Party
Privacy Policy
Last updated 2026-10-11
Draft. This text describes how Party works but has not been reviewed by a lawyer and is not yet legally binding in this form.
Party helps people host and attend real events. This policy explains what personal data Party processes, why, and the choices you have. It is written for Switzerland (FADP) and anticipates the GDPR.
Who is responsible
The controller is [Operator name and address — to be completed before launch]. Contact for privacy requests: see the Support page.
What we process
- Account: email address, authentication data (handled by our authentication provider; passwords are stored only as salted hashes), creation and last sign-in time.
- Profile: name, username, optional photo, bio, city and music interests you choose to add.
- Events you host: details you enter, including the exact address, which is stored separately and shown only to confirmed guests and your event team unless you mark it public.
- Participation: your RSVPs, +1 count, waitlist position, tickets, check-in time, and messages or photos you post in an event.
- Social graph: friends, follows, blocks, and an optional “I’m out tonight” status that expires automatically.
- Safety and operations: reports you file, moderation decisions, security events, and audit records of sensitive actions.
- Device: a push token if you enable notifications. Location is used on your device and sent only as a search parameter for “near me”; we do not store a location history.
Why we process it
- To provide the service you asked for (contract): accounts, invitations, guest lists, tickets and door entry.
- To keep people safe and prevent abuse (legitimate interest): reporting, blocking, rate limits, audit logs.
- With your consent: optional location access, optional notifications, optional profile details.
Who can see what
- Your email address is never shown to other users.
- Hosts and their event team see your name and RSVP for their event.
- Other guests see you on a guest list only if the host enabled the list and your own privacy setting allows it.
- Private event addresses are disclosed only to confirmed guests and the event team.
- Platform administrators can access account and moderation data to operate the service. They do not see private event addresses in the admin tools.
Processors
Party uses infrastructure providers to host the database and authentication (Supabase), the website (Cloudflare), transactional email (Resend) and push delivery (Expo, Apple, Google). A current list with locations and transfer safeguards must be completed before launch.
Retention
- Account and content: until you delete them or your account.
- Notifications: 120 days.
- Security events: 180 days.
- Audit records of sensitive actions are kept without your identity after account deletion.
Your rights
You can access and export your data (Settings › Export my data), correct it in your profile, and delete your account in the app (Settings › Delete account), which removes your profile, tickets, messages and photos. You may also object to processing or lodge a complaint with the Swiss FDPIC or your local authority.
Children
Party is intended for adults (18+). We do not knowingly process data of minors.