FestiGather legal

Privacy Policy

This Privacy Policy explains how FestiGather collects, uses, shares, protects, retains, and deletes personal information when you use the FestiGather mobile application, admin tools, backend services, and related support channels.

Last updated: June 9, 2026 Effective version: 2026-launch Privacy contact: [email protected]

1. Who we are

FestiGather is a festival travel and coordination application operated for the FestiGather service. The application helps users plan festival travel, use festival maps and schedules, manage checklists, communicate with other attendees, interact with vendors, submit feedback, and use community and safety features.

For privacy questions, account deletion requests, or data-rights requests, contact us at [email protected].

2. Scope of this policy

This policy applies to the FestiGather Android app, backend API at api.festi-travel.com, admin web tools, support and feedback features, and related services. It does not replace the privacy policies of third-party services that users choose to open outside FestiGather, such as Google, Clerk, map tile providers, app stores, payment providers, messaging apps, or external vendor websites.

FestiGather does not sell personal and sensitive user data.

3. Data we collect

We collect different data depending on which features you use. We aim to collect only what is needed to provide and protect the app.

Category Examples Purpose
Account and authentication data Email address, username, display name, avatar URL, OAuth provider identifiers, session records, role and permission data, accepted legal-document versions, IP address, user agent, and security audit records. To create and protect your account, authenticate you, maintain sessions, enforce permissions, and comply with safety and legal requirements.
Profile and Meet People data Profile photo, gender, preferred match gender, country, languages, festival attendance, arrival date, music preferences, bio, verification status, likes, passes, matches, blocks, reports, and visibility settings. To operate mutual opt-in discovery, festival-scoped matching, safety controls, and profile visibility.
Community, chat, and social data Posts, comments, likes, reports, chat threads, messages, group metadata, invitations, friend requests, read state, pinned state, and notification records. To deliver community, messaging, moderation, invitation, and notification features.
Festival planning data Trip planner data, ride-share offers and requests, marketplace listings, vendor profiles, checklist state, lineup favorites, reminders, saved map places, and festival preferences. To provide travel planning, marketplace, ride-share, checklist, lineup, and map functionality.
Uploaded media and support data Marketplace images, profile photos, community media, feedback messages, optional feedback screenshots, file metadata, moderation evidence, and admin notes. To display user-submitted content, review uploads, handle reports, provide support, and maintain platform safety.
Device, app, and diagnostic data App version, platform, route name where feedback was submitted, approximate request metadata, logs, crash or error context when available, and rate-limit/security metadata. To troubleshoot issues, prevent abuse, maintain service reliability, and improve app quality.
Location and map-related data On-device GPS location for map display, selected origins/destinations, structured places, map layer preferences, and user-selected places. To show the map, nearby festival places, route previews, travel planning, and map preferences. Precise GPS is intended to remain on-device unless you intentionally use a feature that shares it.

Local-only secure documents

Personal secure documents such as IDs, tickets, visas, insurance documents, and similar files are designed to remain local on your device. They should not be uploaded to FestiGather servers. Access to this feature uses device security such as biometric unlock or device passcode where available.

4. How we use data

  • Provide account login, session restoration, username onboarding, legal acceptance, and user preferences.
  • Operate festival maps, schedules, lineup reminders, checklists, trip planning, ride share, marketplace, vendor, badge, and retention features.
  • Enable chat, groups, friend requests, invitations, Meet People matching, notifications, and moderation.
  • Process reports, blocks, spam-prevention signals, rate limits, audit logs, and admin actions to protect users and the service.
  • Review support feedback, screenshots, bug reports, and operational health so we can fix issues and improve the app.
  • Comply with law, enforce terms, investigate abuse, respond to valid requests, and protect rights, safety, and security.

5. Sharing and service providers

We share personal data only as needed to operate, secure, moderate, and support the service, or when required by law. Depending on the feature, data may be processed by:

  • Authentication providers: Clerk and Google OAuth for sign-in and identity verification.
  • Infrastructure providers: hosting, database, storage, backup, and networking providers used to run FestiGather.
  • Email and communication providers: SMTP or email providers for invitations, notifications, support, or account-related messages.
  • Map and location providers: public map tile, geocoding, routing, or external map applications when you use map or route features.
  • Admins and moderators: authorized FestiGather personnel may review reports, feedback, marketplace submissions, uploaded images, and support data when needed.
  • Other users: public profile fields, usernames, posts, listing information, chat content, and matching information may be visible to other users only as needed for the feature you choose to use.
  • Legal recipients: authorities, courts, or other parties when legally required or necessary to protect rights, safety, and security.

We do not sell personal and sensitive user data. We do not expose Clerk secret keys, internal authentication identifiers, or internal database identifiers to public app surfaces.

6. Google sign-in and Clerk authentication

FestiGather uses Clerk to support OAuth sign-in flows such as Google sign-in. When you choose Google sign-in, Google and Clerk process the identity information required to authenticate you, such as your Google account email, account identity, display name, and profile image when provided by your Google account settings.

FestiGather uses this information to create or sync your FestiGather account, restore your session, protect your account, enforce roles and permissions, and support account deletion. We do not use Google sign-in data for advertising, and we do not sell it.

7. Device permissions

  • Location: used for map display, nearby places, navigation support, and travel planning when you enable it.
  • Camera and photos/files: used when you choose to upload profile photos, marketplace images, feedback screenshots, or other supported app media.
  • Notifications: used for in-app or device notifications where supported, such as messages, reminders, matches, invitations, and operational updates.
  • Biometric or device lock: used locally for secure document access when available.

You can manage app permissions in your device settings. Some features may not work if required permissions are disabled.

8. Security

We use security controls intended to protect personal and sensitive data, including HTTPS transport, server-side authentication and authorization, permission checks, secure file-upload validation, audit logs, rate limiting, backup monitoring, and restricted admin access. No internet service can guarantee perfect security, but we work to protect the service and respond to security issues.

9. Retention and deletion

We retain personal data for as long as needed to provide the app, maintain security, resolve disputes, comply with legal obligations, support moderation, and operate backups. Retention periods vary by data type and feature.

  • Account profile and authentication-link data is kept while your account is active.
  • User content such as posts, listings, messages, reports, and uploads may remain while needed for app functionality, moderation, safety, or legal reasons.
  • Security, audit, rate-limit, and abuse-prevention records may be retained after account deletion when needed to protect users and the platform.
  • Backups may retain deleted data for a limited period until backup cycles expire.

You can request account deletion in the app from Profile Settings, or from the public account deletion page: https://api.festi-travel.com/account-deletion. When an account is deleted, FestiGather revokes sessions and deletes or anonymizes personal profile data where required, while retaining limited records when necessary for security, fraud prevention, legal compliance, disputes, audit, or moderation.

10. Your choices and rights

  • Update profile information, preferences, and visibility settings in the app where available.
  • Disable device permissions through Android settings.
  • Delete content where the app provides deletion controls.
  • Block or report users and content when safety controls are available.
  • Request access, correction, deletion, restriction, or other privacy rights by emailing [email protected].

We may ask you to verify your identity before processing privacy requests.

11. Children

FestiGather is intended for festival attendees and travel coordination users. It is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us so we can review and delete it where appropriate.

12. International processing

FestiGather may process data in countries other than your country of residence, depending on where our infrastructure and service providers operate. We take steps intended to protect data consistently with this policy and applicable law.

13. Changes to this policy

We may update this Privacy Policy as the app, legal requirements, or service providers change. If changes are material, we may notify users in the app or require renewed acceptance where appropriate. The latest version will remain available at https://api.festi-travel.com/privacy-policy.

14. Contact

Privacy contact: [email protected]

Account deletion page: https://api.festi-travel.com/account-deletion