Privacy Policy
Last updated: April 19, 2026
Classy Event Group, LLC ("we," "us," or "our") operates the SocialActivity mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App.
By using SocialActivity, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account Information: When you create an account, we collect your name, username, email address, and profile photo (if provided). You may also optionally provide a bio and phone number. If you sign in through a third-party service (such as Apple or Google), we receive basic profile information from that service (name and email address). If you sign in with your phone number, we use it to send a one-time verification code via SMS.
Contacts: With your permission, SocialActivity accesses your device contacts to help you find friends who are already using the app. Your raw contact data never leaves your device.
- What is hashed: Phone numbers and email addresses from your device contacts.
- Client-side hashing: A SHA-256 hash is computed on your device before any data is transmitted to our servers.
- Server-side protection: Our server applies an additional HMAC with a secret pepper before storage. Even if the database were compromised, the stored hashes cannot be reversed without the pepper.
- What is stored: Only the doubly-hashed values and your user ID — never raw phone numbers or email addresses.
- Retention: Contact hashes are retained as long as your account is active or until you explicitly delete them.
- How to delete: You can delete all stored contact hashes at any time from Settings → Privacy → Delete Contact Data in the app. This is independent of disabling future contact sync.
Only matched user IDs are returned — we never see or store your contacts' actual phone numbers or email addresses. Contact syncing is optional and occurs when you grant permission during onboarding. The app may periodically re-sync (approximately weekly) to find newly joined friends. You can revoke contact access at any time through your device settings.
Location: With your permission, SocialActivity collects your approximate location to show nearby activities from friends and calculate distance to events. Your location is rounded to approximately one-mile precision before being stored — we do not collect or store GPS-precise coordinates. Location is collected only while the app is in use (foreground); we do not track your location in the background. Your approximate location is visible to your friends within the app for the purpose of showing distance to events.
Photos and Camera: With your permission, you may use your camera or photo library to upload a profile picture or team photo. Photos are uploaded to our secure storage service and a URL is saved to your profile. We do not access your full photo library — only the specific image you select.
Calendar: With your permission, SocialActivity can add events you're attending to your device's native calendar. Calendar data is written directly to your device and is not transmitted to our servers.
Activity Data: We collect information about the events and plans you create, share, and interact with, including activity types, dates, times, locations, descriptions, and your responses (RSVPs) to others' plans. If you use team features, we store team names, descriptions, member lists, and chat messages. This data is necessary to provide the core functionality of the App.
Device Information: We collect push notification tokens to deliver notifications about event updates, friend activity, and other relevant alerts. We check whether your device supports push notifications but do not collect device identifiers (such as UDID or IDFA) or advertising identifiers.
Usage Data: We may collect information about how you interact with the App, such as features used and actions taken. This helps us improve the App experience. We do not use any third-party analytics or tracking SDKs. We do not track you across other apps or websites, and we do not collect your device's advertising identifier.
Referral Information: If you join SocialActivity through a referral link, we record which user referred you for the purpose of our referral rewards program. This information is linked to your account.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the SocialActivity service
- Enable you to create, share, and manage social plans with your friends
- Help you find friends through contact matching (using hashed data only)
- Show nearby activities and calculate distance to events using your approximate location
- Send push notifications about event updates, friend activity, and relevant alerts
- Allow you to add events to your device calendar
- Improve, personalize, and expand the App
- Communicate with you about updates, support, and administrative matters
- Administer the referral rewards program
- Detect, prevent, and address technical issues or abuse
3. Data Sharing and Disclosure
We do not sell your personal data. We will never sell, rent, or trade your personal information to third parties for marketing purposes. We do not share your data for advertising or tracking purposes.
We may share your information in the following limited circumstances:
- With other users: Your name, username, profile photo, approximate location, and event activity are visible to friends you connect with in the App. Team information (name, photo, members) is visible to team members. Chat messages are visible to members of the relevant team. This is necessary for the social functionality of the service.
- Service providers: We use the following third-party services to operate the App:
- Supabase — Backend database, authentication, and file storage. Processes account data, hashed contacts, event data, and uploaded photos.
- Google Places API — Location and venue search. Receives search queries and approximate location, routed through our server (not sent directly from your device).
- Google Maps — Map display within the app. Receives event location coordinates for map rendering.
- Expo Push Notification Service — Push notification delivery. Receives push tokens and notification content (titles and messages).
- Open-Meteo — Weather forecasts for events. Receives event location coordinates only (public API, no user data).
- Legal requirements: We may disclose your information if required to do so by law or in response to valid legal process, such as a court order or subpoena.
- Safety and protection: We may share information when we believe it is necessary to protect the safety, rights, or property of our users, ourselves, or others.
4. Data Categories Summary
For transparency and in accordance with Apple's App Privacy requirements, here is a summary of the data we collect:
- Contact Info (name, email, phone number) — Account & authentication. Linked to you.
- Contacts (phone numbers & emails, hashed only) — Friend discovery. Not linked to you.
- Location (approximate, ~1 mile precision) — Nearby events & distance. Linked to you.
- User Content (events, RSVPs, chat messages, photos) — Core functionality. Linked to you.
- Identifiers (user ID, push token) — Account & notifications. Linked to you.
Data NOT collected: Financial information, health data, browsing history, search history, advertising identifiers, precise GPS location, diagnostics, or crash reports.
Tracking: We do not track you across apps or websites owned by other companies. No App Tracking Transparency prompt is required.
5. Data Storage and Security
We take reasonable measures to protect your personal information from unauthorized access, use, or disclosure. Our security practices include:
- Encryption in transit: All data transmitted between your device and our servers uses HTTPS/TLS encryption.
- Encryption at rest: Our database provider (Supabase) encrypts stored data at rest.
- Secure credential storage: Authentication tokens are stored in your device's encrypted keychain (iOS Keychain via Secure Store), not in plaintext.
- Contact privacy: Contact data is hashed on your device before transmission and further protected with server-side cryptographic processing (HMAC). Raw contacts never leave your device.
- Location minimization: Location coordinates are rounded to approximately one-mile precision before storage.
- Access controls: Row-level security policies ensure users can only access their own data and data shared with them by friends.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
6. Data Retention and Deletion
We retain your personal data for as long as your account is active or as needed to provide you with the service.
Contact Data Deletion: You can delete all server-side contact hashes at any time without deleting your account. In the app, go to Settings → Privacy → Delete Contact Data. This immediately and permanently removes all stored hashes associated with your account. Deleting contact data does not affect your existing friends list, but friend discovery from contacts will not work until you sync again. This action is independent of the contact sync toggle — you can disable future syncing and separately delete previously stored hashes.
Account Deletion: You may delete your account at any time from the Settings screen in the app. Account deletion is permanent and immediate — there is no grace period or recovery window. When you delete your account:
- Your profile information (name, username, email, phone, bio, avatar) is permanently deleted
- Your event history, RSVPs, and activity data are removed
- Your friendships and friend requests are deleted
- Your contact hashes are deleted
- Your notification history is deleted
- Your team memberships are removed
- Your uploaded photos are deleted from storage
- Your interests and preferences are deleted
What may remain after deletion:
- Chat messages you sent in team conversations may remain visible to other team members, but will no longer be associated with your account
- If you referred other users, their referral records will be updated to remove your identity
- Some information may be retained in anonymized or aggregated form
- Data may be retained as required by law or for legitimate business purposes (such as resolving disputes)
7. Children's Privacy
SocialActivity is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information as quickly as possible. If you believe a child under 13 has provided us with personal information, please contact us at support@socialactivity.app.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (available directly in the App)
- Object to or restrict certain processing of your data
- Data portability
- Opt out of the sale of personal information (we do not sell your data)
California Residents (CCPA/CPRA): We do not sell or share your personal information for cross-context behavioral advertising. You have the right to know what personal information we collect, request its deletion, and not be discriminated against for exercising your rights. The categories of personal information we collect are described in Section 4 above.
To exercise any of these rights, please contact us at support@socialactivity.app.
9. International Data
Our service infrastructure (Supabase) may process and store data in the United States. By using the App, you consent to the transfer of your information to the United States and other jurisdictions where our service providers operate.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you through the App or via email.
We encourage you to review this Privacy Policy periodically for any changes.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Classy Event Group, LLC
Email: support@socialactivity.app