travelspoon Privacy Policy The operator of travelspoon (the “Operator”) publishes this Privacy Policy to explain how personal data is handled in the travelspoon application and related services. The Operator’s exact legal identity is the entity shown in the developer information for travelspoon on Google Play or the App Store, and privacy requests may be submitted to travel.spoon.official@gmail.com. This Policy explains a common privacy baseline that is not limited to one country. If stronger privacy rules apply where you live, the Operator will respect the rights provided by those rules. 1. Data We Process Depending on the features you use and the choices you make, the Service may process the following data. A. Account and authentication data - Firebase user identifier (UID) - Email address, display name, and profile photo provided through your Google Account - Account creation and recent sign-in times - Authentication tokens needed for sign-in and reauthentication Google authentication tokens are used for authentication and are not stored as travelspoon profile fields. B. Optional profile data - Display name and profile photo - Biography - Preferred languages - Interests or travel styles - Social media links you provide C. Group and travel data - Group identifier, title, description, and image - Travel place, date and time, time zone, preferred languages, and member limit - Identifiers of owners, members, and join requesters, and join messages - Travel time and Group end status and end time D. Chat and media data - Chat room and sender identifiers, message content, and transmission time - Photos, videos, thumbnails, and file URLs you send - Latitude and longitude when you expressly choose to share your location - Chat members, latest message, per-user read times, and unread status Chat messages are processed on the Service’s servers and are not currently provided with end-to-end encryption. Do not send unnecessary sensitive data such as government identifiers, financial data, health data, or a precise home address through chat. E. Map and place-search data - Place search text and app language - Google Place ID, place name, address, coordinates, time zone, and place-photo request information - Current-location or map-camera center coordinates used to query nearby places On the main map screen, travelspoon first asks whether you agree to location use. Your decision, the notice version, decision time, display language, and selection screen are stored with your Account in the `UserAgreements` collection separately from operating-system location permission. The app retrieves and saves this value only through server APIs and does not cache it on the device. Only after you agree does the app check location services and permission and use your current location to query nearby places and center the map. If you decline, or if the app cannot retrieve or save your selection on the server, the app does not retrieve your current location and displays its default map location. Coordinates are stored in a chat message only when you expressly choose to share a location. F. Notification data - Firebase Cloud Messaging device token and, on iOS, related APNs information - Notification recipient, type, title, body, related Group, read status, and creation time G. Technical data that may be generated by the device or processed by external SDKs - IP address and network request information - Device, operating system, app version, language, and time zone - Service identifiers such as a Firebase installation identifier - Crash, error, performance, and diagnostic logs travelspoon does not currently provide personalized advertising and does not sell personal data or share it for cross-context behavioral advertising. Firebase Analytics collection is disabled in the app configuration. Firebase Crashlytics and Performance Monitoring are included in the app and automatically collect and process technical data for crash, error, and performance diagnostics. H. Data stored on your device - Up to five recent place searches and their times - Group filters and the last member-limit value - Language, dark mode, and notification settings - Per-Group unread counts and join-request status - Pending or failed media upload tasks, local file paths, and error status - Network image cache and in-memory chat cache for the current app session - Copies of photos or videos that you expressly save to the device gallery This data is generally stored on your device. Media and related identifiers are sent to the server when you request an upload. 2. Purposes of Processing The Operator processes data only as reasonably necessary to: 1. Create Accounts, sign Users in, reauthenticate, and protect Accounts 2. Display profiles and identify Users 3. Search travel and nearby places, create, join, and manage Groups, and display Group members 4. Provide chat, media, and location sharing among Group members 5. Deliver notifications about join requests, approvals, and chats 6. Upload and download media, retry failed tasks, and maintain continuity 7. Diagnose errors, prevent abuse, maintain security, and improve performance and quality 8. Respond to requests and disputes and comply with legal obligations The Operator will not use data for a new incompatible purpose without providing notice or obtaining consent when required by law. Depending on applicable law, the Operator relies on one or more of the following legal bases: - Performance of a contract to provide the Account, Groups, chat, and other features you request - Your consent for optional location sharing or other processing that requires consent - The Operator’s legitimate interests in security, abuse prevention, diagnostics, and Service improvement - Compliance with legal obligations, including lawful requests from law-enforcement authorities travelspoon does not currently make decisions that have legal or similarly significant effects on Users solely through automated processing. 3. Visibility and Sharing with Other Users 1. Your display name, photo, biography, preferred languages, interests, and social links may be visible through profiles and Group features. 2. Group titles, descriptions, schedules, language preferences, member limits, and owner information may appear in Group search results. 3. Join messages are visible to the relevant Group owner. 4. Chats, photos, videos, and shared locations are visible to members of the relevant chat room or Group. 5. Other Users may save or externally share Content you make available. Review the audience and included personal data before sending it. The Operator does not sell personal data or share it for cross-context behavioral advertising. It does not disclose personal data to unrelated third parties except at your request or with your consent, as required by law, or as necessary to provide the Service. 4. Service Providers and External Services The Service uses the following external providers. A. Google LLC and Google services - Google Sign-In and Firebase Authentication: sign-in, authentication, and Account management - Cloud Firestore: profile, travel-place, Group, chat, media-index, and notification storage - Cloud Functions and Cloud Run: server processing for Groups, chats, and Account deletion - Firebase Cloud Storage: profile photos and chat media - Firebase Cloud Messaging: push notifications - Firebase Crashlytics and Performance Monitoring: included in the app and used for crash, error, and performance diagnostics - Google Maps Platform and Places API: maps, place search, place details, and photos B. Apple Inc. - Apple Push Notification service: push delivery to iOS devices C. Your operating system and app marketplace provider - Camera, photo-library, location, and notification permission management - Installation, updates, device security, and store support External providers may independently process technical data under their own terms and privacy policies. - Google Privacy Policy: https://policies.google.com/privacy - Firebase Privacy and Security: https://firebase.google.com/support/privacy - Apple Privacy Policy: https://www.apple.com/legal/privacy/ 5. International Processing and Transfers Because the Service uses the global infrastructure of Google, Firebase, Google Maps Platform, and Apple, data may be processed or stored outside your country of residence. - Recipients: Google LLC and relevant Google service entities; Apple Inc. and relevant service entities - Countries: the United States and other countries where the providers operate data centers and support teams - Timing and method: transmission through Firebase, Google, and Apple SDKs and communication channels that support HTTPS/TLS when you use authentication, storage, maps, media uploads, notifications, or diagnostics - Data: the Account, profile, Group, chat, media, shared location, notification token, place query and ID, and technical data needed for the relevant feature - Purpose: authentication, cloud storage and processing, maps and places, notifications, and diagnostics described in Section 4 - Retention: the duration of Service use or the service-provider agreement, completion of a deletion request, and any period required by provider policy or applicable law Actual processing countries and storage locations vary based on Firebase project configuration, enabled features, and provider infrastructure. 6. Location, Camera, Media, and Notification Permissions 1. Location permission is used to show your current location, query nearby places, or share a current location when you choose to do so in chat. 2. travelspoon does not continuously track location in the background. 3. Camera and photo or video permissions are used only when you choose to capture, select, send, or save media. 4. Notification permission and device tokens are used to deliver notifications about join requests, approvals, and chats. 5. You may deny or revoke permissions in operating system settings. Only the related features may then be limited. 7. Retention and Deletion The Operator retains personal data only for as long as needed for the purposes described in this Policy. Where one fixed period is not practical, the following criteria determine retention: 1. Account and profile data: while the Account is active and needed to provide the Service 2. Group, chat, media, and notification data: while needed to provide the relevant Group features and conversation history 3. Device tokens: while needed for notifications or until you disable notifications 4. Security, error, and performance records: for a period reasonably needed to investigate incidents, diagnose errors, and stabilize the Service 5. Legal and dispute records: for periods required by law or needed to establish, exercise, or defend legal claims 6. Backups: copies may remain with restricted access until the ordinary backup-rotation cycle completes 7. Local search history: until you delete it or Account deletion succeeds 8. Local settings, filters, unread counts, upload tasks, and cache: until app data is cleared or the app is uninstalled When data is no longer needed, it is deleted or deidentified. Records retained for legal, security, or dispute purposes are restricted to those purposes. 8. Account and Data Deletion 1. You can initiate Account deletion from the settings screen. 2. Google reauthentication may be required to protect the Account. 3. After the server confirms successful deletion, the app signs you out and clears local search history. 4. Other local settings, pending upload files, and image cache may not all be automatically erased. To fully clear local data, clear travelspoon storage and cache in operating system settings or uninstall the app. 5. Account deletion may not remove or retrieve copies already delivered to or separately saved by other Users. 6. Some information may be retained on a limited basis for legal obligations, security, disputes, or ordinary backup rotation. 9. Your Rights Subject to applicable law, you may request: 1. Access to information about whether and how your personal data is processed 2. Correction of inaccurate data 3. Deletion of personal data 4. Restriction of, objection to, or suspension of processing 5. Withdrawal of consent where processing is based on consent 6. Data portability where applicable 7. Opt-out of sale or advertising-related sharing 8. Freedom from discrimination for exercising privacy rights You can edit profile data in the app, disable notifications in the app or operating system, and delete your Account in settings. Other requests may be submitted to travel.spoon.official@gmail.com. The Operator may verify your identity and will respond within the periods and procedures required by applicable law. Regional Privacy Rights - European Economic Area (EEA) and United Kingdom: where applicable, you may have rights of access, correction, deletion, restriction, portability, objection, consent withdrawal, and complaint to a supervisory authority. - California, United States: where applicable, you may have rights to know categories of collection, use, and disclosure; access; correct; delete; opt out of sale or sharing; limit use of sensitive information; and receive non-discriminatory treatment. travelspoon does not currently sell personal data or share it for cross-context behavioral advertising. - Canada: where applicable, you may request an explanation of processing, access and correct your information, and challenge compliance. - Australia, Japan, and the Republic of Korea: rights under applicable local law may include notice, access, correction, deletion, suspension of processing, and complaint to a privacy regulator. - Other countries: any additional privacy rights provided where you live remain unaffected. 10. Security Measures The Operator applies reasonable technical and organizational measures appropriate to the size of the Service and the risks of processing. Examples currently used by the Service include: 1. Account authentication and reauthentication before Account deletion through Firebase Authentication 2. Operating-system permission checks before using camera, photo or video, location, and notification functions 3. Firebase and Google API SDKs or communication channels that support HTTPS/TLS 4. Cleanup of temporary files managed by the chat-media upload queue after successful upload or cancellation No internet service can guarantee absolute security. Protect your Account and device and avoid sending unnecessary sensitive data through chat. 11. Children’s Privacy travelspoon is not directed to users under 17, and users under 17 may not create an Account or use the Service. If your country requires a higher age or parental consent, that local standard applies. The Service does not provide a separate parental-consent process for users who do not meet the applicable age requirement. If the Operator learns that personal data from a user who does not meet the age requirement was processed, it will delete the data or take the protective steps required by applicable law. 12. Changes to This Policy The Operator will update this Policy when the Service, law, or data practices change. Material changes will be announced through the app, store release information, or another reasonable method, together with when the changes apply. 13. Privacy Contact and Remedies Controller: The Operator identified in the developer information for travelspoon in the app marketplace where it is distributed Contact email: travel.spoon.official@gmail.com You may contact the Operator first. If your concern is not resolved, you may complain to the privacy regulator where you live or where the issue occurred. Major regulator directories and agencies include: - European Economic Area: EDPB member supervisory authorities / https://www.edpb.europa.eu/about-edpb/about-edpb/members_en - United Kingdom: Information Commissioner's Office / https://ico.org.uk - California, United States: California Privacy Protection Agency / https://cppa.ca.gov - Canada: Office of the Privacy Commissioner of Canada / https://www.priv.gc.ca - Australia: Office of the Australian Information Commissioner / https://www.oaic.gov.au - Japan: Personal Information Protection Commission / https://www.ppc.go.jp/en - Republic of Korea: Personal Information Protection Commission / https://www.pipc.go.kr/eng