Skip to main content

DeetsView Privacy Policy

Effective Date: March 10, 2026

1. Introduction

Welcome to DeetsView (“the Service”, “we”, “us”, “our”). We provide a platform designed to help you plan, coordinate, and manage events. This Privacy Policy explains how we collect, use, and protect your information in compliance with the EU General Data Protection Regulation (GDPR) and United States Privacy Laws (including the California Consumer Privacy Act/CPRA).

2. Information We Collect

We collect the minimum amount of data necessary to provide our Service:

  • Identifiers: Name and email address. We store your name so other event participants can identify you (e.g., on task lists or schedules).
  • Account Credentials: Password (stored in an encrypted/hashed format).
  • Event Content: Programs, tasks, and guest lists created by you.
  • Activity-Related Expenses: Cost figures you enter against activities or tasks (e.g., "Dinner at Restaurant X — €50 paid by John"). These figures are personal data under GDPR because they link a person to a financial action. We store them solely to power the group cost-sharing feature. We do not collect or store bank account numbers, credit card numbers, payment-card data, or government-issued IDs of any kind.
  • Authentication: We may offer login via Google, Facebook, and Apple ID. If used, we will receive your name and email from those providers.
  • Data Provided by Others (Invited Guests): If you are invited to an event, the event organiser has provided your name and email address to us. We process this data on the legal basis of the Legitimate Interest of the organiser to coordinate a group event. You may delete your account or decline invitations at any time — see "Your Rights" below.
  • Technical & Security Logs: We collect and store your IP address, browser type, and timestamps of your successful and failed login attempts. We process this data based on our Legitimate Interest to ensure the security of our Service, prevent unauthorized access, and mitigate abuse.
  • App Client Information: When you use the DeetsView app or website while logged in, we record an anonymised device identifier (a randomly generated UUID created on your device and stored locally), the app version you are running, and the platform (e.g. Android or web). We store one record per account per device and update it when your app version changes or after an hour of activity. This data is used solely to understand which versions are in active use and to prioritise compatibility fixes. It is not linked to your behaviour, not used for profiling, and not shared with third parties.
  • Push Notification Tokens (Mobile App Only): If you install the DeetsView Android app and grant the operating-system notification permission, your device generates an opaque Firebase Cloud Messaging (FCM) device token. We store this token against your account so we can deliver push notifications about your events (e.g., RSVP updates, task reminders, Q&A replies). The token does not identify you personally outside our system, is never used for advertising, and is deleted when you revoke notification permission, uninstall the app, or delete your account. You can disable push notifications at any time in your device's operating-system settings, and you can mute individual notification categories under Profile → Notifications.
  • Age Verification: To confirm you are 18 or older, we ask you to self-declare your birth month and year during registration. This information is never transmitted to our servers and is never stored. Only a timestamp recording that age verification was completed is saved against your account. On Android, the Google Play Age Signals API may indicate your age tier (adult / minor / unknown) to the app; this signal is evaluated on your device and is likewise never sent to or stored by our backend.
  • Biometric Authentication (Mobile App Only): If you use the DeetsView Android app and enable fingerprint or face-unlock login, the biometric verification is performed entirely by your device's operating system (e.g., Android BiometricPrompt API). We never receive, transmit, or store your biometric data on our servers. The biometric feature is entirely optional — you may always use your password instead.
  • Aggregate Guest-Funnel Metrics: To understand how invited guests progress from invitation to RSVP, we compute aggregate counts (invitations created, opened, accepted, and responded to) directly from the invitation and RSVP records we already hold to run your events, together with the operational timestamp of when an invitation link was last opened. This involves no behavioural tracking, no cookies, no device storage, and no third party; it is ordinary statistical use of data we already process to provide the Service, so it requires no separate consent. The readout is aggregate counts only and is visible solely to our administrators.

Legal Bases for Processing (GDPR Art. 6): We process your account data (name, email, password) on the basis of Contract performance (Art. 6(1)(b)) — it is necessary to provide the Service. Security and analytics data are processed on the basis of Legitimate Interest (Art. 6(1)(f)). Invited guest data is processed on the basis of the organiser's Legitimate Interest in coordinating a group event. Where required (e.g. cookies beyond essential session management), processing is based on your Consent (Art. 6(1)(a)).

3. US Privacy Disclosures (No Sale of Data)

We do not sell, rent, or trade your personal information to third parties. We do not share your data with third parties for their own marketing or cross-context behavioral advertising purposes. We do not collect "Sensitive Personal Information" as defined by California law (e.g., social security numbers, precise geolocation). Data is only shared with the essential service providers listed below to ensure the Service functions correctly.

4. Internal Data Sharing & Use

The Service is designed to allow collaboration. Content you enter (Event details, guest lists, etc.) is only visible to you and the specific users you explicitly choose to share it with within the platform. We do not make your event data public unless you use a feature specifically designed for public sharing. We use your email address solely to send transactional, service-related messages — such as password resets, login codes, event invitations, RSVP updates, task reminders, poll and Q&A activity, expense alerts, and account-lifecycle warnings (inactivity, soft-deletion, restoration). We do not send marketing newsletters, and you can mute most notification categories under Profile → Notifications.

5. Essential Service Providers

To provide the Service, we use a limited number of "Service Providers" who process data strictly on our behalf. As we are based in Denmark, data transferred to US providers is protected by Standard Contractual Clauses. For service providers based in the United States, we rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses to ensure your data receives an equivalent level of protection as it does in the EU.

  • Hetzner Online GmbH: We host our platform and all user data on servers located in Nuremberg, Germany. No data leaves the EU-central network zone. Hetzner operates under strict EU data-protection law.
  • Zepto / Brevo (Transactional Email): We deliver transactional emails (event invitations, RSVP updates, password resets, login codes, task and Q&A notifications, account-lifecycle warnings) via one of two transactional email providers — Zepto (operated by Zoho Corporation) or Brevo (formerly Sendinblue, operated by Sendinblue SAS). Either provider may be used at any given time at our discretion; only the recipient's email address and the message content needed for delivery are shared with the active provider, and both are contractually prohibited from using this data for their own marketing.
  • Firebase Cloud Messaging (Google LLC): We use Firebase Cloud Messaging (FCM) to deliver push notifications to the DeetsView Android app. When a notification is sent, we transmit only the opaque device token issued by your device and the notification payload (title, short body, and an in-app deep link) to Google's FCM service. We do not transmit your name, email, or event content beyond what is needed to render the notification. FCM is used solely for service-related messages and never for advertising.
  • Cloudflare: Acts as a proxy to provide security (DDoS protection) and performance optimisation. Cloudflare processes technical data like IP addresses to protect the site.
  • Google Analytics 4: We use GA4 to understand website traffic. This data is aggregated and anonymised (IP addresses are not stored). We have disabled data sharing with Google for their own advertising purposes.
  • Map Services (Photon, HERE, OpenStreetMap): To display event locations, suggest addresses, and calculate transport routes, we use three map services through our own backend: Photon (operated by komoot GmbH, based on OpenStreetMap data) for address autocomplete and geocoding, HERE Technologies for route calculation, and OpenStreetMap base-map tiles (rendered in your browser via the open-source Leaflet library). All address and route requests are sent from DeetsView's backend, not your browser or device, so your IP address is not shared directly with Photon or HERE. Only the location text or coordinates you enter are sent to these providers, strictly to fulfil your request. OpenStreetMap tile requests are made by your browser when a map is rendered; the OpenStreetMap Foundation may log standard request metadata (such as IP address) subject to its own policy.
  • Authentication: Google, Facebook, and Apple (only if you choose to use their respective login services).
  • Cookies & Tracking: We use "Essential Cookies" for account security and session management; these are always active. We also use "Analytical Cookies" (Google Analytics) to understand site usage, but only after you accept them via our cookie consent banner — if you choose "Decline Optional", no analytics cookies are set. When enabled, analytics is limited to our public marketing pages (it does not track activity inside your account), your IP address is anonymised, and Google ad/data-sharing features are disabled. You can revisit your choice at any time via the "Cookie Settings" link in the footer. We do not use "Targeting" or "Advertising" cookies. Our web and mobile app also uses a service worker (Progressive Web App technology) to cache assets locally on your device for performance and offline access. This local caching does not involve tracking or profiling.
  • Mobile App (Android): The DeetsView Android app requests the following device permissions: INTERNET (network access), and USE_BIOMETRIC / USE_FINGERPRINT (optional biometric unlock — see Section 2). No additional data is collected by the app beyond what is described in this Policy. App downloads are subject to Google Play's Terms of Service.

6. Data Retention & Deletion

We believe in keeping your data only as long as it is useful to you. Retention periods differ based on how you use the Service:

  • Unresponded invitations: If you receive an event invitation and do not respond within 30 days, your account and invitation data are automatically and permanently deleted.
  • Invitation-only accounts (you have accepted an invitation but have never created an event): If your account shows no login activity for 6 months, we will send you a warning email. If no action is taken, your account is soft-deleted for 30 days. During this period you can log back in to cancel the deletion and fully restore your account. After 30 days, all personal data is permanently and irreversibly erased.
  • Event-creator accounts (you have created at least one event): If your account shows no login activity for 12 months, your account is soft-deleted and you will receive a notification email informing you. You have 30 days to log back in to cancel the deletion and fully restore your account. After 30 days, all personal data is permanently and irreversibly erased.
  • The "Cooling-Off Period" (Manual Account Deletion): When you voluntarily delete your account, your data enters a protected holding phase for 30 days. During this period, you can log back in to cancel the deletion and fully restore your account. After 30 days, all personal data is permanently and irreversibly erased. If you wish for immediate permanent erasure before the 30 days have elapsed, please contact us at [email protected].
  • What "soft-deleted" means: A soft-deleted account is hidden from event participant lists (other participants see "Deleted user") and removed from friend lists. The account can be fully restored by logging in during the 30-day window.
  • Event Persistence: When your account is permanently deleted, if you co-owned an event with other owners, ownership is transferred to one of the remaining owners and the event continues unaffected. If you were the sole owner, the event and all its associated data are deleted along with your account. If an event has no remaining owners, it is automatically deleted after 30 days.
  • Security Logs: IP logs and login timestamps are stored for 30 days for security auditing purposes. After this period, they are automatically purged or anonymized, unless they are retained indefinitely on an internal "block list" for users who have specifically violated our Terms of Service.

7. Your Rights

Regardless of your residency, you have the right to:

  • Access & Portability: Request a copy of the data we hold about you.
  • Correction: Update your name or email at any time through your settings.
  • Erasure: You can remove your data at any time:
    • Log in and go to Profile → Account → Danger Zone → Delete Account to initiate the 30-day account deletion process. To remove event data immediately, delete your events from the My Events page before deleting your account.
    • Contact us at [email protected] to request immediate removal of your account or any specific information.
  • Non-Discrimination: We will not provide a lower quality of service if you exercise your privacy rights.
  • Notification Preferences: You can mute individual notification categories (e.g., RSVP updates, task reminders, polls, Q&A activity) under Profile → Notifications. On the Android app, you can also revoke the operating-system notification permission at any time to stop all push messages.
  • Opt-out of tracking: Via the Google Analytics Opt-out Add-on.
  • Right to Complain: If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet, dt.dk), or with the supervisory authority in your country of residence within the EU.

Automated Decision-Making: We do not make automated decisions about you (including profiling) that produce legal or similarly significant effects.

Data Breach Notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority (Datatilsynet) within 72 hours of becoming aware, as required by GDPR Art. 33. Where the breach is likely to result in high risk to individuals, we will also notify affected users directly without undue delay.

8. Age Requirement & Children's Privacy

The Service is restricted to individuals aged 18 or older. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will delete their account and associated data without delay.

9. Contact

For any inquiries or to exercise your privacy rights, please contact us at: [email protected]

Privacidade & PlanejamentoUsamos cookies para proteger seus itinerários. Análises opcionais nos ajudam a criar melhores ferramentas para seu grupo. Política de Privacidade.