Privacy Policy
GB7 Meetup (“we”, “us”) is a social discovery and meetup platform — a community service, not a dating service. This policy explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you have. We build around data minimisation, purpose limitation, and transparent location handling.
1. Controller
The controller responsible for processing your data is:
Grispin Bauknecht (operating as “GB7 Social”), Höhenstraße 16, 70736 Fellbach, Germany. Contact:
dev@gb7social.com. Full provider details are in our
Legal Notice.
2. Data we process
- Account: email address, username, a securely hashed password, email-verification status, and two-factor settings (for authenticator-app 2FA a secret; recovery codes are stored only as hashes).
- Profile (optional): display name, biography, home city/country, interests, languages, and a profile photo. Uploaded photos are re-encoded on our server, which removes all embedded metadata including EXIF GPS.
- Location: the address or place you enter is used only to compute an approximate public point. Your exact coordinates are never published; for travel plans the exact destination is never stored. Precision (approximate / neighbourhood / city) is your choice.
- Content: posts (photos + a city-level location), travel plans, chat messages, connections, and “want to go here” place interests.
- Device & technical: session records (device name, hashed access/refresh tokens), a push-notification device token if you enable notifications, and your IP address — processed transiently for security and rate limiting.
- Safety: reports and blocks you submit, and audit-log entries for security-relevant actions (e.g. sign-in, password change).
3. Why we process it & legal bases (GDPR Art. 6)
- To provide the service — accounts, discovery, chats, connections, posts (Art. 6(1)(b), performance of a contract).
- Location, photos, push notifications, optional profile fields — based on your consent and the choices you make in the app (Art. 6(1)(a)); you can withdraw at any time in Settings or your device settings.
- Security, abuse prevention, and keeping the community safe — verification, rate limiting, reports/blocks, audit logs (Art. 6(1)(f), legitimate interests).
- Legal obligations where applicable (Art. 6(1)(c)).
4. Sharing & processors
We do not sell your personal data. We share it only with service providers acting on our behalf and only as needed:
- Hosting: IONOS SE (servers located in the EU/Germany).
- Push notifications: Apple Push Notification service (Apple Inc.) — only your device token and the notification content, when you enable notifications.
- Other members: your public profile, approximate location, and content are visible to other members according to your privacy & visibility settings.
Place descriptions and ticket links shown for map locations are fetched by your device from Wikipedia and GetYourGuide respectively; when you open those, their own privacy terms apply.
5. International transfers
Where a processor (such as Apple, for push delivery) processes data outside the EU/EEA, the transfer is safeguarded by the EU Standard Contractual Clauses or an equivalent mechanism.
6. Retention
We keep account and profile data for as long as your account exists. Messages and content remain until you or your counterpart delete them or you delete your account. Security logs and rate-limit records are kept only briefly. When you delete your account, we delete or irreversibly anonymise your personal data, except where we must retain limited records to meet legal obligations.
7. Security
Transport is encrypted with TLS. Passwords are hashed with bcrypt; access/refresh and reset tokens are stored only as hashes. Photos are stripped of metadata. Optional two-factor authentication (authenticator app or email code) adds a second step at sign-in. Location is obfuscated before it is ever made public.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise these rights, contact dev@gb7social.com. You may adjust visibility, location precision, and notifications yourself in Settings, and request account deletion in the app. You also have the right to lodge a complaint with a data-protection supervisory authority.
9. Cookies & local storage
The public website uses only what is necessary and does not use advertising or tracking cookies. The login page uses your browser’s session storage to hold your sign-in token for the current session. See our Cookie Information.
10. Children
GB7 Meetup is not intended for anyone under 16. We do not knowingly process data of children under 16.
11. Changes
We will update this policy as the service evolves and post the new version here with a revised date.
12. Contact
Privacy questions: dev@gb7social.com.