Privacy Policy
1. Who We Are & Scope
This Privacy Policy explains how GotPlans, operated by Ernest Ibarolle, doing business as GotPlans (the "Company", "we", "us"), collects, uses, and shares your information, and the choices and rights you have. The Company is the data controller for your personal data. By using the app you acknowledge this Policy.
2. Information We Collect
Account information: your email address and password (passwords are processed by our authentication provider and are never stored by us in plain text). Profile information: display name, username, bio, city, avatar photo, and interests you choose to add. Age: your date of birth, collected once at signup solely to verify you are 18 or older, stored privately and never shown on your public profile. Content you create: events you host, RSVPs, group-chat messages, event cover photos, and reports you submit. Circles and communities: the circles (private groups) and communities (public groups) you create or join, your role and membership in them, any cover image you add, and invitations you send or receive. Connections: your friend requests and friendships, and the accounts you block. Location: the city you provide; if a map feature is added in a future version and you grant permission, your approximate device location to show nearby events. Usage and device data: basic app interactions, log data, and device identifiers used to operate, secure, and improve the service. Support communications: information you provide when you contact us.
3. How We Use Your Information
We use your information to: create and secure your account; verify eligibility (18+); show you relevant events and people; enable hosting, RSVPs, and group chat; operate content moderation and respond to reports; prevent fraud and abuse; provide support; and maintain and improve the app.
4. Legal Bases for Processing (EU/EEA)
Where the GDPR applies, we process your personal data on these legal bases: performance of a contract (to create your account and provide the app's core features); consent (for optional features such as device location and, where required, analytics — you can withdraw consent at any time); legitimate interests (to secure the service, prevent fraud and abuse, moderate content, and improve the app, balanced against your rights and freedoms); and legal obligation (to comply with applicable law and respond to lawful requests).
5. How We Share Information
Other users see your public profile and the content you post (for example, events you host and your messages in event chats). Members of a circle or community you belong to can see that you are a member, your role in it, and content scoped to that group; when you invite someone to a circle, they can see that the invitation came from you. Your friends can see that you are connected to them. We use service providers that process data on our behalf under their own safeguards — including Supabase for authentication, database, storage, and realtime messaging, and Google for place/venue search (your search queries are sent to Google to return results). We may disclose information if required by law or to protect the rights and safety of users or the public. We do not sell your personal information.
6. Analytics & Crash Reporting
We use PostHog (hosted in the European Union) for product analytics and Sentry (hosted in the European Union) for crash and error reporting, to understand how the app is used and to diagnose and fix problems. These tools receive a pseudonymous user identifier and a limited set of non-sensitive properties (such as your city and whether you are an approved host) — never your email address, password, or date of birth. Analytics and crash data are processed on servers in the European Union. We do not use these tools for advertising.
7. International Data Transfers
Our database and file storage are hosted in the United States (Supabase region us-east-2), and we and our service providers process your data there. If you access GotPlans from the EU/EEA or another region, your personal data is transferred to and processed in the United States. Where required for such transfers, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. Data Retention & Account Deletion
We keep your information while your account is active. You can delete your account at any time from Profile → Delete account. When you do, we anonymize your public profile (it appears as "Deleted user"), cancel your upcoming hosted events, release your RSVPs, erase your private date-of-birth and acceptance records, remove your uploaded photos, and disable your login. We retain limited information only where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
9. Your Privacy Rights
You can view and edit your profile in the app and delete your account at any time. Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent where processing is based on it. If the GDPR applies to you, you also have the right to lodge a complaint with your local data-protection supervisory authority in your country of residence. To exercise your rights, contact us at eibarolle@gmail.com.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights regarding your personal information, subject to its exceptions: the right to know the categories and specific pieces of personal information we have collected, the sources, the business purposes for collecting it, and the categories of third parties we share it with; the right to delete personal information we collected from you (you can do this yourself anytime via Profile → Delete account); the right to correct inaccurate personal information; and the right not to be discriminated against for exercising these rights. We do not sell or share your personal information for cross-context behavioral advertising or monetary value (as "sell" and "share" are defined under California law), so there is no opt-out to make, and we do not use sensitive personal information for purposes that would trigger a right to limit. The categories of personal information we collect and our purposes are described in Sections 2 and 3 above. Under California's "Shine the Light" law (Civil Code § 1798.83), we do not disclose personal information to third parties for their own direct-marketing purposes. To exercise any of these rights, contact us at eibarolle@gmail.com; we may need to verify your identity before we respond.
11. Children
GotPlans is for adults 18 and older. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it and remove the account.
12. Security
We use technical and organizational measures — including encryption in transit, encrypted storage of your session on your device, and access controls in our database — to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
13. Data Stored on Your Device
The app stores your login session securely on your device (in the device keychain / secure storage) to keep you signed in, and saves preferences such as your light/dark theme choice locally. This information stays on your device.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
15. Contact
Data controller: Ernest Ibarolle, 11120 East Ocean Air Drive, Suite 101-72, San Diego, California 92130. Questions or requests about your privacy? Contact eibarolle@gmail.com.