ARTICLE 1
Who is responsible?
Stuubs, a sole proprietorship established at Albert van der Meerstraat 15, 7555 LE Hengelo, the Netherlands, and registered with the Dutch Chamber of Commerce under number 96624469, is the controller for the personal data described in this Privacy Policy.
For questions, requests or complaints about privacy, please contact contact@stuubs.com.
ARTICLE 2
Who and what does this policy cover?
This Privacy Policy applies when you use the Stuubs app or website, create an Account, discover events, build a Journey, store Content or share it with Friends, tag other Users, report content or contact Stuubs.
Stuubs is intended for people aged 16 or older. Do not create an Account if you are younger than 16.
ARTICLE 3
Which personal data do we process?
Stuubs processes the following categories of personal data, together with their purpose, legal basis and retention period.
| Category | Examples | Purpose and legal basis | Retention |
|---|---|---|---|
| Account and profile data | Name or display name, username, email address, profile picture, account ID, login credential and confirmation that you are 16 years or older. | Create an account, sign in, display your profile and enforce the age limit. Necessary for the contract; proof and security also rely on legitimate interest and legal obligations. | For as long as the Account exists; afterwards, in principle, deleted or anonymised within 30 days. Proof of consent may be kept for up to 5 years after termination. |
| Journey and event data | Events you view, plan or add; line-up choices, segments, timings, moments attended, scores and your personal Journey. | Deliver the features you choose, show your Journey and improve the Service. Contract performance; product security and aggregated improvement on legitimate interest. | For as long as the Account exists and until you delete the data; after account deletion, in principle within 30 days, with temporary back-ups up to a maximum of 90 days. |
| Content you post | Texts, memories, reviews, photos, videos, tags, timestamps and technical file metadata attached to an upload. | Store, process and display Content to accepted Friends; handle abuse. Contract performance and legitimate interest in safety and moderation. | Until you delete the Content or the Account; afterwards in principle within 30 days, with temporary back-ups up to a maximum of 90 days. Reported Content may be kept slightly longer. |
| Friends, tags and social choices | Friend requests, accepted connections, tags, disconnections and blocks. | Enable private sharing with Friends, tagging and safety settings. Necessary for the contract; abuse prevention on legitimate interest. | For as long as the Account exists. Block and safety data may be kept up to 24 months after the last relevant interaction where necessary to prevent circumvention or abuse. |
| Reports and moderation data | Who or what was reported, reason, screenshots or explanation, timestamp, measure taken, appeal and technical context. The reporter's identity is not shared unnecessarily. | Assess illegal or harmful Content, protect Users, substantiate decisions and comply with legal obligations. Legitimate interest and legal obligation. | In principle up to 24 months after resolution; longer where an investigation, legal proceeding or legal obligation makes this necessary. |
| Technical and security data | IP address, device category, operating system, app or browser version, session and login timestamps, error messages, log data and security signals. | Make the Service function, secure it, resolve errors and prevent fraud or abuse. Legitimate interest and contract performance. | Technical logs in principle up to 12 months; data about a specific incident for as long as necessary for investigation or legal defence. |
| Contact data and correspondence | Email address, content of a question, complaint, privacy request or support conversation and our reply. | Handle questions and requests, exercise rights and keep evidence. Contract, legitimate interest and legal obligation. | In principle up to 2 years after handling; longer where a dispute or legal obligation requires this. |
Account and profile data
- Examples
- Name or display name, username, email address, profile picture, account ID, login credential and confirmation that you are 16 years or older.
- Purpose and legal basis
- Create an account, sign in, display your profile and enforce the age limit. Necessary for the contract; proof and security also rely on legitimate interest and legal obligations.
- Retention
- For as long as the Account exists; afterwards, in principle, deleted or anonymised within 30 days. Proof of consent may be kept for up to 5 years after termination.
Journey and event data
- Examples
- Events you view, plan or add; line-up choices, segments, timings, moments attended, scores and your personal Journey.
- Purpose and legal basis
- Deliver the features you choose, show your Journey and improve the Service. Contract performance; product security and aggregated improvement on legitimate interest.
- Retention
- For as long as the Account exists and until you delete the data; after account deletion, in principle within 30 days, with temporary back-ups up to a maximum of 90 days.
Content you post
- Examples
- Texts, memories, reviews, photos, videos, tags, timestamps and technical file metadata attached to an upload.
- Purpose and legal basis
- Store, process and display Content to accepted Friends; handle abuse. Contract performance and legitimate interest in safety and moderation.
- Retention
- Until you delete the Content or the Account; afterwards in principle within 30 days, with temporary back-ups up to a maximum of 90 days. Reported Content may be kept slightly longer.
Friends, tags and social choices
- Examples
- Friend requests, accepted connections, tags, disconnections and blocks.
- Purpose and legal basis
- Enable private sharing with Friends, tagging and safety settings. Necessary for the contract; abuse prevention on legitimate interest.
- Retention
- For as long as the Account exists. Block and safety data may be kept up to 24 months after the last relevant interaction where necessary to prevent circumvention or abuse.
Reports and moderation data
- Examples
- Who or what was reported, reason, screenshots or explanation, timestamp, measure taken, appeal and technical context. The reporter's identity is not shared unnecessarily.
- Purpose and legal basis
- Assess illegal or harmful Content, protect Users, substantiate decisions and comply with legal obligations. Legitimate interest and legal obligation.
- Retention
- In principle up to 24 months after resolution; longer where an investigation, legal proceeding or legal obligation makes this necessary.
Technical and security data
- Examples
- IP address, device category, operating system, app or browser version, session and login timestamps, error messages, log data and security signals.
- Purpose and legal basis
- Make the Service function, secure it, resolve errors and prevent fraud or abuse. Legitimate interest and contract performance.
- Retention
- Technical logs in principle up to 12 months; data about a specific incident for as long as necessary for investigation or legal defence.
Contact data and correspondence
- Examples
- Email address, content of a question, complaint, privacy request or support conversation and our reply.
- Purpose and legal basis
- Handle questions and requests, exercise rights and keep evidence. Contract, legitimate interest and legal obligation.
- Retention
- In principle up to 2 years after handling; longer where a dispute or legal obligation requires this.
ARTICLE 4
What Stuubs currently does not do
- Stuubs does not request access to GPS location and does not track your position at events.
- Stuubs does not send push notifications at this time and therefore does not process push tokens for that feature.
- Stuubs does not send newsletters or marketing emails. Email is only used when you initiate contact, for necessary account communication or for security and privacy requests.
- Stuubs does not process payments and currently does not sell photobooks, tickets, accommodation or packages through the Service.
- Stuubs does not use facial recognition, voice recognition or biometric identification.
- Stuubs does not use personal photos, videos, texts or other Content to train general or third-party AI models.
Your device may attach technical metadata to photos or videos, sometimes including location data. Stuubs does not use such metadata to track your location. Do not share files with metadata you do not want to share, and remove that metadata before uploading where needed.
ARTICLE 5
Where does personal data come from?
We receive most data directly from you when you create an Account, build a Journey, upload Content, tag someone, submit a report or contact us.
We may also receive data about you from other Users, for example when a Friend tags you or when you appear recognisably in a photo or video. Technical data is generated automatically through use of the App or website.
Event information may originate from public sources, organisers, artists, partners or Users. Such information is in principle not personal data about you.
ARTICLE 6
On which legal bases do we process data?
Stuubs only processes personal data where a valid legal basis exists:
- Contract performance: for the Account, the Journey, Content storage, friend connections, tags and the core features of the Service.
- Legitimate interest: for security, fraud prevention, moderation, support, legal protection and improvement based on aggregated or pseudonymised usage information. Stuubs weighs your interests and privacy rights.
- Consent: where a specific optional processing requires it, for example access to selected media through your device settings. You can withdraw consent via device settings or the indicated route.
- Legal obligation: where Stuubs must retain, disclose or use data to comply with a legal obligation or valid order.
If you do not provide necessary account data, Stuubs cannot offer the Account or the relevant feature.
ARTICLE 7
Photos, videos, tags and other people's data
7.1 When you upload Content in which other people are recognisable, Stuubs also processes personal data about those people. Only upload Content you may share respectfully and lawfully within your circle of friends.
7.2 Do not post confidential, medical, sexual, political, religious or other especially sensitive information about someone else without their explicit consent.
7.3 A tagged or depicted person may report Content or request untagging or removal through the App or via contact@stuubs.com. Stuubs assesses the request and may ask for information to verify identity, context and the rights involved.
7.4 Stuubs's legitimate interest is enabling a private memory service. That interest does not automatically outweigh the rights of a depicted or tagged person. Where an objection is well founded, Stuubs restricts or removes the processing concerned.
ARTICLE 8
Who can see your content?
8.1 Your Content is visible only to you and accepted Friends, plus strictly necessary personnel and service providers who operate, secure or support the Service.
8.2 A friend connection is mutual. You can decline a request, end a connection or block someone. After a block or unfriend, the affected Content within Stuubs is no longer visible to that User.
8.3 Friends may take copies or screenshots outside Stuubs. Stuubs cannot fully prevent that. Choose your friends and the Content you share carefully.
ARTICLE 9
Sharing with organisers and use of aggregated insights
Stuubs does not sell personal data. Stuubs does not provide personal Content, individual journeys or recognisable user profiles to event organisers for their own marketing without a separate legal basis and clear prior information.
Stuubs may create statistics that are genuinely anonymised and aggregated, for example to understand use of the Service or general event experience. Such information cannot reasonably be traced back to an individual User. Once data is truly anonymous, it is no longer personal data.
ARTICLE 10
Service providers and other recipients
Stuubs engages service providers who process personal data solely to deliver, secure and operate the Service. The main categories are:
| Recipient / category | Function | Role and note |
|---|---|---|
| Supabase, Inc. and underlying cloud infrastructure | Database, account authentication, storage of photos/videos and technical backend functions. | Processor for Stuubs. The project is intended to sit in a European hosting region; where access from outside the EEA occurs, appropriate transfer safeguards apply. |
| Website, domain and infrastructure providers | Hosting, security, network traffic, DNS, logs and availability of the website and App. | Processors insofar as they process data on behalf of Stuubs. |
| Apple and Google | Distribution of the App, device platform and any platform login you choose. | May act as independent controllers for their own platform services; their own privacy terms apply. |
| Email and support providers | Receiving and answering messages you send to Stuubs. | Processors for Stuubs or independent providers for their secured infrastructure, depending on the service. |
| Competent authorities and professional advisers | Compliance with valid legal requests, safety, investigations and legal protection. | Only where necessary and lawful. |
Supabase, Inc. and underlying cloud infrastructure
- Function
- Database, account authentication, storage of photos/videos and technical backend functions.
- Role and note
- Processor for Stuubs. The project is intended to sit in a European hosting region; where access from outside the EEA occurs, appropriate transfer safeguards apply.
Website, domain and infrastructure providers
- Function
- Hosting, security, network traffic, DNS, logs and availability of the website and App.
- Role and note
- Processors insofar as they process data on behalf of Stuubs.
Apple and Google
- Function
- Distribution of the App, device platform and any platform login you choose.
- Role and note
- May act as independent controllers for their own platform services; their own privacy terms apply.
Email and support providers
- Function
- Receiving and answering messages you send to Stuubs.
- Role and note
- Processors for Stuubs or independent providers for their secured infrastructure, depending on the service.
Competent authorities and professional advisers
- Function
- Compliance with valid legal requests, safety, investigations and legal protection.
- Role and note
- Only where necessary and lawful.
Stuubs makes arrangements with processors on confidentiality, security and use of personal data. Stuubs does not give service providers more data than necessary.
ARTICLE 11
Transfers outside the European Economic Area
Where possible, Stuubs opts for storage and processing within the European Economic Area (EEA). Some providers or support teams may access data from countries outside the EEA.
For transfers outside the EEA, Stuubs uses a legally recognised protection mechanism, such as an adequacy decision of the European Commission, the EU–US Data Privacy Framework for certified organisations or the European Commission's Standard Contractual Clauses, supplemented by appropriate security measures where needed.
You can request more information about the applicable safeguards via contact@stuubs.com.
ARTICLE 12
Retention and deletion
Stuubs does not keep personal data longer than necessary for the purposes for which it was collected. The main periods are set out in the table in Article 3.
When you delete Content, it is no longer shown to Friends and, in principle, removed or anonymised from active systems within 30 days. Copies in secure back-ups may remain for up to 90 days and are not actively reused during that period, except for recovery after an outage or where the law requires it.
When you delete your Account, Stuubs deletes or anonymises the associated personal data, except data still necessary for handling reports, security, evidence, legal obligations or an ongoing dispute.
ARTICLE 13
Security
Stuubs applies appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration and disclosure. These include, among other things, access restrictions, secured connections, authorisation based on user relationships, logging, updates, back-ups and arrangements with providers.
No digital service is entirely without risk. Use a strong, unique password where applicable and report any suspicion of abuse directly via contact@stuubs.com.
ARTICLE 14
Your privacy rights
Depending on the circumstances, you can exercise the following rights:
- access to your personal data and information about its use;
- correction of inaccurate or incomplete personal data;
- deletion of personal data;
- restriction of processing;
- objection to processing based on a legitimate interest;
- portability of data you have provided yourself, where the right to data portability applies;
- withdrawal of consent, without affecting the lawfulness of prior processing; and
- lodging a complaint with the Dutch Data Protection Authority.
Send a request to contact@stuubs.com. Stuubs may ask for additional information to prevent data being disclosed to the wrong person. Stuubs replies in principle within one month. For complex requests this period may be extended under the GDPR; you will be informed in time.
ARTICLE 15
Deleting your account
You can initiate deletion of your Account through the account settings in the App. If that route is temporarily unavailable, submit the request via contact@stuubs.com. Stuubs deletes the Account and the associated data that does not need to be retained for legal or safety reasons. Deactivation alone does not count as full deletion.
ARTICLE 16
Minors
Stuubs is not intended for children under 16. If Stuubs discovers that a person under 16 has created an Account without valid parental consent, Stuubs may restrict the Account and delete the personal data.
A parent or legal representative who suspects that Stuubs processes data of a child under 16 can contact us at contact@stuubs.com.
ARTICLE 17
Cookies, local storage and device permissions
The website and App may use necessary cookies, tokens or local storage to enable sign-in, security, language choice and basic functionality. Strictly necessary techniques do not require marketing consent.
Stuubs does not use non-essential tracking or marketing techniques without prior consent. If Stuubs later introduces analytics, marketing cookies, push notifications or new device permissions, Stuubs will inform you in advance and ask for consent where the law requires it.
When choosing photos or videos, the App only requests the permission the device platform requires. Stuubs receives the files you select and does not automatically obtain the right to use your entire photo library for other purposes.
ARTICLE 18
Automated decisions and AI
Stuubs does not take solely automated decisions that produce legal effects concerning you or similarly significantly affect you. Technical filters may flag Content or behaviour for safety and moderation, but material measures are reviewed by a person where appropriate.
Personal Content is not used to train general or third-party AI models. If Stuubs later introduces an optional AI feature that processes personal Content, it will separately explain in advance which data is required, for what purpose and on which legal basis.
ARTICLE 19
Complaints
For a privacy complaint, first contact contact@stuubs.com so Stuubs can investigate and resolve the issue.
You also have the right to lodge a complaint with the Dutch Data Protection Authority via www.autoriteitpersoonsgegevens.nl.
ARTICLE 20
Changes
Stuubs may update this Privacy Policy where the Service, providers or legal requirements change. Material changes will be announced clearly through the App or website before the effective date. Where a new processing requires consent, Stuubs will request it separately.
ARTICLE 21
Contact
Stuubs · Albert van der Meerstraat 15, 7555 LE Hengelo, the Netherlands · CoC 96624469 · contact@stuubs.com
Stuubs · Albert van der Meerstraat 15, 7555 LE Hengelo, the Netherlands
CoC 96624469 · contact@stuubs.com