOS devices.
- App Store (Apple) and Google Play — distribution of the app and handling of any purchases; in that respect these providers act as independent controllers.
We also disclose data where the law requires it, in particular to law enforcement authorities on the basis of a valid request.
8Transfers outside the European Union
Some of the providers listed are established in the United States or operate part of their infrastructure there. A transfer of personal data outside the European Union may therefore take place.
Such transfers are governed by the European Commission's standard contractual clauses under Article 46(2)(c) GDPR, except where an adequacy decision under Article 45 applies — for the United States, the recipient's certification under the EU-US Data Privacy Framework.
A copy of the applicable safeguards is provided on request at contact@meetdo.fun. Where a provider allows it, we prefer its European regions.
9Retention periods
We keep personal data only for as long as the purpose requires, then erase it or irreversibly anonymise it.
- Active account: for the whole of the contractual relationship.
- After account deletion: a 30-day grace period — it protects against accidental deletion — then permanent removal from production systems.
- Backups: overwritten no later than 90 days after deletion; until then they are inaccessible outside a restore procedure.
- Technical logs: 30 days, up to 12 months in the event of a security incident.
- Reports and suspension decisions: up to three years.
- Accounting records for paid services: up to ten years, in line with commercial and tax retention obligations.
10Your rights
The GDPR gives you the following rights. Exercising them is free: an informal email to contact@meetdo.fun is enough, and we answer within one month.
- Access (Article 15): a copy of the data we process about you, with the purposes, recipients and retention periods.
- Rectification (Article 16): correction of inaccurate data and completion of incomplete data — for most fields, directly from your profile.
- Erasure (Article 17): deletion of your data, unless a legal retention obligation stands in the way.
- Restriction (Article 18): suspension of processing while accuracy or a balancing of interests is verified.
- Portability (Article 20): return of the data you provided to us, in a common, machine-readable format.
- Objection (Article 21): to processing based on legitimate interest, on grounds relating to your particular situation.
- Withdrawal of consent (Article 7(3)): at any time, for the future — in particular for location and notifications.
Identity check
We answer a request only once we are satisfied it comes from you. The email address on your account is usually enough. If serious doubt remains we ask one targeted question — never more than necessary, and never for a copy of an identity document where a lighter check will do.
11Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, Article 77 GDPR gives you the right to lodge a complaint with a supervisory authority — in the Member State of your residence, of your place of work, or of the alleged infringement.
The authority competent for us is Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, the supervisory authority for North Rhine-Westphalia, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany. A complaint does not require that you contact us first — we would nonetheless welcome the chance to resolve the matter ourselves.
12No automated decision-making
No automated decision within the meaning of Article 22 GDPR producing legal effects concerning you or similarly significantly affecting you is carried out.
Suggestions of activities and members are based on distance, chosen activities and availability. They order what is shown to you and exclude no one; the decision to message someone or join a session is entirely yours.
Suspension decisions are always taken or confirmed by a human being. You may contest them (clause 13 of the terms of use).
13Security of processing
In accordance with Article 32 GDPR we implement technical and organisational measures appropriate to the risk, in particular:
- Encryption of all communication between app and server, according to the state of the art.
- Storage of passwords solely as a salted, non-reversible hash.
- Short-lived session tokens with a renewal mechanism, so that an intercepted token quickly becomes worthless.
- Access to production data restricted to those who need it, and logged.
- Regular backups and restore tests.
- Notification of a personal data breach to the supervisory authority within 72 hours and, where the risk is high, to the individuals concerned (Articles 33 and 34 GDPR).
14Minors
The app is not directed at people under 16. We do not knowingly collect data about children.
If we learn that an account is held by a younger person, we suspend it and delete the associated data promptly. Parents and guardians can report such a case to contact@meetdo.fun.
15Cookies, trackers and device identifiers
The app is a native application: it sets no advertising cookies and embeds no tracking pixels.
- Local device storage: session token, language choice, display mode and notification preferences. Necessary for operation, never leaves the device.
- Device token for notifications: see clause 6, subject to consent.
- Map display: Google Maps may set identifiers of its own to serve tiles; Google's privacy notice applies in addition.
We do not read the operating system advertising identifiers (IDFA, Advertising ID). No cross-app or cross-site tracking is carried out.
16Changes to this policy
We adapt this policy when the app, our providers or the law change. Only the version available in the app is authoritative; its version and effective date appear at the top of the document.
We announce any substantial change — a new category of data, a new purpose, a new recipient — in advance by email and in the app. Where a change requires your consent we obtain it separately: we never base new processing on your merely continuing to use the app.