Privacy policy
Last updated 25 September 2026
Spotco is an app and website for finding and hosting group activities: football, padel, hikes, runs, board game nights, club nights. This policy explains what we collect, why, who else sees it, and how to get it back or removed. It is written to be read, not to be survived.
Who we are
Spotco (Aleje Jerozolimskie 190C, 02-486 Warsaw, Poland) is the data controller for the personal data described here. For anything about your data, write to privacy@spotco.app.
What we collect
What you give us
- Your email address. Required: it is how you sign in and how we send you sign-in links.
- Your name and, if you add one, a profile photo. Both are visible to other people using Spotco.
- If you sign in with Google or Apple, we receive your name, email address and, from Google, your profile photo. We do not receive your password or access to anything else in that account.
- A phone number, if you choose to verify one. We send a one-time code by SMS to confirm it is yours. It is never shown on your public profile. Venue owners confirm their number this way when claiming a venue.
- Your city and your language. The city decides which activities you see; the language decides what language notifications reach you in.
- Content you create: events you host, their names, descriptions, rules and line-ups; photos you add to an event (up to eight); chat messages; reviews of hosts and venues; reports you make.
Your date of birth
You must be 18 or over to use Spotco. You give us your date of birth once, during sign-up, and we keep it on your account. We check it against 18 straight away, and we check it again whenever you join an event whose host has set an age limit. A yes/no flag cannot do that second job: it says you were 18 when you signed up and nothing more, so an age limit would be a sentence on a page rather than a rule.
It is private. Nobody else using Spotco can see it, it is never shown on your profile, and the database enforces that rather than the screen. Nothing else is derived from it: we do not use it for advertising, and we do not send birthday messages. It is deleted when you delete your account.
If you tell us you are under 18, nothing is saved at all, neither the date nor the flag, and the account cannot be used.
This changed in September 2026. Until then we calculated your age and discarded the date, and this policy said so. We now keep it, for the reason above.
Location
- Your city: you pick it, or you let the app suggest one from your approximate location.
- Precise location: only if you grant the permission, and only to sort activities by distance and centre a map. It is used on your device and is not stored as a location history.
- Meeting points you set as a host: the address and pin of an event you create are shown to everyone who can see that event. That is the point of it.
You can refuse or withdraw the location permission at any time in your phone’s settings. The app works without it; you pick a city by hand instead.
What we record as you use it
- Sessions you join, host or leave, and whether you turned up. Hosts mark attendance after an event.
- Your reliability score, and the entries behind it: a no-show, a late cancellation, a completed session. Kept as a list rather than a bare number so it can be explained and corrected.
- Wallet entries: every credit and debit, with its reason and date. When you add credit by card we keep the amount and the payment’s reference, never the card.
- Safety records: reports you make or that are made about you, and accounts you block.
- A notification token for your phone, if you allow notifications, so we can send reminders and updates. It identifies the app on your device, not you, and is removed when you sign out.
Technical data
Our hosting providers process your IP address and standard request information to serve the app and website and to protect them from abuse. The website sets no advertising or tracking cookies; the venue dashboard sets one cookie to keep you signed in.
Product analytics and crash reporting are disabled unless we have configured a key for them. Where enabled, analytics records a small set of actions (viewing a session, joining, starting and publishing an event, starting a venue claim) associated with your account ID. Crash reports include the error and device model. Neither reads your messages.
Why we are allowed to use it
| What | Legal basis (GDPR) |
|---|---|
| Your account, joining and hosting, the wallet, notifications you asked for | Performance of our contract with you |
| Reports, blocking, reliability, reviews, fraud and abuse prevention | Our legitimate interests, and those of everyone else using Spotco, in it being safe to meet strangers through |
| Showing public events on the website | Our legitimate interest in people being able to find events, and the host’s choice to make the event public |
| Precise location; analytics where enabled | Your consent, which you can withdraw |
| Keeping financial records | Legal obligation |
Who else sees it
Other people using Spotco
Your name, photo, reliability score, host rating and the activities you have taken part in are visible on your profile in the app. Your email address, phone number and wallet are not. The database enforces this, not just the screen.
When you join an event, the host and the other participants can see that you have joined. Messages in an event chat are visible to everyone in that chat. A review you write of a host is shown with your name and photo on that host’s events.
The public website
When a host makes an event public, it gets its own page on spotco.app that anyone can open without an account, and that search engines may list. That page shows the event, its place and photos, the host’s name, photo and rating, and reviews of the host, and how many places are taken. It does not list who has joined. An event shared by link only gets a page too, but it is marked so search engines do not list it. Pages stop being listed once the event is over or cancelled.
Venues
If you book an event at a venue, the people who manage that venue are told the booking exists and can see it in their dashboard.
Service providers
- Supabase: database, sign-in, file storage and server functions.
- Vercel: hosts the website.
- Google and Apple: sign-in, if you choose them; maps (Apple Maps on iPhone, Google Maps on Android), which receive what is needed to draw the map.
- Expo, Apple and Google: deliver notifications to your phone. They receive the notification text and your device token.
- Stripe: processes card payments when you add credit. Stripe receives your card details directly; we never see them.
- An SMS provider (Twilio): sends phone verification codes, and receives your phone number to do so.
- OpenStreetMap, or Google Places where enabled: address search while creating an event. Your search text is sent, without your identity.
- Sentry (crash reporting) and PostHog (analytics): only where we have enabled them.
We do not sell your personal data, and we do not share it with advertisers. There are no advertising SDKs in the app.
Where it is held, and for how long
Data is held on our provider’s infrastructure in the European Union. Where a provider processes data outside the EEA, that transfer relies on the European Commission’s standard contractual clauses or an adequacy decision.
- Your account: until you delete it.
- Event chats: become read-only 48 hours after the event ends.
- Wallet entries and payment references: as long as we are required to keep financial records.
- Safety reports: kept after the reported account is deleted, in anonymised form, because a pattern of reports is exactly the thing that stops being visible if it is erased with the account.
Deleting your account, and what survives it
You can delete your account from Settings → Delete my account. It takes effect immediately and you are signed out.
Please read this part. We do not erase your rows outright, because your account is attached to things that belong to other people: the session history of everyone who attended an event with you, reviews you wrote, and any safety reports made about you.
Instead, deleting your account:
- Replaces your name with “Deleted user”
- Removes your email address, phone number and profile photo
- Permanently disables sign-in; the account cannot be recovered
- Leaves your past attendance, your reviews and any reports about you in place, no longer linked to an identifiable person
If you want something erased that this leaves behind, write to us and we will look at it individually.
Your rights
You can ask us for a copy of your data, to correct it, delete it, restrict what we do with it, move it elsewhere, or object to us using it. You can withdraw consent (for location, notifications or analytics) at any time without affecting what came before.
Write to privacy@spotco.app. We will answer within one month.
If you are not satisfied, you can complain to your data protection authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
Children
Spotco is for adults. You must be 18 or over. If we learn that an account belongs to someone under 18 we will close it.
Changes
If we change this policy in a way that affects you, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.