Privacy policy

Last updated:

ProSit lets somebody with a reserved Oktoberfest table offer spare seats to people they would like to sit with. To do that it needs to know a little about you, and it has to show some of it to other people. This page says exactly what, to whom, when, and for how long.

In short. No ads, no tracking, no analytics, no data sales. Your phone number is shown to one person only, and only after you and they both said yes. Other people see your public profile and whatever socials you choose to share. You can delete your account in the app at any time.

1. Who is responsible

The controller under the General Data Protection Regulation (GDPR) for the ProSit apps and this website is:

Netstrada s.r.l.
Via Marche 43
60019 Senigallia (AN)
Italia / Italy
E-mail: hello@netstrada.it
PEC: nestrada@netpec.net

Write to that address for anything about your data. We have not appointed a data protection officer: we are not required to (Art. 37 GDPR), because our core activities consist neither of regular and systematic monitoring of people on a large scale nor of processing special categories of data on a large scale.

2. What we process, why, and on what legal basis

The legal bases below are the ones in Art. 6(1) GDPR: (b) the data is needed to provide the service you signed up for; (f) we have a legitimate interest, which we name, and it is not overridden by yours; (c) the law requires us to keep it.

Account and sign-in

You sign in with Apple or Google. The sign-in itself is handled by our authentication provider, Clerk. We receive a stable account identifier, your e-mail address and your name as Apple or Google pass them on. With Apple you can choose to hide your address; we then only see Apple’s relay address. We do not receive your Apple or Google password.

Why: to create and secure your account and to contact you about it. Basis: Art. 6(1)(b).

Your profile

Why: a request or an offer is a decision about a person. Basis: Art. 6(1)(b).

Phone number

Before you can publish an offer or send a request you verify a mobile phone number. We send a six-digit code by SMS through our SMS provider; the code is stored only in hashed form and expires. We store your verified number (in international format) and when it was verified. A number can belong to only one ProSit account.

Why: a verified number is the basic protection against throwaway and fake accounts, and it is how the person you are matched with can reach you (see section 3). Basis: Art. 6(1)(b) for sharing it after a match; Art. 6(1)(f) for using it to prevent abuse — our legitimate interest is keeping fake hosts and fake guests off the platform.

Instagram handle

Optional. If you add an Instagram handle you also choose, with a switch, whether to share it. Only when the switch is on is the handle shown — to the host of a table you ask to join, and to the one person you are matched with. Sharing nothing is always allowed. Basis: Art. 6(1)(b).

Offers (if you host)

The tent, date and time, number of seats, the price per seat you paid, what a seat includes, your group’s size, age range, languages and vibe, a headline and a description, and the offer’s status. Offers are visible to every signed-in user. Basis: Art. 6(1)(b).

Requests (if you ask to join)

The offer you asked for, how many seats, your introduction message and, for each person you bring along, the name, age, languages and an optional note you enter. Please only enter details about friends who are happy for the host to see them. We also keep each request’s history (sent, opened, accepted, declined, met, and so on, with times) and, for hosts, an optional note when declining. Basis: Art. 6(1)(b).

Photos of friends you bring

Optional. When you ask for more than one seat you can add a photo of each friend coming with you. When you send the request you confirm that your friend agreed to be shown to that host. A friend’s photo is attached to that one request only and is seen by exactly two people: the host of that table and you. It never appears on any profile, in discovery or on another request.

It is deleted 3 days after the request ends (accepted and met, declined, expired, withdrawn or cancelled). A photo you uploaded but never sent is deleted after 24 hours. Deleting your account deletes them at once.

Why: a host deciding who joins their table is choosing a group, not only you. Basis: for you, Art. 6(1)(b) — it is part of the request you send; for your friend, Art. 6(1)(a) — their consent, which you confirm to us when you send it. Only add a friend’s photo if they have agreed to it, and please show them this section first.

If you are the friend: we have no way of reaching you, so this section is our information to you under Art. 14 GDPR. We received your photo, and the name, age, languages and note entered with it, from the guest who brought you; we use them only to show them to the host of that one table, and delete them as described above. You can withdraw your consent at any time, without giving a reason: ask the guest to withdraw the request, or write to hello@netstrada.it with the guest’s name and the table, and we delete your photo at once. Withdrawing does not affect what was shown before. You have all the rights in section 8.

Meeting at the table, and ratings

At the table the host can scan a QR code on the guest’s phone, or type a six-digit code, to confirm the meeting on the spot; it is generated from a secret, is valid for about a minute and contains no personal data. Scanning is optional — many real meetings won’t — so from the moment the table starts, either of you can instead say in the app that you met, or that the other one wasn’t there. We store who said what, and when. Agreement, or three days with no answer, settles it; a contradiction is stored too, as “disputed”, and settles nothing. A guest can say the host wasn’t there at most three times in 30 days, a limit we also store in order to enforce it. Only a request that settles as met — by scan, by agreement or by silence — opens rating: a rating is 1 to 5 stars with an optional comment, and is shown on the rated person’s profile. Basis: Art. 6(1)(b), and Art. 6(1)(f) — honest records of who showed up, whether from a scan or an unchallenged word, keep the platform trustworthy for everyone.

Reports and blocking

You can report an offer or a person. A report stores who reported, what, the reason and your description, and is read by a person at ProSit. We may suspend an account that breaks the terms. Basis: Art. 6(1)(f) — our legitimate interest, and yours, is safety and preventing fraud.

Brezn, clips and purchases

Three Brezn send one request. We store one row per Brezn you hold or held: where it came from (the welcome gift, your phone verification, a purchase, a Prosit, a Brezn code, or a correction by us), when it was given and when it expires, and what became of it — spent on which request, returned, expired or revoked.

Clips. For each clip you earn we store which milestone earned it (your account, a number of Prosits or a number of tables met), when you earned it, the text you write on it and when you wrote it, and the order you put your clips in. Your written clips are public (see section 3); a clip you have not written yet is seen by nobody but you. When you destroy a clip it is no longer shown to anybody; we keep a record that the milestone was earned, so it cannot be earned twice, until you delete your account. The text you wrote on it is erased at once.

Prosit connections. When you and another person connect by scanning a code, we store that the two of you are connected and when, and that the pair has already been rewarded — so it cannot be rewarded twice. The code itself is a short-lived signed token for your account; it carries no location and nothing about where you are. A Prosit is shown on both profiles until either of you removes it.

Brezn codes. If you redeem a Brezn code we store the code, your account and when — so the same code cannot be redeemed twice by you, and so we can enforce any total number of uses or end date the code carries. A code is handed out by us and is not personal data about anyone else.

Brezn are sold as in-app purchases through the App Store or Google Play. Apple or Google process the payment; we never see your card or bank details. We receive and store the product you bought, the store’s transaction id or purchase token, the platform and the time. When a store tells us a purchase was refunded, we record that and take its Brezn back; Brezn you had already spent are recorded as debt until it is worked off. Basis: Art. 6(1)(b); Art. 6(1)(f) to detect refund abuse. These records are deleted with your account.

Because Apple and Google are the sellers, the tax and accounting records of each sale are theirs. Our own accounting holds the stores’ sales and payout reports, which contain no name, e-mail address or phone number; like all our accounting records we keep them for 10 years, as Italian law requires (Art. 2220 of the Civil Code). Basis: Art. 6(1)(c).

Tents you follow, and push notifications

If you follow a tent we store that, to tell you when a table opens there. If you allow notifications we store your device’s push token, its platform (iOS or Android) and its language setting. Notifications are delivered by Apple (APNs) or Google (Firebase Cloud Messaging). They never contain a phone number or a social handle — only a short message and the ids the app needs to open the right screen. Basis: Art. 6(1)(b).

Server logs and backups

Our servers keep technical logs to run the service and to find faults and attacks. The application log records, per request, the method, path, response status, duration and a request id, but not your IP address; it is overwritten automatically once it reaches a fixed size. The web server in front of it records a standard access log that does include the IP address, time, requested address and the app’s user agent; it is deleted automatically after at most 14 days. IP addresses are also used briefly in memory to rate-limit requests. The database, and the photos still stored on our server, are backed up every night; backups are kept for at most 14 days and then deleted. Basis: Art. 6(1)(f) — our legitimate interest is a secure, working service.

This website

This website sets no cookies, loads no scripts, fonts or images from other companies and runs no analytics. If you pick a language with the language button, your browser remembers that choice locally; it is never sent to us. The site is served by our own server at Hetzner in Germany, which keeps no access log for it: your IP address is used only to deliver the page you asked for. The files themselves are stored with DigitalOcean in Frankfurt; our server fetches them from there and does not pass your IP address on, so DigitalOcean never receives it. Basis: Art. 6(1)(f) — our legitimate interest is delivering the website.

3. Who sees what, and when

Nobody sees your phone number before a mutual yes. Contact details are revealed to exactly one counterpart, and only for the table you were matched on.

What other people see of you
MomentThe host sees of the guestThe guest sees of the host
Browsing—Public profile. No contact details.
A request is sentPublic profile, the request and the socials the guest chose to share—
The host acceptsPhone number and shared socialsPhone number and shared socials
Declined, expired, withdrawn, cancelledNothing moreNothing

4. Service providers and other recipients

We use these providers. Those marked “processor” act only on our instructions and are bound by a data processing agreement under Art. 28 GDPR. The others decide themselves how they process data for their own service, under their own privacy policies.

ProviderWhat forWhere
Hetzner Online GmbH, Gunzenhausen, GermanyHosting of our servers and database (processor)Germany (Nuremberg)
DigitalOcean, LLC, USAStorage of profile photos, friends’ photos and tent photos, and their delivery to the apps through DigitalOcean’s content delivery network, which processes your IP address to do so; storage of this website’s files (processor)Germany (Frankfurt); the delivery network also has servers outside the EU
Clerk, Inc., USASign-in and account authentication; receives your account identifier, e-mail address, name, and your device’s IP address and user agent when you sign in (processor)USA
Twilio Inc., USASending the SMS verification code to your phone number (processor)USA, and the mobile networks delivering the SMS
Apple Inc. / Apple Distribution International Ltd., IrelandSign in with Apple, App Store purchases (Apple is the seller of the Brezn), push notifications (APNs)EU / USA
Google LLC / Google Ireland Ltd.Sign in with Google, Google Play purchases (Google is the seller of the Brezn), push notifications (Firebase Cloud Messaging), and on Android the ML Kit library that reads QR codes (see section 9)EU / USA

For in-app purchases Apple and Google act as merchant of record under their own privacy policies; they process your payment details, not us. Other ProSit users receive the data described in section 3. We disclose data to authorities only when the law obliges us to. We never sell personal data.

5. Transfers outside the EU

Our servers are in Germany. Clerk, Twilio, DigitalOcean, Apple and Google are, or belong to groups, based in the USA, and personal data can reach them there. Each of them — Clerk, Inc., Twilio Inc., DigitalOcean, LLC, Apple Inc. and Google LLC — is certified under the EU–US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR); the transfer relies on that decision. Should it cease to apply, the data processing agreements of our processors provide for the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR). You can check a company’s certification at dataprivacyframework.gov.

6. How long we keep data

DataKept
Account, profile, phone number, Instagram handleAs long as your account exists
The other person’s contact details on a matched requestShown until 24 hours after the table ends
Offers, requests and their history, follows, your Brezn and their history, your clips (including a record of destroyed ones), Prosit connections, your purchase records, push tokensAs long as your account exists; push tokens are removed earlier when the store reports them invalid
Photos of friends added to a requestDeleted 3 days after the request ends; if never sent, after 24 hours; at once if you delete your account
Phone verification codesHashed; valid for minutes; deleted with the account
Ratings you gaveKept after you delete your account, without your name or any link to you
ReportsReports you filed are deleted with your account. A report about you is kept until it has been handled and then for 12 months, so repeated problems can be recognised; after that it is deleted automatically
Stores’ sales and payout reports (no name or contact details)10 years, as Italian law requires for accounting records
Server access logs (with IP address)At most 14 days
Application logs (without IP address)Overwritten automatically once they reach a fixed size
BackupsAt most 14 days

7. Deleting your account

In the app: Profile → Delete account. It takes effect immediately. If you no longer have the app, see how to request deletion by e-mail, which also explains exactly what is deleted and what is not. Deleted data disappears from backups when they expire, at the latest after 14 days.

8. Your rights

You have the right to:

Write to hello@netstrada.it. We answer within one month.

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). As Netstrada s.r.l. is established in Italy, our lead supervisory authority is:

Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it

You may also complain to the supervisory authority of the EU country where you live or work, or where you believe the infringement took place.

9. No tracking, no ads, no analytics

The ProSit apps contain no advertising, no analytics or crash-reporting SDKs of our own and no tracking across apps or websites. The Android app includes two Google libraries: Firebase Cloud Messaging, for the sole purpose of delivering push notifications, and ML Kit, which reads QR codes on your phone — the camera picture never leaves the device. ML Kit sends Google technical diagnostics about itself (device and app information, performance and error codes; no pictures and nothing you entered), which Google uses for diagnostics and usage statistics of the library. We receive none of it. We do not build advertising profiles and we do not sell or rent personal data. Your contact details are never sent to analytics, push payloads or the app stores.

10. Age, required data, automated decisions, changes