Privacy policy
Last updated:
ProSit lets somebody with a reserved Oktoberfest table offer spare seats to people they would like to sit with. To do that it needs to know a little about you, and it has to show some of it to other people. This page says exactly what, to whom, when, and for how long.
In short. No ads, no tracking, no analytics, no data sales. Your phone number is shown to one person only, and only after you and they both said yes. Other people see your public profile and whatever socials you choose to share. You can delete your account in the app at any time.
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) for the ProSit apps and this website is:
Netstrada s.r.l.Via Marche 43
60019 Senigallia (AN)
Italia / Italy
E-mail: hello@netstrada.it
PEC: nestrada@netpec.net
Write to that address for anything about your data. We have not appointed a data protection officer: we are not required to (Art. 37 GDPR), because our core activities consist neither of regular and systematic monitoring of people on a large scale nor of processing special categories of data on a large scale.
2. What we process, why, and on what legal basis
The legal bases below are the ones in Art. 6(1) GDPR: (b) the data is needed to provide the service you signed up for; (f) we have a legitimate interest, which we name, and it is not overridden by yours; (c) the law requires us to keep it.
Account and sign-in
You sign in with Apple or Google. The sign-in itself is handled by our authentication provider, Clerk. We receive a stable account identifier, your e-mail address and your name as Apple or Google pass them on. With Apple you can choose to hide your address; we then only see Apple’s relay address. We do not receive your Apple or Google password.
Why: to create and secure your account and to contact you about it. Basis: Art. 6(1)(b).
Your profile
- Display name and profile photo. Hosts choose who joins their table, so there has to be a person to choose.
- Birth year. We store the year and show other people only the resulting age. ProSit is for adults (see section 10).
- Languages you speak, and a short bio if you write one.
- Reliability figures shown on your profile: how many tables you met at, your average rating, the number of ratings, how often you cancelled an accepted seat and how often a table ended with you not showing up — as a guest or, since hosts can be absent too, as a host.
Why: a request or an offer is a decision about a person. Basis: Art. 6(1)(b).
Phone number
Before you can publish an offer or send a request you verify a mobile phone number. We send a six-digit code by SMS through our SMS provider; the code is stored only in hashed form and expires. We store your verified number (in international format) and when it was verified. A number can belong to only one ProSit account.
Why: a verified number is the basic protection against throwaway and fake accounts, and it is how the person you are matched with can reach you (see section 3). Basis: Art. 6(1)(b) for sharing it after a match; Art. 6(1)(f) for using it to prevent abuse — our legitimate interest is keeping fake hosts and fake guests off the platform.
Instagram handle
Optional. If you add an Instagram handle you also choose, with a switch, whether to share it. Only when the switch is on is the handle shown — to the host of a table you ask to join, and to the one person you are matched with. Sharing nothing is always allowed. Basis: Art. 6(1)(b).
Offers (if you host)
The tent, date and time, number of seats, the price per seat you paid, what a seat includes, your group’s size, age range, languages and vibe, a headline and a description, and the offer’s status. Offers are visible to every signed-in user. Basis: Art. 6(1)(b).
Requests (if you ask to join)
The offer you asked for, how many seats, your introduction message and, for each person you bring along, the name, age, languages and an optional note you enter. Please only enter details about friends who are happy for the host to see them. We also keep each request’s history (sent, opened, accepted, declined, met, and so on, with times) and, for hosts, an optional note when declining. Basis: Art. 6(1)(b).
Photos of friends you bring
Optional. When you ask for more than one seat you can add a photo of each friend coming with you. When you send the request you confirm that your friend agreed to be shown to that host. A friend’s photo is attached to that one request only and is seen by exactly two people: the host of that table and you. It never appears on any profile, in discovery or on another request.
It is deleted 3 days after the request ends (accepted and met, declined, expired, withdrawn or cancelled). A photo you uploaded but never sent is deleted after 24 hours. Deleting your account deletes them at once.
Why: a host deciding who joins their table is choosing a group, not only you. Basis: for you, Art. 6(1)(b) — it is part of the request you send; for your friend, Art. 6(1)(a) — their consent, which you confirm to us when you send it. Only add a friend’s photo if they have agreed to it, and please show them this section first.
If you are the friend: we have no way of reaching you, so this section is our information to you under Art. 14 GDPR. We received your photo, and the name, age, languages and note entered with it, from the guest who brought you; we use them only to show them to the host of that one table, and delete them as described above. You can withdraw your consent at any time, without giving a reason: ask the guest to withdraw the request, or write to hello@netstrada.it with the guest’s name and the table, and we delete your photo at once. Withdrawing does not affect what was shown before. You have all the rights in section 8.
Meeting at the table, and ratings
At the table the host can scan a QR code on the guest’s phone, or type a six-digit code, to confirm the meeting on the spot; it is generated from a secret, is valid for about a minute and contains no personal data. Scanning is optional — many real meetings won’t — so from the moment the table starts, either of you can instead say in the app that you met, or that the other one wasn’t there. We store who said what, and when. Agreement, or three days with no answer, settles it; a contradiction is stored too, as “disputed”, and settles nothing. A guest can say the host wasn’t there at most three times in 30 days, a limit we also store in order to enforce it. Only a request that settles as met — by scan, by agreement or by silence — opens rating: a rating is 1 to 5 stars with an optional comment, and is shown on the rated person’s profile. Basis: Art. 6(1)(b), and Art. 6(1)(f) — honest records of who showed up, whether from a scan or an unchallenged word, keep the platform trustworthy for everyone.
Reports and blocking
You can report an offer or a person. A report stores who reported, what, the reason and your description, and is read by a person at ProSit. We may suspend an account that breaks the terms. Basis: Art. 6(1)(f) — our legitimate interest, and yours, is safety and preventing fraud.
Brezn, clips and purchases
Three Brezn send one request. We store one row per Brezn you hold or held: where it came from (the welcome gift, your phone verification, a purchase, a Prosit, a Brezn code, or a correction by us), when it was given and when it expires, and what became of it — spent on which request, returned, expired or revoked.
Clips. For each clip you earn we store which milestone earned it (your account, a number of Prosits or a number of tables met), when you earned it, the text you write on it and when you wrote it, and the order you put your clips in. Your written clips are public (see section 3); a clip you have not written yet is seen by nobody but you. When you destroy a clip it is no longer shown to anybody; we keep a record that the milestone was earned, so it cannot be earned twice, until you delete your account. The text you wrote on it is erased at once.
Prosit connections. When you and another person connect by scanning a code, we store that the two of you are connected and when, and that the pair has already been rewarded — so it cannot be rewarded twice. The code itself is a short-lived signed token for your account; it carries no location and nothing about where you are. A Prosit is shown on both profiles until either of you removes it.
Brezn codes. If you redeem a Brezn code we store the code, your account and when — so the same code cannot be redeemed twice by you, and so we can enforce any total number of uses or end date the code carries. A code is handed out by us and is not personal data about anyone else.
Brezn are sold as in-app purchases through the App Store or Google Play. Apple or Google process the payment; we never see your card or bank details. We receive and store the product you bought, the store’s transaction id or purchase token, the platform and the time. When a store tells us a purchase was refunded, we record that and take its Brezn back; Brezn you had already spent are recorded as debt until it is worked off. Basis: Art. 6(1)(b); Art. 6(1)(f) to detect refund abuse. These records are deleted with your account.
Because Apple and Google are the sellers, the tax and accounting records of each sale are theirs. Our own accounting holds the stores’ sales and payout reports, which contain no name, e-mail address or phone number; like all our accounting records we keep them for 10 years, as Italian law requires (Art. 2220 of the Civil Code). Basis: Art. 6(1)(c).
Tents you follow, and push notifications
If you follow a tent we store that, to tell you when a table opens there. If you allow notifications we store your device’s push token, its platform (iOS or Android) and its language setting. Notifications are delivered by Apple (APNs) or Google (Firebase Cloud Messaging). They never contain a phone number or a social handle — only a short message and the ids the app needs to open the right screen. Basis: Art. 6(1)(b).
Server logs and backups
Our servers keep technical logs to run the service and to find faults and attacks. The application log records, per request, the method, path, response status, duration and a request id, but not your IP address; it is overwritten automatically once it reaches a fixed size. The web server in front of it records a standard access log that does include the IP address, time, requested address and the app’s user agent; it is deleted automatically after at most 14 days. IP addresses are also used briefly in memory to rate-limit requests. The database, and the photos still stored on our server, are backed up every night; backups are kept for at most 14 days and then deleted. Basis: Art. 6(1)(f) — our legitimate interest is a secure, working service.
This website
This website sets no cookies, loads no scripts, fonts or images from other companies and runs no analytics. If you pick a language with the language button, your browser remembers that choice locally; it is never sent to us. The site is served by our own server at Hetzner in Germany, which keeps no access log for it: your IP address is used only to deliver the page you asked for. The files themselves are stored with DigitalOcean in Frankfurt; our server fetches them from there and does not pass your IP address on, so DigitalOcean never receives it. Basis: Art. 6(1)(f) — our legitimate interest is delivering the website.
3. Who sees what, and when
Nobody sees your phone number before a mutual yes. Contact details are revealed to exactly one counterpart, and only for the table you were matched on.
| Moment | The host sees of the guest | The guest sees of the host |
|---|---|---|
| Browsing | — | Public profile. No contact details. |
| A request is sent | Public profile, the request and the socials the guest chose to share | — |
| The host accepts | Phone number and shared socials | Phone number and shared socials |
| Declined, expired, withdrawn, cancelled | Nothing more | Nothing |
- Public profile — visible to any signed-in ProSit user: display name, photo, age (not the birth year), languages, bio, reliability figures, recent ratings, the clips you have written (the three you chose first, and the whole collection) and how many clips you have, the people you have made a Prosit with, and when you joined. It never contains your phone number, e-mail address or social handles.
- One phone number per date. When a host accepts you, your other open requests for that date are withdrawn automatically, so at most one host per date ever sees your number.
- The reveal expires. The other person’s contact details stop being shown 24 hours after the table ends. The request stays in your history; the contact card on it does not. (Anything the other person wrote down or saved on their phone in the meantime is, of course, outside our control.)
- Friends’ photos you add to a request are seen only by the host of that request and by you, and are deleted 3 days after the request ends.
- Buying Brezn never unlocks anybody’s contact details.
- A host never sees how many other tables a guest asked, or where the guest is.
4. Service providers and other recipients
We use these providers. Those marked “processor” act only on our instructions and are bound by a data processing agreement under Art. 28 GDPR. The others decide themselves how they process data for their own service, under their own privacy policies.
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Hosting of our servers and database (processor) | Germany (Nuremberg) |
| DigitalOcean, LLC, USA | Storage of profile photos, friends’ photos and tent photos, and their delivery to the apps through DigitalOcean’s content delivery network, which processes your IP address to do so; storage of this website’s files (processor) | Germany (Frankfurt); the delivery network also has servers outside the EU |
| Clerk, Inc., USA | Sign-in and account authentication; receives your account identifier, e-mail address, name, and your device’s IP address and user agent when you sign in (processor) | USA |
| Twilio Inc., USA | Sending the SMS verification code to your phone number (processor) | USA, and the mobile networks delivering the SMS |
| Apple Inc. / Apple Distribution International Ltd., Ireland | Sign in with Apple, App Store purchases (Apple is the seller of the Brezn), push notifications (APNs) | EU / USA |
| Google LLC / Google Ireland Ltd. | Sign in with Google, Google Play purchases (Google is the seller of the Brezn), push notifications (Firebase Cloud Messaging), and on Android the ML Kit library that reads QR codes (see section 9) | EU / USA |
For in-app purchases Apple and Google act as merchant of record under their own privacy policies; they process your payment details, not us. Other ProSit users receive the data described in section 3. We disclose data to authorities only when the law obliges us to. We never sell personal data.
5. Transfers outside the EU
Our servers are in Germany. Clerk, Twilio, DigitalOcean, Apple and Google are, or belong to groups, based in the USA, and personal data can reach them there. Each of them — Clerk, Inc., Twilio Inc., DigitalOcean, LLC, Apple Inc. and Google LLC — is certified under the EU–US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR); the transfer relies on that decision. Should it cease to apply, the data processing agreements of our processors provide for the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR). You can check a company’s certification at dataprivacyframework.gov.
6. How long we keep data
| Data | Kept |
|---|---|
| Account, profile, phone number, Instagram handle | As long as your account exists |
| The other person’s contact details on a matched request | Shown until 24 hours after the table ends |
| Offers, requests and their history, follows, your Brezn and their history, your clips (including a record of destroyed ones), Prosit connections, your purchase records, push tokens | As long as your account exists; push tokens are removed earlier when the store reports them invalid |
| Photos of friends added to a request | Deleted 3 days after the request ends; if never sent, after 24 hours; at once if you delete your account |
| Phone verification codes | Hashed; valid for minutes; deleted with the account |
| Ratings you gave | Kept after you delete your account, without your name or any link to you |
| Reports | Reports you filed are deleted with your account. A report about you is kept until it has been handled and then for 12 months, so repeated problems can be recognised; after that it is deleted automatically |
| Stores’ sales and payout reports (no name or contact details) | 10 years, as Italian law requires for accounting records |
| Server access logs (with IP address) | At most 14 days |
| Application logs (without IP address) | Overwritten automatically once they reach a fixed size |
| Backups | At most 14 days |
7. Deleting your account
In the app: Profile → Delete account. It takes effect immediately. If you no longer have the app, see how to request deletion by e-mail, which also explains exactly what is deleted and what is not. Deleted data disappears from backups when they expire, at the latest after 14 days.
8. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR);
- have it corrected (Art. 16) — most of it you can edit yourself in the app;
- have it erased (Art. 17) — see section 7;
- restrict its processing (Art. 18);
- receive it in a portable format (Art. 20);
- object to processing based on legitimate interests, on grounds relating to your situation (Art. 21).
Write to hello@netstrada.it. We answer within one month.
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). As Netstrada s.r.l. is established in Italy, our lead supervisory authority is:
Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it
You may also complain to the supervisory authority of the EU country where you live or work, or where you believe the infringement took place.
9. No tracking, no ads, no analytics
The ProSit apps contain no advertising, no analytics or crash-reporting SDKs of our own and no tracking across apps or websites. The Android app includes two Google libraries: Firebase Cloud Messaging, for the sole purpose of delivering push notifications, and ML Kit, which reads QR codes on your phone — the camera picture never leaves the device. ML Kit sends Google technical diagnostics about itself (device and app information, performance and error codes; no pictures and nothing you entered), which Google uses for diagnostics and usage statistics of the library. We receive none of it. We do not build advertising profiles and we do not sell or rent personal data. Your contact details are never sent to analytics, push payloads or the app stores.
10. Age, required data, automated decisions, changes
- Age. ProSit is only for people aged 18 or over. Oktoberfest tents serve alcohol; the app does not accept a birth year under 18.
- Required data. You can browse without a phone number or a complete profile. To publish an offer or send a request you need a verified phone number, a profile photo, a display name, at least one language and a birth year. Without them we cannot provide those parts of the service.
- No automated decisions. Offers are sorted by a simple match (shared languages, age range, how soon); that is a sort order, not a decision about you. Whom to accept is always decided by a person.
- Changes. If this policy changes we update the date at the top, and tell you in the app when the change matters.