Privacy Policy
App privacy policy · Last updated: 12 July 2026
This Privacy Policy explains how the Droppin mobile app ("Droppin", "we", "us") collects, uses, and shares your information, and the choices you have. It complements the website privacy notice (Datenschutzerklärung), which covers the droppin.eu website only.
Droppin is intended for users 18 and older.
1. Who is responsible
Email: support@droppin.eu · Phone: +49 651 43665799
For the purposes of the EU General Data Protection Regulation (GDPR), the above is the data controller for the app.
2. What we collect
Information you provide
- Account: email address and password (sign-up), or a Google account (Google sign-in). Passwords are handled by our authentication provider and are never stored by us in readable form.
- Profile: username, display name, bio, date of birth (used to verify you are 18+; we store the date and derive age), gender, interests, spoken languages, and an optional profile photo.
- Content: events ("Drops") you create or join (title, description, category, venue, address, map coordinates, date/time, capacity, visibility), posts and photos, comments, likes, and chat messages (including replies and any images you send).
- Social actions: follows and follow requests, blocks, reports, and event participation.
- Support: feedback you submit and messages you send us.
Information collected automatically
- Location: with your permission, your device location is used to show nearby Drops and to place a Drop you create. The coordinates of a Drop you create become part of that Drop and are shown to others according to its visibility setting. We do not continuously broadcast or store your live location as a "friends on the map" feature.
- Push token: a push-notification token and platform, so we can deliver notifications.
- Technical/operational data: data needed to run the service (e.g. timestamps, conversation read state) and standard server logs on our backend/host.
We do not use advertising SDKs or third-party behavioral-tracking/analytics SDKs in the app.
Sensitive information (special categories)
We do not ask you for special categories of personal data (Art. 9 GDPR — e.g. data revealing racial or ethnic origin, religious or philosophical beliefs, political opinions, health, sexual orientation, or sex life). However, information you choose to share — such as free-text interests or bio, or joining or hosting a Drop with a particular theme (for example a religious, political, health-related, or LGBTQ+ event) — may reveal such information to us and to other users. Where you voluntarily post this in areas visible to others, you make it public through your own action; where explicit consent is required, we rely on the consent you give by choosing to share it. Please do not share sensitive information you do not want others to see.
Storing information on your device (TDDDG)
To run core features, we store and read a limited amount of information on your device — an encrypted login session, your app preferences, an image cache, and the push token. This access is strictly necessary to provide the features you request (§ 25(2) TDDDG); we do not use it for advertising or cross-service tracking.
3. Device permissions
| Permission | Why we ask |
|---|---|
| Location (while using the app) | Center the map on you, show nearby Drops, and set the location of a Drop you create. |
| Photo library | Choose a profile picture and add photos to posts (gallery only). |
| Notifications | Send you event reminders and chat/social notifications. |
| Calendar | Only when you tap "Add to calendar": open your device's event composer prefilled with the Drop. |
Each permission is requested in context, the first time you use the related feature, and you can change these anytime in your device settings.
4. Why we use your data (legal bases)
- To provide the service — creating your account, showing and running events, chat, feed, follows and notifications (Art. 6(1)(b) GDPR, performance of a contract).
- With your consent — location, photo, calendar and notification access, which you grant via the OS prompts and can withdraw anytime (Art. 6(1)(a) GDPR).
- Legitimate interests — keeping the service secure, preventing abuse and fraud, moderating content, and operating features you request (Art. 6(1)(f) GDPR).
- Legal obligations — where we must retain or disclose data by law, including complying with our duties under the Digital Services Act (Art. 6(1)(c) GDPR).
- Special-category data — where content you post reveals special categories of data, we process it only because you have manifestly made it public yourself (Art. 9(2)(e) GDPR) or on the basis of your explicit consent (Art. 9(2)(a) GDPR).
5. Advertising
Droppin does not currently show advertising and does not use your personal data for advertising or profiling. When we introduce advertising, it will take the form of Sponsored Drops — events a business pays to show more prominently on the map. These are created by the advertiser and are selected using general context only (such as the map area you are viewing and the event category), which does not involve profiling you or processing your personal data for personalisation. We will:
- clearly label Sponsored Drops as advertising and, as required by the Digital Services Act, tell you the main parameters used to show them to you;
- never use your posts, Drops, or other content for advertising;
- never use special categories of data (see §2) to target ads.
If we later introduce personalised advertising that uses your personal data, we will update this policy first, ask for your consent (Art. 6(1)(a) GDPR) with an easy way to decline or withdraw, and, on iOS, show Apple's App Tracking Transparency prompt before any cross-app tracking.
6. Who we share it with
We do not sell your personal data. We share data with service providers ("processors") only as needed to run Droppin, under data-processing agreements (Art. 28 GDPR):
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Backend: database, authentication, file storage, realtime | Your account and content data |
| Mapbox | Map display and place/address search | Device IP and requested coordinates / search text |
| Expo (push service) | Delivering push notifications | Push token + notification content |
| Apple Push / Google Firebase Cloud Messaging | OS-level push delivery (iOS / Android) | Push token + notification content |
| Google / Apple | Sign-in with Google (and Apple, where offered) | Basic account info (email, name) at login |
| Resend | Transactional email (confirmations, resets, email changes) | Your email address and the message |
We may also disclose data where required by law, to respond to lawful requests from authorities, or to protect the rights, safety, and security of our users, the public, or Droppin.
International transfers
Our backend (Supabase) hosts your data in the European Union (Frankfurt, Germany — AWS eu-central-1). Some providers (e.g. Apple, Google, Mapbox) may process data outside the EU/EEA, including in the United States. Where that happens, the transfer relies on an appropriate safeguard under Chapter V GDPR — an EU adequacy decision or EU Standard Contractual Clauses — or on a derogation under Art. 49 GDPR. You can request a copy of the relevant safeguards from us. Map data is © OpenStreetMap contributors (ODbL) via Mapbox.
7. What other users can see
Droppin is a social app. Your username, display name, bio, avatar, the Drops you host, and your posts are visible to others according to your settings. Setting your profile to private restricts your posts, post images, and follower/following lists to approved followers (non-followers see only your name, avatar, bio, and counts). Anything you share in an event chat or a Drop is visible to its participants.
Messages and chats are stored, not end-to-end encrypted. Event chats and direct messages (including any images you send) are stored on our backend so the service can deliver and display them. They are encrypted in transit (HTTPS/TLS) and protected by access controls, but they are not end-to-end encrypted. We do not read your private messages as a matter of routine, but we — and our backend provider acting on our behalf — can access stored messages where necessary to operate and secure the service, to review content that is reported to us, or to comply with a legal obligation or lawful request. Please treat direct messages as private between participants, not as secret or encrypted communication, and do not share information in chat that you would not want stored.
8. How long we keep it
We keep your data while your account is active and for as long as needed to provide the service. As a guide:
- Account & content — kept until you delete the item or your account.
- Server logs — kept for a short period (typically up to 90 days) for security and troubleshooting, then deleted or anonymised.
- Back-ups — removed content may persist in encrypted back-ups for a limited rotation period (typically up to 30 days) before being overwritten.
- Safety & moderation records — reports and blocks, and a minimal record of enforcement actions, may be kept after account deletion to keep the service safe and to comply with the DSA, for as long as necessary.
- Legal records — some data may be retained longer where required by law (e.g. tax/commercial retention) or to establish, exercise, or defend legal claims.
When you delete your account in the app, we anonymize your profile and remove your engagement data, and the underlying authentication record is deleted so your email/identity can be reused. You can also delete individual content (posts, Drops, messages) in the app.
9. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability and to lodge a complaint with a supervisory authority. Where processing is based on consent, you can withdraw it at any time without affecting prior processing. You can:
- Edit your profile, change your password, and set your profile private in the app.
- Manage notification preferences, block/report users, and leave conversations.
- Delete your account (Settings → Delete Account) to erase your data.
- Contact us at support@droppin.eu to exercise any right; we respond within one month.
Your competent supervisory authority in our region is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, but you may also complain to the authority where you live or work.
10. Security
We use industry-standard measures to protect your data, including encrypted transport (HTTPS/TLS), an encrypted on-device session store, and access controls (row-level security) on the backend. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach is likely to result in a high risk to your rights, we will notify you and the competent authority as required by law.
11. Children
Droppin is not directed to anyone under 18. During onboarding we ask for your date of birth and block sign-up for under-18s. If you believe a minor has provided us data, contact us and we will remove it.
12. Changes to this policy
We may update this policy as the app evolves. We will post the updated version here with a new "last updated" date and, where the change is significant, notify you in the app or by email before it takes effect.
13. Contact
Questions about privacy? Email support@droppin.eu.