Privacy policy
Last updated 28 August 2026
Spotco is an app for finding and hosting group activities — football, hikes, board game nights, club nights. This policy explains what we collect, why, who else sees it, and how to get it back or removed. It is written to be read, not to be survived.
Who we are
Spotco (Aleje Jerozolimskie 190C, 02-486 Warsaw, Poland) is the data controller for the personal data described here. For anything about your data, contact privacy@spotco.app.
What we collect
What you give us
- Your email address. Required — it is how you sign in and how we send you sign-in links.
- Your name and, if you add one, a profile photo. Both are visible to other people using the app.
- A phone number, if you choose to add one. Optional, and never shown on your public profile.
- Your city. Used to decide which activities you see.
- Content you create: events you host, their names, descriptions and any flyer image you upload; chat messages; reviews of hosts and venues.
Your date of birth — which we do not keep
You must be 18 or over to use Spotco. When you confirm your date of birth during sign-up, we calculate whether you are 18 and then discard the date. What we store is a single yes/no flag. We cannot tell you your own birthday, because we never wrote it down.
Location
- Your city — you pick it, or you let the app suggest one from your approximate location. This is what filters your feed.
- Precise location — only if you grant the permission, and only to sort activities by how far away they are and to centre a map. It is used on your device and is not stored as a location history.
- Meeting points you set as a host — the address and coordinates of an event you create are shown to everyone who can see that event. That is the point of it.
You can refuse or withdraw the location permission at any time in your phone’s settings. The app works without it; you pick a city by hand instead.
What we record as you use it
- Sessions you join, host or leave, and whether you turned up. Hosts mark attendance after an event.
- Your reliability score, and the individual entries behind it — a no-show, a late cancellation, a completed session. Kept as a list rather than a bare number so it can be explained and corrected.
- Wallet entries — every credit and debit, with its reason and date.
- Safety records — reports you make or that are made about you, and accounts you block.
Technical data
Our hosting provider processes your IP address and standard request information to serve the app and protect it from abuse.
Product analytics and crash reporting are disabled unless we have configured a key for them. Where enabled, analytics records six specific actions — viewing a session, tapping join, completing a join, starting the host flow, publishing an event, and starting a venue claim — associated with your account ID. Crash reports include the error and device model. Neither reads your messages.
Why we are allowed to use it
| What | Legal basis (UK/EU GDPR) |
|---|---|
| Your account, joining and hosting, the wallet | Performance of our contract with you |
| Reports, blocking, reliability, fraud and abuse prevention | Our legitimate interests, and those of everyone else using the app, in it being safe to meet strangers through |
| Precise location; analytics where enabled | Your consent, which you can withdraw |
| Keeping financial records | Legal obligation |
Who else sees it
Other people using Spotco
Your name, photo, reliability score, host rating and the activities you have taken part in are visible on your public profile. Your email address, phone number and wallet are not — the app enforces this in the database, not just by hiding it on a screen.
When you join an event, the host and the other participants can see that you have joined. Messages you send in an event chat are visible to everyone in that chat.
Venues
If you book an event at a venue, the people who manage that venue are told the booking exists and can see it in their dashboard.
Service providers
- Supabase — hosting, database, authentication, file storage.
- Apple — map display on iOS. Apple receives what is needed to draw the map.
- OpenStreetMap — address search when you type an address while creating an event. Your search text is sent to their servers. We do not send your identity with it.
- Sentry (crash reporting) and PostHog (analytics) — only where we have enabled them.
We do not sell your personal data, and we do not share it with advertisers. There are no advertising SDKs in the app.
Where it is held, and for how long
Data is held on our provider’s infrastructure in the European Union. Where a provider processes data outside the UK or EEA, that transfer relies on the European Commission’s standard contractual clauses.
- Your account — until you delete it.
- Event chats — become read-only 48 hours after the event ends.
- Wallet entries — kept as long as we are required to keep financial records.
- Safety reports — kept after the reported account is deleted, in anonymised form, because a pattern of reports is exactly the thing that stops being visible if it is erased with the account.
Deleting your account — and what survives it
You can delete your account from Settings → Delete my account. It takes effect immediately and you are signed out.
Please read this part. We do not erase your rows outright, because your account is attached to things that belong to other people: the session history of everyone who attended an event with you, the reviews you wrote about venues, and any safety reports made about you. Deleting your account would take all of that with it.
Instead, deleting your account:
- Removes your name, replacing it with “Deleted user”
- Removes your email address, phone number and profile photo
- Permanently disables sign-in — the account cannot be recovered
- Leaves your past attendance, your reviews and any reports about you in place, no longer linked to an identifiable person
If you want something erased that this leaves behind, write to us and we will look at it individually.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to us using it. You can withdraw consent — for location or analytics — at any time without affecting what came before.
Write to privacy@spotco.app. We will answer within one month.
If you are not satisfied, you can complain to your data protection authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
Children
Spotco is for adults. You must be 18 or over. If we learn that an account belongs to someone under 18 we will close it.
Changes
If we change this policy in a way that affects you, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.